Hardware implementation device and method compatible with ASCON cryptographic algorithm family

By designing a hardware implementation device compatible with the Ascon algorithm family, and uniformly handling Ascon-128 encryption/decryption, Ascon-128a encryption/decryption, Ascon-hash, and Ascon-hasha algorithms, the problems of hardware resource consumption and computational complexity are solved, achieving efficient hardware deployment and improved data throughput.

CN120880658AActive Publication Date: 2025-10-31NANJING UNIV
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511344093.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-19
Publication Date
2025-10-31
Estimated Expiration
2045-09-19

AI Technical Summary

Technical Problem

Existing technologies struggle to be compatible with the AEAD and hash branches of the Ascon algorithm family on the same hardware circuit, leading to increased hardware resource consumption, higher computational complexity, and lower clock frequency, thus failing to fully realize the performance potential of specific modes.

Method used

Design a hardware implementation device and method compatible with the Ascon cryptographic algorithm family. By combining an initialization processing module, a related data processing module, an input data processing module, and a termination processing module, it can uniformly process Ascon-128 encryption and decryption, Ascon-128a encryption and decryption, Ascon-hash, and Ascon-hasha algorithms. It adopts pre-computation optimization techniques and permutation operations to achieve the fusion and pipelined processing of different algorithms.

Benefits of technology

It improves the hardware deployment efficiency and compatibility of the Ascon algorithm family, increases data throughput, provides a foundation for efficient deployment in different application scenarios, and reduces hardware resource consumption and computational complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880658A_ABST
    Figure CN120880658A_ABST
Patent Text Reader

Abstract

The invention relates to a hardware implementation device and method compatible with an Ascon algorithm family, and belongs to the field of digital integrated circuit design optimization and cryptography. The method comprises the following steps of: uniformly dividing an algorithm of Ascon-128 encryption and decryption, an algorithm of Ascon-128 encryption and decryption, an algorithm of Ascon-128 encryption and decryption, an algorithm of Ascon-hash and an algorithm of Ascon-hash into four processing stages: initialization processing, related data processing, input data processing and termination processing; streamlined processing is carried out on the four processing stages to improve the data throughput rate; the hardware deployment efficiency and compatibility of the Ascon algorithm family are improved, and a foundation is laid for efficient deployment of the Ascon algorithm in different application scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a hardware implementation device and method compatible with the Ascon cryptographic algorithm family, belonging to the fields of digital integrated circuit design optimization and cryptography. Background Technology

[0002] With the widespread application of IoT technology, countless miniature smart terminals are changing people's lives and work, from smart homes to industrial monitoring, from implantable medical devices to in-vehicle systems. These devices typically have limited processing power, limited storage space, and constrained energy supply, yet they bear the responsibility of collecting and transmitting large amounts of sensitive data. The theft or tampering of this sensitive data could lead to serious consequences. Therefore, lightweight, efficient, and secure encryption solutions are needed.

[0003] The Ascon algorithm is a lightweight authentication encryption and hashing algorithm jointly developed by a team of cryptographers from Graz University of Technology, Infineon Technologies, and Radboud University. Compared with existing algorithms, Ascon provides a more comprehensive solution, supporting both authentication encryption / decryption and hashing functions, offering comprehensive protection for IoT security. This algorithm excels in security, resource consumption, processing speed, flexibility, and compatibility, making it particularly suitable for security applications in resource-constrained environments.

[0004] The Ascon algorithm family primarily consists of the AEAD (Authorized Encryption with Associated Data) branch and the hash branch. The AEAD branch provides both confidentiality and integrity protection, its core principle being a nonce-based encryption authentication process. By generating an authentication tag, it ensures data integrity during transmission, primarily used in IoT devices and mobile communications to guarantee data integrity and confidentiality. The main algorithms in this branch are Ascon-128 and Ascon-128a. The hash branch, on the other hand, generates fixed-length hash values ​​to ensure data integrity, and is often used for both data integrity and authentication. The main algorithms in this branch are Ascon-hash and Ascon-hasha.

[0005] While the Ascon algorithm family has matured in software algorithm design, hardware compatibility and design optimization for this algorithm family still need to be improved. In the article "Scalable and efficient hardware architectures for authenticated encryption in IoT applications[J]. IEEE Internet of Things Journal, 2021, 8(14): 11260-11275.", Safiullah Khan proposed a fully expanded architecture and a round processing architecture to implement the Ascon algorithm family. The fully expanded architecture achieves complete encryption in a single cycle through combinational circuits, eliminating the need for intermediate registers and improving performance. The round processing architecture performs multiple rounds of permutation in a single cycle, dynamically balancing throughput and area, and improving the throughput-to-area ratio. Although this scheme implements the Ascon-128 and Ascon-128a algorithms, the encryption and decryption algorithms are calculated through two independent modules, resulting in additional hardware overhead and not being compatible with hash branch algorithms. In their paper "A hardware architecture of NIST lightweight cryptography applied in IPSec to secure high-throughput low-latency IoT networks[J]. IEEE Access, 2023, 11: 89240-89248," SY-NAM TRAN proposed a high-performance, low-latency hardware architecture suitable for the Ascon algorithm and described its implementation on an FPGA, evaluating the method for the IPSec ESP protocol. While this method implements both Ascon-128a encryption and decryption modes in the same module, it does not implement Ascon-128 and Ascon hash modes.In his paper "Asic implementation of asconlightweight cryptography for IoT applications[J]. IEEE Transactions on Circuits and Systems II: Express Briefs, 2024," NGUYEN KD implemented the Ascon encryption algorithm on a RISC-V SoC, achieving a maximum frequency of 294MHz, and for the first time measured the Ascon implementation on a physical chip. This method can implement five modes, including Ascon-128 encryption / decryption, Ascon-128a encryption / decryption, and Ascon-Hash. However, its implementation is still modular, calling the substitution module within modules operating in different modes, without optimizing and integrating different algorithms; this still results in additional hardware resource consumption.

[0006] Therefore, hardware circuits that are compatible with both AEAD and hash branches are of great significance for the efficient deployment of the Ascon algorithm family in IoT devices. This allows encryption and decryption algorithms and hash algorithms with different algorithm stages to be implemented on the same hardware circuit, which saves the additional overhead introduced by discrete design and supports different application scenarios.

[0007] However, although Ascon's four algorithm modes are based on the same permutation primitive, the number of permutation rounds, the processing width of the core data block, and the operation flow and control logic required by different algorithms are completely different. Deploying these six different algorithms on the same hardware circuit will inevitably require more complex hardware design, consume more computing and storage resources, and lead to an increase in hardware circuit area and power consumption. Moreover, different algorithms require different control logic, involving different allocation of hardware resources and coordination of software resources. It is impossible to fully utilize the 128-bit performance potential of specific modes (such as 128a and hasha), and simultaneously being compatible with different algorithms will increase computational complexity and hardware resource consumption, which will lead to a decrease in clock frequency and affect the final performance.

[0008] Therefore, in order to solve the problems existing in the above-mentioned prior art, it is necessary to design an efficient hardware circuit that can support Ascon-128 encryption and decryption, Ascon-128a encryption and decryption, Ascon-hash, and Ascon-hasha. Summary of the Invention

[0009] To achieve good compatibility between AEAD and hash branches in hardware deployment of the Ascon algorithm family and further promote the efficient hardware deployment of the Ascon algorithm family, this invention proposes a hardware implementation device and method compatible with the Ascon algorithm family.

[0010] The first objective of this invention is to provide a hardware implementation device compatible with the Ascon cryptographic algorithm family, the device comprising: an initialization processing module process_initial, a related data processing module process_A, an input data processing module process_I, and a termination processing module process_final; The initialization module `process_initial`, the related data processing module `process_A`, the input data processing module `process_I`, and the termination module `process_final` receive clock signals `clk` and reset signals `rstn` from outside the device. `INIT` represents the data processed and output by the initialization module `process_initial`, `PA_PI` represents the data processed and output by the related data processing module `process_A`, and `PI_FINAL` represents the data processed and output by the input data processing module `process_I`. `FINAL_PI_ready` indicates that the termination module `process_final` is idle, `PI_PA_ready` indicates that the input data processing module `process_I` is idle, and `PA_INIT_ready` indicates that the related data processing module `process_A` is idle.

[0011] The inputs to the initialization processing module process_initial are the input data validity signal I_valid_input, the mode selection signal I_mode, the related data I_data_A, the length of the related data I_data_A I_length_A, the input data I_data_I, the length of the input data I_data_I I_length_I, the input key I_data_K, the public information code I_data_N, the authentication tag I_data_T, and the ready signal PA_INIT_ready from the related data processing module process_A. The output signals of the initialization module `process_initial` are connected to the inputs of the related data processing module `process_A`. The outputs of `process_initial` are: the output data validity signal `INIT_PA_valid` for the related data processing module `process_A`, the mode selection signal `INIT_PA_mode` for the related data processing module `process_A`, the key `INIT_PA_data_K` for the related data processing module `process_A`, the output status `INIT_PA_data_S` for the initialization module `process_initial`, the related data output by the initialization module `process_initial` `INIT_PA_data_A`, the length of the related data output by the initialization module `process_initial` `INIT_PA_length_A`, the input data of the related data processing module `process_A` `INIT_PA_data_I`, the length of the input data of the related data processing module `process_A` `INIT_PA_length_I`, and the authentication tag `INIT_PA_data_T` for the input data of the related data processing module `process_A`.

[0012] The relevant data processing module process_A receives signals from the initialization processing module process_initial and the ready signal PI_PA_ready from the input data processing module process_I. It outputs the valid signal PA_PI_valid for the input data processing module process_I, the mode selection signal PA_PI_mode for the input data processing module process_I, the key PA_PI_data_K for the input data processing module process_I, the output status PA_PI_data_S of the relevant data processing module process_A, the input data PA_PI_data_I of the input data processing module process_I, the length of the input data PA_PI_length_I of the input data processing module process_I, and the tag input data PA_PI_data_T of the input data processing module process_I. The input of the input data processing module process_I is the output of the relevant data processing module process_A and the ready signal FINAL_PI_ready from the termination processing module process_final; the outputs are the output validity signal PI_FINAL_valid for the termination processing module process_final, the mode selection signal PI_FINAL_mode for the termination processing module process_final, the key PI_FINAL_data_K for the termination processing module process_final, the output status PI_FINAL_data_S for the input data processing module process_I, the output data block PI_FINAL_data_O for the input data processing module process_I, the length of the output data block PI_FINAL_length_O for the input data processing module process_I, and the output tag PI_FINAL_data_T for the input data processing module process_I.

[0013] The input to the termination processing module process_final is the output of the input data processing module process_I. The outputs are the top-level Ascon_top output valid signal O_valid_output, the top-level Ascon_top output data O_data_O, the length of the top-level Ascon_top output data O_length_O, and the output label of the top-level Ascon_top output data O_data_T.

[0014] The initialization module `process_initial` performs an OR operation on the input key `I_data_K`, algorithm feature `IV`, and public information code `I_data_N` in authentication and encryption / decryption mode. Then, it performs `a` rounds of permutation on the OR result and performs a bitwise XOR operation with the padded key `padding_data_K` to obtain the output state `INIT_PA_data_S` of the initialization module `process_initial`. In hash mode, it uses pre-computation optimization techniques to assign the pre-computation optimized result to the output state `INIT_PA_data_S` of the initialization module `process_initial`. The related data processing module `process_A` is used to segment the related data `INIT_PA_data_A` output by the initialization processing module `process_initial` into data blocks, padding it with bits that are multiples of `r`, resulting in a data block length of `r`. When the length of the related data `INIT_PA_data_A` output by the initialization processing module `process_initial` is 0, no padding is needed in encryption / decryption mode, but in hash mode, it needs to be padded to a data block of `r` bits. Subsequently, the module absorbs the related data `INIT_PA_data_A` output by the initialization processing module `process_initial` into the output state `INIT_PA_data_S`, and finally outputs the output state `PA_PI_data_S` of the related data processing module `process_A`. The input data processing module process_I is used to implement plaintext processing for encryption algorithms, ciphertext processing for decryption algorithms, and terminalization operations for hash algorithms. First, it performs compatible encryption / decryption and hash algorithm fusion and padding operations on the input data PA_PI_data_I of the input data processing module process_I. Then, it performs data block segmentation. Finally, it performs b rounds of permutation operations with the output state PA_PI_data_S of the relevant data processing module process_A to obtain the output data block PI_FINAL_data_O and the output state PI_FINAL_data_S of the input data processing module process_I.

[0015] The termination processing module `process_final` performs b rounds of permutation operations on the output state `PI_FINAL_data_S` of the input data processing module `process_I` in encryption / decryption mode to obtain the termination state `S_FNL`. Then, it XORs the last 128 bits of `S_FNL` with the last 128 bits of the termination processing module `process_final`'s key `PI_FINAL_data_K` to calculate the output tag `O_data_T` of the top-level `Ascon_top` output data. In hash mode, the authentication tag is not calculated, and the top-level `Ascon_top` output data `O_data_O` is directly output.

[0016] Furthermore, the initialization processing module process_initial includes permu and pre-stored hash state values; permu is used to implement a round of permutation operation on the output state INIT_PA_data_S of the initialization processing module process_initial in authentication and encryption / decryption mode, while the pre-stored hash state values ​​are used to assign the corresponding state values ​​to the output state INIT_PA_data_S of the initialization processing module process_initial in hash mode.

[0017] Furthermore, the relevant data processing module process_A includes relevant data distribution data_disb_A and relevant data calculation cal_A. The relevant data distribution data_disb_A is used to perform padding operations on the relevant data INIT_PA_data_A output by the initialization processing module process_initial and divide it into multiple data blocks, which are then output to the relevant data calculation cal_A in order from high bit to low bit for calculation. The relevant data calculation cal_A, after receiving the output state INIT_PA_data_S from the initialization processing module process_initial, performs XOR and permutation operations with the data blocks divided by the relevant data distribution data_disb_A to obtain the output state PA_PI_data_S of the relevant data processing module process_A.

[0018] Furthermore, the input data processing module process_I includes input data distribution data_disb_I and input data calculation cal_I. Input data distribution data_disb_I is used to perform padding operations on the input data PA_PI_data_I received from the input data processing module process_I and divide it into multiple data blocks, which are then output to the input data calculation cal_I in order from high bit to low bit for calculation. Input data calculation cal_I, after receiving the output state PA_PI_data_S of the relevant data processing module process_A, performs XOR and permutation operations with the data block passed in by the input data distribution data_disb_I to generate the output state PI_FINAL_data_S and the output data block PI_FINAL_data_O of the input data processing module process_I.

[0019] Furthermore, the termination processing module process_final receives the output state PI_FINAL_data_S from the input data processing module process_I, and then performs a rounds of permutation operations on the output state PI_FINAL_data_S to obtain the termination state S_FNL. The last 128 bits of S_FNL are then XORed with the last 128 bits of the key PI_FINAL_data_K of the termination processing module process_final to calculate the output tag O_data_T of the top-level Ascon_top output data. In hash mode, the authentication tag is not calculated, and the top-level Ascon_top output data O_data_O is directly output.

[0020] A second objective of this invention is to provide a method for implementing a hardware device compatible with the Ascon cryptographic algorithm family, the method comprising: (1) The inputs of this device are the mode selection signal I_mode, the input key I_data_K, the public information code I_data_N, the relevant data I_data_A and its length I_length_A, and the input data I_data_I and its length I_length_I. The initialization processing module process_initial performs the corresponding operation according to the mode selection signal I_mode; If it is in encryption / decryption mode, then perform 12 rounds of permutation operations on data_S_init to obtain the output status INIT_PA_data_S of the initialization processing module process_initial; If it is hash mode, the state value pre-stored in the hardware is assigned to the output state INIT_PA_data_S of the initialization processing module process_initial.

[0021] (2) Subsequently, the relevant data processing module process_A calculates the relevant data INIT_PA_data_A output by the initialization processing module process_initial and the output state INIT_PA_data_S of the initialization processing module process_initial, and generates the output state PA_PI_data_S of the relevant data processing module process_A. The relevant data processing module includes relevant data distribution data_disb_A and relevant data calculation cal_A; The related data distribution data_disb_A will perform padding operations on the related data INIT_PA_data_A received from the initialization processing module process_initial and divide it into multiple data blocks A1, A2, ..., A sThe data is output sequentially from the most significant bit to the least significant bit and then into the relevant data calculation cal_A. The relevant data calculation cal_A receives the output state INIT_PA_data_S from the initialization processing module process_initial, performs XOR and permutation operations with the data block passed in by the relevant data distribution data_disb_A to generate a new state, and calculates this new state with the new round of relevant data blocks until the last data block is calculated. Finally, it outputs the output state PA_PI_data_S from the relevant data processing module process_A.

[0022] (3) Next, the input data processing module process_I is used to receive the input data PA_PI_data_I and the output state PA_PI_data_S of the related data processing module process_A, perform calculations, generate the processed output state PI_FINAL_data_S of the input data processing module process_I and the output data block PI_FINAL_data_O of the input data processing module process_I without shift processing, and temporarily store the received K and pattern. After processing, all data is output to the next stage. The input data processing module includes input data distribution data_disb_I and input data calculation cal_I. The input data distribution module `data_disb_I` performs padding on the input data `PA_PI_data_I` received from the input data processing module `process_I` and divides it into multiple data blocks `I1`, `I2`, ..., `I`. s The data is output sequentially from the most significant bit to the least significant bit and then fed into the input data calculation cal_I. The function of input data calculation cal_I is to receive the output state PA_PI_data_S of the relevant data processing module process_A, perform XOR and permutation operations with the relevant data block passed in by input data distribution data_disb_I, generate a new state and the output data block PI_FINAL_data_O of the input data processing module process_I, calculate the new state with the new round of input data blocks, until the last data block is calculated, and output the output state PI_FINAL_data_S and the output data block PI_FINAL_data_O of the input data processing module process_I.

[0023] (4) Finally, the termination processing module process_final receives the output status PI_FINAL_data_S of the input data processing module process_I and the output data block PI_FINAL_data_O of the input data processing module process_I. The termination processing module process_final first performs a shift operation on the output data block PI_FINAL_data_O of the input data processing module process_I until the valid data of the output data block PI_FINAL_data_O of the input data processing module process_I is shifted to the least significant bit of the register, thus obtaining the output data O_data_O of the top layer Ascon_top. In hash mode, the termination processing module process_final only outputs the top-level Ascon_top output data O_data_O; In encrypted mode, the termination processing module `process_final` performs a bitwise XOR operation on the output states `PI_FINAL_data_S` and `padding_data_K` of the input data processing module `process_I`, followed by 12 rounds of permutations to form a new state `S_FNL`. The lowest 128 bits of this generated `S_FNL` are then XORed with the key `PI_FINAL_data_K` of the termination processing module `process_final` to generate the output tag `O_data_T` for the top-level Ascon_top output data. Finally, the termination processing module `process_final` outputs the top-level Ascon_top output data `O_data_O` and the output tag `O_data_T`. In decryption mode, the termination processing module `process_final` performs a bitwise XOR operation on the output state `PI_FINAL_data_S` and `padding_data_K` of the input data processing module `process_I`, followed by 12 rounds of permutations to form a new state `S_FNL`. The lowest 128 bits of this generated `S_FNL` are then XORed with the key `PI_FINAL_data_K` of the termination processing module `process_final` to generate the output tag `O_data_T` of the top-level Ascon_top output data. The termination processing module `process_final` compares the output tag `O_data_T` of the top-level Ascon_top output data with the output tag `PI_FINAL_data_T` of the input data processing module `process_I`. If they match, the value of data `O_data_O` is output; otherwise, -1 is output.

[0024] The beneficial effects of this invention are: This invention discloses a hardware implementation device and method compatible with the Ascon cryptographic algorithm family. By analyzing the initialization stages of Ascon-128 encryption / decryption, Ascon-128a encryption / decryption, Ascon-hash, and Ascon-hasha, and combining pre-computation optimization techniques, the different initialization stages of these algorithms are converted into a unified initialization process. Subsequently, by padding and segmenting the relevant data I_data_A (different modes perform the same padding operation on data A with a non-zero length), the associated data processing stage of the encryption / decryption algorithm and the information absorption stage of the hash algorithm are fused. Then, by fusion and padding the input data I_data_I, the plaintext processing of the encryption algorithm, the ciphertext processing of the decryption algorithm, and the termination processing of the hash algorithm are fused and unified. Finally, the termination processing module completes the termination output of the encryption / decryption algorithm and the hash algorithm according to different mode information. This invention unifies these six algorithms into four major processing stages: initialization processing, related data processing, input data processing, and termination processing. Each processing stage supports different processing stages for encryption / decryption algorithms and hash algorithms, and the four processing stages are piped to improve data throughput. This improves the hardware deployment efficiency and compatibility of the Ascon algorithm family, laying the foundation for the efficient deployment of Ascon algorithms in different application scenarios. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0026] Figure 1 A schematic diagram of the top-level architecture of a hardware implementation device compatible with the Ascon cryptographic algorithm family provided by the present invention; Figure 2 A hardware pipeline diagram of a hardware implementation device compatible with the Ascon cryptographic algorithm family provided by the present invention; Figure 3 This is a schematic diagram showing the mode and algorithm comparison of a hardware implementation device and method compatible with the Ascon cryptographic algorithm family provided by the present invention. Figure 4 A schematic diagram of the hash mode pre-calculation state value in a hardware implementation device and method compatible with the Ascon cryptographic algorithm family provided by the present invention; Figure 5 The permutation operation permu structure diagram is provided in the hardware implementation device and method compatible with the Ascon cryptographic algorithm family provided by the present invention; Figure 6 The structure diagram of the initialization module process_initial in a hardware implementation device compatible with the Ascon cryptographic algorithm family provided by the present invention; Figure 7 The structure diagram of the process_A data processing module in a hardware implementation device compatible with the Ascon cryptographic algorithm family provided by the present invention; Figure 8 The flowchart of the data_disb_A shift register shift output process in a hardware implementation device and method compatible with the Ascon cryptographic algorithm family provided by the present invention is as follows: Figure 9 The structure diagram of the input data processing module process_I in a hardware implementation device compatible with the Ascon cryptographic algorithm family provided by the present invention; Figure 10 The diagram shows the structure of the process_final module in a hardware implementation device compatible with the Ascon cryptographic algorithm family provided by this invention. Detailed Implementation

[0027] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.

[0028] Example 1 This embodiment provides a hardware implementation device compatible with the Ascon cryptographic algorithm family, such as... Figure 1 As shown, the device includes an initialization processing module process_initial, a related data processing module process_A, an input data processing module process_I, and a termination processing module process_final; The initialization module `process_initial`, the related data processing module `process_A`, the input data processing module `process_I`, and the termination module `process_final` receive clock signals `clk` and reset signals `rstn` from outside the device. `INIT` represents the data processed and output by the initialization module `process_initial`, `PA_PI` represents the data processed and output by the related data processing module `process_A`, and `PI_FINAL` represents the data processed and output by the input data processing module `process_I`. `FINAL_PI_ready` indicates that the termination module `process_final` is idle, `PI_PA_ready` indicates that the input data processing module `process_I` is idle, and `PA_INIT_ready` indicates that the related data processing module `process_A` is idle.

[0029] The inputs to the initialization module process_initial are the input data validity signal I_valid_input, the mode selection signal I_mode, the related data I_data_A and its length I_length_A, the input data I_data_I and its length I_length_I, the input key I_data_K, the public information code I_data_N, the authentication tag I_data_T, and the ready signal PA_INIT_ready from the related data processing module process_A. Among them, the mode selection signal I_mode is a 6-bit wide one-hot code signal that indicates the mode for executing the Ascon algorithm. The output signals of the initialization module `process_initial` are connected to the inputs of the related data processing module `process_A`. The outputs of `process_initial` are: the output data validity signal `INIT_PA_valid` for the related data processing module `process_A`, the mode selection signal `INIT_PA_mode` for the related data processing module `process_A`, the key `INIT_PA_data_K` for the related data processing module `process_A`, the output status `INIT_PA_data_S` for the initialization module `process_initial`, the related data output by the initialization module `process_initial` `INIT_PA_data_A`, the length of the related data output by the initialization module `process_initial` `INIT_PA_length_A`, the input data of the related data processing module `process_A` `INIT_PA_data_I`, the length of the input data of the related data processing module `process_A` `INIT_PA_length_I`, and the authentication tag `INIT_PA_data_T` for the input data of the related data processing module `process_A`.

[0030] The relevant data processing module process_A receives signals from the initialization processing module process_initial and the ready signal PI_PA_ready from the input data processing module process_I. It outputs the valid signal PA_PI_valid for the input data processing module process_I, the mode selection signal PA_PI_mode for the input data processing module process_I, the key PA_PI_data_K for the input data processing module process_I, the output status PA_PI_data_S of the relevant data processing module process_A, the input data PA_PI_data_I of the input data processing module process_I, the length of the input data PA_PI_length_I of the input data processing module process_I, and the tag input data PA_PI_data_T of the input data processing module process_I. The input of the input data processing module process_I is the output of the relevant data processing module process_A and the ready signal FINAL_PI_ready from the termination processing module process_final; the outputs are the output validity signal PI_FINAL_valid for the termination processing module process_final, the mode selection signal PI_FINAL_mode for the termination processing module process_final, the key PI_FINAL_data_K for the termination processing module process_final, the output status PI_FINAL_data_S for the input data processing module process_I, the output data block PI_FINAL_data_O for the input data processing module process_I, the length of the output data block PI_FINAL_length_O for the input data processing module process_I, and the output tag PI_FINAL_data_T for the input data processing module process_I.

[0031] The input to the termination processing module process_final is the output of the input data processing module process_I. The outputs are the top-level Ascon_top output valid signal O_valid_output, the top-level Ascon_top output data O_data_O, the length of the top-level Ascon_top output data O_length_O, and the output label of the top-level Ascon_top output data O_data_T.

[0032] The structure of the initialization module process_initial is as follows: Figure 6As shown, this includes permu and a pre-stored hash state value. permu is used in authentication and encryption / decryption mode to perform an OR operation on the input key I_data_K, algorithm feature IV, and public information code I_data_N. The result of the OR operation is then subjected to a rounds of permutation operations, and finally XORed with the padded key padding_data_K to obtain the output state INIT_PA_data_S of the initialization processing module process_initial. The pre-stored hash state value is used in hash mode, combined with pre-computation optimization techniques, to assign the pre-computation optimized result to the output state INIT_PA_data_S of the initialization processing module process_initial. The related data processing module `process_A` is used to segment the related data `INIT_PA_data_A` output by the initialization processing module `process_initial` into data blocks, padding it with bits that are multiples of `r`, resulting in a data block length of `r`. When the length of the related data `INIT_PA_data_A` output by the initialization processing module `process_initial` is 0, no padding is needed in encryption / decryption mode, but in hash mode, it needs to be padded to a data block of `r` bits. Subsequently, the module absorbs the related data `INIT_PA_data_A` output by the initialization processing module `process_initial` into the output state `INIT_PA_data_S`, and finally outputs the output state `PA_PI_data_S` of the related data processing module `process_A`. The structure of the relevant data processing module process_A is as follows: Figure 7 As shown, the process includes data distribution (data_disb_A), data calculation (cal_A), generation (O_ready_process_A), and registers. Data distribution (data_disb_A) performs padding on the received data (INIT_PA_data_A) and divides it into multiple data blocks, outputting them sequentially from high to low bits to data calculation (cal_A) for computation. Data calculation (cal_A), upon receiving INIT_PA_data_S from the initialization module (process_initial), performs an XOR and permutation operation with the data blocks divided by data distribution (data_disb_A) to obtain the data processing output status PA_PI_data_S. Generation (O_ready_process_A) generates the idle signal PA_INIT_ready for the data processing module (process_A). Registers are used to temporarily store the input data of the data processing module (process_A).

[0033] The input data processing module process_I is used to implement plaintext processing of encryption algorithms, ciphertext processing of decryption algorithms, and terminalization operations of hash algorithms. First, the input data PA_PI_data_I of the input data processing module process_I is subjected to compatible encryption and decryption and hash algorithm fusion and lengthening operations. Then, data block segmentation is performed. Finally, the data block is subjected to b rounds of permutation operation with the output state PA_PI_data_S of the relevant data processing module process_A to obtain the output data block PI_FINAL_data_O and the output state PI_FINAL_data_S of the input data processing module process_I. The structure of the input data processing module process_I is as follows: Figure 9 As shown, the system includes input data distribution (data_disb_I), input data calculation (cal_I), generation (O_ready_process_I), and registers. Input data distribution (data_disb_I) performs padding on the received input data I and divides it into multiple data blocks, outputting them sequentially from high to low bits to input data calculation (cal_I) for calculation. Input data calculation (cal_I), after receiving the relevant data processing output status S_A from the relevant data processing module, performs an XOR and permutation operation with the data block passed from input data distribution (data_disb_I) to generate the data block containing the input data processing status S_I and output data O. Generation (O_ready_process_I) generates the idle signal PI_PA_ready for the input data processing module process_I. Registers are used to temporarily store the input data of the relevant data processing module process_I.

[0034] The termination processing module process_final receives the output status PI_FINAL_data_S and the output data block PI_FINAL_data_O of the input data processing module process_I. The input data processing module process_final first performs a shift operation on the output data block PI_FINAL_data_O of the input data processing module process_I until the valid data of the output data block PI_FINAL_data_O of the input data processing module process_I is shifted to the least significant bit of the register, thus obtaining the output data O_data_O of the top layer Ascon_top. The structure of the termination processing module process_final is as follows: Figure 10As shown, it includes shifting, padding with zeros, bitwise XOR, permutation, comparison, merging, and selectors; the finalization module process_final first performs a shift operation on the output data block PI_FINAL_data_O of the input data processing module process_I; If in hash mode, the shifted result is directly selected by the selector and sent to the output data block O_data_O.

[0035] If in encrypted mode, the termination processing module `process_final` first pads the input termination processing module's key `PI_FINAL_data_K` with zeros. Then, it XORs the zero-padded result with the output state `PI_FINAL_data_S` of the input data processing module `process_I`. This result is then input into `process_final` for 12 rounds of permutation to form a new state `S_FNL`. The lowest 128 bits of this generated `S_FNL` are XORed with the termination processing module's key `PI_FINAL_data_K` to generate the output tag `O_data_T` of the top-level Ascon_top output data. Simultaneously, the output tag `O_data_T` of the top-level Ascon_top output data is merged with the result of shifting the output data block `PI_FINAL_data_O` of the input data processing module `process_I`. Finally, the output data `O_data_O` of the top-level Ascon_top is selected and output through a selector.

[0036] If in decryption mode, the termination processing module process_final compares the output label O_data_T of the top-level Ascon_top output data with the output label PI_FINAL_data_T of the input data processing module process_I. If they match, the shifted result is selected to the output data block O_data_O through a two-level selector. If they do not match, -1 is output.

[0037] Example 2 This embodiment provides a method for using a hardware implementation device compatible with the Ascon cryptographic algorithm family. The method is based on the device described in Embodiment 1 and includes: For the Ascon-128 / 128a encryption algorithm, I_data_K, I_data_N, I_data_A, I_length_A, I_data_I, and I_length_I correspond to the input key K, public information code N, related data value, related data length, plaintext value, and plaintext length, respectively; I_data_T is fixed at 0; O_data_O and O_length_O represent the value and length of the output ciphertext C, respectively; and O_data_T represents the calculated authentication tag value.

[0038] For the Ascon-128 / 128a decryption algorithm, I_data_K, I_data_N, I_data_A, I_length_A, I_data_I, I_length_I, and I_data_T correspond to the input key K, public information code N, the value of related data A, the effective length of related data A, the value of ciphertext C, the effective length of ciphertext C, and the value of input authentication tag T, respectively. O_data_O and O_length_O represent the value and effective length of the output plaintext P, respectively. If the input authentication tag does not match the calculated authentication tag, both O_data_O and O_length_O output -1. The output of O_data_T is fixed at 0.

[0039] For the Ascon-Hash / Hasha algorithm, the inputs I_data_K and I_data_N are fixed at 0; I_data_A and I_length_A correspond to the value of the input information M and the effective length, respectively; the input I_data_I is 0, and the input I_length_I is fixed at 256; O_data_O and O_length_O correspond to the value of the output hash value H and the effective length, respectively; the output O_data_O is always 0.

[0040] The inputs for different working modes are as follows: When the device is in Ascon-128 encryption mode, the input 6-bit mode selection signal is 6'b000100; When the device is in Ascon-128 decryption mode, the input 6-bit mode selection signal is 6'b010000. The Ascon-128 algorithm signature IV is 80400𝑐0600000000; When the device is in Ascon-128a encryption mode, the input 6-bit mode selection signal is 6'b001000; When the device is in Ascon-128a decryption mode, the input 6-bit mode selection signal is 6'b100000, and the algorithm feature IV of Ascon-128a is 80800𝑐0800000000; When the device is in Ascon-hash mode, the input 6-bit mode selection signal is 6'b000001; When the device is in Ascon-hasha mode, the input 6-bit mode selection signal is 6'b000010.

[0041] Input the data five times consecutively; the flow stages in this device are as follows: Figure 2 As shown, the data above the processing modules represents input data, and the data below represents output data. The initialization processing module `process_initial` receives input data K, A, I, T, processes it, and outputs S, K, A, I, T to the relevant data processing module `process_A`. `process_A` processes this data and outputs S, K, I, T to the input data processing module `process_I`. `process_I` processes this data and outputs S, K, O to the finalization processing module `process_final`, which finally outputs O and T. After each processing stage completes its output, it enters an idle state. If the input is valid, it processes the next round of input data.

[0042] The mode selection in this device is as follows: Figure 3 As shown, a total of 6 algorithm modes are supported: Ascon-Hash, Ascon-Hasha, Ascon-128 encryption, Ascon-128a encryption, Ascon-128 decryption, and Ascon-128a decryption. A 6-bit one-hot code array 𝑚 is used to represent the selected mode.

[0043] Figure 5 This paper presents the workflow of the permutation operation module of this device. In Ascon-128 encryption / decryption, Ascon-128a encryption / decryption, Hash, and Hasha, 6, 8, and 12 rounds of permutation operations are used. Each round of permutation operations includes constant addition, S-box replacement, and linear diffusion operations. The core module includes a constant addition layer. p C Replacement layer p S and linear diffusion layer p LEach round of the permutation operation requires processing of state S by the permutation core module. The permu controls the number of permutation core operations performed: when mode is 2'b01, the module performs 6 rounds of permutation core operations; when mode is 2'b10, the module performs 8 rounds; and when mode is 2'b11, the module performs 12 rounds. For control signals, the permutation module internally defines the flag signals pc_flg, ps1_flg, fs2_flg, pl_flg, and flg, as well as the counting signal cnt. Here, pc_flg represents... p C The completion signal of the operation, ps1_flg represents p S The completion signal for the operation, ps2_flg, is delayed by one cycle compared to ps1_flg. This delay is to temporarily store the state S after the substitution operation is complete. pl_flg represents... p L The operation completion signal, flg, indicates that all rounds of P operations are complete. pc_flg goes high when an input is detected or the flg signal is high; ps1_flg goes high when pc_flg is detected as high; ps2_flg goes high when ps1_flg is detected as high; pl_flg goes high when ps2_flg is detected as high; flg goes high when pc_flg, ps1_flg, fs2_flg, and pl_flg are all high. The counter signal cnt increments by 1, and after two consecutive high cycles, ps1_flg, fs2_flg, pl_flg, and flg go low to begin the next round of operations. The result is output when cnt has accumulated the round count (6, 8, or 12). For data register signals, the module defines three 320-bit registers: state, state1, and state2. When data is read in, S is stored in state for processing. p C During the operation, the result of the constant addition is stored in the state. p S During operation, the state is temporarily stored in state1. The result of the S-box replacement is first stored in state2. When pc_flg, ps1_flg, and fs2_flg are high and pl_flg is low, the state in state2 is stored in state1. p L The diffusion result is directly stored in the state. After all rounds of permutation operations are completed, the state S will be output.

[0044] When the operating mode is hash mode (Ascon-hash, Ascon-hasha), INIT_PA_data_S will be assigned a pre-computed initialized state value, such as... Figure 4 As shown, these state values ​​are pre-stored in the hardware, and INIT_PA_valid is pulled high. In this way, the hash mode will skip the substitution operation and directly output the state INIT_PA_data_S.

[0045] When the operating mode is encryption / decryption (Ascon-128 encryption / decryption, Ascon-128a encryption / decryption), the `data_S_init` in the initialization module `process_initial` is assigned the value IV||I_data_K||I_data_N, and the valid signal `valid_S_init` is pulled high. `valid_S_init` and `data_S_init` serve as inputs to the permutation module. After the permutation operation, `permu` pulls the valid data signal `valid_S_permu` high and passes the data into `data_S_permu`. When `valid_S_permu` is detected to be high, `S` outputs the result of a bitwise XOR operation between `data_S_permu` and the value of `K` padded with 0s to 320 bits.

[0046] When the output data of the initialization module process_initial is input to the relevant data processing module, such as Figure 7 As shown, the relevant data distribution module `data_disb_A` first receives the valid output data signal `INIT_PA_valid` from the relevant data processing module `process_A`, the relevant data `INIT_PA_data_A` output by the initialization processing module `process_initial`, and the length of the relevant data output by the initialization processing module `process_initial` `INIT_PA_length_A`. It then performs padding and block segmentation operations on the relevant data `INIT_PA_data_A` output by the initialization processing module `process_initial` using a shift register. The principle is as follows: Figure 8As shown, assuming the length of the input related data I_data_A is L, a 1 and several 0s will be padded to the lower bits of data A until L is a multiple of r. When L is a multiple of r, the related data A will be left-shifted to the highest bit. Subsequently, the shift register will perform an r-bit left shift each time, outputting data block A_Block. Simultaneously, the register temporarily stores the mode selection signal INIT_PA_mode of the related data processing module process_A, the key INIT_PA_data_K of the related data processing module process_A, the input data INIT_PA_data_I of the related data processing module process_A, the length INIT_PA_length_I of the input data of the related data processing module process_A, and the authentication tag INIT_PA_data_T of the input data of the related data processing module process_A. After the relevant data distribution data_disb_A completes the padding and block division operations of the relevant data INIT_PA_data_A output by the initialization processing module process_initial, if it is detected that the relevant data calculation cal_A is idle (i.e., A_CAL_DISB_ready is high), the block data DISB_CAL_data_A and its valid signal DISB_CAL_valid_A, the last data block indicator signal DISB_CAL_last_A, and the null data signal DISB_CAL_null_A are output to the relevant data calculation cal_A.

[0047] When cal_A receives both the output data valid signal INIT_PA_valid from the relevant data processing module process_A and the ready signal PI_PA_ready from the input data processing module process_I, it reads the output status INIT_PA_data_S from the initialization module process_initial and the mode selection signal INIT_PA_mode from the relevant data processing module process_A. Then, cal_A performs an XOR and permutation operation with the data block DISB_CAL_data_A divided by the relevant data distribution data_disb_A to obtain the relevant data processing output status PA_PI_data_S and its valid signal PA_PI_valid. Simultaneously, the temporarily stored PA_PI_mode, PA_PI_data_K, PA_PI_data_I, PA_PI_length_I, and PA_PI_data_T in the registers will be output to the next stage.

[0048] When the output data of the relevant data processing module process_A is input to the input data processing module, the input data distribution data_disb_I first receives the valid signal PA_PI_valid for the input data processing module process_I, the input data PA_PI_data_I of the input data processing module process_I, and the input data length PA_PI_length_I of the input data processing module process_I. It then performs padding and block division operations on the input data PA_PI_data_I of the input data processing module process_I. At the same time, the register temporarily stores the mode selection signal PA_PI_mode of the input data processing module process_I, the key PA_PI_data_K of the input data processing module process_I, the input data length PA_PI_length_I of the input data processing module process_I, and the tag input data PA_PI_data_T of the input data processing module process_I. After the input data distribution data_disb_I completes the padding and block division of the input data PA_PI_data_I of the input data processing module process_I, if it detects that the related data calculation cal_I is idle (i.e., I_CAL_DISB_ready is high), the block data DISB_CAL_data_I, along with its valid signal DISB_CAL_valid_I, the last data block indicator signal DISB_CAL_last_I, and the null data signal DISB_CAL_null_I, are output to the related data calculation cal_I.

[0049] When the valid signal PA_PI_valid received by cal_I for the input data processing module process_I and the ready signal FINAL_PI_ready output by the termination processing module process_final are both high, it will read the output status PA_PI_data_S of the relevant data processing module process_A, the mode selection signal PA_PI_mode of the input data processing module process_I, and the value of the input data length PA_PI_length_I of the input data processing module process_I. Subsequently, cal_I is XORed and permuted with the data block DISB_CAL_data_I divided by the related data distribution data_disb_I to obtain the output status PI_FINAL_data_S of the input data processing module process_I, the output valid signal PI_FINAL_valid for the termination processing module process_final, and the output data block PI_FINAL_data_O of the input data processing module process_I. At the same time, the mode selection signal PI_FINAL_mode of the termination processing module process_final, the key PI_FINAL_data_K of the termination processing module process_final, the length of the output data block PI_FINAL_length_O of the input data processing module process_I, and the output tag PI_FINAL_data_T of the input data processing module process_I, which are temporarily stored in the register, will be output to the next stage.

[0050] The termination processing module process_final first performs a shift operation on the output data block PI_FINAL_data_O of the input data processing module process_I. If in hash mode, the shifted result is directly selected by the selector Mux and sent to the output data block O_data_O.

[0051] If in encrypted mode, the termination processing module `process_final` first pads the input termination processing module's key `PI_FINAL_data_K` with zeros. Then, it XORs the zero-padded result with the output state `PI_FINAL_data_S` of the input data processing module `process_I`. This result is then input into `process_final` for 12 rounds of permutation to form a new state `S_FNL`. The lowest 128 bits of this generated `S_FNL` are XORed with the termination processing module's key `PI_FINAL_data_K` to generate the output tag `O_data_T` of the top-level Ascon_top output data. Simultaneously, the output tag `O_data_T` of the top-level Ascon_top output data is merged with the result of shifting the output data block `PI_FINAL_data_O` of the input data processing module `process_I`. Finally, the output data `O_data_O` of the top-level Ascon_top is selected and output through a selector.

[0052] If in decryption mode, the termination processing module process_final compares the output label O_data_T of the top-level Ascon_top output data with the output label PI_FINAL_data_T of the input data processing module process_I. If they match, the shifted result is selected to the output data block O_data_O through a two-level selector. If they do not match, -1 is output.

[0053] Some steps in the embodiments of the present invention can be implemented using software, and the corresponding software program can be stored in a readable storage medium, such as an optical disc or a hard disk.

[0054] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A hardware implementation device compatible with the Ascon cryptographic algorithm family, characterized in that, The device includes: an initialization processing module process_initial, a related data processing module process_A, an input data processing module process_I, and a termination processing module process_final; The initialization processing module process_initial, the related data processing module process_A, the input data processing module process_I, and the termination processing module process_final jointly receive the clock signal clk and the reset signal rstn from outside the device; The initialization processing module is used to obtain the initial state by combining the key and public information code in the authentication encryption and decryption mode, and then output the state after a permutation operation. In hash mode, pre-computation optimization is performed, and the result obtained after pre-computation optimization is assigned to the output state; The related data processing module is used to divide the related data I_data_A into data blocks, calculate the output state and the related data I_data_A, and then output a new state. The input data processing module is used to implement plaintext processing of encryption algorithms, ciphertext processing of decryption algorithms, and termination operations of hash algorithms. The termination processing module is used to perform a permutation operation on the output state of the input data processing module in encryption / decryption mode to obtain the output state of the termination processing module. Finally, the output state of the termination processing module and the key are combined to obtain the authentication tag, and the data is directly output in hash mode.

2. The apparatus according to claim 1, characterized in that, The inputs to the initialization processing module process_initial are the input data validity signal I_valid_input, the mode selection signal I_mode, the related data I_data_A, the length of the related data I_data_A I_length_A, the input data I_data_I, the length of the input data I_data_I I_length_I, the input key I_data_K, the public information code I_data_N, the authentication tag I_data_T, and the ready signal PA_INIT_ready from the related data processing module process_A.

3. The apparatus according to claim 2, characterized in that, The initialization module process_initial includes process and pre-stored hash state values; The permu is used to perform a permutation operation on the output state of the initialization processing module process_initial in the authentication encryption and decryption mode, and the pre-stored hash state value is used to assign the corresponding state value to the output state of the initialization processing module process_initial in the hash mode.

4. The apparatus according to claim 3, characterized in that, The relevant data processing module process_A includes relevant data distribution data_disb_A and relevant data calculation cal_A; The related data distribution data_disb_A is used to perform padding operations on the output of the received initialization processing module process_initial and divide it into multiple data blocks, which are then output to the related data calculation cal_A in order from high bit to low bit for calculation. After receiving the output of the initialization processing module process_initial, the related data calculation cal_A is XORed and permuted with the data block divided by the related data distribution data_disb_A to obtain the output of the related data processing module process_A.

5. The apparatus according to claim 4, characterized in that, The input data processing module process_I includes input data distribution data_disb_I and input data calculation cal_I; The input data distribution data_disb_I is used to perform padding operations on the input of the data processing module process_I and divide it into multiple data blocks, which are then output to the input data calculation cal_I in order from high bit to low bit for calculation. The input data calculation cal_I is used to perform an XOR and permutation operation on the output of the relevant data processing module process_A and the data block passed in by the input data distribution data_disb_I to generate the output of the input data processing module process_I.

6. The apparatus according to claim 5, characterized in that, The termination processing module `process_final` receives the output of the input data processing module `process_I`, performs `a` rounds of permutation operations on it to obtain the output of the termination processing module, and then XORs the last 128 bits of the output of the termination processing module with the last 128 bits of the key of the termination processing module `process_final` to obtain the final output. In hash mode, the authentication tag is not calculated, and the final calculation result is output directly.

7. The apparatus according to claim 6, characterized in that, The initialization processing module process_initial, the related data processing module process_A, the input data processing module process_I, and the termination processing module process_final are divided into four pipeline stages; The device supports Ascon-128 encryption and decryption, and Ascon128a encryption and decryption modes; the hash mode supports Ascon-hash and Ascon-hasha.

8. A method of using a hardware implementation device compatible with the Ascon cryptographic algorithm family, characterized in that, The method is implemented based on the apparatus described in any one of claims 1-7.

9. The method of use according to claim 8, characterized in that, The method of use includes: Step 1: The initialization module process_initial performs the corresponding operation according to the mode selection signal; If it is in encryption / decryption mode, then 12 rounds of permutation operations are performed to obtain the output of the initialization processing module process_initial; If it is hash mode, the state value pre-stored in the hardware is assigned to the output of the initialization module process_initial; Step 2: The relevant data processing module process_A calculates the data and status output by the initialization processing module process_initial, and generates the output of the relevant data processing module process_A; Step 3: The input data processing module process_I calculates the output of the relevant data processing module process_A, generates the processed output of the input data processing module process_I and the unshifted output of the input data processing module process_I, temporarily stores the received key and pattern, and outputs all data to the next stage after processing is completed. Step 4: The termination processing module process_final performs a shift operation on the output of the input data processing module process_I until the valid data output by the input data processing module process_I is shifted to the least significant bit of the register, thus obtaining the final output.

10. The method of use according to claim 9, characterized in that, In step two: The related data distribution module `data_disb_A` in the related data processing module `process_A` performs padding operations on the output received from the initialization processing module `process_initial` and divides it into multiple data blocks A1, A2, ..., A1. s The data is output sequentially from the most significant bit to the least significant bit and then into the relevant data calculation cal_A. The related data processing module process_A receives the output of the initialization processing module process_initial, performs XOR and permutation operations with the data block passed in by the related data distribution data_disb_A, and generates the output state of the temporary related data processing module process_A. The output state of the temporary related data processing module process_A is calculated with the new round of related data blocks until the last data block is calculated, and then the output of the related data processing module process_A is output. In step three: The input data distribution data_disb_I in the input data processing module process_I performs padding operations on the input of the input data processing module process_I and divides it into multiple data blocks I1, I2, ..., I. s The data is output sequentially from the most significant bit to the least significant bit and then fed into the input data calculation cal_I. The input data processing module process_I performs XOR and permutation operations on the output of the relevant data processing module process_A and the relevant data block passed in by the input data distribution data_disb_I to generate a temporary output of the input data processing module process_I. The output of the temporary input data processing module process_I is then used to calculate with the new round of input data blocks until the last data block is calculated. Finally, the output status and data block of the input data processing module process_I are output. In step four: In hash mode, the finalization module process_final only outputs the final data; In encrypted mode, the termination processing module process_final performs a bitwise XOR operation on the output of the input data processing module process_I, and then performs 12 rounds of permutation to form a new state. The lowest 128 bits of the new state are then XORed with the key of the termination processing module process_final to generate the final output tag. The final output data and tag are then combined. In decryption mode, the termination processing module process_final performs a bitwise XOR operation on the output of the input data processing module process_I, and then performs 12 rounds of permutation to form a new state. The lowest 128 bits of the new state are then bitwise XORed with the key of the termination processing module process_final to generate the final output tag. The termination processing module process_final compares the final output tag with the output tag of the input data processing module process_I. If they match, the value of data O_data_O is output; otherwise, -1 is output.

Citation Information

Patent Citations

  • Efficient and safe password hardware for sharing core function

    CN115021893A

  • Fault analysis method for Ascon algorithm

    CN117834134A

  • Hardware implementation device and method for Ascon lightweight encryption algorithm

    CN118118160A

  • Hardware security implementation device and method for lightweight algorithm ASCON

    CN118869189A

  • Ascon algorithm optimization implementation method based on RISC-V processor

    CN120090792A