ZUC cryptographic algorithm based on random bit generator and application
By generating an initial key and vector using a random bit generator and verifying the integrity of the ciphertext using the SM3 hash algorithm, the problem of insufficient randomness in the Zu Chongzhi cryptographic algorithm and the security issues of outsourced data storage are solved, thus realizing a highly secure and reliable data storage scheme.
Patent Information
- Application Number
- CN202511096161.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-11-11
AI Technical Summary
In existing technologies, the initial key and initial vector of Zu Chongzhi's cryptographic algorithm are often manually set or fixedly configured, which lacks randomness and is easily analyzed and predicted by attackers. Furthermore, the data outsourcing storage scheme lacks an effective integrity verification mechanism, leading to a security and trust crisis.
A random bit generator is used to generate a random sequence as the initial key and initial vector. The integrity of the encrypted data is verified by combining the SM3 hash algorithm. The hash value is stored locally for comparison and verification when the data is stored in an outsourced manner, so as to ensure the confidentiality and integrity of the data.
It improves the key randomness and anti-attack capability of Zu Chongzhi's cryptographic algorithm, enhances the security and integrity verification of outsourced data storage, reduces reliance on cloud trust, and improves processing speed and security response speed.
Smart Images

Figure CN120934738A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial internet related technologies, especially to data security and encryption algorithms in the industrial internet, and in particular to a Zu Chongzhi cryptographic algorithm and its application based on a random bit generator. Background Technology
[0002] With the rapid development of information technology, the amount of personal and corporate data is exploding, making data storage and security protection a critical challenge. Data outsourcing storage technology effectively reduces users' hardware and software maintenance costs by entrusting data to third-party service providers, but it also brings serious security risks. Data stored directly in plaintext or with simple encryption is highly susceptible to leakage, tampering, or malicious attacks during transmission or storage. Ensuring data confidentiality and integrity has become a core challenge in the field of data outsourcing storage.
[0003] The Zu Chongzhi Cryptographic Algorithm (ZUC), as a stream cipher algorithm, is widely used in fields such as communications due to its good security and efficiency. However, the initial key and initial vector of the traditional Zu Chongzhi algorithm are often manually set or fixedly configured, resulting in insufficient randomness and vulnerability to analysis and prediction by attackers. This weakness limits its application in high-security scenarios. The randomness and unpredictability of the key sequence are the core of stream cipher security. Manually input sequences often exhibit regularity, making them difficult to resist complex cryptanalysis attacks.
[0004] Random bit generators, as a key component for generating highly random sequences, directly impact the security strength of cryptographic algorithms. While existing random bit generators can provide a certain degree of randomness, individual generators have limitations in terms of attack resistance, adaptability, or efficiency. For example, some generators are based on specific mathematical problems, resulting in high computational costs; others rely on system entropy sources, which can lead to a decrease in randomness when the entropy source is insufficient. Therefore, effectively integrating random bit generators with Zu Chongzhi's algorithm, leveraging the former's high randomness to compensate for the latter's shortcomings in key generation, has become an important direction for improving the security of encryption schemes.
[0005] Furthermore, even with encryption technology to ensure confidentiality, existing data outsourcing storage solutions still struggle to prevent malicious tampering by cloud service providers. The lack of an effective integrity verification mechanism means users cannot confirm whether retrieved data matches the uploaded data, further exacerbating the trust crisis in data outsourcing storage. Therefore, there is an urgent need to develop an integrated solution that combines highly secure encryption with reliable integrity verification to address the complex security threats in data outsourcing scenarios. Summary of the Invention
[0006] The core technical problems that this invention aims to solve include: first, improving the key randomness of Zu Chongzhi's cryptographic algorithm and overcoming the security risks caused by manually setting keys; second, integrating the advantages of different random bit generators to enhance the anti-attack capability and scenario adaptability of the encryption algorithm; and third, constructing a mechanism that combines encryption and integrity verification to comprehensively protect the confidentiality and integrity of outsourced data storage, providing reliable technical support for the secure storage and application of massive amounts of data.
[0007] Based on the first main aspect of the present invention, a Zu Chongzhi cryptographic algorithm based on a random bit generator is provided, comprising the following steps executed by a computer:
[0008] A random sequence is generated using a random bit generator, and this random sequence is used as the initial key and initial vector for the Zu Chongzhi cryptographic algorithm.
[0009] The Zu Chongzhi cryptographic algorithm is initialized based on the initial key and initial vector to generate an encrypted key stream;
[0010] The plaintext data is encrypted using the encryption key stream to obtain ciphertext data;
[0011] The hash value of the ciphertext data is calculated using the SM3 hash algorithm to verify the integrity of the ciphertext data.
[0012] As a further preferred embodiment, in the aforementioned algorithm, the random bit generator includes at least one of a Rabin generator, a Fortuna generator, a Hash_DRBG, an HMAC_DRBG, or a CTR_DRBG, and the random sequence is generated through the entropy pool initialization, reseeding, and state update mechanism of the random bit generator.
[0013] As a further preferred embodiment, in the aforementioned algorithm, the initialization of the Zu Chongzhi cryptographic algorithm based on the initial key and initial vector includes: expanding the initial key and initial vector to the initial state of a linear feedback shift register, generating an encryption key stream through bit recombination and nonlinear functions, and obtaining ciphertext data by bitwise XORing the encryption key stream with the plaintext data.
[0014] As a further preferred embodiment, in the aforementioned algorithm, the Rabin generator generates a random sequence through the product of large prime numbers, the Fortuna generator collects system entropy through a multi-entropy pool and reseedes it periodically, the Hash_DRBG and HMAC_DRBG generate random sequences based on hash functions, and the CTR_DRBG generates random sequences based on a block cipher counter mode.
[0015] Furthermore, when the Rabin generator generates a random sequence, it selects two large prime numbers to calculate the product n, generates random numbers based on an iterative formula, and extracts the least significant bit as a random bit; the Fortuna generator collects entropy sources, including system events and time, through multiple entropy pools and periodically re-seeds to update its internal state.
[0016] As a further preferred embodiment, the aforementioned algorithm further includes a data security outsourcing storage step: uploading the encrypted data to a cloud server and storing the hash value of the encrypted data locally; when retrieving the encrypted data from the cloud server, recalculating its hash value and comparing it with the locally stored hash value, decrypting the data after verifying its integrity.
[0017] As a further preferred embodiment, in the aforementioned algorithm, the decryption step includes: regenerating the initial key and initial vector consistent with those used during encryption using a random bit generator, generating a decryption key stream using the Zu Chongzhi cryptographic algorithm, and bitwise XORing the decryption key stream with the ciphertext data to obtain the plaintext data.
[0018] Furthermore, in the decryption step, the regenerated initial key and initial vector are consistent with the random bit generator type, parameters, and entropy source input used during encryption to ensure that the generated decryption key stream is exactly the same as the encryption key stream; after decryption, the correctness is verified by the plaintext's own characteristics.
[0019] Based on a second key aspect of the present invention, a Zu Chongzhi cryptographic algorithm encryption device based on a random bit generator is provided, comprising:
[0020] The random sequence generation unit is used to generate random sequences using a random bit generator, which serve as the initial key and initial vector for the Zu Chongzhi cryptographic algorithm.
[0021] The algorithm initialization unit is used to initialize the Zu Chongzhi cryptographic algorithm based on the initial key and initial vector, and generate an encryption key stream.
[0022] An encryption unit is used to encrypt plaintext data using the encryption key stream to obtain ciphertext data;
[0023] The hash verification unit is used to calculate the hash value of the ciphertext data using the SM3 hash algorithm to verify the integrity of the ciphertext data.
[0024] According to a third key aspect of the present invention, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to invoke the instructions stored in the memory to execute the aforementioned Zu Chongzhi cryptographic algorithm based on a random bit generator.
[0025] Based on a fourth key aspect of the present invention, a computer-readable storage medium is provided having computer program instructions stored thereon, which, when executed by a processor, implement the Zu Chongzhi cryptographic algorithm based on a random bit generator as described above.
[0026] Based on the fifth main aspect of the present invention, the aforementioned Zu Chongzhi cryptographic algorithm based on a random bit generator is provided for application in secure outsourced data storage, including:
[0027] A random sequence is generated using a random bit generator as the initial key and initial vector for the Zu Chongzhi cryptographic algorithm, and the algorithm is initialized to generate an encrypted key stream.
[0028] Plaintext data is encrypted to obtain ciphertext data, and the hash value of the ciphertext is calculated using the SM3 hash algorithm;
[0029] The encrypted data is uploaded to the cloud server through an encrypted transmission channel, and the hash value is associated with the file identification information and stored locally.
[0030] When ciphertext data is retrieved from the cloud server, its hash value is recalculated and compared with the hash value stored locally. After verifying its integrity, the same random bit generator parameters are used to generate a decryption key stream to decrypt and obtain the plaintext.
[0031] Compared with existing technologies, this invention achieves significant breakthroughs in cryptographic security, data integrity assurance, and cloud storage applications by deeply integrating a random bit generator with the Zu Chongzhi Cryptographic Algorithm (ZUC) and innovatively incorporating a national cryptographic hash verification mechanism. Its technical effects are mainly reflected in the following four aspects:
[0032] First, in existing technologies, the initial key and vector of the ZUC algorithm often use fixed values or simple pseudo-random number generators (such as linear congruential methods), resulting in a limited key space and vulnerability to predictive attacks. This invention combines hardware-level random sources such as Rabin generators and Fortuna generators with ZUC, achieving dynamic and high-entropy key generation. For example, the Rabin generator calculates the modulus n by multiplying large prime numbers and then uses modulo-square operations to generate random sequences; its difficulty in factoring large integers ensures the unpredictability of the key. The Fortuna generator, by collecting entropy sources such as system events and time in real time and periodically reseeding to update its internal state, completely overcomes the periodicity defect of traditional pseudo-random number generators. This design improves both the key space and resistance to brute-force attacks, fundamentally solving the industry pain point of insufficient randomness in the initial parameters of the ZUC algorithm.
[0033] Secondly, in traditional encryption schemes, data integrity verification often uses independent hash algorithms (such as SHA-256) and is separate from the encryption process, posing a risk of hash value tampering or untimely verification. This invention deeply embeds the SM3 hash algorithm into the ZUC encryption process. Immediately after encryption, the ciphertext hash value is calculated and stored locally. Before decryption, the hash value is recalculated and compared with the local copy, forming a complete security chain. This design first utilizes the collision resistance of SM3 to ensure the uniqueness of the hash value. Local storage of the hash value also avoids the trust dependency of cloud storage. Furthermore, file identification information (filename, timestamp, etc.) is associated with the hash value, enabling precise location of data tampering. One possible implementation is that in a cloud storage scenario, if an attacker tampers with the ciphertext data, a failed hash comparison will immediately trigger an anomaly alarm, whereas in existing technologies, manual intervention may be required to detect data anomalies.
[0034] Third, existing data outsourcing storage solutions generally suffer from two major drawbacks. First, key management relies on static storage, making it susceptible to data loss due to cloud leaks. Second, they lack a systematic integrity verification mechanism, making them vulnerable to man-in-the-middle attacks. This invention constructs a novel security paradigm of ciphertext upload to the cloud, local hashing, and key regeneration. During decryption, it utilizes the same random bit generator type, parameters, and entropy source input as encryption, ensuring absolute consistency between the decryption and encryption key streams, thus completely solving the key synchronization problem in traditional solutions. Furthermore, this invention combines file identification information (such as timestamps and file sizes) for hash comparison, preventing attackers from bypassing verification by replacing filenames. If the hash comparison fails or the file identification does not match, the system automatically refuses decryption and triggers multi-level alarms. Compared to the manual verification process required in existing technologies, the response speed is improved by several orders of magnitude.
[0035] Finally, in high-speed scenarios such as 5G and IoT, the hardware implementation efficiency of the ZUC algorithm is crucial. This invention, through modular design, decomposes the encryption process into a hierarchical architecture of random sequence generation unit, algorithm initialization unit, encryption unit, and hash verification unit, improving parallel processing capabilities. Random sequence generation and algorithm initialization can be performed synchronously, resulting in faster processing speeds compared to traditional sequential execution processes. In this invention, the SM3 hash calculation unit and encryption unit share hardware circuitry, reducing chip area footprint. This invention supports seamless switching between multiple random sources such as Rabin and Fortuna. For example, in low-power devices, the Fortuna generator can be automatically selected to reduce energy consumption, while in high-performance servers, the Rabin generator is used to enhance security. Attached Figure Description
[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, obtaining other drawings based on these drawings without creative effort still falls within the scope of the present invention.
[0037] Figure 1 This invention illustrates the Zu Chongzhi cryptographic algorithm based on a random bit generator and its overall application flow in one embodiment.
[0038] Figure 2 This illustrates the design flow of Zu Chongzhi's cryptographic algorithm based on a Rabin generator in one embodiment of the present invention;
[0039] Figure 3 It shows Figure 2 The structure of the "Zu Chongzhi Cryptographic Algorithm" module in the document;
[0040] Figure 4 A flowchart of Zu Chongzhi's algorithm based on the Fortuna generator is shown in one embodiment of the present invention;
[0041] Figure 5 A flowchart of Zu Chongzhi's algorithm based on Hash_DRBG is shown in one embodiment of the present invention;
[0042] Figure 6 A flowchart of Zu Chongzhi's algorithm based on HMAC_DEBG is shown in one embodiment of the present invention;
[0043] Figure 7 A flowchart of Zu Chongzhi's algorithm based on CTR_DRBG is shown in one embodiment of the present invention.
[0044] Figure 8 A model of a data security outsourcing storage scheme in one embodiment of the present invention is shown. Detailed Implementation
[0045] The preferred embodiments of the present invention will be described in detail below to provide a clearer understanding of the purpose, features, and advantages of the invention. It should be understood that the following embodiments are not intended to limit the scope of the invention, but are merely illustrative of the essential content of the technical solution of the present invention.
[0046] In the following description, certain specific details are set forth for the purpose of illustrating various disclosed embodiments in order to provide a thorough understanding of the various disclosed embodiments. However, those skilled in the art will recognize that embodiments may be practiced without one or more of these specific details. In other instances, well-known techniques associated with the invention may not have been shown or described in detail to avoid unnecessarily obscuring the description of the embodiments.
[0047] Throughout this specification, references to "an embodiment" or "an embodiment" indicate that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Therefore, the appearance of "in an embodiment" or "an embodiment" in various places throughout the specification does not necessarily refer to the same embodiment. Furthermore, a particular feature, structure, or characteristic may be combined in any manner in one or more embodiments.
[0048] like Figure 1 As shown in the following embodiment, the implementation steps of Zu Chongzhi's cryptographic algorithm based on a random bit generator are described in detail, including the complete process of random sequence generation, algorithm initialization, data encryption, and integrity verification, as follows:
[0049] A random sequence is generated using the Fortuna random bit generator, which serves as the initial key (128 bits) and initial vector (128 bits) for the Zu Chongzhi Cryptographic Algorithm (ZUC).
[0050] A feasible implementation process is as follows:
[0051] S110, A random sequence is generated using a random bit generator, and the random sequence is used as the initial key and initial vector of the Zu Chongzhi cryptographic algorithm;
[0052] First, the entropy pool is initialized, which means that the Fortuna generator contains 32 entropy pools, collecting random data from system entropy sources (such as CPU instruction cycles, disk I / O timestamps, and user input events). Reseeding is triggered when each entropy pool is full of 8192 bits.
[0053] Then, a reseeding mechanism is implemented, which is to mix the data from each entropy pool using the hash function SHA-256 to generate a 256-bit seed and update the internal state.
[0054] Finally, sequence generation is achieved: based on the updated state, a pseudo-random bitstream is generated using the AES-256 algorithm in CTR mode, and the first 256 bits (128-bit key k + 128-bit vector IV) are extracted, denoted as:
[0055] , .
[0056] S120, initialize the Zu Chongzhi cryptographic algorithm based on the initial key and initial vector to generate an encrypted key stream;
[0057] The ZUC is initialized based on the initial key K and the initialization vector IV to generate the encryption key stream. The specific calculation process is as follows:
[0058] Initialize the linear feedback shift register (LFSR), that is, reassemble K and IV bit by bit into a 160-bit initial state: , , , , , , , , ;
[0059] Perform 32 LFSR shift operations, that is: ,in, This is a carry flag.
[0060] Perform nonlinear function F processing, that is: extract intermediate states from LFSR. The calculation is performed using S-box transformation (8×8-bit nonlinear permutation) and linear transformations L1 (circular left shift by 1 bit and XOR with left shift by 2 bits) and L2 (circular left shift by 3 bits and XOR with left shift by 1 bit). ;
[0061] Discard the first 32 key outputs and proceed to the working phase to generate the encrypted key stream. (32 characters per character).
[0062] S130, the plaintext data is encrypted using the encryption key stream to obtain ciphertext data;
[0063] The plaintext data is encrypted in blocks, and the specific process is as follows:
[0064] The plaintext data is grouped into 32-bit blocks, denoted as... (Pad with 0s if less than 32 bits); Perform XOR encryption, XORing each long plaintext block with the corresponding word in the keystream bit by bit, i.e. Obtain the encrypted data .
[0065] S140, The hash value of the ciphertext data is calculated using the SM3 hash algorithm to verify the integrity of the ciphertext data.
[0066] The ciphertext hash value is calculated using the SM3 hash algorithm as follows:
[0067] Perform message padding, that is: pad the ciphertext C to make its length a multiple of 512 bits. The padding rule is: first pad with 1 "1", then pad with k "0"s, and finally pad with 64 bits of the original length information.
[0068] Perform iterative compression: Divide the padded message into blocks (512 bits each), and iteratively update the initial vector IV = 0x7380166f… (256 bits) using the SM3 compression function CF, finally outputting a 256-bit hash value. ;
[0069] Storage and Verification: The hash value H is associated with the ciphertext C and stored. During decryption, the hash value of the ciphertext is recalculated and compared with H. If they match, the ciphertext is considered complete.
[0070] This embodiment ensures high randomness of the initial key through the Fortuna generator, enhances encryption strength by combining ZUC nonlinear transformation, and finally achieves reliable verification of ciphertext integrity through SM3, forming a full-process security mechanism.
[0071] In some embodiments, the random bit generator includes at least one of a Rabin generator, a Fortuna generator, a Hash_DRBG, an HMAC_DRBG, or a CTR_DRBG, and the random sequence is generated through the entropy pool initialization, reseeding, and state update mechanism of the random bit generator.
[0072] In most embodiments, the computer hardware system first performs entropy pool initialization, and all generators include at least one entropy pool for collecting initial random sources (such as hardware noise, system events, user input, etc.).
[0073] In a feasible implementation, during Hash_DRBG initialization, the external entropy source data is compressed into a 256-bit seed using a hash function (such as SHA-256) and written into the entropy pool as the initial state; CTR_DRBG then encrypts the initial entropy source using a block cipher (such as AES-128) to generate a 128-bit initial key and counter value.
[0074] Then the computer hardware system executes a reseeding mechanism, that is, when the amount of data in the entropy pool is lower than the threshold or reaches the preset period, reseeding is triggered.
[0075] In a feasible implementation, taking HMAC_DRBG as an example, the current state is used as the key for HMAC (Hash-based Message Authentication Code), and the newly collected entropy source data is used as the message to calculate the HMAC value and update the internal state, ensuring that randomness is continuously enhanced.
[0076] Finally, a state update is performed, meaning that the generator automatically updates its internal state after each random sequence is generated.
[0077] In one feasible implementation, the Fortuna generator transforms its internal state once every 16 bytes of random number it outputs using a hash function; the Rabin generator updates its state using an iterative formula to avoid sequence repetition.
[0078] In most embodiments, the Rabin generator calculates the modulus by multiplying large prime numbers and generates random sequences using the modulo square operation, the Fortuna generator collects system entropy through a multi-entropy pool and reseedes periodically, the Hash_DRBG and HMAC_DRBG generate random sequences based on hash functions, and the CTR_DRBG generates random sequences based on a block cipher counter pattern.
[0079] Furthermore, when the Rabin generator generates a random sequence, it selects two large prime numbers to calculate the product n, generates random numbers based on an iterative formula, and extracts the least significant bit as a random bit; the Fortuna generator collects entropy sources, including system events and time, through multiple entropy pools and periodically re-seeds to update its internal state.
[0080] The following feasible embodiment illustrates the computation process of the Rabin generator.
[0081] The Rabin random bit generator algorithm is based on the Rabin public-key cryptography algorithm. It uses the least significant bits of the iterative equation, where:
[0082]
[0083]
[0084] Where n is the product of two prime numbers p and q, and p and q both satisfy... .
[0085] In this embodiment, the Rabin random bit generator is a pseudo-random number generator based on large prime numbers. An attacker can only crack the random bits generated by the Rabin random bit generator if the prime factors p and q of n can be factored out. Currently, there are no sufficiently efficient algorithms for factoring large numbers, so the random sequences generated by the Rabin generator have good anti-analysis properties.
[0086] The sequences generated by the Rabin random bit generator algorithm are unpredictable. That is, given any bit sequence, it is impossible to predict what the next bit will be.
[0087] The design process of Zu Chongzhi's cryptographic algorithm based on the Rabin generator is as follows: Figure 2As shown.
[0088] In the algorithm implementation, the Rabin generator first uses an auxiliary function to generate two large prime numbers p and q, calculates n = p × q, and then randomly selects a number x less than n, and calculates... .
[0089] The above process generates a random sequence k and an IV, and then the key loading process generates 16 31-bit integers as LFSR register units. The initial state is then used to encrypt the data according to the Zu Chongzhi algorithm. Figure 2 The structure of the "Zu Chongzhi Cryptographic Algorithm" module is as follows: Figure 3 As shown.
[0090] The following example illustrates the computation process of the Fortuna generator.
[0091] Fortuna satisfies the next-bit test. That is, given the first k bits of a random sequence, no multinomial-time algorithm can predict the (k+1)th bit with a success rate higher than 50%. A generator that passes the next-bit test will pass all other multinomial-time randomness tests.
[0092] Fortuna possesses statistical randomness, making it resistant to "state leakage expansion attacks" even if an attacker obtains access to the generator's initial state or a portion of its running state. Reconstructing and reproducing the previous stream of random numbers is difficult if part or all of the state is revealed (or correctly guessed). Fortuna changes its key after each data request, so future key leaks do not jeopardize previous generator outputs. This property is sometimes described as "fast key erasure" or "forward secrecy."
[0093] Fortuna collects randomness from multiple entropy sources, which can include keystrokes, mouse movements, system time, hardware noise, and more. By collecting entropy from multiple unrelated sources, Fortuna reduces the risk of a single entropy source being predictable or controllable by an attacker. Fortuna uses multiple entropy pools (up to 32) to store the collected entropy. Each entropy pool collects entropy independently, and the pools are large enough that attackers cannot predict or analyze the exact contents of the pools.
[0094] Fortuna periodically updates the generator's seed using data from the entropy pool. This update mechanism ensures that the generator's internal state does not remain static for extended periods, thus increasing the difficulty of prediction. Even if the generator's state is leaked under certain circumstances, Fortuna can recover to a safe state by continuously collecting new entropy.
[0095] like Figure 4As shown, the algorithm implementation of the Fortuna generator part requires initializing the entropy pool (usually using system entropy). After initialization, new entropy (system response events, current time, etc.) needs to be added to the entropy pool.
[0096] This embodiment uses the current system time as the entropy added to the entropy pool, and generates a random sequence by obtaining the byte at the current index of the entropy pool as the random byte. Before generating the random sequence, it is necessary to determine whether the entropy pool needs to be reseeded. If reseeding is required, the entropy pool should be reseeded with the new entropy before repeating the above operation to generate the random sequence.
[0097] The generator's random sequence k and IV, after undergoing a key loading process, are used to encrypt data according to the Zu Chongzhi algorithm. Figure 4 The structure of the "Zu Chongzhi Cryptographic Algorithm" module is as follows: Figure 3 As shown.
[0098] The following example illustrates the calculation process of Hash_DRBG.
[0099] Hash_DRBG relies on a strong cryptographic hash function, such as SHA-256 or SHA-512. The collision resistance and anti-prediction properties of the hash function provide the foundation for Hash_DRBG's security.
[0100] Hash_DRBG's design does not rely on storing the complete internal state, which reduces the security risks caused by state leakage. Even if an attacker obtains partial state information, it is difficult to recover the complete internal state.
[0101] Hash_DRBG's design allows for adaptation to different security levels and application requirements, enabling parameter tuning to meet specific security objectives. If the seed and entropy inputs are secure, the random number sequence generated by DRBG is unpredictable to an external observer. DRBG's design does not rely on storing complete internal state, which helps resist side-channel attacks. Due to the deterministic nature of DRBG, replaying previous random number sequences does not increase security risk. DRBG's design helps reduce the correlation between output random numbers, thus resisting correlation attacks.
[0102] like Figure 5 The flowchart shown is a diagram of Zu Chongzhi's algorithm based on Hash_DRBG, designed in conjunction with the algorithm flow of the Hash_DRBG generator. The random sequence k and IV generated by Hash_DRBG are expanded into 16 31-bit integers as LFSR register units after the key loading process. The initial state is then used to encrypt data according to the Zu Chongzhi algorithm. The structure of the "Zu Chongzhi Cryptographic Algorithm" module in the diagram is similar to... Figure 3 Consistent.
[0103] The following example illustrates the calculation process of HMAC_DEBG.
[0104] The key used in HMAC adds a degree of randomness, making it difficult for attackers to deduce the internal key. HMAC is compatible with various hash functions, so a suitable hash function can be chosen based on specific needs. HMAC effectively prevents message tampering because attackers do not know the internal key and cannot recalculate the correct HMAC value.
[0105] The collision resistance of the HMAC algorithm mainly depends on the hash function used. If the chosen hash function is highly collision-resistant, then HMAC will also have high collision resistance.
[0106] A preimage attack refers to an attacker's attempt to find a message whose HMAC (Hardware Key Mapping) matches a known HMAC without knowing the key. One of the design goals of HMAC is to defend against preimage attacks. Because the internal key of the HMAC is unknown, attackers cannot effectively construct a message that matches a known HMAC.
[0107] HMAC_DRBG utilizes the HMAC algorithm, which combines a hash function and a key to provide message authentication. The security of the HMAC algorithm means that even if the underlying hash function (such as SHA-256 or SHA-512) is cracked, HMAC can still provide a certain level of security.
[0108] The random number sequences generated by HMAC_DRBG are highly unpredictable, which is crucial for applications that require secure random numbers, such as cryptographic key generation. HMAC_DRBG is resistant to rollback attacks, meaning that even if an attacker gains access to the random number generator's state, it is very difficult to predict future random number outputs.
[0109] The flowchart of Zu Chongzhi's algorithm, which combines the HMAC_DRBG algorithm, is as follows: Figure 6 As shown, the algorithm is similar to the Fortuna generator in terms of process. The difference is that HMAC_DRBG uses the input entropy to update the values of the key K and vector V through the update method, and updates the entropy pool with the new key and vector during reseeding.
[0110] Furthermore, in HMAC_DRBG, V=HMAC(K, V) is used to generate random bits, and new V values are concatenated in a loop until an output that meets the conditions is generated.
[0111] The output random sequence is then expanded into a key loading process. The sequence is followed by the Zu Chongzhi algorithm for data encryption. The structure of the "Zu Chongzhi Cryptographic Algorithm" module in the diagram is similar to... Figure 3 Consistent.
[0112] The following example illustrates the calculation process of CTR_DRBG.
[0113] CTR_DRBG uses a strong block cipher algorithm, such as AES, as its encryption engine. This means that the security of CTR_DRBG largely depends on the security of the underlying block cipher algorithm. CTR_DRBG allows configuration of different parameters, such as the choice of block cipher algorithm, key length, and entropy source, to suit different security requirements.
[0114] Furthermore, due to the design of CTR_DRBG, even if an attacker knows the current state of the random number generator, they cannot predict previous random number outputs. Because the random numbers generated by CTR_DRBG are highly unpredictable, it helps prevent replay attacks. Since the sequence of random numbers generated by CTR_DRBG is unknown to the attacker, it helps resist known-plaintext attacks and chosen-plaintext attacks.
[0115] The collision resistance of CTR_DRBG primarily depends on the chosen block cipher function. If the chosen block cipher function (such as AES) is collision-resistant, then CTR_DRBG will also have high collision resistance. Due to its design, CTR_DRBG offers some resistance to side-channel attacks. For example, because it does not directly use the input entropy, attackers cannot obtain information about the input by analyzing the output.
[0116] The flowchart of Zu Chongzhi's algorithm, designed using CTR_DRBG, is as follows: Figure 7 As shown.
[0117] Unlike the previous algorithms, CTR_DRBG first initializes the generator with a seed (the seed can be any random or pseudo-random data), and then uses the seed value and a security key derivation function to generate a key and vector. It then uses the CTR mode of a cryptographic algorithm (such as AES) and the generated key to encrypt a fixed block, and the generated encrypted block is the required random sequence.
[0118] The update of CTR_DRBG uses the newly generated random number output as input. After generating the required random sequence, the Zu Chongzhi algorithm is invoked for key loading and data encryption. The structure of the "Zu Chongzhi Cryptographic Algorithm" module in the diagram is similar to... Figure 3 Consistent.
[0119] The following embodiment illustrates a performance comparison analysis between the Zu Chongzhi cryptographic algorithm based on a random bit generator of the present invention and the original Zu Chongzhi algorithm.
[0120] To compare the encryption speed of the Zu Chongzhi algorithm based on random bit generators with the original Zu Chongzhi algorithm, given a direct initial key k and initialization vector IV, the initial Zu Chongzhi algorithm was used to repeatedly encrypt a text file (long plaintext, approximately 2600 Chinese characters) 10 times, and the time required for each encryption was recorded. Then, the initial key k and initialization vector IV of the original Zu Chongzhi algorithm were replaced with random sequences generated by several random bit generators, and the same text file was encrypted 10 times, with the time required for each encryption recorded. The encryption time records are shown in Tables 1-6.
[0121] The code used in the experiment was written in Java, and the compiler was IntelliJ IDEA.
[0122]
[0123] For encrypting uniformly long plaintext, the average encryption time of the Zu Chongzhi algorithm without any bit generator is 5.8ms, while the average encryption time of several Zu Chongzhi algorithms based on random bit generators ranges from 6.3ms to 8.9ms, all longer than the encryption time without any bit generator, with a time difference between 0.5ms and 3.1ms. For encrypting short plaintext, the original Zu Chongzhi algorithm has an average encryption time of 2.4ms, while the average encryption time of several Zu Chongzhi algorithms based on random bit generators ranges from 3.5ms to 5.6ms, with a time difference between 1.1ms and 2.1ms. Therefore, the Zu Chongzhi algorithm based on a random bit generator is slightly slower than the original Zu Chongzhi algorithm in terms of encryption speed and is affected by the plaintext length, but the time difference is still in the millisecond range. In real-world scenarios, except for those with extremely strict encryption speed requirements, the difference is negligible.
[0124] In terms of security, the structural design of the Zu Chongzhi algorithm endows it with excellent security characteristics, such as resistance to side-channel attacks, differential attacks, discriminant analysis, fast correlation attacks, cryptographic attacks, and guess-deterministic attacks. Through security analysis of several random bit generators combined with the Zu Chongzhi algorithm, it is evident that the security performance of the algorithm is significantly improved in all aspects after incorporating bit generators.
[0125] This invention applies a random bit generator to the key generation process of the Zu Chongzhi algorithm, which greatly increases the algorithm's stealth, unpredictability, and resistance to replay attacks. This is because the random numbers generated by the various random bit generators used are unpredictable each time. Even if an attacker obtains some information or state, they cannot predict the next output. Furthermore, using a bit generator to participate in the key stream generation means that the key will be changed each time encryption is performed. Future key leaks will not affect previous outputs. Therefore, the key stream generated by the Zu Chongzhi algorithm is more concealed, and the difficulty for attackers to steal and crack information is greatly increased.
[0126] The Rabin generator is designed based on the difficulty of factoring large integers. Currently, there is no universally accepted effective algorithm that can solve the difficulty of factoring large integers. Therefore, the Zu Chongzhi cryptographic algorithm based on the Rabin generator is also based on the difficulty of factoring large integers. Compared with the basic Zu Chongzhi algorithm, it has higher resistance to analysis and differential attacks.
[0127] The Fortuna generator, Hash_DRBG, HMAC_DRBG, and CTR_DRBG are designed to use entropy or an initial seed, combined with a hash function and a cryptographic function (such as AES) to generate random numbers. The source of entropy or the initial seed is generally information that changes constantly, such as system response events and the current time, which has strong randomness. In addition, the reseeding and update mechanism makes it difficult for attackers to capture the corresponding state to carry out various attacks.
[0128] The collection of entropy allows the Fortuna generator to restore its safe state by continuously collecting new entropy even if its state is leaked. Therefore, Zu Chongzhi's algorithm based on the Fortuna generator has both anti-attack characteristics and the ability to restore a safe state, thus possessing more complete security features.
[0129] The design of Hash_DRBG relies on hash functions. The collision resistance of hash functions gives Hash_DRBG high resistance to attacks. Furthermore, the implementation of Hash_DRBG does not depend on storing the complete internal state, reducing the security risks that may be caused by state leakage and helping to resist side-channel attacks. The resistance to side-channel attacks of Zu Chongzhi's algorithm based on Hash_DRBG is greatly improved.
[0130] Furthermore, HMAC_DRBG is implemented based on the HMAC algorithm. HMAC has anti-tampering capabilities and can still provide a certain level of security even if the underlying hash function is cracked. This feature makes the Zu Chongzhi algorithm based on HMAC_DRBG more comprehensive in terms of security and reliability.
[0131] Unlike the previous two, the collision resistance of CTR_DRBG depends on the selected block cipher function, and the block cipher function can be selected according to specific security requirements. This feature makes the Zu Chongzhi algorithm combined with CTR_DRBG have a higher level of security.
[0132] In some embodiments, the method further includes a data security outsourcing storage step: uploading the encrypted data to a cloud server and storing the hash value of the encrypted data locally; when retrieving the encrypted data from the cloud server, recalculating its hash value and comparing it with the locally stored hash value, decrypting the data after verifying its integrity. The specific implementation is as follows:
[0133] After the plaintext is encrypted to obtain the ciphertext data, the 256-bit hash value (denoted as H) of the ciphertext is calculated using the SM3 hash algorithm. The hash value is then associated with the file identification information (such as filename, generation timestamp, and file size) corresponding to the ciphertext and stored on a local device (such as a user terminal or trusted hardware) to prevent the hash value from being tampered with in the cloud.
[0134] The encrypted data is uploaded to the cloud server through an encrypted transmission channel (such as SSL / TLS protocol). The cloud server only stores the encrypted data and cannot obtain the hash value or key information, thus ensuring the confidentiality of the data in the cloud.
[0135] When a user retrieves encrypted data from the cloud server, the associated hash value H is first retrieved locally, and the SM3 hash value (denoted as H) is recalculated on the downloaded encrypted data. ), by comparing H with Verify the integrity of the ciphertext. If they match, proceed with the decryption process; if they do not match, refuse decryption and trigger an exception alert (such as logging or user notification).
[0136] In some embodiments, the decryption step includes: regenerating the initial key and initial vector consistent with those used during encryption using a random bit generator, generating a decryption key stream using the Zu Chongzhi cryptographic algorithm, and bitwise XORing the decryption key stream with the ciphertext data to obtain plaintext data.
[0137] Furthermore, in the decryption step, the regenerated initial key and initial vector are consistent with the random bit generator type, parameters, and entropy source input used during encryption to ensure that the generated decryption key stream is exactly the same as the encryption key stream; after decryption, the correctness is verified by the plaintext's own characteristics.
[0138] The core of the decryption process is to ensure that the key stream is completely consistent with that of the encryption phase. The specific implementation is as follows:
[0139] The user calls the same type of random bit generator used during encryption (e.g., if the Fortuna generator is used during encryption, the Fortuna generator will still be enabled during decryption), and inputs parameters that are exactly the same as those used in the encryption phase (e.g., entropy source type, reseeding period), to regenerate the initial key and initial vector, ensuring that they are exactly the same as the key and vector used during encryption.
[0140] Based on the regenerated initial key and vector, the initialization process of Zu Chongzhi's algorithm (linear feedback shift register initialization, bit recombination, and nonlinear function processing) is repeated to generate a decryption key stream that is completely consistent with the encryption stage.
[0141] The decryption key stream and the ciphertext data are XORed bitwise to obtain the plaintext data. After decryption, the correctness is verified by the characteristics of the plaintext itself (such as file format verification and comparison of preset check bits). For example, for text files, the format identifier (such as UTF-8 encoding header) can be checked to ensure that the decryption result conforms to the characteristics of the original data.
[0142] The following example illustrates an application of Zu Chongzhi's cryptographic algorithm based on a random bit generator.
[0143] Data outsourcing storage refers to enterprises or users entrusting data storage tasks to professional third-party service providers. This service model allows enterprises to utilize external resources to manage their data storage needs, typically including functions such as data backup, recovery, archiving, and access.
[0144] Outsourcing data storage in a cloud environment involves enterprises or users entrusting data storage tasks to cloud service providers, while also allowing for operations such as querying and maintenance. However, this method of directly outsourcing data storage carries significant security risks. First, direct data transmission and storage exposes the data to interception, tampering, and eavesdropping attacks during the transmission process. Second, storing data directly on cloud servers cannot guarantee the complete trustworthiness of the cloud service provider; storing plaintext data directly on a cloud server means the data may be backed up, leaked, or tampered with by the cloud service provider. Faced with these two threats, the confidentiality and integrity of the data cannot be guaranteed.
[0145] To prevent attacks on the confidentiality and integrity of user data when it is outsourced for storage, users can encrypt the data before storing it on a cloud server. The encrypted data is then uploaded to the cloud server, and the cloud service provider cannot obtain the plaintext data without knowing the key.
[0146] This invention utilizes a random bit generator for key generation in the Zu Chongzhi cryptographic algorithm, significantly enhancing its security and anti-predictability. This makes the key stream generated by the algorithm more concealed, greatly increasing the difficulty for attackers to steal and decipher the information. Applying the Zu Chongzhi algorithm based on a random bit generator to secure outsourced data storage better protects data confidentiality. Even if a semi-trusted cloud service provider or unauthorized individual obtains the ciphertext, they cannot decipher the true result. Furthermore, because the random sequence generated by the bit generator is different each time the Zu Chongzhi algorithm encrypts data, the key generated by the algorithm is also different each time. Even if a cloud service provider or unauthorized individual obtains a portion of the input from the same user multiple times, they cannot decipher all the information.
[0147] While encrypting plaintext before storage effectively prevents cloud service providers or other unauthorized parties from accessing data uploaded by users to cloud servers, ensuring data confidentiality, the risk of malicious tampering by cloud service providers remains. If a cloud service provider maliciously tampers with the encrypted data uploaded by a user and then returns the modified ciphertext to the user, the user will not be able to obtain the correct plaintext after decryption, thus compromising data integrity.
[0148] To ensure data integrity, in addition to using the Zu Chongzhi cryptographic algorithm based on a random bit generator to encrypt the data, the SM3 hash algorithm is introduced. The SM3 hash algorithm has strong collision resistance and is used to generate message digests, which can be used for message authentication. Users use SM3 to perform a hash operation on the ciphertext to generate a message digest, which is saved by the user. When the previously stored ciphertext is retrieved from the cloud server, the ciphertext is first hashed using SM3 to obtain a new message digest. By comparing whether the two generated message digests are consistent, it can be determined whether the uploaded ciphertext has been tampered with.
[0149] In one embodiment of the present invention, the model of the data security outsourcing storage scheme is as follows: Figure 8 As shown.
[0150] The above embodiments involve technical terms, technical principles, or technical means related to the technical solutions of the present invention. Any techniques or conventional means not described in detail above are well-known techniques or conventional means that are known to those skilled in the art.
[0151] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.
Claims
1. A Zu Chongzhi cryptographic algorithm based on a random bit generator, characterized in that, This includes the following steps performed by computer hardware: A random sequence is generated using a random bit generator, and this random sequence is used as the initial key and initial vector for the Zu Chongzhi cryptographic algorithm. The Zu Chongzhi cryptographic algorithm is initialized based on the initial key and initial vector to generate an encrypted key stream; The plaintext data is encrypted using the encryption key stream to obtain ciphertext data; The hash value of the ciphertext data is calculated using the SM3 hash algorithm to verify the integrity of the ciphertext data.
2. The Zu Chongzhi cryptographic algorithm based on a random bit generator according to claim 1, characterized in that, The random bit generator includes at least one of Rabin generator, Fortuna generator, Hash_DRBG, HMAC_DRBG or CTR_DRBG, and the random sequence is generated through the entropy pool initialization, reseeding and state update mechanism of the random bit generator.
3. The Zu Chongzhi cryptographic algorithm based on a random bit generator according to claim 1, characterized in that, The initialization algorithm of Zu Chongzhi's cryptography based on the initial key and initial vector includes: expanding the initial key and initial vector to the initial state of a linear feedback shift register, generating an encryption key stream through bit recombination and nonlinear functions, and XORing the encryption key stream with the plaintext data to obtain ciphertext data.
4. The Zu Chongzhi cryptographic algorithm based on a random bit generator according to claim 2, characterized in that, The Rabin generator generates random sequences through the product of large prime numbers, the Fortuna generator collects system entropy through a multi-entropy pool and re-seeds it periodically, the Hash_DRBG and HMAC_DRBG generate random sequences based on hash functions, and the CTR_DRBG generates random sequences based on a block cipher counter mode. Furthermore, when the Rabin generator generates a random sequence, it selects two large prime numbers to calculate the product n, generates random numbers based on an iterative formula, and extracts the least significant bit as a random bit; the Fortuna generator collects entropy sources, including system events and time, through multiple entropy pools and periodically re-seeds to update its internal state.
5. The Zu Chongzhi cryptographic algorithm based on a random bit generator according to claim 1, characterized in that, The method further includes a data security outsourcing storage step: uploading the encrypted data to a cloud server and storing the hash value of the encrypted data locally; when retrieving the encrypted data from the cloud server, recalculating its hash value and comparing it with the locally stored hash value, decrypting the data after verifying its integrity.
6. The Zu Chongzhi cryptographic algorithm based on a random bit generator according to claim 5, characterized in that, The decryption steps include: regenerating the initial key and initial vector consistent with those used during encryption using a random bit generator, generating a decryption key stream using the Zu Chongzhi cryptographic algorithm, and XORing the decryption key stream with the ciphertext data bitwise to obtain the plaintext data. Furthermore, in the decryption step, the regenerated initial key and initial vector are consistent with the random bit generator type, parameters, and entropy source input used during encryption to ensure that the generated decryption key stream is exactly the same as the encryption key stream; after decryption, the correctness is verified by the plaintext's own characteristics.
7. An encryption device based on the Zu Chongzhi cryptographic algorithm using a random bit generator, characterized in that, include: The random sequence generation unit is used to generate random sequences using a random bit generator, which serve as the initial key and initial vector for the Zu Chongzhi cryptographic algorithm. The algorithm initialization unit is used to initialize the Zu Chongzhi cryptographic algorithm based on the initial key and initial vector, and generate an encryption key stream. An encryption unit is used to encrypt plaintext data using the encryption key stream to obtain ciphertext data; The hash verification unit is used to calculate the hash value of the ciphertext data using the SM3 hash algorithm to verify the integrity of the ciphertext data.
8. An electronic device, characterized in that, include: processor; A memory for storing processor-executable instructions; wherein the processor is configured to invoke the instructions stored in the memory to execute the Zu Chongzhi cryptographic algorithm based on a random bit generator as described in any one of claims 1-6.
9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the Zu Chongzhi cryptographic algorithm based on a random bit generator as described in any one of claims 1-6.
10. The application of the Zu Chongzhi cryptographic algorithm based on a random bit generator as described in any one of claims 1-6 in secure outsourced data storage, characterized in that... include: A random sequence is generated using a random bit generator as the initial key and initial vector for the Zu Chongzhi cryptographic algorithm, and the algorithm is initialized to generate an encrypted key stream. Plaintext data is encrypted to obtain ciphertext data, and the hash value of the ciphertext is calculated using the SM3 hash algorithm; The encrypted data is uploaded to the cloud server through an encrypted transmission channel, and the hash value is associated with the file identification information and stored locally. When ciphertext data is retrieved from the cloud server, its hash value is recalculated and compared with the hash value stored locally. After verifying its integrity, the same random bit generator parameters are used to generate a decryption key stream to decrypt and obtain the plaintext.