Abstract data generation method and system and storage medium

By introducing dynamic parameter configuration and hardware-based filling operations, the problem of the secure hash algorithm hardware module being fixed on a single algorithm is solved, dynamic adaptation of multiple encryption modes and efficient processing of heterogeneous data input are achieved, and the flexibility and real-time performance of the system are improved.

CN120750520APending Publication Date: 2025-10-03SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511071696.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

In the existing technology, the secure hash algorithm hardware module solidifies a single algorithm variant and cannot be dynamically configured, resulting in poor system flexibility. In addition, additional conversion modules are required when heterogeneous data is input, which increases resource waste and delays.

Method used

A dynamic parameter configuration mechanism is introduced to achieve bit width adaptation through the data bridging module, and hardware filling operations are performed using the data filling module, eliminating the conversion module for heterogeneous data input and improving system flexibility and real-time performance.

Benefits of technology

It realizes dynamic adaptation of multiple encryption modes, supports heterogeneous data input, reduces resource waste and delay, and improves the flexibility, compatibility and real-time performance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750520A_ABST
    Figure CN120750520A_ABST
Patent Text Reader

Abstract

The invention discloses a summary data generation method and system and a storage medium, and relates to the technical field of data processing, and the summary data generation method comprises the step of realizing a self-adaptive data processing flow by dynamically configuring encryption types and configuration parameters. Specifically, target data, encryption type indication information and encryption configuration parameters are obtained, data are dynamically grouped according to encryption types, differential filling rules are executed for different encryption modes, and finally abstract data are generated through iterative processing. Through the design, a single system can flexibly adapt to various encryption algorithm requirements, the technical problems that a traditional abstract generation method is poor in compatibility and cannot dynamically adapt to different security scenes due to the fact that an encryption algorithm is fixed are solved, and the technical effects of improving system compatibility, reducing resource redundancy and optimizing processing efficiency are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a method, system and storage medium for generating summary data. Background Art

[0002] With the development of cryptographic technology, secure hash algorithms have become the core infrastructure in fields such as data integrity verification, digital signatures, and blockchain due to their anti-collision, irreversibility, and resistance to quantum attacks.

[0003] In related technologies, hardware modules that implement secure hash algorithms mostly use predefined parameter configurations, usually only solidifying support for a single algorithm variant or its specific operating mode. Parameters cannot be dynamically configured to support all standard variants based on actual security requirements, limiting the flexibility of the system. Summary of the Invention

[0004] The present application provides a method, system, and storage medium for generating summary data, to at least solve the problem in related technologies of rigid hardware module functions and poor configuration flexibility.

[0005] The present application provides a method for generating summary data, comprising: obtaining target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters, wherein the encryption type indication information is used to indicate the type of encryption method; performing grouping processing on the target data according to the encryption type indication information and the encryption configuration parameters to obtain multiple grouped data corresponding to the target data; performing filling processing on each grouped data according to a data filling rule corresponding to the encryption method to obtain target filled data corresponding to each grouped data; and iteratively processing the target filled data to generate target summary data corresponding to the target data.

[0006] The present application also provides a summary data generation system, including: a data bridging module, including multiple data input interfaces, the multiple data input interfaces are used to receive target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters, the encryption type indication information is used to indicate the type of encryption method; the data bridging module is used to group the target data according to the encryption type indication information and the encryption configuration parameters to obtain multiple grouped data corresponding to the target data; a data filling module, connected to the data bridging module, the data filling module is used to fill each grouped data according to the data filling rules corresponding to the encryption method, and obtain target filled data corresponding to each grouped data; a data iteration module, connected to the data filling module, the data iteration module is used to iteratively process the target filled data to generate target summary data corresponding to the target data.

[0007] The present application also provides a summary data generation device, including: an acquisition module, used to obtain target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters, where the encryption type indication information is used to indicate the type of encryption method; a grouping module, used to group the target data according to the encryption type indication information and the encryption configuration parameters, and obtain multiple grouped data corresponding to the target data; a filling module, used to fill each grouped data according to the data filling rule corresponding to the encryption method, and obtain target filled data corresponding to each grouped data; and a generation module, used to iteratively process the target filled data to generate target summary data corresponding to the target data.

[0008] The present application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of any of the above-mentioned summary data generation methods when executing the computer program.

[0009] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned summary data generation methods are implemented.

[0010] The present application also provides a computer program product, including a computer program, which implements the steps of any of the above-mentioned summary data generation methods when executed by a processor.

[0011] Through this application, since the data grouping strategy is dynamically adjusted according to the type of specific encryption method and its specific configuration requirements, and the unique filling rules of the encryption method are strictly applied for standardized processing, it is possible to solve the problem of hardware module function rigidity and poor configuration flexibility in related technologies, and achieve the technical effect of supporting multiple secure hash algorithm variants and their working modes for on-demand dynamic configuration. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0013] Figure 1 A structural block diagram of a system for generating summary data provided in an embodiment of the present application;

[0014] Figure 2 A structural block diagram of another system for generating summary data provided in an embodiment of the present application;

[0015] Figure 3A flowchart of a method for generating summary data provided in an embodiment of the present application;

[0016] Figure 4 A flowchart of another method for generating summary data provided in an embodiment of the present application;

[0017] Figure 5 A schematic diagram of a data filling process provided in an embodiment of the present application;

[0018] Figure 6 A schematic diagram of another data filling process provided in an embodiment of the present application;

[0019] Figure 7 A schematic diagram of another data filling process provided in an embodiment of the present application;

[0020] Figure 8 A schematic diagram of another data filling process provided in an embodiment of the present application;

[0021] Figure 9 A schematic diagram of a data filling process provided in an embodiment of the present application;

[0022] Figure 10 A flowchart of another method for generating summary data provided in an embodiment of the present application;

[0023] Figure 11 A schematic diagram of the data iteration process provided in an embodiment of the present application;

[0024] Figure 12 A structural block diagram of a device for generating summary data provided in an embodiment of the present application;

[0025] Figure 13 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0026] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0027] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.

[0028] With the development of cryptographic technology, secure hash algorithms, such as the third-generation Secure Hash Algorithm 3 (SHA-3), have become the core infrastructure in fields such as data integrity verification, digital signatures, and blockchain due to their collision resistance, irreversibility, and resistance to quantum attacks.

[0029] In related technologies, the implementation of secure hash algorithms faces several key bottlenecks. Current hardware modules (such as ASICs / FPGAs) typically only support a single secure hash algorithm variant (such as SHA3-256 or SHA3-512) and are unable to dynamically adjust output length or internal capacity parameters based on different security requirements. This makes the system inflexible when dealing with diverse encryption scenarios. In addition, data processing typically relies on a fixed-bitwidth bus (such as 64 or 128 bits). When the bit width of the input data is inconsistent, additional data conversion modules must be introduced, which not only wastes hardware resources but also increases timing complexity. Secondly, traditional designs delegate data padding tasks to software, which frequently causes data flow interruptions in high-throughput scenarios, resulting in significant additional delays, thus severely restricting the real-time performance of the system. Therefore, there is an urgent need for a digest generation solution that can dynamically adapt to multiple encryption modes, support heterogeneous data input, and eliminate padding delays to meet the collaborative needs of flexibility, compatibility, and efficiency in high-speed encryption scenarios.

[0030] In view of this, the technical solution of this application introduces a dynamic parameter configuration mechanism, which switches the algorithm mode in real time in a unified hardware architecture according to the encryption type indication information and encryption configuration parameters, fully supports secure hash algorithm variants, and breaks through the limitations of traditional hardware solidification of a single algorithm. Secondly, bit width adaptation is achieved through the data bridging module, and bit splicing or zero-value padding is dynamically performed based on the mathematical relationship between the input data bit width and the packet length, eliminating the additional conversion module when heterogeneous data is input, reducing resource waste. At the same time, the padding operation is completely hardware-based, and mask generation and bit-by-bit logical operations are used to implement standard padding rules in parallel in the pipeline, avoiding data flow interruptions caused by traditional software padding, significantly reducing the delay in high-throughput scenarios, and thus improving system flexibility, compatibility, and real-time performance.

[0031] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0032] In this embodiment, a system for generating summary data is provided. Figure 1 As shown, the system includes: a data bridging module 1, a data filling module 2 and a data iteration module 3.

[0033] The data bridging module 1 includes a plurality of data input interfaces, each of which is configured to receive target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters, wherein the encryption type indication information is configured to indicate a type of encryption method; the data bridging module 1 is configured to group the target data according to the encryption type indication information and the encryption configuration parameters to obtain a plurality of grouped data corresponding to the target data;

[0034] The data filling module 2 is connected to the data bridging module 1 and is used to fill each packet data according to the data filling rule corresponding to the encryption method to obtain the target filling data corresponding to each packet data;

[0035] The data iteration module 3 is connected to the data filling module 2. The data iteration module 3 is used to iteratively process the target filling data to generate target summary data corresponding to the target data.

[0036] Target data refers to the raw data that needs to be processed by the system to generate the final digest result. Encryption type indication information refers to a signal or flag that indicates a specific processing mode and can distinguish different processing variants, such as different output length requirements or functional modes. Encryption configuration parameters refer to parameters used to configure data bridging and padding. The encryption method refers to the specific processing mode used by the system, with different modes corresponding to different processing rules. A data input interface refers to a physical or logical interface for receiving external information. The data bridging module 1 is a module that adapts to input data of varying bit widths. It can receive data to be processed of various bit widths and convert it into fixed-length packets required by the corresponding algorithm through various methods to adapt to subsequent processing flows. Specifically, the data bridging module 1 includes multiple data input interfaces for receiving different types of data, including the raw data to be processed (i.e., target data), encryption type indication information, and encryption configuration parameters. The encryption type indication information indicates the specific encryption mode, such as different encryption algorithms, while the encryption configuration parameters include settings that control how data is grouped and processed. These may include the input data bit width (32 / 64 / 128 bits), the total length of the target data, and the last data indicating the end of the data.

[0037] The data bridging module 1 determines how to group the target data based on the encryption type indication and encryption configuration parameters. Specifically, the data bridging module 1 performs appropriate grouping processing on the target data according to predetermined rules to generate grouped data. The purpose of grouping is to ensure that each data block meets the encryption method requirements, such as packet length and data structure.

[0038] Data filling rules refer to the filling standards determined according to the encryption method. Target filling data refers to the result data obtained after the packet data is filled. Data filling module 2 refers to the hardware module that fills the packet data. According to the data filling rules corresponding to the encryption method, specific bits are added to the end of the packet data so that the length of the filled data meets the requirements. Specifically, the function of data filling module 2 is to fill the packet data according to a specific encryption method. The data filling rules are defined in the encryption method, which determines how to supplement the data so that its length meets the requirements. For example, it can include specific suffixes to be added, combinations of filling bits, and final length requirements. Data filling module 2 fills the packet data according to these rules to generate target filling data.

[0039] The target summary data refers to the final result after the system processes the target data. The data iteration module 3 refers to a hardware module that performs iterative operations on the target filling data, and gradually processes the target filling data through preset function operations to obtain the target summary data. Specifically, the function of the data iteration module 3 is to further process the filled data to generate the final target summary data. The data iteration module 3 performs iterative calculations on the target filling data, and gradually processes the data until the final summary result is obtained. This process is based on preset function or algorithm rules. The data iteration module 3 continuously applies these rules to process the data until the data meets the output requirements of the summary. Finally, the target summary data generated by the data iteration module 3 is the final result of the target data after all processing steps.

[0040] For example, when the encryption type is the SHA-3 series algorithm, Figure 2As shown, the summary data generation system includes a data bridging module 1 (Data Bridging), a data padding module 2 (Padding), and a data iteration module 3 (Round_function). sha3_type is encryption type information, indicating the currently used encryption method, such as different hash variants SHA3-224, SHA3-256, SHA3-384, and SHA3-512, and the scalable output functions SHAKE128 and SHAKE256, which determine the subsequent grouping, padding, and iteration rules. data_in (32 / 64 / 128) is a data input interface that receives 32 / 64 / 128-bit-wide target data to be processed, adapting to input scenarios with different bus bit widths. data_length is the total length of the target data, recording the total number of bits of the data to be processed. last_data is a data termination identifier, indicating whether the current input is the last set of data, allowing data bridging module 1 to clearly define the processing boundary.

[0041] Data bridging module 1, acting as a converter between input data and packet data, cuts or concatenates data_in of arbitrary length into fixed-length packets (e.g., data_576, data_832, data_1088) based on sha3_type, data_length, last_data, and 32 / 64 / 128-bit width. The length is determined by the packet length corresponding to the encryption type. Data bridging module 1 generates multiple packets (e.g., 576 / 832 / 1088-bit blocks) and simultaneously passes the last_data signal to data padding module 2.

[0042] Data padding module 2 pads each packet according to the data padding rules corresponding to sha3_type to ensure that the data length meets the requirements, preparing for iterative processing. Data padding module 2 receives the packet data (such as data_576) and the last_data signal from data bridging module 1, and generates the target padding data padding_out and the last_padding signal. Padding_out is the standard packet data after padding, and the last_padding signal is used to indicate whether it is the last packet.

[0043] Data iteration module 3 includes a Ctrl (control unit) and multiple f functions (i.e., iteration functions). Ctrl coordinates data iteration module 3 and performs multiple rounds of iterative operations on padding_out, gradually compressing the data and extracting features to ultimately generate the target digest data digest_out.

[0044] The summary data generation system provided in this embodiment builds a highly flexible, configurable, and hardware-friendly summary generation system architecture. The entire system implements a complete summary processing pipeline through a data bridging module, a data filling module, and a data iteration module with clear functions and close integration. The data bridging module serves as the front-end entry point, receiving and parsing externally input encryption type indication information and encryption configuration parameters. This enables the system to dynamically adapt to a variety of different encryption algorithms, rather than being limited to a single fixed mode. Furthermore, the data bridging module receives target data through multiple data input interfaces and intelligently groups the data based on the encryption type indication information and encryption configuration parameters. This effectively solves the problem of adaptive processing of inputs of varying bit widths and avoids the resource waste and performance bottlenecks of traditional fixed bit width solutions in heterogeneous environments. The data filling module is directly connected to the bridging module, fully hardware-implementing the algorithm-specific filling rules. It performs real-time and efficient filling operations on the grouped data based on the rules determined by the encryption type indication information. This design completely eliminates the data flow interruptions, additional delays, and potential security risks caused by traditional solutions that rely on software filling, significantly improving system throughput and real-time performance. The data iteration module serves as the end point of the processing chain. It receives the filled data and executes the core iterative operation of the algorithm, ultimately generating the target summary data. Its universal design ensures that the core computing unit can serve the processing needs under a variety of configurations. The modular design of the entire architecture not only achieves functional decoupling, reduces system complexity and maintenance costs, but also naturally fits the design concept of hardware pipelines or parallel processing. More importantly, by abstracting the encryption type indication information and encryption configuration parameters into externally configurable inputs, the system improves flexibility and versatility, and a set of hardware architecture can cover a wide range of cryptographic summary application scenarios.

[0045] According to an embodiment of the present application, an embodiment of a method for generating summary data is provided. It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0046] In this embodiment, a method for generating summary data is provided, which can be used in the above-mentioned system for generating summary data. Figure 3 is a flow chart of a method for generating summary data according to an embodiment of the present application. Figure 3 As shown, the process includes the following steps:

[0047] Step S101: Obtain target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters. The encryption type indication information is used to indicate the type of encryption method.

[0048] When acquiring target data to be processed, the system first receives the externally provided raw data through the data input interface. This raw data serves as the target data. Simultaneously, it also receives encryption type indication information and encryption configuration parameters. The encryption type indication information informs the system of the desired encryption mode, while the encryption configuration parameters define the specific configuration corresponding to the encryption process, such as the input data bit width, the total length of the target data, and the data end flag. This information is transmitted to the system through the data input interface, providing the necessary background data for subsequent data processing.

[0049] Step S102: performing group processing on the target data according to the encryption type indication information and the encryption configuration parameters to obtain a plurality of grouped data corresponding to the target data.

[0050] After receiving the target data, encryption type indication information, and encryption configuration parameters, the data bridging module 1 determines the encryption method to be used based on the encryption type indication information and, in combination with the encryption configuration parameters, performs grouping processing on the target data. The purpose of grouping processing is to ensure that each group meets the requirements of the encryption method, such as the set group length and data structure.

[0051] Step S103 , performing filling processing on each packet data according to the data filling rule corresponding to the encryption method, and obtaining target filling data corresponding to each packet data.

[0052] The data padding module 2 pads each packet data according to the data padding rules corresponding to the encryption method. Specifically, the data padding rules will add specific padding bits at the end of the packet data according to the requirements of different encryption methods to ensure that the padded data meets the length requirements of the encryption method and generate the target padded data.

[0053] Step S104: iteratively process the target filling data to generate target summary data corresponding to the target data.

[0054] After the target populated data is prepared, the data iteration module 3 gradually processes the populated data using a pre-set iterative calculation function or algorithm. Specifically, the iterative processing process includes a series of computational steps, which convert the target populated data into summary data by continuously applying the calculation function. Each iteration further processes the data based on the previous calculation. After multiple rounds of iteration, the target summary data corresponding to the target data is generated as the final result of the data processing.

[0055] The summary data generation method provided in this embodiment obtains encryption type indication information and encryption configuration parameters, enabling grouping and padding processing to dynamically adapt to different encryption methods without modifying the core process, thereby expanding the method's applicability. Furthermore, grouping, padding, and iterative processing ensure modularity and efficiency, facilitating implementation and maintenance. Furthermore, padding and iteration based on rules corresponding to the encryption method ensure the correctness and standardization of summary generation, providing a unified framework for diverse encryption requirements.

[0056] In this embodiment, a method for generating summary data is provided, which can be used in the above-mentioned system for generating summary data. Figure 4 is a flow chart of a method for generating summary data according to an embodiment of the present application. Figure 4 As shown, the process includes the following steps:

[0057] Step S201: Obtain target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters. The encryption type indication information is used to indicate the type of encryption method. Figure 3 Step S101 of the illustrated embodiment will not be described in detail here.

[0058] Step S202: performing group processing on the target data according to the encryption type indication information and the encryption configuration parameters to obtain a plurality of grouped data corresponding to the target data.

[0059] Specifically, the above step S202 includes:

[0060] Step S2021: Determine the preset packet length according to the encryption type indication information.

[0061] The preset packet length refers to a fixed data block length determined by the encryption type indicator, denoted as r. Specifically, the encryption type indicator identifies the currently used encryption method (e.g., different hash algorithm variants). Each encryption method corresponds to a fixed packet length standard. Based on the encryption type indicator, the corresponding packet length value is matched and extracted from a pre-stored parameter table or algorithm configuration, serving as the core basis for subsequent packet processing. For example, the corresponding packet length for SHA3-512 is 576 bits.

[0062] Step S2022: Count the bit width of the target data according to the encryption configuration parameter to determine the bit width value of the target data.

[0063] The bit width value is the value obtained by counting the bit width of the target data according to the encryption configuration parameter. Specifically, the total number of bits of the target data received is determined according to the encryption configuration parameter to obtain the bit width value of the target data.

[0064] Step S2023 : performing grouping processing on the target data based on the relationship between the bit width value and the preset group length to obtain a plurality of grouped data corresponding to the target data.

[0065] How to segment or splice the target data into multiple data blocks, ie, multiple packet data corresponding to the target data, is determined by the numerical relationship between the bit width value of the target data and the preset packet length.

[0066] The summary data generation method provided in this embodiment determines the preset group length based on the encryption type indication information, so that the grouping rules can be dynamically adjusted with the encryption algorithm, breaking through the limitations of fixed grouping. The target data bit width value is parsed through encryption configuration parameters, and a mathematical relationship between the bit width value and the group length is established to achieve seamless conversion of heterogeneous bus data. The bit width counting and relationship determination logic can be directly mapped to hardware counters and comparators, providing standardized input for subsequent filling modules and reducing conversion overhead. Therefore, this method realizes intelligent adaptation of data bit width and group length in different encryption scenarios through a parameterized dynamic grouping mechanism.

[0067] In some optional implementations, the encryption configuration parameter includes a single input bit width corresponding to the target data; and the above step S2023 includes:

[0068] Step a1: when the bit width value is equal to the preset packet length, output packet data with a bit width equal to the preset packet length.

[0069] The single input bit width refers to the bit width of each input data entry defined in the encryption configuration parameters (e.g., 32 / 64 / 128 bits), and is the basic bit width unit when the data bridging module 1 receives the target data. Specifically, when receiving the target data, the data bridging module 1 accumulates and counts the data bit width (i.e., the bit width value) using the single input bit width in the encryption configuration parameters as the unit. When the accumulated bit width value is exactly equal to the preset packet length determined by the encryption type indication information, it indicates that the length of the currently received data meets the packetization requirements. At this time, the data bridging module 1 directly outputs this portion of data as a complete packet data without the need for additional padding or splicing.

[0070] Step a2: When the bit width value is less than the preset packet length and the target data transmission is completed, the remaining target data is supplemented with zero-valued bits to the preset packet length to obtain packet data.

[0071] The remaining target data refers to the remaining data fragments that have not been fully packetized. Specifically, when the accumulated bit width value of the data bridging module 1 is less than the preset packet length, and the target data transmission is confirmed to have ended (no more data input) through the last data identifier in the encryption configuration parameters, the data bridging module 1 will process the remaining target data and append zero-valued bits to the end of the remaining target data until the total bit width after appending equals the preset packet length, thereby forming a complete packet data and outputting it.

[0072] Step a3: When the preset packet length and the single input bit width do not satisfy an integer multiple relationship, the target data is cached according to a preset period, and packet data with a bit width equal to the preset packet length is generated according to a preset bit splicing rule.

[0073] The preset period refers to the number of times the input data is cached to ensure that the total cache bit width is an integer multiple of the preset group length. The bit splicing rule refers to the rule of splicing the bit width data input multiple times in chronological order within the preset period to generate groups of preset group length. Specifically, when the preset group length does not have an integer multiple relationship with the single input bit width, for example, the input bit width is 128bit, r=576bit, 576 is 4.5 times of 128), the data bridging module 1 will first determine the preset period, that is, the number of times the input data is cached, which must satisfy "number of cycles × single input bit width" as an integer multiple of r, such as 128bit×9=1152bit=576bit×2, so the period is 9 times. Subsequently, the input data is cached according to the period, and then processed according to the bit splicing rule to generate group data with a bit width equal to the preset group length. Taking 128-bit to 576-bit conversion as an example, first cache 5 times of 128-bit data, take the first 576 bits (that is, the first 4 complete data + the first 64 bits of the fifth data) as the first group; the remaining 64 bits of the fifth data are spliced ​​with the subsequent 4 times of 128-bit data to form the second 576-bit group, thereby periodically generating group data that meets the preset group length.

[0074] In the above implementation, when the input bit width equals the preset packet length, direct output is performed, eliminating conversion overhead. Data with insufficient bit width at the end of transmission is automatically padded to the packet length, ensuring packet integrity and preventing data loss. Furthermore, when the preset packet length is not an integer multiple of the single input bit width, lossless conversion is achieved through pre-set cycle caching and bit splicing rules, significantly reducing hardware complexity. Therefore, this method systematically addresses the engineering challenge of mismatching packet length and input bit width through a triple bit width adaptation mechanism.

[0075] Step S203 , performing filling processing on each packet data according to the data filling rule corresponding to the encryption method, and obtaining target filling data corresponding to each packet data.

[0076] Specifically, the above step S203 includes:

[0077] Step S2031: Determine the first additional suffix bit corresponding to the packet data based on the encryption type indication information.

[0078] The first additional suffix bit refers to a specific bit sequence that needs to be attached to the end of the packet data, which is determined based on the encryption type indication information. Specifically, the encryption type indication information is used to distinguish the specific type of encryption method, such as a hash algorithm or an extensible output function algorithm. The first additional suffix bit corresponding to the packet data is determined according to the specific type of encryption method. For example, when the encryption type is a SHA-3 series algorithm, if the encryption type indication information indicates that it is a hash algorithm (such as SHA3-224, SHA3-256, etc.), the first additional suffix bit is 2 bits of "01"; if it indicates an extensible output function algorithm (such as SHAKE128, SHAKE256), the first additional suffix bit is 4 bits of "1111". That is, the corresponding algorithm type is matched by the encryption type indication information, and then the specific suffix bit sequence that needs to be attached is determined.

[0079] Step S2032: Add a first suffix bit to the end of the packet data to obtain the first target packet data.

[0080] The first target packet data refers to the intermediate data obtained by appending the first additional suffix bit to the end of the packet data. Specifically, after determining the first additional suffix bit, the suffix bit sequence is directly spliced ​​to the end of the packet data, and the spliced ​​result is the first target packet data.

[0081] Step S2033 , at the end of the first target packet data, sequentially fill in a first preset filling value of a first preset number of bits, a second preset filling value of a second preset number of bits, and a third preset filling value of a third preset number of bits to obtain target filling data.

[0082] The preset padding value refers to a specific value for padding, and the preset number of digits refers to the number of digits for the padding value. Specifically, at the end of the first target packet data, the first preset padding value of the first preset number of digits, the second preset padding value of the second preset number of digits, and the third preset padding value of the third preset number of digits are sequentially filled, so that the total length of the data after padding is exactly an integer multiple of the preset packet length, and the final result is the target padding data. For example, when the encryption type is the SHA-3 series algorithm, according to the "pad10*1" padding rule of SHA3, the first preset number of digits is 1, and the first preset padding value is 1-bit "1"; the second preset number of digits is j (j≥0, the specific value is determined by whether the total length after padding is an integer multiple of the preset packet length), and the second preset padding value is j-bit "0"; the third preset number of digits is 1, and the third preset padding value is 1-bit "1". At the end of the first target packet data, first fill in 1-bit "1", then fill in j-bit "0", and finally fill in 1-bit "1", so that the total length of the data after padding is exactly an integer multiple of the preset packet length, and the target padding data is obtained, which is recorded as P i .

[0083] The method for generating summary data provided in this embodiment determines the first additional suffix bit based on the encryption type indication information, unifying the padding requirements of different algorithm variants into a single process. Padding is decomposed into three sequential operations, forming atomic steps that can be hardware-pipelined, avoiding the complexity of the combinational logic in traditional solutions. The fixed bit value design of the first preset value, the second preset value, and the third preset value, combined with masking and shifting operations, can be directly mapped to hardware XOR gates and selector circuits, significantly reducing resource consumption. Therefore, this method accurately implements the complex padding rules of the encryption algorithm at the hardware level through a standardized three-stage padding process.

[0084] In some optional implementations, the above step S203 further includes:

[0085] Step b1, obtaining the last group of data among the multiple grouped data, and the valid data length of the last group of data.

[0086] The last set of data refers to the last data block in all the generated packet data after the target data is grouped and processed. The effective data length refers to the number of original data bits actually contained in the last set of data. Specifically, after generating multiple packet data, by tracking the order of the packet sequence, the data block at the end of the sequence is located, which is the last set of data. The effective data length of the last set of data refers to the number of bits of original target data actually contained in the packet, that is, excluding the zero-valued bits added during data bridging. It can be calculated by dividing the total target data length in the encryption configuration parameters by the preset packet length, that is, effective data length = total target data length % preset packet length. If the result is 0, it is equal to the preset packet length.

[0087] Step b2: If the valid data length is less than or equal to the preset length, mask data is generated based on the valid data length and the preset packet length corresponding to the encryption type indication information.

[0088] The preset length refers to a threshold length associated with the preset packet length. Mask data refers to a binary mask generated based on the valid data length and the preset packet length. Specifically, the preset length is determined based on the specific type of encryption method. For example, when the encryption type is a SHA-3 family algorithm, if the encryption type indication information indicates a hash algorithm (such as SHA3-224, SHA3-256, etc.), the preset length is r-4; if it indicates an extensible output function algorithm (such as SHAKE128, SHAKE256), the preset length is r-6. When the valid data length is ≤ the preset length, the mask data is a binary signal with a bit width equal to the preset packet length, where the first valid data length bit is 1 (corresponding to the valid data portion) and the remaining bits are 0 (corresponding to the portion to be padded). The specific generation method is: mask data = {preset packet length {1'b1}} << (preset packet length - valid data length). For example, when the valid data length is 572 bits and the preset packet length is 576 bits, the first 572 bits of the mask data are 1, and the last 4 bits are 0, used to filter the valid data.

[0089] Step b3: perform bitwise AND processing on the last set of data and the mask data to obtain valid data in the last set of data.

[0090] Valid data refers to the portion of the original data that remains after the last set of data is bitwise ANDed with the mask data. Specifically, the bitwise AND operation involves performing a logical AND operation on each bit of the last set of data with the corresponding bit of the mask data. This means that bits that are 1 in the mask data (corresponding to valid data positions) retain the original value of the last set of data, while bits that are 0 in the mask data (corresponding to supplementary zero-valued bits or invalid bits) clear the corresponding bits of the last set of data, ultimately resulting in a result containing only the original valid data.

[0091] Step b4: determining the first padding data corresponding to the last group of data based on the valid data length, the preset packet length and the preset padding sequence.

[0092] The preset padding sequence refers to a predefined fixed bit pattern. The first padding data refers to a padding bit sequence generated according to the valid data length, the preset packet length and the preset padding sequence. Specifically, the preset padding sequence includes an additional suffix (such as the 2-bit "01" of the hash algorithm) and a preset padding value sequence (such as 1-bit "1", several 0s, and 1-bit "1" corresponding to the "pad101" rule). The first padding data needs to cover the remaining bits from the end of the valid data to the preset packet length. The generation method can be to calculate the remaining spaces according to the valid data length (i.e., the preset packet length-valid data length), and fill the remaining spaces with the additional suffix and the preset padding value sequence in sequence. For example, when the valid data length is 572 bits and the preset packet length is 576 bits, the remaining 4 bits are filled with "0111" (including the suffix and padding bits), and finally form the first padding data with a bit width of the preset packet length. Alternatively, after determining the preset padding sequence according to the specific type of encryption method, the shift amount can be calculated according to the valid data length, i.e., the preset packet length-the bit width of the preset padding sequence-valid data length. Finally, the preset padding sequence is left-shifted by the shift amount to generate the first padding data with a bit width of the preset packet length. In this padding data, the preset padding sequence is located exactly at the end of the valid data, and the remaining bits are 0. For example, when the encryption type is the SHA-3 hash function and the valid data length num ≤ r-4, the r-bit-wide signal mask is defined as {r{1'b1}}<<(r–num). The last input data set is bitwise ANDed (&) with the mask, resulting in the valid data for the last set of data. The valid data is then ORed with the r-bit padding value 3'b011<<(r-3-num), resulting in the first padding data. For the scalable output function, the logic is similar, with only the suffix and padding details added to adapt to the rules.

[0093] Step b5: performing bitwise OR processing on the valid data and the first filling data to obtain target filling data.

[0094] When performing a bitwise OR operation, the original bits of the valid data and the padding bits of the first padding data are combined. Specifically, the valid data portion retains the original value, while the padding bits retain the value of the first padding data. The resulting target padding data has a bit width equal to the preset packet length and contains the complete valid data and padding sequence.

[0095] In the above implementation, a mask is dynamically generated based on the valid data length, and invalid bits are removed through a bitwise AND operation, avoiding the redundant data interference found in traditional solutions. Combining the preset packet length with the padding sequence, the position and value of the padding bits are directly calculated, eliminating the software overhead of real-time calculation of the number of padding bits. Bitwise AND and bitwise OR operations can be completed in a single cycle, significantly reducing the processing latency of the last set of data. Therefore, this method, through the hardware synergy of mask isolation and the preset padding sequence, efficiently solves the problem of dynamic padding of the last set of data.

[0096] In some optional implementations, the above step S203 further includes:

[0097] Step c1: If the valid data length is greater than the preset length, determine whether the valid data length is equal to the preset packet length.

[0098] When the effective data length of the last group of data is greater than the preset length, the effective data length is compared with the preset group length. If the values ​​of the two are equal, it is determined that the effective data length is equal to the preset group length.

[0099] Step c2: if the valid data length is equal to the preset packet length, the last group of data is determined as the first packet data corresponding to the last group of data, and the second packet data corresponding to the last group of data is generated based on the preset length and the preset padding sequence.

[0100] First packet data refers to when the valid data length of the last set of data equals the preset packet length, that data block is directly used as the first packet data. Second packet data refers to when the valid data length of the last set of data equals the preset packet length, a new data block is generated based on the preset length and preset padding sequence. Specifically, when the valid data length equals the preset packet length, the last set of original packet data does not require internal padding and is directly determined as the first packet data (retaining the original valid data). The generation of the second packet data must follow the preset padding sequence and preset length. For example, when the encryption type is the SHA-3 hash function algorithm, the preset padding sequence includes appending the suffix "01" and the "pad10*1" rule. Therefore, the second packet data is {3'b011, (r-4){1'b0}, 1'b1} (i.e., first append 3 bits of "011", then pad r-4 zeros in the middle, and finally add 1 bit of "1"), ensuring its length is r and complies with the padding rule. For the extensible output function, the logic is similar, only the appended suffix and padding details are adapted to its rules.

[0101] Step c3: determining target filling data based on the first grouped data and the second grouped data.

[0102] The target padding data must have a total length that is an integer multiple of the preset packet length. When the valid data length is r, the first packet is the original complete packet, and the second packet is the padding packet generated according to the preset padding sequence. The combined total length of the two is 2r, which meets the requirement of being an integer multiple of r. Therefore, the final target padding data can be obtained by sequentially combining the first and second packet data.

[0103] In the above-described embodiment, when the effective data length equals the preset packet length, the original data is directly reused as the first packet data, avoiding invalid conversion. A second padding packet is independently generated based on the preset length and padding sequence, eliminating real-time computational overhead. The dual-packet output is triggered by a simple equation, resulting in a minimal logic circuit that can be completed in a single cycle, completely avoiding the timing bottleneck of dynamically calculating the number of padding bits in traditional solutions. Therefore, this method, through the dual-packet prefabrication mechanism, efficiently solves the boundary padding problem when the effective data length equals the packet length.

[0104] In some optional implementations, the above step S203 further includes:

[0105] Step d1: If the valid data length is greater than the preset length and less than the preset packet length, the second padding data corresponding to the last group of data is determined based on the valid data length, the preset packet length and the preset padding sequence.

[0106] The second padding data refers to the padding bit sequence generated when the valid data length of the last group of data is greater than the preset length and less than the preset packet length. Specifically, when the valid data length is greater than the preset length and less than the preset packet length, the second padding data is determined based on the preset padding sequence and shift logic. For example, when the encryption type is the SHA-3 hash function algorithm, the preset padding sequence contains 3'b011, and the right shift amount (num-r+3) needs to be calculated based on the valid data length num, and 3'b011 is shifted right by this amount (for example, when num=573 and r=576, the right shift amount is 0, that is, 3'b011; when num=574, the right shift is 1 bit to obtain 2'b01), forming a padding value that has a value only at the empty space at the end of the valid data, and then expanding it to a signal with a bit width of r (the remaining bits are 0), which is the second padding data, used to complete the valid part of the last group of data to a length of r.

[0107] Step d2: performing a bitwise OR operation on the last group of data and the second padding data to obtain third grouped data corresponding to the last group of data.

[0108] The third grouped data refers to the completed data block obtained by bitwise ORing the last group of data with the second padding data. Specifically, in the last group of data, the first num bits are valid data, and the remaining r-num bits are invalid bits. In the second padding data, only the r-num bits after the num bits contain the padding value (such as 3'b011 or its shifted result), and the remaining bits are 0. When bitwise ORing is performed, the num bits of the valid data retain the original value, and the invalid bits after the num bits are merged with the padding value of the second padding data, eventually forming a third grouped data with a bit width of r, containing complete valid data and a partial padding sequence, completing the padding of the original group.

[0109] Step d3: Generate a fourth group of data corresponding to the last group of data based on the preset length, the valid data length, the preset group length, and the preset padding sequence.

[0110] The fourth grouped data refers to an additional data block generated based on the preset length, valid data length, etc. when the valid data length of the last group of data is greater than the preset length and less than the preset group length. Specifically, the fourth grouped data is a padding group added to meet the total length of an integer multiple of r, and its generation follows the preset length, valid data length, preset group length, and preset padding sequence. For example, for the hash algorithm, it is necessary to combine num and r to calculate the remaining padding bits (r-(r-num+3)), and fill them according to the "pad10*1" rule (fill 1bit1 first, fill 0 in the middle, and fill 1bit1 at the end). For example, when the encryption type is the SHA-3 hash function algorithm, a (r-1) bit wide signal add_group={3'b011,{(r-4){1'b0}}}<<(r-num) is defined, and the fourth grouped data is {add_group, 1'b1}.

[0111] Step d4: determining target filling data based on the third grouped data and the fourth grouped data.

[0112] The third packet data is the valid data block after the original packet is padded, and the fourth packet data is the newly added padding packet. After the two are spliced ​​in sequence, the total length is 2r (an integer multiple of r) and completely contains the preset padding sequence. Therefore, the spliced ​​result is the target padding data.

[0113] Taking the SHA512 algorithm as an example, r = 576, the padding process can be divided into the following five cases according to the effective length of the last set of data:

[0114] (1) num <= 572 bits, then fill with 3'b011, j'b0, and 1'b1, which does not affect the number of packet data; Figure 5 As shown, when num = 24 bits, fill 3'b011, 548'b0, and 1'b1;

[0115] (2) num=573bit, then we need to add a packet data. The first packet data is padded with 3'b011 at the end, and the second packet data is {575'b0,1'b1}, such as Figure 6 As shown;

[0116] (3) num=574bit, then a packet data needs to be added. The first packet data is padded with 2'b01, and the second packet data is {1'b1,574'b0,1'b1}, such as Figure 7 As shown;

[0117] (4) num=575bit, then a packet data needs to be added. The first packet data is padded with 1'b0, and the second packet data is {2'b11,573'b0,1'b1}, as shown in the following example: Figure 8 As shown;

[0118] (5) num=576bit, then a packet data needs to be added. The first packet data is the original data, and the second packet data is {3'b011,572'b0,1'b1}, such as Figure 9 shown.

[0119] Step S204: iteratively process the target filling data to generate target summary data corresponding to the target data. Figure 3 Step S104 of the illustrated embodiment will not be described in detail here.

[0120] In the above implementation, a preset padding sequence is dynamically offset based on the effective data length, and a third group of data is generated by bitwise or directly merging with the last group of data, avoiding the cache overhead of traditional solutions. A fourth group of data is pre-generated based on the difference between the preset group length and the effective data length, achieving hardware pre-alignment of the padding bits. The synchronous output mechanism of the third and fourth groups compresses the non-aligned padding that would otherwise require multiple cycles to complete into a single cycle. Therefore, this method, through two-level hardware splicing and dynamic offset of the preset sequence, efficiently solves complex padding scenarios involving non-integer multiples of the effective length.

[0121] In this embodiment, a method for generating summary data is provided, which can be used in the above-mentioned system for generating summary data. Figure 10 is a flow chart of a method for generating summary data according to an embodiment of the present application. Figure 10 As shown, the process includes the following steps:

[0122] Step S301: Obtain target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters. The encryption type indication information is used to indicate the type of encryption method. Figure 4 Step S401 of the illustrated embodiment will not be described in detail here.

[0123] Step S302: group the target data according to the encryption type indication information and encryption configuration parameters to obtain multiple group data corresponding to the target data. Figure 4 Step S402 of the illustrated embodiment will not be described in detail here.

[0124] Step S303: Fill each packet data according to the data filling rule corresponding to the encryption method to obtain the target filling data corresponding to each packet data. Figure 4 Step S403 of the illustrated embodiment will not be described in detail here.

[0125] Step S304: iteratively process the target filling data to generate target summary data corresponding to the target data.

[0126] Specifically, the above step S304 includes:

[0127] Step S3041: Obtain the initial state value, capacity value, and digest length corresponding to the encryption type indication information.

[0128] The initial state value refers to the initial state parameter at the start of the iterative process, denoted as S0. For example, the initial state value of the SHA3 algorithm is a 1600-bit all-zero value. The capacity value refers to the algorithm capacity parameter corresponding to the encryption type indication information, denoted as c. Its relationship to the preset packet length r is b = r + c, where b is a fixed value of 1600 bits. The digest length refers to the fixed length of the final output digest data corresponding to the encryption method, which is determined by the encryption type indication information. Specifically, the encryption type indication information specifies the specific encryption method, through which the corresponding parameters are matched from a predefined parameter table, including the initial state value being a fixed 1600-bit all-zero value; the capacity value is determined according to the encryption method (e.g., c = 1024 bits for SHA3-512, c = 512 bits for SHA3-256, and c = 256 bits for SHAKE128); and the digest length is determined by the encryption method (e.g., 224 bits for SHA3-224 and 256 bits for SHA3-256) and is directly associated with the encryption type indication information.

[0129] Step S3042: Fill the target filling data according to the capacity value to obtain third filling data.

[0130] The third padding data refers to the data obtained by padding the target padding data with zeros according to the capacity value. Specifically, the target padding data Pi is a packet data with a length equal to the preset packet length. According to the rules of the encryption algorithm absorption phase, it is necessary to add zero-valued bits with a length equal to the capacity value at the end of the target padding data to make the total length equal to the fixed value b = 1600 bits (because b = r + c). For example, for SHA3-512 (r = 576 bits, c = 1024 bits), the target padding data (576 bits) is supplemented with 1024 bits of zeros to form 1600 bits of data, namely the third padding data Pi||0c.

[0131] Step S3043: perform an XOR process on the third filling data and the initial state value to obtain an XOR result.

[0132] The XOR result refers to the result of the bitwise XOR operation between the third filling data and the initial state value. Specifically, the third filling data is P i ||0 c , the initial state value is S0, and the XOR processing is to perform a logical XOR operation on each bit, and perform XOR on each bit of the third filling data and the corresponding bit of the initial state value (that is, 1⊕1=0, 1⊕0=1, 0⊕0=0). The result is the XOR result, which is used as the input of the subsequent mapping function.

[0133] Step S3044: Process the XOR result according to a preset mapping rule to obtain a target state value.

[0134] The preset mapping rule refers to the fixed operation rule for converting the XOR result in the iterative process. The target state value refers to the new state value obtained after the XOR result is processed by the preset mapping rule, which is denoted as S i+1 Specifically, the preset mapping rule is the f function of the encryption algorithm, which includes five mapping functions with 24 rounds of iterations. The column XOR is calculated by the θ function, and the 25 lanes are cyclically shifted by the ρ function. The Slice is then transposed by the π function, and the row bits are combined by the χ function. Finally, the specific bits are modified by the τ function combined with the round constant (RC). After the XOR result is processed by these 24 complete rounds of mapping functions, the generated 1600-bit new state value is the target state value S i+1 .

[0135] in, f=τ(χ(π(ρ(θ(A)))),i r ), 0≤i r ≤23. Specifically, θ(A) represents the process of XORing the 5 bits in the two columns surrounding a certain bit and then XORing them with the bit. The formula is:

[0136]

[0137] ρ(A) is the cyclic shift of 25 lanes, as shown in Table 1, and is the offset of different lanes.

[0138] Table 1

[0139] x=3 x=4 x=0 x=1 x=2 y=2 153 231 3 10 171 y=1 55 276 36 300 6 y=0 28 91 0 1 190 y=4 120 78 210 66 253 y=3 21 136 105 45 15

[0140] π(A) is a fixed transposition of Slice, and the formula is: A'[x,y,z]=A[(x+3y)mod 5,x,z].

[0141] χ(A) is the bit combination of row, the formula is:

[0142] τ(A,i r ) is to modify some bits of Lane(0,0), where 0≤i r ≤23, the formula is:

[0143] RC=0 w ;

[0144] RC[2 j -1]=rc(j+7i r );

[0145]

[0146] RC is first initialized to all 0s of w bits, and then some bits are modified. The value of RC is related to the number of rounds of function f. Its value in 24 rounds is shown in Table 2.

[0147] Table 2

[0148]

[0149] Step S3045: intercept the target state value according to the digest length to obtain target digest data.

[0150] The target state value is the final state obtained after the absorption phase is completed, denoted as S n Since the length of r in the encryption algorithm is always greater than the required digest length (such as r = 1088 bits for SHA3-256, and the digest length is 256 bits), there is no need to execute the f function in the squeeze phase, and the S n The target summary data can be obtained by intercepting the first N bits (N is the digest length) of the r-bit output part. For example, in the SHA3-256 algorithm, the first 256 bits of the r=1088-bit data (Z0) output in the absorption phase are the final target summary data. Figure 11As shown, the absorption phase is the core link of the encryption algorithm to compress the packet data into a state value. The initial state S0 is determined and the input packet P is i , first with the current state S i Perform bitwise XOR operation to obtain the intermediate result, and then process the intermediate result through multiple rounds of f function to generate a new state S i+1 Repeat this process to process all input packets (P0 to P n-1 ), and finally the final state S of the absorption stage is obtained n , completing the compression conversion of data features to state values. The compression phase is the output link of the encryption algorithm to generate a summary from the state value. First, the final state S of the absorption phase is generated. n The first r bits are extracted as the first output block Z0. Theoretically, Z0 can generate an infinite length output sequence (such as Z1, Z2, etc.) through the iteration of the f function. However, since the block length r of the encryption algorithm is always greater than the target digest length, in practice, the final digest value can be obtained by directly intercepting the first N bits of Z0 (N is the target digest length) without performing multiple f function iterations.

[0151] The digest data generation method provided in this embodiment obtains the initial state value, capacity value, and digest length based on encryption type indication information, enabling the same hardware to adapt to all encryption algorithm variants. This method directly implements bit-splitting circuitry to append zeros to the target padding data according to the capacity value, eliminating software intervention. XOR processing and pre-set mapping rules form a fixed-cycle operation chain, enabling deep pipelined execution of multiple permutation rounds. Therefore, this method achieves standardized and efficient execution of the encryption algorithm iteration phase through parameterized sponge structure hardware mapping.

[0152] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0153] This embodiment provides a device for generating summary data, such as Figure 12 As shown, including:

[0154] An acquisition module 1201 is configured to acquire target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters, where the encryption type indication information indicates the type of encryption method.

[0155] The grouping module 1202 is configured to group the target data according to the encryption type indication information and the encryption configuration parameters to obtain a plurality of grouped data corresponding to the target data;

[0156] The filling module 1203 is used to perform filling processing on each packet data according to the data filling rule corresponding to the encryption method to obtain the target filling data corresponding to each packet data;

[0157] The generating module 1204 is configured to iteratively process the target filling data to generate target summary data corresponding to the target data.

[0158] In some optional implementations, the grouping module 1202 includes:

[0159] A first determining submodule, configured to determine a preset packet length according to the encryption type indication information;

[0160] A counting submodule, configured to count the bit width of the target data according to the encryption configuration parameters and determine the bit width value of the target data;

[0161] The grouping submodule is used to group the target data based on the relationship between the bit width value and the preset group length to obtain multiple group data corresponding to the target data.

[0162] In some optional implementations, the encryption configuration parameter includes a single input bit width corresponding to the target data; and the grouping submodule includes:

[0163] A first grouping unit, configured to output packet data having a bit width equal to the preset packet length when the bit width value is equal to the preset packet length;

[0164] The second grouping unit is configured to, when the bit width value is less than the preset group length and the target data transmission is completed, supplement the remaining target data with zero-valued bits to the preset group length to obtain grouped data;

[0165] The third grouping unit is used to cache target data according to a preset period when the preset group length and the single input bit width do not satisfy an integer multiple relationship, and generate group data with a bit width equal to the preset group length according to a preset bit splicing rule.

[0166] In some optional implementations, the filling module 1203 includes:

[0167] A second determining submodule, configured to determine a first additional suffix bit corresponding to the packet data based on the encryption type indication information;

[0168] an appending submodule, configured to append a first appending suffix bit to the end of the packet data to obtain first target packet data;

[0169] The first filling submodule is used to fill the end of the first target packet data with a first preset filling value of a first preset number of bits, a second preset filling value of a second preset number of bits, and a third preset filling value of a third preset number of bits in sequence to obtain target filling data.

[0170] In some optional implementations, the filling module 1203 further includes:

[0171] A first acquisition submodule is used to acquire the last group of data in the plurality of grouped data, and the effective data length of the last group of data;

[0172] A first generating submodule is configured to generate mask data based on the valid data length and a preset packet length corresponding to the encryption type indication information if the valid data length is less than or equal to the preset length;

[0173] The first processing submodule is used to perform bitwise AND processing on the last set of data and the mask data to obtain valid data in the last set of data;

[0174] A third determining submodule, configured to determine first padding data corresponding to the last group of data based on the valid data length, the preset packet length, and the preset padding sequence;

[0175] The second processing submodule is configured to perform a bitwise OR process on the valid data and the first filling data to obtain target filling data.

[0176] In some optional implementations, the filling module 1203 further includes:

[0177] A judgment submodule, configured to judge whether the valid data length is equal to a preset packet length if the valid data length is greater than a preset length;

[0178] a second generating submodule, configured to determine the last group of data as the first group of data corresponding to the last group of data if the valid data length is equal to the preset group length, and generate the second group of data corresponding to the last group of data based on the preset length and the preset padding sequence;

[0179] The fourth determining submodule is configured to determine target filling data based on the first grouped data and the second grouped data.

[0180] In some optional implementations, the filling module 1203 further includes:

[0181] a fifth determining submodule, configured to determine, if the valid data length is greater than a preset length and less than a preset packet length, second padding data corresponding to the last group of data based on the valid data length, the preset packet length, and the preset padding sequence;

[0182] A third processing submodule is used to perform bitwise OR processing on the last group of data and the second padding data to obtain third grouped data corresponding to the last group of data;

[0183] A third generating submodule, configured to generate a fourth group of data corresponding to the last group of data based on a preset length, a valid data length, a preset group length, and a preset padding sequence;

[0184] The sixth determining submodule is configured to determine target filling data based on the third grouped data and the fourth grouped data.

[0185] In some optional implementations, the generating module 1204 includes:

[0186] The second acquisition submodule is used to obtain the initial state value, capacity value and digest length corresponding to the encryption type indication information;

[0187] A second filling submodule is used to fill the target filling data according to the capacity value to obtain third filling data;

[0188] a fourth processing submodule, configured to perform an XOR process on the third filling data and the initial state value to obtain an XOR result;

[0189] A fifth processing submodule is used to perform data processing on the XOR result according to a preset mapping rule to obtain a target state value;

[0190] The interception submodule is used to intercept the target state value according to the summary length to obtain the target summary data.

[0191] For the description of the features in the embodiment corresponding to the summary data generating device, reference can be made to the relevant description of the embodiment corresponding to the summary data generating method, which will not be repeated here.

[0192] The embodiment of the present application also provides an electronic device, such as Figure 13 As shown, it includes a memory 10 and a processor 20. The memory 10 stores a computer program, and the processor 20 is configured to run the computer program to execute the steps in any of the above-mentioned summary data generation method embodiments.

[0193] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps of any of the above-mentioned summary data generation method embodiments when running.

[0194] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.

[0195] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps of any of the above-mentioned summary data generation method embodiments are implemented.

[0196] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of any of the above-mentioned summary data generation method embodiments are implemented.

[0197] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0198] The above is a detailed introduction to a method, system and storage medium for generating summary data provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of ​​the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the claims of the present application.

Claims

1. A method for generating summary data, characterized in that: include: Obtain target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters, wherein the encryption type indication information is used to indicate the type of encryption method; performing grouping processing on the target data according to the encryption type indication information and the encryption configuration parameters to obtain a plurality of grouped data corresponding to the target data; Performing padding processing on each of the grouped data according to the data padding rule corresponding to the encryption method to obtain target padding data corresponding to each of the grouped data; Iteratively process the target filling data to generate target summary data corresponding to the target data.

2. The method for generating summary data according to claim 1, wherein: The performing grouping processing on the target data according to the encryption type indication information and the encryption configuration parameters to obtain a plurality of grouped data corresponding to the target data includes: Determining a preset packet length according to the encryption type indication information; Counting the bit width of the target data according to the encryption configuration parameter to determine the bit width value of the target data; Based on the relationship between the bit width value and the preset group length, the target data is grouped to obtain a plurality of grouped data corresponding to the target data.

3. The method for generating summary data according to claim 2, wherein: The encryption configuration parameter includes a single input bit width corresponding to the target data; and the grouping processing of the target data based on the relationship between the bit width value and the preset group length to obtain a plurality of grouped data corresponding to the target data includes: When the bit width value is equal to the preset packet length, outputting packet data with a bit width equal to the preset packet length; When the bit width value is less than the preset packet length and the target data transmission is completed, the remaining target data is supplemented with zero-valued bits to the preset packet length to obtain packet data; When the preset packet length and the single input bit width do not satisfy an integer multiple relationship, the target data is cached according to a preset period, and packet data with a bit width equal to the preset packet length is generated according to a preset bit splicing rule.

4. The method for generating summary data according to claim 1, wherein: The step of performing filling processing on each of the grouped data according to the data filling rule corresponding to the encryption method to obtain target filling data corresponding to each of the grouped data includes: Determining a first additional suffix bit corresponding to the packet data based on the encryption type indication information; Adding the first additional suffix bit to the end of the packet data to obtain first target packet data; At the end of the first target packet data, a first preset filling value of a first preset number of bits, a second preset filling value of a second preset number of bits, and a third preset filling value of a third preset number of bits are sequentially filled to obtain the target filling data.

5. The method for generating summary data according to claim 1, wherein: The method further comprises: performing filling processing on each of the grouped data according to the data filling rule corresponding to the encryption method to obtain target filling data corresponding to each of the grouped data. Obtaining a last group of data from the plurality of grouped data, and a valid data length of the last group of data; If the valid data length is less than or equal to the preset length, generating mask data based on the valid data length and the preset packet length corresponding to the encryption type indication information; Performing bitwise AND processing on the last set of data and the mask data to obtain valid data in the last set of data; Determining first padding data corresponding to the last group of data based on the valid data length, the preset packet length, and a preset padding sequence; Performing a bitwise OR operation on the valid data and the first filling data to obtain the target filling data.

6. The method for generating summary data according to claim 5, wherein: The method further comprises: If the valid data length is greater than the preset length, determining whether the valid data length is equal to the preset packet length; If the valid data length is equal to the preset packet length, determining the last group of data as the first packet data corresponding to the last group of data, and generating the second packet data corresponding to the last group of data based on the preset length and the preset padding sequence; The target filling data is determined based on the first group data and the second group data.

7. The method for generating summary data according to claim 6, wherein: The method further comprises: If the valid data length is greater than the preset length and less than the preset packet length, determining second padding data corresponding to the last group of data based on the valid data length, the preset packet length, and the preset padding sequence; Performing a bitwise OR operation on the last group of data and the second padding data to obtain third grouped data corresponding to the last group of data; Generate a fourth group of data corresponding to the last group of data based on the preset length, the valid data length, the preset group length, and the preset padding sequence; The target filling data is determined based on the third grouped data and the fourth grouped data.

8. The method for generating summary data according to claim 1, wherein: The iterative processing of the target filling data to generate target summary data corresponding to the target data includes: Obtaining the initial state value, capacity value, and digest length corresponding to the encryption type indication information; Filling the target filling data according to the capacity value to obtain third filling data; Performing an XOR process on the third filling data and the initial state value to obtain an XOR result; According to a preset mapping rule, data processing is performed on the XOR result to obtain a target state value; According to the summary length, data interception is performed on the target state value to obtain the target summary data.

9. A system for generating summary data, characterized in that: include: The data bridging module includes a plurality of data input interfaces, wherein the plurality of data input interfaces are used to receive target data to be processed, encryption type indication information corresponding to the target data, and encryption configuration parameters, wherein the encryption type indication information is used to indicate a type of encryption method; the data bridging module is used to group the target data according to the encryption type indication information and the encryption configuration parameters to obtain a plurality of grouped data corresponding to the target data; a data filling module connected to the data bridging module, configured to perform filling processing on each of the packet data according to the data filling rule corresponding to the encryption method, to obtain target filling data corresponding to each of the packet data; A data iteration module is connected to the data filling module, and is used for iteratively processing the target filling data to generate target summary data corresponding to the target data.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the steps of the method for generating summary data according to any one of claims 1 to 8 are implemented.