Encryption round number determination method and device and storage medium

By dynamically determining the number of encryption rounds and key-driven permutation operations, the problem of insufficient security of existing AES encryption methods under quantum computing attacks is solved, and the encryption strength and security are improved.

CN120729508APending Publication Date: 2025-09-30SHENZHEN ZHUXIN NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510915961.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-03
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

Existing encryption methods based on the AES symmetric encryption algorithm are not secure enough when facing attack methods with powerful parallel computing capabilities such as quantum computing.

Method used

The offset is obtained by taking the first byte of the target key and taking the modulus from the preset modulus. The number of encryption rounds is dynamically determined based on the number of key words and the Shannon entropy of the plaintext. The encryption strength is improved through dynamically changing key-driven permutation, cyclic shift and XOR operations.

Benefits of technology

The dynamic change of the number of encryption rounds is achieved, which enhances the protection of important plaintext information, improves encryption security, and increases the cost and complexity of cracking for attackers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729508A_ABST
    Figure CN120729508A_ABST
Patent Text Reader

Abstract

The invention discloses an encryption round number determination method and device and a storage medium, and relates to the technical field of information security. The method comprises the following steps: firstly, obtaining a target key, and carrying out modulus operation on a first byte of the target key and a preset modulus to obtain an offset; then, the key word number of the target key is determined, and the reference number of rounds of encryption is determined according to the sum of the key word number and the offset; and determining the additional round number of encryption according to the Shannon entropy of the plaintext, and determining the encryption round number according to the sum of the reference round number and the additional round number. According to the method, the number of encryption rounds dynamically changes along with the characteristics of the target key, and the additional number of encryption rounds is determined according to the Shannon entropy of the plaintext, so that the important plaintext information is further encrypted, and the encryption security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a method, device, and storage medium for determining the number of encryption rounds. Background Art

[0002] Current encryption methods based on the AES symmetric encryption algorithm typically use a fixed number of rounds to encrypt plaintext, such as 10, 12, and 14 rounds for 128-, 192-, and 256-bit keys, respectively. However, these fixed-round encryption methods are insecure against new attack methods with powerful parallel computing capabilities, such as quantum computing.

[0003] The above content is only used to assist in understanding the technical solution of this application and does not constitute an admission that the above content is prior art. Summary of the Invention

[0004] The main purpose of this application is to provide a method, device and storage medium for determining the number of encryption rounds, aiming to solve the technical problem of how to improve encryption security.

[0005] To achieve the above objectives, the present application proposes a method for determining the number of encryption rounds, which includes: Obtain a target key, and take the first byte of the target key modulo a preset modulus to obtain an offset; Determining the number of key words of the target key, and determining a reference number of encryption rounds according to the sum of the number of key words and the offset; The number of additional rounds of encryption is determined according to the Shannon entropy of the plaintext, and the number of encryption rounds is determined according to the sum of the reference number of rounds and the additional number of rounds.

[0006] In one embodiment, after the steps of determining the additional number of encryption rounds based on the Shannon entropy of the plaintext and determining the number of encryption rounds based on the sum of the base number of rounds and the additional number of rounds, the method further includes: In the Nth round of encryption, obtaining the round key corresponding to the current round and the index value of each plaintext byte in the plaintext; Determining a first round key byte of each plaintext byte in the round key according to a modulus value of an index value of each plaintext byte and a length of the round key; Determining a replacement step length for each of the plaintext bytes according to the first-round key bytes, and determining a target replacement byte for each of the plaintext bytes in the plaintext according to the replacement step length; Each of the plaintext bytes is replaced with the target replacement byte to obtain the first ciphertext of the Nth round of encryption.

[0007] In one embodiment, after the step of replacing each of the plaintext bytes with the target replacement bytes to obtain the first ciphertext of the Nth round of encryption, the method further includes: Dividing the first ciphertext into at least one ciphertext group according to a preset number of bytes; determining, in the round key, a second round key byte for each first ciphertext byte in the ciphertext block according to a modulo value of an index value of each first ciphertext byte in the ciphertext block and a length of the ciphertext block; determining a first cyclic shift amount for each of the first ciphertext bytes according to the second-round key bytes, and performing a cyclic shift on each of the first ciphertext bytes in each of the ciphertext groups according to the first cyclic shift amount; Perform S-box replacement on each of the first ciphertext bytes after cyclic shift to obtain a second ciphertext encrypted in the Nth round.

[0008] In one embodiment, after the step of performing S-box replacement on each of the cyclically shifted first ciphertext bytes to obtain the second ciphertext encrypted in the Nth round, the method further includes: cyclically shifting each second ciphertext byte in the second ciphertext according to a preset second cyclic shift amount; Determining a third round key byte for each second ciphertext byte in the round key according to a modulus value of an index value of each second ciphertext byte after cyclic shift and a length of the round key; XOR each of the third-round key bytes with a round constant to obtain an encryption mask for each of the second ciphertext bytes; Each of the second ciphertext bytes is XORed with the encryption mask to obtain a third ciphertext of the Nth round of encryption.

[0009] In one embodiment, after the step of performing an XOR operation on each of the second ciphertext bytes and the encryption mask to obtain the third ciphertext of the Nth round of encryption, the method further includes: Dividing the third ciphertext into a first ciphertext block and a second ciphertext block according to the number of bytes of the third ciphertext; determining, in the first ciphertext block, a target XOR byte for each of the second block bytes according to a modulo value of an index value of each second block byte in the second ciphertext block and a length of the first ciphertext block; determining, in the round key, a fourth round key byte of each of the second block bytes according to an index value of each of the second block bytes in the third ciphertext and a modulo value of the length of the round key; XORing each of the second block bytes with the target XOR byte, and then adding the resultant to the fourth round key byte to obtain a new second ciphertext block; The first block of bytes in the first ciphertext block is placed at an even index, and the second block of bytes in the new second ciphertext block is placed at an odd index, and the bytes are combined to obtain a fourth ciphertext of the Nth round of encryption.

[0010] In one embodiment, the step of placing the first block of bytes in the first ciphertext block at an even index, placing the second block of bytes in the new second ciphertext block at an odd index, and merging them to obtain the fourth ciphertext of the Nth round of encryption includes: Creating a target ciphertext array, and determining an index value to be written to each fourth ciphertext byte in the target ciphertext array; determining a fifth round key byte for each fourth ciphertext byte in the round key according to a modulo value of the to-be-written index value and the length of the round key; XORing each of the fifth round key bytes with the round constant to obtain a delay byte of each of the fourth ciphertext bytes; Each of the fourth ciphertext bytes and the delay byte is written into the target ciphertext array to obtain the target ciphertext of the Nth round of encryption.

[0011] In one embodiment, after the step of performing XOR operation on each of the fifth round key bytes and the round constant to obtain the delayed byte of each of the fourth ciphertext bytes, the method further includes: Using the index value of the fourth ciphertext byte in the fourth ciphertext as the position byte; After writing each of the fourth ciphertext bytes, the delay byte, and the position byte into the target ciphertext array, the length of the fourth ciphertext is written into the target ciphertext array to obtain the target ciphertext of the Nth round of encryption.

[0012] In one embodiment, after the step of writing the length of the fourth ciphertext into the target ciphertext array to obtain the target ciphertext for the Nth round of encryption, the method further includes: determining a round constant expansion factor in the target key according to the current round number; After performing S-box replacement on the sum of the round constant expansion factor and the round constant, the sum is XORed with the round constant to obtain the round constant for the N+1th round of encryption.

[0013] In addition, to achieve the above-mentioned purpose, the present application also proposes a device for determining the number of encryption rounds, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the computer program is configured to implement the steps of the method for determining the number of encryption rounds as described above.

[0014] In addition, to achieve the above-mentioned purpose, the present application also proposes a storage medium, which is a computer-readable storage medium and stores a computer program. When the computer program is executed by a processor, the steps of the method for determining the number of encryption rounds as described above are implemented.

[0015] This application provides a method for determining the number of encryption rounds. The method first obtains a target key and takes the first byte of the target key modulo a preset modulus to obtain an offset. The method then determines the number of key characters in the target key and determines the baseline number of encryption rounds based on the sum of the key character count and the offset. The method also determines the number of additional encryption rounds based on the Shannon entropy of the plaintext, and the number of encryption rounds based on the sum of the baseline number and the additional number of rounds. This method dynamically changes the number of encryption rounds based on the characteristics of the target key and determines the number of additional encryption rounds based on the Shannon entropy of the plaintext, further protecting important plaintext information and improving encryption security. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0018] Figure 1 A flowchart illustrating a method for determining the number of encryption rounds according to the first embodiment of the present invention; Figure 2 A flowchart illustrating a second embodiment of the method for determining the number of encryption rounds of this application is provided; Figure 3 A flowchart illustrating a method for determining the number of encryption rounds according to a third embodiment of the present invention is provided; Figure 4 A flowchart illustrating a fourth embodiment of the method for determining the number of encryption rounds of the present application is provided; Figure 5 A flowchart illustrating a fifth embodiment of the method for determining the number of encryption rounds of the present application is provided; Figure 6 Flowcharts showing the sixth and seventh embodiments of the method for determining the number of encryption rounds of this application; Figure 7 Schematic diagram of the device structure of the hardware operating environment involved in the method for determining the number of encryption rounds in an embodiment of the present application.

[0019] The purpose, features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0020] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not intended to limit the present application.

[0021] In order to better understand the technical solution of this application, the following will be described in detail with reference to the accompanying drawings and specific implementation methods. It should be noted that all actions of obtaining signals, information or data in this application are carried out in compliance with the relevant data protection laws and policies of the country where they are located and with the authorization of the owner of the corresponding device.

[0022] Current encryption methods based on the Advanced Encryption Standard (AES) symmetric encryption algorithm typically use a fixed number of rounds to encrypt plaintext, such as 10, 12, and 14 rounds for 128-, 192-, and 256-bit keys, respectively. However, these fixed-round encryption methods lack security against new attack methods with powerful parallel computing capabilities, such as quantum computing.

[0023] In response to the above issues, this application proposes a method for determining the number of encryption rounds. The method first obtains the target key and takes the first byte of the target key modulo a preset modulus to obtain an offset. The target key's key word count is then determined, and the baseline number of encryption rounds is determined based on the sum of the key word count and the offset. The number of additional encryption rounds is determined based on the Shannon entropy of the plaintext, and the number of encryption rounds is determined based on the sum of the baseline number and the additional number of rounds. This method allows the number of encryption rounds to dynamically change with the characteristics of the target key and determines the number of additional encryption rounds based on the Shannon entropy of the plaintext, further protecting important plaintext information and improving encryption security.

[0024] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication and program running functions, such as a tablet computer, personal computer, mobile phone, etc., or an electronic device that can realize the above functions, AES encryption system, etc.

[0025] Based on this, the first embodiment proposed in this application provides a method for determining the number of encryption rounds, referring to Figure 1 In this embodiment, the method for determining the number of encryption rounds includes steps S10 to S30: Step S10: Obtain a target key, and perform a modulus operation on the first byte of the target key and a preset modulus to obtain an offset.

[0026] It should be noted that the target key refers to the original encryption master key, or the initial key in the AES encryption system, and can be 128, 192, or 256 bits long. The offset is calculated by taking the first byte of the target key and applying a preset modulus, such as 3. The modulus can be a power of 2, such as 2 or 4, using the AND instruction for fast bitwise calculation. Alternatively, it can be a non-power of 2, using the DIV instruction for division.

[0027] Step S20: determining the number of key words of the target key, and determining a reference number of encryption rounds according to the sum of the number of key words and the offset.

[0028] First, determine the total byte length of the target key. Then, group the target key into 4-byte groups to determine the target key's key word count. For example, if the target key is 128-bit and its total byte length is 16, then the key word count is 16 / 4 = 4. Then, determine the base number of encryption rounds based on the sum of the target key's key word count and the offset.

[0029] Step S30: determining the number of additional encryption rounds according to the Shannon entropy of the plaintext, and determining the number of encryption rounds according to the sum of the reference number of rounds and the additional number of rounds.

[0030] It should be noted that Shannon Entropy is an indicator used in information theory to measure information uncertainty, reflecting the randomness or degree of chaos of data. For a piece of plaintext data, the calculation formula for its Shannon Entropy is: . Among them, X represents all the symbols in the plaintext data, It is a symbol The probability of appearing in plaintext, n is the total number of plaintext symbols.

[0031] Understandably, data with high Shannon entropy, such as encryption keys and financial data, is generally more sensitive and requires stronger protection, while data with low Shannon entropy, such as duplicate logs, is less sensitive. Therefore, plaintext with high Shannon entropy may conceal more structural information, requiring additional obfuscation rounds to disrupt statistical features.

[0032] Optionally, a linear relationship between the Shannon entropy of the plaintext and the increment of the number of rounds is set to determine the additional number of encryption rounds, and then the additional number of encryption rounds is added to the base number of rounds to obtain the total number of encryption rounds.

[0033] For example, assuming there is a 128-bit or 16-byte target key masterKey[0x3B, 0x7E, 0x15, 0x16, 0x28, 0xAE, 0xD2, 0xA6, 0xAB, 0xF7, 0x15, 0x88, 0x09, 0xCF, 0x4F, 0x3C], take the first byte of the target key masterKey[0]: 0x3B and the preset modulus 3 to obtain the offset offset=0x3B%3=2. Then, determine the number of key words of the target key nk=4, and determine the base number of encryption rounds baseRounds=nk+r1+offset=13 rounds based on the sum of the number of key words and the offset. Where r1 represents the basic number of rounds, such as 7, which can be customized by the user. For example, in the conventional AES standard, the fixed round number calculation formula is round number=nk+6, where 6 is the basic round number. Next, assuming the Shannon entropy calculated for the plaintext is 4.5 and the linear coefficient is set to 0.3, the extra rounds are obtained after multiplication and rounding: extraRounds=4.5 0.3 1. Finally, the number of encryption rounds is determined to be 14.

[0034] In this embodiment, by taking the modulo offset of the first byte of the target key, the number of encryption rounds is dynamically adjusted based on the characteristics of the target key, changing the attack complexity from a fixed target to a moving target. While traditional fixed-round methods only require cracking a fixed number of rounds, this approach, using a 128-bit key as an example, requires an attacker to cover 11-13 rounds, resulting in a higher cracking cost. Furthermore, the number of additional encryption rounds is determined based on the Shannon entropy of the plaintext, further protecting important plaintext information and enhancing encryption security.

[0035] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar contents as those in the above embodiment 1 can be referred to the above introduction and will not be described in detail later. Figure 2 After step S30, the method for determining the number of encryption rounds further includes steps S40 to S70: Step S40: in the Nth round of encryption, obtain the round key corresponding to the current round and the index value of each plaintext byte in the plaintext.

[0036] For example, when the encryption process enters the Nth round, the current round key is loaded from the key expansion buffer, where N Number of encryption rounds. It should be noted that the round key is generated from the target key through the key expansion algorithm, and each round of encryption uses a different round key.

[0037] Specifically, in AES, regardless of whether the target key length is 128, 192, or 256 bits, the target key is first split into "words" of 4 bytes. Taking a 128-bit target key as an example, the target key length is 16 bytes and is split into 4 words: W[0], W[1], W[2], and W[3]. Each word contains 4 bytes, for example: W[0] = [K0, K1, K2, K3]. Among them, W[0] to W[3] are the seed keys for key expansion, which are used to generate all round keys in the subsequent encryption process. For example, assuming a 128-bit target key, 44 words (W[0] to W

[43] ) are generated as round keys, of which W[0] to W[3] are the seed keys, and the remaining 40 round keys are expanded. That is, the round keys used for the rth round of encryption are composed of W[4r] to W[4r+3], where r = 0 to 10.

[0038] The generation of round keys follows an iterative rule, and the key expansion algorithm formula can be expressed as: W[i]=W[i-nk]⊕f(W[i-1]). ⊕ represents an XOR operation, and "f()" is a transformation function. Depending on whether the index i is divisible by nk, there are two processing methods: if i is a multiple of nk, f(W[i-1])=S-box replacement (circular left shift (W[i-1]))⊕round constant. If i is not a multiple of nk, f(W[i-1])=W[i-1]. For example, the initial key W[0]~W[3] is directly used as the first four words, W[4]=W[0]⊕f(W[3]), where f(W[3]) needs to undergo a circular left shift, S-box replacement, and round constant XOR. The S-box is the only nonlinear component in AES. It is a predefined, immutable nonlinear substitution table in AES and is responsible for byte substitution.

[0039] Step S50: determining the first round key byte of each plaintext byte in the round key according to the modulus of the index value of each plaintext byte and the length of the round key.

[0040] For example, for each plaintext byte P0[j], first calculate its corresponding round key index key_index1 = j % key_length, where key_length is the length of the round key round_key corresponding to round N. Then, based on the round key index key_index1, extract the first round key byte key_byte1 = round_key[key_index1] from the round key.

[0041] Step S60: determining a replacement step length for each of the plaintext bytes according to the first-round key bytes, and determining a target replacement byte for each of the plaintext bytes in the plaintext according to the replacement step length.

[0042] For example, after extracting the first round key byte key_byte1 from the current round's round key according to round key index key_index1, it is mapped to an integer range as the permutation step for the plaintext byte P0[j]. For example, the permutation step can be calculated as: step = (key_byte1 % r2) + 1, mapping the first round key byte to an integer range of 1 - r2. If the first round key byte is 0xAB (decimal 171) and r2 = 7, then the permutation step is step = 171 % 7 + 1 = 4. Next, the target permutation byte P0[j+step] for the plaintext byte P0[j] is determined.

[0043] Step S70: Replace each of the plaintext bytes with the target replacement bytes to obtain the first ciphertext of the Nth round of encryption.

[0044] Traditional AES permutation operations like ShiftRows are fixed, meaning the number of bytes shifted per row is pre-set. For example, the first row is not shifted, while the second row is shifted by 1 byte. In this embodiment, the permutation step size is dynamically calculated based on the round key bytes. Because each byte has a different round key index, the round key bytes retrieved are also different, meaning the permutation step size for each plaintext byte can vary. This dynamic nature allows the same plaintext to have completely different permutation paths under different keys, making it more difficult for attackers to analyze ciphertext patterns and thus enhancing encryption security.

[0045] Based on the above embodiments of the present application, in the third embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 3 After step S70, the method for determining the number of encryption rounds further includes steps S80 to S110: Step S80: Divide the first ciphertext into at least one ciphertext group according to a preset number of bytes.

[0046] For example, assuming the preset number of bytes is 4, the first ciphertext P1 is divided into at least one ciphertext group C with 4 bytes as a group. At the same time, a group pointer k is created for each ciphertext group C to point to the index value of each first ciphertext byte in the ciphertext group.

[0047] Step S90: determining a second round key byte for each first ciphertext byte in the round key according to the modulo value of the index value of each first ciphertext byte in the ciphertext block and the length of the ciphertext block.

[0048] For example, for each first ciphertext byte C[k] in the ciphertext block, its corresponding round key index key_index2 = k % key_length is calculated. Then, based on the round key index key_index2, the second round key byte key_byte2 = round_key[key_index2] is retrieved from the round key.

[0049] Step S100: determining a first cyclic shift of each of the first ciphertext bytes according to the second-round key bytes, and cyclically shifting each of the first ciphertext bytes in each of the ciphertext groups according to the first cyclic shift.

[0050] Exemplarily, after extracting the second round key byte key_byte2 from the round key round_key of the current round according to the round key index key_index2, it is mapped to an integer range as the first cyclic shift of the first ciphertext byte C[k]. For example, the calculation formula of the first cyclic shift can be expressed as: shift1=(key_byte2 % len)+1, where len represents the length of the ciphertext block in which the first ciphertext byte C[k] is located. The first ciphertext byte C[k] is then cyclically shifted right by shift1 positions within the ciphertext block in which it is located. For example, assuming there is a ciphertext block C[K0, K1, K2, K3], and the first cyclic shift shift1=2, then the ciphertext block after cyclic shift becomes C[K2, K3, K0, K1].

[0051] Step S110: Perform S-box replacement on each of the first ciphertext bytes after cyclic shift to obtain a second ciphertext encrypted in the Nth round.

[0052] The first ciphertext byte in each ciphertext group is shifted and then replaced with an S-box to obtain the second ciphertext P2 of the Nth round of encryption.

[0053] In this embodiment, a key-driven dynamic shift mechanism within a group overcomes the limitations of traditional AES fixed row shifts, enabling the same plaintext to produce distinct obfuscation paths under different keys, reducing the success rate of differential attacks. Secondly, in single-round encryption, a shifted quadratic S-box nonlinear replacement is added to the traditional single-byte replacement, increasing the complexity of linear analysis and improving encryption security.

[0054] Based on the above embodiments of the present application, in the fourth embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 4 After step S110, the method for determining the number of encryption rounds further includes steps S120 to S150: Step S120: cyclically shift each second ciphertext byte in the second ciphertext according to a preset second cyclic shift amount.

[0055] Step S130 : determining the third round key byte of each second ciphertext byte in the round key according to the index value of each second ciphertext byte after cyclic shift and the modulus value of the length of the round key.

[0056] For example, the second ciphertext P2 is loaded, and each second ciphertext byte is cyclically shifted left according to the preset second cyclic shift amount shift2 to obtain .right Every second ciphertext byte [1], calculate the corresponding round key index key_index3 = 1 % key_length. Then, according to the round key index key_index3, take out the third round key byte key_byte3 = round_key[key_index3] from the round key.

[0057] Step S140: XOR each of the third-round key bytes with the round constant to obtain an encryption mask for each of the second ciphertext bytes.

[0058] Step S150: XOR each of the second ciphertext bytes with the encryption mask to obtain a third ciphertext of the Nth round of encryption.

[0059] Exemplarily, determining each second ciphertext byte [l] After the corresponding third round key byte key_byte3, the third round key byte key_byte3 is XORed with the round constant to obtain the second ciphertext byte of each [l] Generate an encryption mask. Then combine the encryption mask with the corresponding second ciphertext byte. [l] Perform XOR and obtain the third ciphertext P3 of the Nth round of encryption.

[0060] To better understand the solution provided in this example, this example is further explained in conjunction with specific application scenarios.

[0061] Assume that the round key round_key of the Nth round encryption is [0x2B, 0x7E, 0x15, 0x16], the second ciphertext P2 is [0x32, 0x88, 0x31, 0xE0], the fixed value corresponding to the current round number, i.e., the round constant Rcon is 0x01, and the second cyclic shift shift2 is 3.

[0062] First, perform a 3-byte cyclic left shift on the second ciphertext P2 to obtain =[0x88, 0x31, 0xE0, 0x32], then Calculate the encryption mask for each second ciphertext byte in . For example, [0] as an example: first calculate the round key index key_index3=0 % 4=0, then its corresponding third round key byte key_byte3=round_key[0]=0x2B, [0] The corresponding third round key byte 0x2B is XORed with the round constant 0x01 to obtain the encryption mask 0x2A. Similarly, follow the above steps to calculate The corresponding encryption mask array is [0x2A, 0x7F, 0x14, 0x17]. Each second ciphertext byte in is XORed with its corresponding encryption mask to obtain the third ciphertext P3 = [0xA2, 0x4E, 0xF4, 0x25].

[0063] In this embodiment, unlike the traditional AES fixed group processing mode, the originally adjacent bytes are dispersed into different areas, making the local statistical analysis completely invalid, reducing the success rate of attackers in deducing the key by observing the local characteristics of the data. At the same time, the key and the round constant are XORed as an encryption mask, and a nonlinear factor is injected into the key layer. Even if the attacker obtains part of the key fragment, he cannot deduce other key segments, thereby improving the security of the encryption.

[0064] Based on the above embodiments of the present application, in the fifth embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 5 After step S150, the method for determining the number of encryption rounds further includes steps S160 to S200: Step S160: Divide the third ciphertext into a first ciphertext block and a second ciphertext block according to the number of bytes of the third ciphertext.

[0065] For example, the number of bytes P3_SIZE in the third ciphertext P3[0-p] is divided by 2 and rounded to an integer to obtain the parameter half. The third ciphertext obtained in step S160 is then divided equally into a first ciphertext block L[0-half-1] and a second ciphertext block R[half-p]. Pointers are created for each of the first and second ciphertext blocks.

[0066] Step S170: Determine a target XOR byte for each second block byte in the first ciphertext block according to a modulus value of an index value of each second block byte in the second ciphertext block and a length of the first ciphertext block.

[0067] For example, for each second-block byte R[g] in the second ciphertext block, first determine the first ciphertext block index L_index = g % L_length based on its index value g and the length L_length of the first ciphertext block. Then, extract the target XOR byte L[L_index] from the first ciphertext block based on the first ciphertext block index L_index.

[0068] Step S180: determining the fourth round key byte of each second block byte in the round key according to the index value of each second block byte in the third ciphertext and the modulus value of the length of the round key.

[0069] Illustratively, according to each second block byte R[g], its corresponding key index key_index4=(g+half) % key_length is calculated according to its index value in the third ciphertext, i.e., g+half. Then, according to the key index key_index4, the fourth round key byte key_byte4=round_key[key_index4] is taken out from the round key.

[0070] Step S190: XOR each of the second block bytes with the target XOR byte, and then add the resultant bytes to the fourth round key byte to obtain a new second ciphertext block.

[0071] For example, each second block byte R[g] is XORed with its corresponding target XOR byte L[L_index], and then added to the fourth round key byte key_byte4 to obtain a new second ciphertext block [g]=(R[g]⊕L[L_index])+key_byte4.

[0072] Step S200: Place the first block of bytes in the first ciphertext block at an even index, and place the second block of bytes in the new second ciphertext block at an odd index, and combine them to obtain the fourth ciphertext of the Nth round of encryption.

[0073] For example, a new array P4 is created, the first block of bytes in the first ciphertext block L is placed at the even index of P4, and the second ciphertext block The second block of bytes in is placed at the odd index of P4, cross-mixed, and P4 is used as the fourth ciphertext of the Nth round of encryption.

[0074] In this embodiment, the round key bytes are dynamically bound based on the position index, so that the same data uses differentiated encryption paths at different positions, and the global key cannot be derived by cracking a single position, thereby improving the anti-attack capability. At the same time, the original ciphertext bytes are interleaved according to the parity index to break the original data position relationship, making the frequency analysis, differential attack and other technologies that rely on data position invalid, thereby improving the security of encryption.

[0075] Based on the above embodiments of the present application, in the sixth embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 6 After step S200, the method for determining the number of encryption rounds further includes steps S210 to S240: Step S210: Create a target ciphertext array, and determine the index value to be written of each fourth ciphertext byte in the target ciphertext array.

[0076] Exemplarily, a target ciphertext array is created to reserve a maximum amount of space for each fourth ciphertext byte in the fourth ciphertext. Exemplarily, because each fourth ciphertext byte may be written with a delay byte during subsequent encryption, if each fourth ciphertext byte is written with an extra byte, the maximum space occupied by a single byte increases from 1 byte to 2 bytes. Therefore, the length of the target ciphertext array can be expanded to twice the length of the fourth ciphertext.

[0077] Step S220 : determining the fifth round key bytes of each of the fourth ciphertext bytes in the round key according to the modulus of the index value to be written and the length of the round key.

[0078] Step S230: XOR each of the fifth round key bytes with the round constant to obtain a delay byte of each of the fourth ciphertext bytes.

[0079] Traverse each fourth ciphertext byte P4[s] in the fourth ciphertext and confirm its to-be-written index value s' in the target ciphertext array. For example, the to-be-written index value of P4[0] in the target ciphertext array P is P[0]. If P[0] has a delayed byte, its delayed byte will be written to P[1]. At this time, the to-be-written index value of P4[1] in the target ciphertext array P is P[2].

[0080] Based on the modulus of the to-be-written index s' of the fourth ciphertext byte P4[s] and the length of the round key key_length, determine its corresponding key index key_index5 = s' % key_length. Then, based on this key index key_index5, retrieve the fifth round key byte key_byte5 = round_key[key_index5] from the round key. The fifth round key byte key_byte5 is then XORed with the round constant to obtain the delay byte of the fourth ciphertext byte P4[s]: delay_byte = key_byte5 ⊕ round constant.

[0081] Step S240: Write each of the fourth ciphertext bytes and the delay byte into the target ciphertext array to obtain the target ciphertext of the Nth round of encryption.

[0082] Each fourth ciphertext byte P4[s] and its delay byte delay_byte are written into the target ciphertext array P, and the target ciphertext array P is used as the target ciphertext for the Nth round of encryption.

[0083] Optionally, a delay byte is generated for each fourth ciphertext byte P4[s] based on a preset probability.

[0084] Exemplarily, assuming that the probability of generating a delay byte for each fourth ciphertext byte P4[s] is preset to 15%, when traversing to the fourth ciphertext byte P4[s], a random number within 100 is randomly generated. If the random number is less than 15, a delay byte is generated for the traversed fourth ciphertext byte P4[s], and the traversed fourth ciphertext byte P4[s] and its fourth ciphertext byte P4[s] are written into the target ciphertext array P.

[0085] In this embodiment, by creating a target ciphertext array and reserving a maximum bump-inflation space, and introducing the concept of delay bytes, the encryption complexity is effectively increased, the ciphertext length is made more flexible and the content is richer, the difficulty for attackers to analyze the ciphertext structure is increased, and the security of encryption is improved.

[0086] Based on the above embodiments of the present application, in the seventh embodiment of the present application, the same or similar contents as those in the above embodiments can be referred to the above introduction and will not be described in detail later. Figure 6 After step S230, the method for determining the number of encryption rounds further includes steps S250 to S260: Step S250: Use the index value of the fourth ciphertext byte in the fourth ciphertext as the position byte.

[0087] Step S260: After writing each of the fourth ciphertext bytes, the delay byte, and the position byte into the target ciphertext array, the length of the fourth ciphertext is written into the target ciphertext array to obtain the target ciphertext of the Nth round of encryption.

[0088] For example, in order to accurately delete the delayed bytes during subsequent decryption to correctly restore the plaintext, when the fourth ciphertext byte and its delayed byte are written into the target ciphertext array P, the index value of the fourth ciphertext byte in the fourth ciphertext is used as the position byte and written into the target ciphertext array P together to obtain the target ciphertext of the Nth round of encryption.

[0089] It is understood that in order to allow the target ciphertext array P to accommodate the position byte, the length of the target ciphertext array can be adjusted to three times the length of the fourth ciphertext when creating the target ciphertext array P. Optionally, the length of the fourth ciphertext can be appended to the target ciphertext array.

[0090] Optionally, after step S260, the method for determining the number of encryption rounds further includes steps S270 to S290: Step S270: When decrypting the target ciphertext, traverse the fourth ciphertext byte in the target ciphertext array, and perform an XOR operation on the fifth round key byte corresponding to the fourth ciphertext byte and the round constant to obtain an expected byte.

[0091] Step S280: If the expected byte is the same as the delayed byte corresponding to the fourth ciphertext byte, remove the delayed byte.

[0092] Step S290: Re-determine the position of the fourth ciphertext byte in the target ciphertext array according to the position byte to decrypt the target ciphertext.

[0093] For example, when encryption reaches the Nth round, the fifth-round key byte corresponding to each fourth ciphertext byte in the target ciphertext array is XORed with the round constant to obtain the expected byte corresponding to the fourth ciphertext byte: expected = key_byte5 ⊕ round constant. If the expected byte expected is equal to the delay byte corresponding to the fourth ciphertext byte, it indicates that the delay byte was generated by a valid round key and can be safely removed. The position of each fourth ciphertext byte is then re-determined based on the position byte, and the target ciphertext is restored to the fourth ciphertext.

[0094] In this embodiment, the index value of the fourth ciphertext byte in the fourth ciphertext is used as the position byte and written into the target ciphertext array along with the fourth ciphertext byte and the delay byte during encryption. Furthermore, the length of the fourth ciphertext is appended to the target ciphertext array. This provides crucial auxiliary information for the decryption process, improving the reversibility of encryption and the accuracy of decryption. During decryption, the expected byte is obtained by XORing the fifth round key byte with the round constant and then compared with the delay byte to verify the legitimacy of the delay byte, preventing tampering and thus enhancing encryption security.

[0095] Based on the above embodiments of the present application, in the eighth embodiment of the present application, the same or similar contents as the above embodiments can be referred to the above introduction and will not be repeated hereafter. On this basis, after step S230, the method for determining the number of encryption rounds further includes steps S300 to S310: Step S300: determining a round constant expansion factor in the target key according to the current round number.

[0096] Step S310 : After performing S-box replacement on the sum of the round constant expansion factor and the round constant, XOR is performed with the round constant to obtain the round constant for the N+1th round of encryption.

[0097] The round constant is used for round key expansion in the AES algorithm, and its value changes as the number of rounds increases. In current AES, the round constant is a predefined constant table, but this embodiment dynamically generates an expansion factor through the key, enhancing key dependency.

[0098] For example, the round constant R[N+1] of the N+1th round of encryption can be expressed as: R[N+1]=(R[N] r3)⊕SBox[(R[N]+masterKey[N%r4])%256] Where R[N] is the round constant for round N. The target index value of the target key is determined based on the modulus of the current round number and r4, and the corresponding byte is extracted from the target key. The role of r4 is to avoid insufficient bytes of the target key when the round number is long, such as exceeding the length of the target key, to ensure that all target key bits continue to participate in the calculation. r4 can be any number that is divisible by the length of the target key, and r3 is a Galois field multiplication (GF(2 8 )).

[0099] Before performing S-box replacement on the sum of the round constant extension factor and the round constant, the sum of the round constant extension factor masterKey[N%r2] and the round constant may be modulo 256 to ensure that the sum is limited to the range of 0-255.

[0100] Optionally, the sum of the round constant expansion factor and the round constant may be subjected to S-box replacement and then directly XORed with the round constant R[N].

[0101] It's understandable that in the traditional AES algorithm, the round constant for each round is a fixed value completely unrelated to the target key, allowing attackers to infer the key by reversing the round key expansion process. However, in this embodiment, round constant generation depends on the target key bytes and the previous round constant, and nonlinear S-box substitution is introduced to disrupt the linear relationship between input and output, thus resisting key derivation attacks.

[0102] It should be noted that the above examples are only used to understand the present application and do not constitute a limitation on the method for determining the number of encryption rounds of the present application. More simple transformations based on this technical concept are all within the scope of protection of the present application.

[0103] The present application provides a device for determining the number of encryption rounds, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method for determining the number of encryption rounds in the above-mentioned embodiment 1.

[0104] Reference below Figure 7, which shows a schematic diagram of the structure of a device suitable for implementing an embodiment of the present application to determine the number of encryption rounds. The device for determining the number of encryption rounds in the embodiment of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, personal digital assistants (PDAs), tablet computers (PADs), portable multimedia players (PMPs), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 7 The device for determining the number of encryption rounds shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.

[0105] like Figure 7 As shown, the device for determining the number of encryption rounds may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. RAM 1004 also stores various programs and data required for the operation of the device for determining the number of encryption rounds. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems may be connected to I / O interface 1006: input device 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output device 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage device 1003 including, for example, a magnetic tape, hard disk, etc.; and communication device 1009. Communication device 1009 may allow the device for determining the number of encryption rounds to communicate wirelessly or wired with other devices to exchange data. While the figure illustrates a device for determining the number of encryption rounds with various systems, it should be understood that implementation or provision of all illustrated systems is not required. More or fewer systems may alternatively be implemented or provided.

[0106] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are performed.

[0107] The device for determining the number of encryption rounds provided in this application, employing the method for determining the number of encryption rounds in the above-described embodiment, can solve the technical problem of improving encryption security. Compared to the prior art, the device for determining the number of encryption rounds provided in this application has the same beneficial effects as the method for determining the number of encryption rounds provided in the above-described embodiment. Other technical features of the device for determining the number of encryption rounds provided in this application are the same as those disclosed in the method in the above-described embodiment and are not further described here.

[0108] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0109] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0110] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, a computer program) stored thereon, the computer-readable program instructions being used to execute the method for determining the number of encryption rounds in the above-mentioned embodiment.

[0111] The computer-readable storage medium provided herein may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including, but not limited to, wires, optical cables, radio frequency (RF), etc., or any suitable combination thereof.

[0112] The computer-readable storage medium may be included in the device for determining the number of encryption rounds; or may exist independently without being incorporated into the device for determining the number of encryption rounds.

[0113] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the device for determining the number of encryption rounds, the device for determining the number of encryption rounds determines the number of encryption rounds.

[0114] Computer program code for performing the operations of the present application may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, or as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0115] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, program segment or part of code, and the module, program segment or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, as well as the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or can be implemented using a combination of dedicated hardware and computer instructions.

[0116] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.

[0117] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned method for determining the number of encryption rounds. This computer-readable storage medium addresses the technical problem of improving encryption security. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are similar to those of the method for determining the number of encryption rounds provided in the aforementioned embodiments, and are not further elaborated here.

[0118] The present application also provides a computer program product, including a computer program, which implements the steps of the method for determining the number of encryption rounds as described above when the computer program is executed by a processor.

[0119] The computer program product provided in this application can solve the technical problem of how to improve encryption security. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as the beneficial effects of the method for determining the number of encryption rounds provided in the above embodiment, and will not be repeated here.

[0120] The above description is only part of the embodiments of the present application and does not limit the patent scope of the present application. All equivalent structural transformations made by using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.

Claims

1. A method for determining the number of encryption rounds, characterized in that: The method for determining the number of encryption rounds includes: Obtain a target key, and take the first byte of the target key modulo a preset modulus to obtain an offset; Determining the number of key words of the target key, and determining a reference number of encryption rounds according to the sum of the number of key words and the offset; The number of additional rounds of encryption is determined according to the Shannon entropy of the plaintext, and the number of encryption rounds is determined according to the sum of the reference number of rounds and the additional number of rounds.

2. The method for determining the number of encryption rounds according to claim 1, wherein: After the steps of determining the additional number of encryption rounds according to the Shannon entropy of the plaintext, and determining the number of encryption rounds according to the sum of the reference number of rounds and the additional number of rounds, the method further includes: In the Nth round of encryption, obtaining the round key corresponding to the current round and the index value of each plaintext byte in the plaintext; Determining a first round key byte of each plaintext byte in the round key according to a modulus value of an index value of each plaintext byte and a length of the round key; Determining a replacement step length for each of the plaintext bytes according to the first-round key bytes, and determining a target replacement byte for each of the plaintext bytes in the plaintext according to the replacement step length; Each of the plaintext bytes is replaced with the target replacement byte to obtain the first ciphertext of the Nth round of encryption.

3. The method for determining the number of encryption rounds according to claim 2, wherein: After the step of replacing each of the plaintext bytes with the target replacement bytes to obtain the first ciphertext of the Nth round of encryption, the method further includes: Dividing the first ciphertext into at least one ciphertext group according to a preset number of bytes; determining, in the round key, a second round key byte for each first ciphertext byte in the ciphertext block according to a modulo value of an index value of each first ciphertext byte in the ciphertext block and a length of the ciphertext block; determining a first cyclic shift amount for each of the first ciphertext bytes according to the second-round key bytes, and performing a cyclic shift on each of the first ciphertext bytes in each of the ciphertext groups according to the first cyclic shift amount; Perform S-box replacement on each of the first ciphertext bytes after cyclic shift to obtain a second ciphertext encrypted in the Nth round.

4. The method for determining the number of encryption rounds according to claim 3, wherein: After the step of performing S-box replacement on each of the cyclically shifted first ciphertext bytes to obtain the second ciphertext encrypted in the Nth round, the method further includes: cyclically shifting each second ciphertext byte in the second ciphertext according to a preset second cyclic shift amount; Determining a third round key byte for each second ciphertext byte in the round key according to a modulus value of an index value of each second ciphertext byte after cyclic shift and a length of the round key; XOR each of the third-round key bytes with a round constant to obtain an encryption mask for each of the second ciphertext bytes; Each of the second ciphertext bytes is XORed with the encryption mask to obtain a third ciphertext of the Nth round of encryption.

5. The method for determining the number of encryption rounds according to claim 4, wherein: After the step of performing XOR operation on each of the second ciphertext bytes and the encryption mask to obtain the third ciphertext of the Nth round of encryption, the method further includes: Dividing the third ciphertext into a first ciphertext block and a second ciphertext block according to the number of bytes of the third ciphertext; determining, in the first ciphertext block, a target XOR byte for each of the second block bytes according to a modulo value of an index value of each second block byte in the second ciphertext block and a length of the first ciphertext block; determining, in the round key, a fourth round key byte of each of the second block bytes according to an index value of each of the second block bytes in the third ciphertext and a modulo value of the length of the round key; XORing each of the second block bytes with the target XOR byte, and then adding the resultant to the fourth round key byte to obtain a new second ciphertext block; The first block of bytes in the first ciphertext block is placed at an even index, and the second block of bytes in the new second ciphertext block is placed at an odd index, and the bytes are combined to obtain a fourth ciphertext of the Nth round of encryption.

6. The method for determining the number of encryption rounds according to claim 5, wherein: The step of placing the first block of bytes in the first ciphertext block at an even index, placing the second block of bytes in the new second ciphertext block at an odd index, and combining them to obtain the fourth ciphertext encrypted in the Nth round includes: Creating a target ciphertext array, and determining an index value to be written to each fourth ciphertext byte in the target ciphertext array; determining a fifth round key byte for each fourth ciphertext byte in the round key according to a modulo value of the to-be-written index value and the length of the round key; XORing each of the fifth round key bytes with the round constant to obtain a delay byte of each of the fourth ciphertext bytes; Each of the fourth ciphertext bytes and the delay byte is written into the target ciphertext array to obtain the target ciphertext of the Nth round of encryption.

7. The method for determining the number of encryption rounds according to claim 6, wherein: After the step of performing XOR operation on each of the fifth round key bytes and the round constant to obtain the delayed bytes of each of the fourth ciphertext bytes, the method further includes: Using the index value of the fourth ciphertext byte in the fourth ciphertext as the position byte; After writing each of the fourth ciphertext bytes, the delay byte, and the position byte into the target ciphertext array, the length of the fourth ciphertext is written into the target ciphertext array to obtain the target ciphertext for the Nth round of encryption.

8. The method for determining the number of encryption rounds according to claim 7, wherein: After the step of writing the length of the fourth ciphertext into the target ciphertext array to obtain the target ciphertext for the Nth round of encryption, the method further includes: determining a round constant expansion factor in the target key according to the current round number; After performing S-box replacement on the sum of the round constant expansion factor and the round constant, the sum is XORed with the round constant to obtain the round constant for the N+1th round of encryption.

9. A device for determining the number of encryption rounds, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the method for determining the number of encryption rounds according to any one of claims 1 to 8.

10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the method for determining the number of encryption rounds according to any one of claims 1 to 8 are implemented.