Encryption method, electronic device, storage medium and computer program
By using multiple different sets of SBOX for nonlinear processing in the DES algorithm, the vulnerability of the DES algorithm to side-channel attacks is solved, thereby improving the security of encryption and the difficulty of cracking.
Patent Information
- Application Number
- CN202511174488.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-11-11
AI Technical Summary
The DES algorithm is vulnerable to side-channel attacks and has low security.
Using multiple different sets of SBOX for nonlinear processing, and using different SBOX in adjacent rounds of encryption, increases the power consumption of nonlinear processing and the randomness of intermediate value storage, thereby improving the security of encryption.
It improves encryption security, increases the difficulty of cracking the key, and prevents side-channel attacks.
Smart Images

Figure CN120934739A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of encryption technology, and in particular to an encryption method, electronic device, storage medium, and computer program. Background Technology
[0002] In the field of information security technology, encryption technology is an important research area. Encryption can prevent information from being stolen or tampered with during transmission or storage, thereby protecting the integrity and confidentiality of data.
[0003] In some encryption scenarios (such as IoT communication encryption), the Data Encryption Standard (DES) algorithm is used for data encryption. However, the DES algorithm is vulnerable to side-channel attacks and has relatively low security. Summary of the Invention
[0004] Some embodiments of this application provide an encryption method, electronic device, storage medium, and computer program. The following describes this application from multiple aspects, and the embodiments and beneficial effects of the following aspects can be referred to each other.
[0005] Firstly, embodiments of this application provide an encryption method applied to an electronic device. The method includes: determining a first plaintext to be encrypted; performing N rounds of iterative encryption processing on the first plaintext based on a first key to obtain a first ciphertext, where N is an integer greater than 1; wherein the iterative encryption processing includes nonlinear processing, and the nonlinear processing method of the nth round is different from that of the (n-1)th round, where n is an integer greater than 1 and less than N-1. Because the nonlinear processing methods used in adjacent rounds of iterative encryption are different, the power consumption generated by the nonlinear processing in adjacent rounds is different, and the intermediate values generated are also different. This increases the randomness of the nonlinear processing power consumption in each round of iterative encryption, as well as the randomness of the flipping power consumption generated when the intermediate value is stored in the register after each round of iterative encryption. This increases the difficulty of cracking the key based on the nonlinear processing power consumption and the register flipping power consumption, thereby improving the security of the encryption.
[0006] In some embodiments, obtaining a first ciphertext by performing N rounds of iterative encryption on a first plaintext based on a first key includes: performing an initial permutation on the first plaintext to obtain a second plaintext; performing N rounds of iterative encryption on the left and right sequences of the second plaintext based on the first key to obtain the second ciphertext, wherein the left and right sequences are sequences obtained after splitting the second plaintext; performing an inverse initial permutation on the second ciphertext to obtain the first ciphertext; and during the i-th round of iterative encryption, using the right sequence input in the i-th round as the left sequence output in the i-th round, and the base... The right sequence input in round i is processed by the subkey of round i to obtain the right encryption sequence. The left sequence input in round i is then processed by the right encryption sequence to obtain the right sequence output in round i. Here, i is an integer greater than or equal to 1 and less than or equal to N. The subkey of round i is generated based on the first key. The left sequence input in round 1 is the left sequence of the second plaintext, and the right sequence input in round 1 is the right sequence of the second plaintext. The second ciphertext is a combination of the left and right sequences output in round N.
[0007] When an electronic device encrypts a 64-bit first plaintext, it can first perform an initial permutation on the first plaintext to obtain a second plaintext, then split the second plaintext into a left sequence L′0 (32 bits) and a right sequence R′0 (32 bits), and then perform 16 (as an example of N) rounds of iterative encryption on the left sequence L′0 and the right sequence R′0 based on the first key to obtain a 64-bit second ciphertext, and then perform an inverse initial permutation on the second ciphertext to obtain a 64-bit first ciphertext.
[0008] Rounds 1, 5, 9, and 13 are encrypted using the following formula:
[0009]
[0010] Among them, R′ 4b For the right sequence input in round 4b+1, L′ 4b+1 L is the left sequence output in round 4b+1. ′ 4b Given the left sequence input in round 4b+1, R′ 4a+1 K′ is the right sequence output in round 4b+1. 4b+1 f1(R′) is the subkey for round 4b+1. 4b ,K′ 4b+1 ) is about R′ 4b and K′ 4b+1 The function, and its operation process includes MSBOX. 11-18 The corresponding operation process, where b is an integer.
[0011] Rounds 2, 6, 10, and 14 are encrypted using the following formula:
[0012]
[0013] Among them, R′ 4b+1 For the right sequence input in round 4b+2, L′ 4b+2 L′ is the left sequence output in round 4b+2. 4b+1 R′ is the left sequence input in round 4b+2. 4b+2 K′ is the right sequence output in round 4b+2. 4b+2 f2(R′) is the subkey for round 4b+2. 4b+1 ,K′ 4b+2 ) is about R′ 4b+1 and K′ 4b+2 The function, and its operation process includes MSBOX. 21-28 The corresponding calculation process.
[0014] Rounds 3, 7, 11, and 15 are encrypted using the following formula:
[0015]
[0016] Among them, R′ 4b+2 For the right sequence input in round 4b+3, L′ 4b+3 L′ is the left sequence output in round 4b+3. 4b+2 R′ is the left sequence input in round 4b+3. 4a+3 K′ is the right sequence output in round 4b+3. 4b+3 f3(R′) is the subkey for round 4b+3. 4b+2 ,K′ 4b+3 ) is about R′ 4b+2 and K′ 4b+3 The function, and its operation process includes MSBOX. 31-38 The corresponding calculation process.
[0017] Rounds 4, 8, 12, and 16 are encrypted using the following formula:
[0018]
[0019] Among them, R′ 4b+3 For the right sequence input in round 4b+4, L′ 4b+4 L′ is the left sequence output in round 4b+4. 4b+3 R′ is the left sequence input in round 4b+4. 4a+4 K′ is the right sequence output in round 4b+4. 4b+4 f4(R′) is the subkey for round 4b+4. 4b+3 ,K′ 4b+4) is about R′ 4b+3 and K′ 4b+4 The function, and its operation process includes MSBOX. 41-48 The corresponding calculation process.
[0020] In some embodiments, a right encryption sequence is obtained by performing corresponding nonlinear processing on the right sequence input in the i-th round based on the subkey of the i-th round, including: performing bit expansion processing on the right sequence input in the i-th round to obtain a first sequence; performing a first operation on the first sequence and the subkey of the i-th round to obtain a second sequence; performing nonlinear processing on the second sequence to obtain a third sequence; and rearranging the bit order of the third sequence to obtain the right encryption sequence; wherein the right sequence, the third sequence, and the right encryption sequence all include H bits, and the first sequence, the subkey, and the second sequence all include V bits, where H is less than V, and H and V are both positive integers. The left sequence includes H bits. H is 32, and V is 48.
[0021] For example, first use the E-box to process the 48-bit right sequence R′ 4b Bit extension is performed to obtain a 48-bit sequence. (as the first sequence), then the subkey K′ of round 4b+1. 4b+1 with sequence Performing an XOR operation yields the sequence. (As the second sequence), then the sequence Split into eight 6-bit sequences A1' 4b+1 ~A8' 4b+1 Then through the first group of MSBOX 11-18 MSBOX 11 ~MSBOX 18 For sequence A1' respectively 4b+1 ~A8' 4b+1 Nonlinear processing is performed to obtain the corresponding 4-bit sequence B1' 4b+1 ~B8' 4b+1 Then, the 4-bit sequence B1' 4b+1 ~B8' 4b+1 Concatenating them together yields a 32-bit sequence. (As the third sequence). Finally, the sequence is passed through the P-box. The order of the digits is rearranged to obtain sequence Y' 4b+1 (As the right encryption sequence).
[0022] For example, first, the 48-bit right sequence R′ is processed through the E-box. 4b+1 Bit extension is performed to obtain a 48-bit sequence. (as the first sequence), then the subkey K′ of round 4b+2. 4b+1 with sequence Performing an XOR operation yields the sequence. (As the second sequence), then the sequence Split into eight 6-bit sequences A1' 4b+2 ~A8' 4b+2 Then through the second group of MSBOX 21-28 MSBOX 21 ~MSBOX 28 For sequence A1' respectively 4b+2 ~A8' 4b+2 Nonlinear processing is performed to obtain the corresponding 4-bit sequence B1' 4b+2 ~B8' 4b+2 Then, the 4-bit sequence B1' 4b+2 ~B8' 4b+2 Concatenating them together yields a 32-bit sequence. (As the third sequence). Finally, the sequence is passed through the P-box. The order of the digits is rearranged to obtain sequence Y' 4b+2 (As the right encryption sequence).
[0023] For example, first pass the 48-bit right sequence R′ through the E-box. 4b+2 Bit extension is performed to obtain a 48-bit sequence. (as the first sequence), then the subkey K′ of round 4b+3. 4b+3 with sequence Performing an XOR operation yields the sequence. (As the second sequence), then the sequence Split into eight 6-bit sequences A1' 4b+3 ~A8' 4b+3 Then through the 3rd MSBOX 31-38 MSBOX 31 ~MSBOX 38 For sequence A1' respectively 4b+3 ~A8' 4b+3 Nonlinear processing is performed to obtain the corresponding 4-bit sequence B1' 4b+3 ~B8' 4b+3 Then, the 4-bit sequence B1' 4b+3 ~B8' 4b+3 Concatenating them together yields a 32-bit sequence. (As the third sequence). Finally, the sequence is passed through the P-box. The order of the digits is rearranged to obtain sequence Y' 4b+3 (As the right encryption sequence).
[0024] For example, first, the 48-bit right sequence R′ is processed through the E-box. 4b+3 Bit extension is performed to obtain a 48-bit sequence. (as the first sequence), then the subkey K′ of round 4b+4. 4b+4 with sequence Performing an XOR operation yields the sequence. (As the second sequence), then the sequence Split into eight 6-bit sequences A1' 4b+4 ~A8' 4b+4 Then through the 4th group of MSBOX 41-48 MSBOX 41 ~MSBOX 48 For sequence A1' respectively 4b+4 ~A8' 4b+4 Nonlinear processing is performed to obtain the corresponding 4-bit sequence B1' 4b+4 ~B8' 4b+4 Then, the 4-bit sequence B1' 4b+4 ~B8' 4b+4 Concatenating them together yields a 32-bit sequence. (As the third sequence). Finally, the sequence is passed through the P-box. The order of the digits is rearranged to obtain sequence Y' 4b+4 (As the right encryption sequence).
[0025] In some embodiments, the electronic device includes M sets of permutation tables, where M is an integer greater than 2; the nonlinear processing in the nth round is the nonlinear permutation processing corresponding to the i-th permutation table; the nonlinear processing in the (n-1)-th round is the nonlinear permutation processing corresponding to the j-th permutation table; where i and j are both integers greater than 0 and less than or equal to M, and i is not equal to j. The M sets of permutation tables are obtained by performing masking operations on a preset set of permutation tables based on M different masks. N is 16, and M is 4.
[0026] For example, an M-group permutation table could be 4 groups of MSBOX: MSBOX 11-18 MSBOX 21-28 MSBOX 31-38 and MSBOX 41-48 The permutation table.
[0027] In some embodiments, the data type of the first plaintext includes text, image, or audio.
[0028] Secondly, embodiments of this application provide an electronic device, including a memory for storing instructions executable by one or more processors of the electronic device; and a processor, which, when executing the instructions in the memory, causes the electronic device to perform the method described in any embodiment of the first aspect of this application. The beneficial effects achievable in the second aspect can be referred to the beneficial effects of the method provided in any embodiment of the first aspect, and will not be repeated here.
[0029] Thirdly, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method described in any embodiment of the first aspect. The beneficial effects achievable through this third aspect can be referenced to the beneficial effects of the method provided in any embodiment of the first aspect, and will not be repeated here.
[0030] Fourthly, embodiments of this application provide a computer program product including computer program code. When the computer program code is run on a computer, it causes the computer to implement the method described in any embodiment of the first aspect. The beneficial effects achievable in this fourth aspect can be found in the beneficial effects of the method provided in any embodiment of the first aspect, and will not be repeated here. Attached Figure Description
[0031] Figure 1 According to some embodiments of this application, an exemplary application scenario diagram is shown;
[0032] Figure 2A According to some embodiments of this application, an encryption flowchart of the DES algorithm is shown;
[0033] Figure 2B According to some embodiments of this application, a flowchart of the nonlinear permutation process for SBOX is shown;
[0034] Figure 3 According to some embodiments of this application, flowcharts of the encryption methods corresponding to Table 3 are shown;
[0035] Figure 4A According to some embodiments of this application, a flowchart of a nonlinear permutation process for an MSBOX is shown;
[0036] Figure 4B According to some embodiments of this application, a flowchart of another nonlinear permutation process for MSBOX is shown;
[0037] Figure 4C According to some embodiments of this application, a flowchart of another nonlinear permutation process for MSBOX is shown;
[0038] Figure 4D According to some embodiments of this application, a flowchart of another nonlinear permutation process for MSBOX is shown;
[0039] Figure 5 According to some embodiments of this application, a flowchart of an encryption method is shown;
[0040] Figure 6 According to some embodiments of this application, a schematic diagram of the structure of an electronic device is shown. Detailed Implementation
[0041] The illustrative embodiments of this application include, but are not limited to, an encryption method, an electronic device, a storage medium, and a computer program.
[0042] To more clearly illustrate the solutions of the embodiments of this application, some terms involved in the embodiments of this application will be explained below.
[0043] 1. Data Encryption Standard (DES) Algorithm:
[0044] The DES algorithm is a symmetric encryption algorithm used to encrypt 64-bit plaintext.
[0045] 2. Side-channel attack
[0046] Side-channel attacks refer to non-intrusive attacks on encryption methods, which break encryption methods by leaking side-channel information during the operation of encrypted electronic devices. Side-channel attacks mainly include timing attacks, energy analysis attacks, and electromagnetic analysis attacks targeting encryption methods. These new types of attacks are far more effective than mathematical methods of cryptanalysis, thus posing a serious threat to cryptographic devices.
[0047] 3. Replacement box (SBOX)
[0048] SBOX is a fundamental component in the field of cryptography. Based on the logical expressions in SBOX, non-linear data permutations can be achieved.
[0049] Figure 1 An exemplary application scenario diagram is shown according to some embodiments of this application.
[0050] like Figure 1 As shown, when electronic device 100 (taking a mobile phone as an example) transmits data (such as text, images, or audio) to electronic device 200 (taking a tablet as an example), in order to ensure the security of data transmission, electronic device 100 can first use the DES algorithm to encrypt the data to be transmitted as plaintext to obtain the corresponding ciphertext, and then transmit the ciphertext to electronic device 200.
[0051] Understandable. Figure 1 The application scenarios shown are not intended to limit this application, which can also be applied to any scenario that requires encryption.
[0052] The electronic devices mentioned in this application include, but are not limited to, mobile phones, tablets, smart screens, wearable devices (e.g., watches, bracelets, helmets, headphones, etc.), in-vehicle devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPCs), netbooks, personal digital assistants (PDAs), etc.
[0053] The encryption process of the DES algorithm is described below.
[0054] Figure 2A According to some embodiments of this application, an encryption flowchart of the DES algorithm is shown.
[0055] like Figure 2A As shown, the encryption process of the DES algorithm can be divided into the following three stages:
[0056] (1) Initial permutation (IP)
[0057] The position of each bit in the input 64-bit plaintext is adjusted according to the IP permutation table (a 64-bit permutation table), that is, the rules of the IP permutation table (such as changing the 1st bit to the 58th bit) to reorder the input 64-bit plaintext. Then, the 64-bit data after the initial permutation is split into two 32-bit sequences, namely the left sequence L0 and the right sequence R0.
[0058] (2) 16 rounds of iterative encryption
[0059] In some embodiments, 16 rounds of iterative encryption can be performed using the encryption method shown in the following formula (1).
[0060]
[0061] Where 1 ≤ n ≤ 16, and n is an integer, ⊕ represents the XOR operation, and K n For the subkey (48 bits) of the nth round, f(R) n-1 ,K n ) is about R n-1 and K n The f function.
[0062] Specifically, such as Figure 2A As shown, the first round of encryption is: L1 = R0, R1 = L0⊕f(R0,K1); the second round of encryption is: L2 = R1, R2 = L1⊕f(R1,K2); ... and so on, the 16th round of encryption is: L 16 =R15 R 16 =L 15 ⊕f(R 15 ,K 16 ).
[0063] Table 1 below shows how the sub-keys for each round are generated.
[0064] Table 1
[0065] step operate Output Initial processing <![CDATA[P1 replacement → split (C0, D0)]]> <![CDATA[56-bit (C0 + D0)]]> Round 1 <![CDATA[Shift C0 and D0 left by 1 bit → P2 permutation]]> <![CDATA[Sub-key K1 (48 bits)]]> Round 2 <![CDATA[Shift C1 and D1 one bit to the left → P2 substitution]]> <![CDATA[Sub-key K2 (48 bits)]]> Rounds 3-8 <![CDATA[C j and D j Shift left by 2 bits → P2 permutation]]> <![CDATA[Sub-key K3 to K8 (48 bits)]]> Round 9 <![CDATA[Shift C8 and D8 left by 1 bit → P2 permutation]]> <![CDATA[Sub-key K9 (48 bits)]]> Rounds 10-15 <![CDATA[C z and D z Shift left by 2 bits → P2 permutation]]> <![CDATA[Sub - key K 10 ~K 15 (48 bits)]]> Round 16 <![CDATA[C 15 and D 15 Shift left by 1 bit → P2 permutation]]> <![CDATA[Sub-key K 16 (48 bits)]]>
[0066] As shown in Table 1, the 8 parity bits of the 64-bit initial key can be removed using a fixed P1 permutation table (a mapping table that maps 56-bit input data to 56-bit output data). The remaining 56-bit key is then rearranged according to the P1 permutation table (i.e., P1 permutation) to obtain a 56-bit valid key. This valid key is then split into two halves: the left half is C0 (28 bits), and the right half is D0 (28 bits). For the first round, C0 and D0 are shifted left by 1 bit to obtain C1 and D1 respectively. Then, the combination sequence of C1 and D1 is rearranged using the P2 permutation table (a mapping table that maps 48-bit input data to 48-bit output data) (i.e., P2 permutation) to obtain the subkey K1 for the first round. For the second round, C1 and D1 are shifted left by 1 bit to obtain C2 and D2 respectively. Then, the combination sequence of C2 and D2 is rearranged using the P2 permutation table to obtain the subkey K2 for the second round. For rounds 3 through 8, C j and D j Left-shift by 2 bits yields C j+1 and D j+1 And through the P2 substitution table, C j+1 and D j+1 The combined sequences are reordered to obtain subkeys K3 to K8 for rounds 3 to 8, where 2 ≤ j ≤ 7 and j is an integer. For round 9, C8 and D8 are shifted left by 1 bit to obtain C9 and D9 respectively. Then, the combined sequences of C9 and D9 are reordered using the P2 permutation table to obtain the subkey K9 for round 9. For rounds 10 to 15, C... z and D z Left shift by 2 bits to get C z+1 and D z+1 Then, C is replaced using the P2 substitution table. z+1 and D z+1 The combined sequences are reordered to obtain the subkeys K for rounds 10 to 15. 10 ~K 15 Where 9 ≤ z ≤ 14, and z is an integer. For the 16th round, C 15 and D 15 Shifting left by 1 bit yields C16 and D 16 Then, C is replaced using the P2 substitution table. 16 and D 16 The combined sequence is reordered to obtain the subkey K for the 16th round. 16 .
[0067] The following is combined with Figure 2B For Y n =f(R) n-1 ,K n The operation process of ) will be introduced.
[0068] like Figure 2B As shown, the 48-bit right sequence R is first processed by an E-box (a type of bit-expanding permutation used to expand fixed-length input data (e.g., 32 bits) into longer output data (e.g., 48 bits)). n-1 Bit extension is performed to obtain a 48-bit sequence. Then the subkey K for the nth round n with sequence Performing an XOR operation yields the sequence. (Specifically, ), then the sequence The sequence is split into eight 6-bit sequences A1 to A8. Then, a set of SBOX: S1 to S8 is used to perform non-linear processing on sequences A1 to A8 respectively to obtain their corresponding 4-bit sequences B1 to B8. Finally, the 4-bit sequences B1 to B8 are concatenated together to obtain a 32-bit sequence. Finally, the sequence is processed using a P-box (a transposer used to rearrange the bit order of the input data). The order of the bits is rearranged to obtain sequence Y. n Among them, S1 to S8 are different, and correspondingly, the nonlinear processing methods for S1 to S8 are different.
[0069] In some embodiments, each SBOX is a permutation table of 4 rows × 16 columns. When looking up an SBOX, its row number is determined by the first and last bits of the input (b1b6), and its column number is determined by the middle 4 bits (b2b3b4b5).
[0070] Table 2 will be used as an example of the permutation table for S1 for the following illustrative explanation.
[0071] Table 2
[0072]
[0073] For example, if the 6-bit binary number 010101 is input into S1 as shown in Table 2, the first bit 0 and the last bit 1 of the binary data 010101 can be taken to form a two-bit binary number 01, and the binary number 01 can be converted into the decimal number 1. The middle 4 bits 1010 of the binary number 010101 can be taken and converted into the decimal number 10. Then, the data 6 in the 1st row and 10th column of Table 2 (its row number is 0 and its column number is 9) can be found and converted into a 4-bit binary number 0110 for output.
[0074] (3) Inverse initial permutation
[0075] First, the left sequence L obtained from the 16th round of iterative encryption processing is... 16 and right sequence R 16 The data is concatenated to obtain a 64-bit data set, and then the inverse initial permutation is performed on this data set to obtain a 64-bit ciphertext. The inverse initial permutation is the reverse of the initial permutation.
[0076] It's understandable that the non-linear processing of the SBOX involves replacing a 6-bit input data with a 4-bit output data. Since the DES algorithm uses the same set of SBOXes (S1-S8) for its 16 encryption iterations, attackers can easily test the power consumption generated by the non-linear processing of the SBOXes during these 16 iterations. Because this power consumption is related to the input data of the SBOXes, attackers might be able to deduce the distribution of the input data based on this power consumption, thereby inferring the key used for encryption (since the key is mixed with the input data). In other words, attackers can use the power consumption generated by the SBOXes in each iteration of encryption processing to perform a side-channel attack and crack the key.
[0077] Furthermore, during the data encryption process of the electronic device executing the aforementioned DES algorithm, the electronic device will use the intermediate value L generated in each encryption iteration. n and R n The data is stored in a register. Therefore, after each encryption iteration, this register is updated, resulting in a change in power consumption (or "flip power consumption"). The input plaintext and key (in subkeys K1 to K...) are then used. 16 If the register flipping power consumption is fixed after each encryption iteration, and this power consumption is related to the key, then an attacker can first calculate the register flipping power consumption during each encryption iteration, and then calculate the intermediate value L generated by each encryption iteration based on the plaintext. n and R n Then, based on the power consumption of register flipping during each round of encryption and the intermediate value L... n and R nThis allows attackers to deduce the key used in the encryption process. In other words, attackers can exploit the power consumption generated by register flipping during each iteration of encryption to perform a side-channel attack and obtain the key used for encryption.
[0078] Therefore, the DES algorithm has relatively low security and is susceptible to cracking. In view of this, this application provides an encryption method that provides multiple different sets of SBOXes, with each adjacent round of iterative encryption using a different SBOX for nonlinear processing. Because adjacent rounds of iterative encryption employ different nonlinear processing methods, the power consumption and intermediate values generated by these processes differ, increasing the randomness of the nonlinear processing power consumption in each round of encryption, as well as the randomness of the flipping power consumption generated when the intermediate value is stored in the register after each round of encryption. This increases the difficulty of cracking the key based on the nonlinear processing power consumption and the register flipping power consumption, thereby improving encryption security.
[0079] For example, an electronic device can perform masking operations (such as OR, AND, XOR, or bitwise NOT operations) on a set of SBOXes (S1 to S8) in the DES algorithm using four preset masks (e.g., Q0, Q1, Q2, and Q3) to obtain four new SBOXes (hereinafter referred to as "MSBOX"). These four MSBOXes are, in order, MSBOX. 11-18 (This indicates the first group of MSBOXs, which includes 8 MSBOXs) MSBOX 21-28 (This indicates the second group of MSBOXs, which includes 8 MSBOXs) MSBOX 31-38 (This refers to the 3rd group of MSBOX, which includes 8 MSBOX) and MSBOX 41-48 (This indicates the 4th group of MSBOXs, comprising 8 MSBOXs). Then, electronic devices can first access the MSBOXs. 11-18 MSBOX 21-28 MSBOX 31-38 and MSBOX 41-48 The algorithm randomly selects a set of MSBOXs to replace the SBOXes from the first round of the DES algorithm. Then, it sequentially replaces the SBOXes from the remaining rounds of the DES algorithm according to the order of these four MSBOXs. The electronic device can then encrypt the plaintext using the same encryption process as the DES algorithm to obtain the corresponding ciphertext.
[0080] It is understandable that using masking operations to obtain MSBOX and applying it to the encryption process can mask the original data, increase the difficulty of key cracking, and thus improve encryption security.
[0081] Tables 3 to 6 below show four ways to replace SBOX with MSBOX.
[0082] Table 3
[0083] Rounds MSBOX 1 <![CDATA[MSBOX 11-18 ]]> 2 <![CDATA[MSBOX 21-28 ]]> 3 <![CDATA[MSBOX 31-38 ]]> 4 <![CDATA[MSBOX 41-48 ]]> 5 <![CDATA[MSBOX 11-18 ]]> …… …… 16 <![CDATA[MSBOX 41-48 ]]>
[0084] As shown in Table 3, electronic devices can replace SBOX with MSBOX in the first round of the DES algorithm. 11-18 Replace SBOX with MSBOX in the second round of the DES algorithm. 21-28 Replace SBOX with MSBOX in round 3 of the DES algorithm. 31-38 Replace SBOX with MSBOX in round 4 of the DES algorithm. 41-48 Replace SBOX with MSBOX in round 5 of the DES algorithm. 11-18 ...and so on, replacing SBOX with MSBOX in round 16 of the DES algorithm. 41-48 .
[0085] Table 4
[0086] Rounds MSBOX 1 <![CDATA[MSBOX 21-28 ]]> 2 <![CDATA[MSBOX 31-38 ]]> 3 <![CDATA[MSBOX 41-48 ]]> 4 <![CDATA[MSBOX 11-18 ]]> 5 <![CDATA[MSBOX 21-28 ]]> …… …… 16 <![CDATA[MSBOX 11-18 ]]>
[0087] As shown in Table 4, electronic devices can replace SBOX with MSBOX in the first round of the DES algorithm. 21-28 Replace SBOX with MSBOX in the second round of the DES algorithm. 31-38 Replace SBOX with MSBOX in round 3 of the DES algorithm. 41-48 Replace SBOX with MSBOX in round 4 of the DES algorithm. 11-18 Replace SBOX with MSBOX in round 5 of the DES algorithm. 21-28 ...and so on, replacing SBOX with MSBOX in round 16 of the DES algorithm. 11-18 .
[0088] Table 5
[0089] Rounds MSBOX 1 <![CDATA[MSBOX 31-38 ]]> 2 <![CDATA[MSBOX 41-48 ]]> 3 <![CDATA[MSBOX 11-18 ]]> 4 <![CDATA[MSBOX 21-28 ]]> 5 <![CDATA[MSBOX 31-38 ]]> …… …… 16 <![CDATA[MSBOX 21-28 ]]>
[0090] As shown in Table 5, electronic devices can replace SBOX with MSBOX in the first round of the DES algorithm. 31-38 Replace SBOX with MSBOX in the second round of the DES algorithm. 41-48 Replace SBOX with MSBOX in round 3 of the DES algorithm. 11-18 Replace SBOX with MSBOX in round 4 of the DES algorithm. 21-28 Replace SBOX with MSBOX in round 5 of the DES algorithm. 31-38 ...and so on, replacing SBOX with MSBOX in round 16 of the DES algorithm. 21-28 .
[0091] Table 6
[0092]
[0093]
[0094] As shown in Table 6, electronic devices can replace SBOX with MSBOX in the first round of the DES algorithm. 41-48 Replace SBOX with MSBOX in the second round of the DES algorithm. 11-18 Replace SBOX with MSBOX in round 3 of the DES algorithm. 21-28 Replace SBOX with MSBOX in round 4 of the DES algorithm. 31-38 Replace SBOX with MSBOX in round 5 of the DES algorithm. 41-48 ...and so on, replacing SBOX with MSBOX in round 16 of the DES algorithm. 31-38 .
[0095] It can be understood that the nonlinear permutation processing of MSBOX is equivalent to first performing a masking operation (such as an XOR operation) on the input data, then inputting the masking operation result into SBOX for nonlinear permutation processing to obtain the output data of SBOX, and then performing a masking operation on the output data of SBOX to obtain the output data after the masking operation (equivalent to the output data of MSBOX). That is, it is equivalent to retaining the nonlinear permutation processing process of SBOX and performing a masking operation on the input and output data of SBOX.
[0096] For example, the formula for SBOX is shown in formula (2) below:
[0097] Y = SBOX(X)(2)
[0098] Where Y is the output data of SBOX, X is the input data of SBOX, and SBOX() is the SBOX function, representing the nonlinear permutation processing of SBOX.
[0099] The formula for MSBOX is shown in formula (3) below:
[0100] MSY = MSBOX(MSX) = SBOX(X⊕Q) 11 )⊕Q 12 (3)
[0101] Where MSY is the output data of MSBOX, MSX is the input data of MSBOX, MSBOX() is the MSBOX function, representing the nonlinear permutation processing of MSBOX, and Q... 11 and Q 12 For the mask, and Q11 and Q 12 different.
[0102] Figure 3 According to some embodiments of this application, flowcharts of the encryption methods corresponding to Table 3 are shown.
[0103] like Figure 3 As shown, when an electronic device encrypts a 64-bit first plaintext, it can first perform an initial permutation on the first plaintext to obtain a second plaintext, then split the second plaintext into a left sequence L′0 (32 bits) and a right sequence R′0 (32 bits), and then perform 16 rounds of iterative encryption on the left sequence L′0 and the right sequence R′0 based on the first key to obtain a 64-bit second ciphertext, and then perform an inverse initial permutation on the second ciphertext to obtain a 64-bit first ciphertext.
[0104] In some embodiments, rounds 1, 5, 9, and 13 are encrypted using the following formula (4):
[0105]
[0106] Among them, R′ 4b For the right sequence input in round 4b+1, L′ 4b+1 L′ is the left sequence output in round 4b+1. 4b Given the left sequence input in round 4b+1, R′ 4b+1 K′ is the right sequence output in round 4b+1. 4b+1 f1(R′) is the subkey for round 4b+1. 4b ,K′ 4b+1 ) is about T′ 4b and K′ 4b+1 The function, and its operation process includes MSBOX. 11-18 The corresponding operation process, where b is an integer.
[0107] like Figure 4A As shown, Y′ 4b+1 =f1(R′) 4b ,K′ 4b+1 The calculation process is as follows:
[0108] First, the 48-bit right sequence R′ is processed using the E-box. 4b Bit extension is performed to obtain a 48-bit sequence. Then the subkey K′ of round 4b+1 4b+1 with sequence Performing an XOR operation yields the sequence. (Specifically, ), then the sequence Split into eight 6-bit sequences A1'4b+1 ~A8' 4b+1 Then through the first group of MSBOX 11-18 MSBOX 11 ~MSBOX 18 For sequence A1' respectively 4b+1 ~A8' 4b+1 Nonlinear processing is performed to obtain the B1' of the corresponding 4-bit sequences. 4b+1 ~B8' 4b+1 Then take the 4-bit sequence B1' 4b+1 ~B8' 4b+1 Concatenating them together yields a 32-bit sequence. Finally, the sequence is processed using P-boxes. The order of the digits is rearranged to obtain sequence Y' 4b+1 .
[0109] In some embodiments, rounds 2, 6, 10, and 14 are encrypted using the following formula (5):
[0110]
[0111] Among them, R′ 4b+1 For the right sequence input in round 4b+2, L′ 4b+2 L′ is the left sequence output in round 4b+2. 4b+1 R′ is the left sequence input in round 4b+2. 4b+2 K′ is the right sequence output in round 4b+2. 4b+2 f2(R′) is the subkey for round 4b+2. 4b+1 ,K′ 4b+2 ) is about R′ 4b+1 and K′ 4b+2 The function, and its operation process includes MSBOX. 21-28 The corresponding calculation process.
[0112] like Figure 4B As shown, Y′ 4b+2 =f2(R′) 4b+1 ,K′ 4b+2 The calculation process is as follows:
[0113] First, the 48-bit right sequence R′ is processed using the E-box. 4b+1 Bit extension is performed to obtain a 48-bit sequence. Then the subkey K′ of round 4b+2 4b+2 with sequence Performing an XOR operation yields the sequence. (Specifically, ), then the sequence Split into eight 6-bit sequences A1'4b+2 ~A8' 4b+2 Then through the second group of MSBOX 21-28 MSBOX 21 ~MSBOX 28 For sequence A1' respectively 4b+2 ~A8' 4b+2 Nonlinear processing is performed to obtain the corresponding 4-bit sequence B1' 4b+2 ~B8' 4b+2 Then, the 4-bit sequence B1' 4b+2 ~B8' 4b+2 Concatenating them together yields a 32-bit sequence. Finally, the sequence is processed using P-boxes. The order of the digits is rearranged to obtain sequence Y' 4b+2 .
[0114] In some embodiments, rounds 3, 7, 11, and 15 are encrypted using the following formula (6):
[0115]
[0116] Among them, R′ 4b+2 For the right sequence input in round 4b+3, L′ 4b+3 L′ is the left sequence output in round 4b+3. 4b+2 R′ is the left sequence input in round 4b+3. 4b+3 K′ is the right sequence output in round 4b+3. 4b+3 f3(R′) is the subkey for round 4b+3. 4b+2 ,K′ 4b+3 ) is about R′ 4b+2 and K′ 4b+3 The function, and its operation process includes MSBOX. 31-38 The corresponding calculation process.
[0117] like Figure 4C As shown, Y′ 4b+3 =f3(R′) 4b+2 ,K′ 4b+3 The calculation process is as follows:
[0118] First, the 48-bit right sequence R′ is processed using the E-box. 4b+2 Bit extension is performed to obtain a 48-bit sequence. Then the subkey K′ of round 4b+3 4b+3 with sequence Performing an XOR operation yields the sequence. (Specifically, ), then the sequence Split into eight 6-bit sequences A1' 4b+3~A8' 4b+3 Then through the 3rd MSBOX 31-38 MSBOX 31 ~MSBOX 38 For sequence A1' respectively 4b+3 ~A8' 4b+3 Nonlinear processing is performed to obtain the corresponding 4-bit sequence B1' 4b+3 ~B8' 4b+3 Then, the 4-bit sequence B1' 4b+3 ~B8' 4b+3 Concatenating them together yields a 32-bit sequence. Finally, the sequence is processed using P-boxes. The order of the digits is rearranged to obtain sequence Y' 4b+3 .
[0119] In some embodiments, rounds 4, 8, 12, and 16 are encrypted using the following formula (7):
[0120]
[0121] Among them, R′ 4b+3 For the right sequence input in round 4b+4, L′ 4b+4 L′ is the left sequence output in round 4b+4. 4b+3 R′ is the left sequence input in round 4b+4. 4b+4 K′ is the right sequence output in round 4b+4. 4b+4 f4(R′) is the subkey for round 4b+4. 4b+3 ,K′ 4b+4 ) is about R′ 4b+3 and K′ 4b+4 The function, and its operation process includes MSBOX. 41-48 The corresponding calculation process.
[0122] like Figure 4D As shown, K′ 4b+4 =f4(R′) 4b+3 ,K′ 4b+4 The calculation process is as follows:
[0123] First, the 48-bit right sequence R′ is processed using the E-box. 4b+3 Bit extension is performed to obtain a 48-bit sequence. Then the subkey K′ of round 4b+4 4b+4 with sequence Performing an XOR operation yields the sequence. (Specifically, ), then the sequence Split into eight 6-bit sequences A1' 4b+4 ~A8'4b+4 Then through the 4th group of MSBOX 41-48 MSBOX 41 ~MSBOX 48 For sequence A1' respectively 4b+4 ~A8' 4b+4 Nonlinear processing is performed to obtain the corresponding 4-bit sequence B1' 4b+4 ~B8' 4b+4 Then, the 4-bit sequence B1' 4b+4 ~B8' 4b+4 Concatenating them together yields a 32-bit sequence. Finally, the sequence is processed using P-boxes. The order of the digits is rearranged to obtain sequence Y' 4b+4 .
[0124] Understandable. Figure 3 Subkeys K'1 to K' in 16 It is generated based on the first key, and its generation method is the same as... Figure 2A K1~K 16 The generation method is the same, so it will not be repeated here. Alternatively, subkeys K'1 to K' 16 It can also be generated in other ways, which are not limited here.
[0125] In other examples, the electronic device can also perform masking operations on a set of SBOXes (S1 to S8) in the DES algorithm using fewer or more masks (such as 3, 5, 6, or 7), to obtain fewer or more MSBOXs, and then encrypt the first plaintext using fewer or more MSBOXs in fewer or more rounds (such as 8 rounds, 32 rounds, or 48 rounds) to obtain the first ciphertext.
[0126] The encryption method provided in this application is described below with reference to a specific flowchart.
[0127] Figure 5 According to some embodiments of this application, a flowchart of an encryption method is shown.
[0128] like Figure 5 As shown, the encryption methods include:
[0129] S101: The electronic device determines the first plaintext to be encrypted.
[0130] In some embodiments, the data type of the first plaintext may be text, image, or audio.
[0131] It is understood that the first plaintext in the embodiments of this application can be 64 bits, or it can be 32 bits, 48 bits or 96 bits, etc., and there is no limitation thereto. The following description uses a first plaintext of 64 bits as an example.
[0132] S102: The electronic device performs N rounds of iterative encryption processing on the first plaintext based on the first key to obtain the first ciphertext. The iterative encryption processing includes nonlinear processing, and the nonlinear processing method of the nth round is different from that of the (n-1)th round. Here, N is an integer greater than 1, and n is an integer greater than 1 and less than N-1.
[0133] It is understandable that N can be 16, or N can be other values, such as 8, 32 or 64, etc. There is no limitation on this. The following text will use N as 16 as an example for illustration.
[0134] In some embodiments, the electronic device may perform an initial permutation process on the first plaintext to obtain a second plaintext, and then perform N rounds of iterative encryption on the left sequence (e.g., the aforementioned left sequence L′0) and the right sequence (e.g., the aforementioned right sequence R′0) of the second plaintext based on a first key to obtain the second ciphertext, wherein the left sequence and the right sequence are sequences obtained by splitting the second plaintext. Then, the electronic device may perform an inverse initial permutation process on the second ciphertext to obtain the first ciphertext.
[0135] In some embodiments, during the iterative encryption process of the i-th round, the electronic device can use the right sequence input in the i-th round as the left sequence output in the i-th round, and perform corresponding nonlinear processing on the right sequence input in the i-th round based on the subkey of the i-th round to obtain the right encrypted sequence. Then, the electronic device can perform a first operation on the left sequence input in the i-th round and the right encrypted sequence to obtain the right sequence output in the i-th round, where i is an integer greater than or equal to 1 and less than or equal to N. The left sequence input in the first round is the left sequence of the second plaintext, and the right sequence input in the first round is the right sequence of the second plaintext. The second ciphertext is a combination sequence of the left and right sequences output in the N-th round (i.e., a sequence concatenated from the left and right sequences).
[0136] In some embodiments, the above-mentioned nonlinear processing specifically includes: the electronic device performing bit-expansion processing on the right sequence of the i-th round input to obtain a first sequence (such as the aforementioned). or Combine the first sequence with the subkey of the i-th round (such as the aforementioned subkey K′). 4b+1 K′ 4b+2 K′ 4b+3 Or K′ 4b+4 Perform the first operation (such as XOR, or it could be AND, OR, bitwise NOT, etc., without limitation) to obtain the second sequence (such as the aforementioned). or Then, the second sequence undergoes nonlinear processing (such as the aforementioned MSBOX). 11-18 MSBOX 21-28MSBOX 31-38 Or MSBOX 41-48 The corresponding nonlinear permutation process) yields the third sequence (such as the one mentioned above). or Then, the bit order of the third sequence is rearranged to obtain the right encrypted sequence (such as the aforementioned Y'). 4b+1 Y' 4b+2 Y' 4b+3 Or Y' 4b+48 The right sequence, the third sequence, and the right encryption sequence all include H bits, while the first sequence, the subkey, and the second sequence all include V bits, where H is less than V, and both H and V are positive integers. The subkey for the i-th round is generated based on the first key.
[0137] It is understandable that H can be 32 and V can be 48, or H and V can be other values, such as H being 64 and V being 96, etc., without any restrictions.
[0138] In some embodiments, the electronic device includes M permutation tables, where M is an integer greater than 2. The nonlinear processing in the nth round is the nonlinear permutation processing corresponding to the i-th permutation table. The nonlinear processing in the (n-1)-th round is the nonlinear permutation processing corresponding to the j-th permutation table. Here, i and j are both integers greater than 0 and less than or equal to M, and i is not equal to j. The M permutation tables are obtained by performing masking operations on a preset set of permutation tables using M different masks.
[0139] In some embodiments, M is 4, and the M sets of permutation tables can be the aforementioned MSBOX. 11-18 MSBOX 21-28 MSBOX 31-38 and MSBOX 41-48 The four sets of MSBOX permutation tables are obtained by performing masking operations on the SBOX permutation tables in the DES algorithm using four different masks.
[0140] In other embodiments, M may also be other values, such as 3, 5, 6 or 7, etc., without limitation.
[0141] In this embodiment, the nonlinear processing methods used in adjacent rounds of iterative encryption processing are different, resulting in different power consumption. This increases the randomness of the power consumption generated by the nonlinear processing in adjacent rounds, increases the difficulty of side-channel attacks, and thus improves the security of encryption.
[0142] To facilitate understanding of the technical solutions of each embodiment of this application, the hardware structure of the electronic device 100 is described below.
[0143] further, Figure 6According to some embodiments of this application, a schematic diagram of the structure of an electronic device 100 is shown. For example... Figure 6 The electronic device 100 shown includes one or more processors 101, system memory 102, non-volatile memory (NVM) 103, communication interface 104, input / output device 105, system control logic unit 106, and instruction set 107.
[0144] The processor 101 may include one or more processing units, such as a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a microprocessor (MCU), an AI (Artificial Intelligence) processor, or a processing module or circuit of a programmable gate array (FPGA). The AI processor may include a neural network processing unit (NPU), a Zhouyi AIPU, etc.
[0145] System memory 102 is volatile memory, such as random-access memory (RAM), double data rate synchronous dynamic random access memory (DDR SDRAM), etc. System memory is used for temporary storage of data and / or instructions. For example, in some embodiments, system memory 102 can be used to store instructions related to the aforementioned neural network model encryption method.
[0146] The non-volatile memory 103 may include one or more tangible, non-transitory computer-readable media for storing data and / or instructions. In some embodiments, the non-volatile memory 103 may include any suitable non-volatile memory such as flash memory and / or any suitable non-volatile storage device, such as a hard disk drive (HDD), a compact disc (CD), a digital versatile disc (DVD), a solid-state drive (SSD), etc. In some embodiments, the non-volatile memory 103 may also be a removable storage medium, such as a Secure Digital (SD) memory card, etc.
[0147] Specifically, system memory 102 and non-volatile memory 103 may each include a temporary copy and a permanent copy of instruction 107. Instruction 107 may include: executed by at least one of processors 101 to cause electronic device 100 to implement the encryption methods provided in the embodiments of this application.
[0148] The communication interface 104 may include a transceiver for providing a wired or wireless communication interface for the electronic device 100, thereby enabling communication with any other suitable device via one or more networks. In some embodiments, the communication interface 104 may be integrated into other components of the electronic device 100, for example, the communication interface 104 may be integrated into the processor 101. In some embodiments, the electronic device 100 may communicate with other devices through the communication interface 104.
[0149] Input / output device 105 may include input devices such as keyboard and mouse, and output devices such as monitor. Users can interact with electronic device 100 through input / output device 105.
[0150] The system control logic unit 106 may include any suitable interface controller to provide any suitable interface to other modules of the electronic device 100. For example, in some embodiments, the system control logic unit 106 may include one or more memory controllers to provide an interface to the system memory 102 and the non-volatile memory 103.
[0151] In some embodiments, at least one of the processors 101 may be packaged together with the logic of one or more controllers for the system control logic unit 106 to form a system-in-package (SiP). In other embodiments, at least one of the processors 101 may also be integrated on the same chip with the logic of one or more controllers for the system control logic unit 106 to form a system-on-chip (SoC).
[0152] It is understood that electronic device 100 can be any electronic device capable of running neural network models, including but not limited to mobile phones, wearable devices (such as smartwatches), tablets, desktops, laptops, handheld computers, laptops, super mobile personal computers, netbooks, as well as cellular phones, personal digital assistants, AR / VR devices, etc., and this application embodiment does not limit it.
[0153] Understandable. Figure 6 The structure of the electronic device 100 shown is merely an example. In other embodiments, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0154] This application also provides a readable storage medium storing one or more programs, which, when executed by an electronic device, enable the electronic device to implement the methods provided in the foregoing embodiments.
[0155] This application also provides a program product that, when executed on an electronic device, enables the electronic device to implement the methods provided in the foregoing embodiments.
[0156] The various embodiments of the mechanisms disclosed in this application can be implemented in hardware, software, firmware, or a combination of these implementation methods. Embodiments of this application can be implemented as computer programs or program code executable on a programmable system, the programmable system including at least one processor, a storage system (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device.
[0157] Program code can be applied to input instructions to execute the functions described in this application and generate output information. The output information can be applied to one or more output devices in a known manner. For the purposes of this application, the processing system includes any system having a processor such as, for example, a Digital Signal Processor (DSP), a microcontroller, an Application Specific Integrated Circuit (ASIC), or a microprocessor.
[0158] The program code can be implemented using a high-level procedural language or an object-oriented programming language to communicate with the processing system. Assembly language or machine language can also be used when needed. The mechanisms described in this application are not limited to any particular programming language. In either case, the language can be a compiled language or an interpreted language.
[0159] In some cases, the disclosed embodiments may be implemented in hardware, firmware, software, or any combination thereof. The disclosed embodiments may also be implemented as instructions carried or stored thereon on one or more temporary or non-temporary machine-readable (e.g., computer-readable) storage media, which may be read and executed by one or more processors. For example, the instructions may be distributed via a network or through other computer-readable media. Therefore, machine-readable media may include any mechanism for storing or transmitting information in a machine-readable (e.g., computer-readable) form, including but not limited to floppy disks, optical disks, CD-ROMs, magneto-optical disks, read-only memory (ROM), random access memory (RAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic cards or optical cards, flash memory, or tangible machine-readable storage for transmitting information (e.g., carrier waves, infrared signals, digital signals, etc.) using the Internet in the form of electrical, optical, acoustic, or other forms of propagated signals. Therefore, machine-readable media include any type of machine-readable medium suitable for storing or transmitting electronic instructions or information in a machine-readable (e.g., computer-readable) form.
[0160] In the accompanying drawings, some structural or methodological features may be shown in a specific arrangement and / or order. However, it should be understood that such a specific arrangement and / or order may not be necessary. Rather, in some embodiments, these features may be arranged in a manner and / or order different from that shown in the illustrative drawings. Furthermore, the inclusion of structural or methodological features in a particular figure does not imply that such features are required in all embodiments, and in some embodiments, these features may be omitted or may be combined with other features.
[0161] It should be noted that all units / modules mentioned in the device embodiments of this application are logical units / modules. Physically, a logical unit / module can be a physical unit / module, a part of a physical unit / module, or a combination of multiple physical units / modules. The physical implementation of these logical units / modules themselves is not the most important factor; the combination of functions implemented by these logical units / modules is the key to solving the technical problems proposed in this application. Furthermore, to highlight the innovative aspects of this application, the above-described device embodiments of this application have not introduced units / modules that are not closely related to solving the technical problems proposed in this application. This does not mean that the above-described device embodiments do not contain other units / modules.
[0162] It should be noted that, in the examples and description of this patent, the terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one" does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0163] Although this application has been illustrated and described with reference to certain preferred embodiments thereof, those skilled in the art should understand that various changes in form and detail may be made thereto without departing from the spirit and scope of this application.
Claims
1. An encryption method, characterized in that, Applied to electronic devices, the method includes: Determine the first plaintext to be encrypted; The first plaintext is encrypted using the first key for N rounds to obtain the first ciphertext, where N is an integer greater than 1. The iterative encryption process includes nonlinear processing, and the nonlinear processing method for the nth round is different from that for the (n-1)th round, where n is an integer greater than 1 and less than N-1.
2. The method according to claim 1, characterized in that, The process of performing N rounds of iterative encryption on the first plaintext based on the first key to obtain the first ciphertext includes: The first plaintext is subjected to an initial permutation process to obtain the second plaintext; Based on the first key, the left and right sequences of the second plaintext are subjected to N rounds of iterative encryption to obtain the second ciphertext, wherein the left and right sequences are sequences obtained after splitting the second plaintext; The first ciphertext is obtained by performing an inverse initial permutation on the second ciphertext; In the iterative encryption process of the i-th round, the right sequence input in the i-th round is used as the left sequence output in the i-th round, and the right sequence input in the i-th round is subjected to corresponding nonlinear processing based on the subkey of the i-th round to obtain the right encryption sequence. The left sequence input in the i-th round and the right encryption sequence are subjected to a first operation to obtain the right sequence output in the i-th round, where i is an integer greater than or equal to 1 and less than or equal to N. The subkey for the i-th round is generated based on the first key; The left sequence input in the first round is the left sequence of the second plaintext, and the right sequence input in the first round is the right sequence of the second plaintext; The second ciphertext is a combination of the left and right sequences output in the Nth round.
3. The method according to claim 2, characterized in that, The step of performing corresponding nonlinear processing on the right sequence input in the i-th round based on the subkey of the i-th round to obtain the right encrypted sequence includes: The right sequence input in the i-th round is bit-extended to obtain the first sequence; The first sequence is combined with the subkey of the i-th round to obtain the second sequence; The third sequence is obtained by performing the nonlinear processing on the second sequence; The right encryption sequence is obtained by rearranging the bit order of the third sequence; The right sequence, the third sequence, and the right encryption sequence all include H bits, and the first sequence, the subkey, and the second sequence all include V bits, wherein H is less than V, and both H and V are positive integers.
4. The method according to claim 3, characterized in that, The left sequence includes H bits.
5. The method according to claim 4, characterized in that, H is 32, and V is 48.
6. The method according to claim 5, characterized in that, The electronic device includes M sets of permutation tables, where M is an integer greater than 2; The nonlinear processing in the nth round is the nonlinear permutation processing corresponding to the i-th permutation table; The nonlinear processing in the (n-1)th round is the nonlinear permutation processing corresponding to the j-th permutation table; Where i and j are both integers greater than 0 and less than or equal to M, and i is not equal to j.
7. The method according to claim 6, characterized in that, The M permutation tables are obtained by performing masking operations on a preset set of permutation tables using M different masks.
8. The method according to claim 7, characterized in that, N is 16, M is 4.
9. The method according to any one of claims 1 to 8, characterized in that, The data type of the first plaintext includes text, image, or audio.
10. An electronic device, characterized in that, include: Memory, used to store instructions; A processor, when executing the instructions in the memory, causes the electronic device to perform the method of any one of claims 1 to 9.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a computer, cause the computer to perform the method of any one of claims 1 to 9.
12. A computer program product, characterized in that, Includes a computer program / instruction, which, when executed, causes a computer to perform the method of any one of claims 1 to 9.