Flash memory controller and block cipher method thereof
By using a single multiplier circuit in the flash memory controller to support two block cipher mechanisms, the high circuit cost problem in traditional methods is solved, and efficient encryption and decryption operations are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SILICON MOTION INC
- Filing Date
- 2025-01-06
- Publication Date
- 2026-04-28
AI Technical Summary
Traditional block cipher methods require two multiplier circuits, which increases circuit cost.
The flash memory controller uses a single multiplier circuit to support two different types of block cipher mechanisms. The encryption mode is selected by the microcontroller and combined with a mutual exclusion circuit for data encryption and decryption.
It effectively reduces circuit costs and supports two different types of block cipher mechanisms, improving encryption and decryption efficiency.
Smart Images

Figure CN121935979A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to an encryption mechanism, and more particularly to a flash memory controller and a corresponding block cipher method. Background Technology
[0002] Generally speaking, traditional block cipher methods require two multiplier circuits to support two different block cipher mechanisms, which inevitably increases circuit cost. Summary of the Invention
[0003] Therefore, one of the objectives of this invention is to provide a flash memory controller and a corresponding block cipher method to solve the above-mentioned problems.
[0004] According to an embodiment of the present invention, a flash memory controller is disclosed. The flash memory controller is coupled between a host device and a flash memory device and includes a microcontroller and an encryption circuit. The encryption circuit is coupled to the microcontroller and includes a first encryption circuit, a second encryption circuit, a multiplier, a first OR-INF circuit, a third encryption circuit, a fourth encryption circuit, and a second OR-INF circuit. The first encryption circuit is used to encrypt a seed value in a first block cipher mode according to a second key to generate an encrypted seed value. The second encryption circuit is used to encrypt the seed value in a second block cipher mode according to the second key to generate an encrypted seed value. The multiplier is coupled to the first and second encryption circuits and is used to multiply the encrypted seed value generated in the first or second block cipher mode by a specific value α according to a mode selection signal. jA multiplication result at position j (j-th) is generated, where α is a primitive element corresponding to a polynomial of a finite field multiplier. A first mutually exclusive OR circuit is coupled to the multiplier and performs a first mutually exclusive OR operation on the multiplication result at position j and a plaintext block at position j to produce a first mutually exclusive OR result. A data unit sent from the host device and to be written to the flash memory device is received by the flash memory controller and contains a series of plaintext blocks, including the plaintext block at position j. A third encryption circuit is coupled to the first mutually exclusive OR circuit and encrypts the first mutually exclusive OR result in a first block cipher mode according to a first key to produce an encrypted mutually exclusive OR result. A fourth encryption circuit is coupled to the first mutually exclusive OR circuit and encrypts the first mutually exclusive OR result in a second block cipher mode according to the first key to produce the encrypted mutually exclusive OR result. The second mutually exclusive OR circuit is coupled to the multiplier, the third encryption circuit, and the fourth encryption circuit, and is used to perform a second mutually exclusive OR operation on the multiplication result at the j-th position and the encrypted mutually exclusive OR result generated in the first block cipher mode or the second block cipher mode, to produce a second mutually exclusive OR result as a ciphertext block at the j-th position, which is then written to the flash memory device. The multiplier operating in the first block cipher mode or the second block cipher mode is determined by either the mode selection signal generated by the microcontroller or the mode selection signal recorded in the plaintext block at the 0th position of the series of plaintext blocks.
[0005] According to an embodiment of the present invention, a block cipher method for a flash memory controller connected between a host device and a flash memory device is disclosed. The block cipher method includes: providing a first encryption circuit for encrypting a subvalue in a first block cipher mode according to a second key to generate an encrypted seed value; providing a second encryption circuit for encrypting the seed value in a second block cipher mode according to a second key to generate an encrypted seed value; and using a multiplier to multiply the encrypted seed value generated in the first block cipher mode or the second block cipher mode by a specific value α according to a mode selection signal. jTo generate a multiplication result at the j-th position, where α is an original element corresponding to a polynomial of a finite field multiplier; to perform a first mutually exclusive OR operation on the multiplication result at the j-th position and a plaintext block at the j-th position to generate a first mutually exclusive OR result, wherein a data unit sent from the host device and to be written to the flash memory device is received by the flash memory controller and contains a series of plaintext blocks, including the plaintext block at the j-th position; to provide a third encryption circuit to encrypt the first mutually exclusive OR result in the first block cipher mode according to a first key to generate an encrypted mutually exclusive OR result; to provide a fourth encryption circuit to encrypt the first mutually exclusive OR result in the second block cipher mode according to the first key. In the block cipher mode, the first mutually exclusive OR result is encrypted to produce the encrypted mutually exclusive OR result; and a second mutually exclusive OR operation is performed on the multiplication result at the j-th position and the encrypted mutually exclusive OR result generated in the first block cipher mode or the second block cipher mode to produce a second mutually exclusive OR result as a ciphertext block at the j-th position, which is written to the flash memory device; the multiplier operating in the first block cipher mode or the second block cipher mode is determined by either the mode selection signal generated by a microcontroller controlled by the flash memory or the mode selection signal recorded in the plaintext block at the 0th position of the series of plaintext blocks. Attached Figure Description
[0006] Figure 1 This is a schematic diagram of a flash memory controller according to an embodiment of the present invention.
[0007] Figure 2 This is an embodiment of the present invention. Figure 1 The diagram shows the operation of the multiplier.
[0008] Figure 3 This is an embodiment of the present invention. Figure 1 The circuit diagram of the multiplier in the image.
[0009] Figure 4 This is a schematic diagram of a flash memory controller according to another embodiment of the present invention.
[0010] Figure 5 This is an embodiment of the present invention. Figure 4 The circuit diagram of the multiplier in the image.
[0011] [Symbol Explanation]
[0012] 100,400: Flash memory controller
[0013] 101: Main unit
[0014] 102: Flash memory device
[0015] 105D: Decryption Circuit
[0016] 105E: Encryption Circuit
[0017] 110: Microcontroller
[0018] 115A: First encryption circuit
[0019] 115B: Second encryption circuit
[0020] 115C: Third encryption circuit
[0021] 115D: Fourth Encryption Circuit
[0022] 120A: Fifth Encryption Circuit
[0023] 120B: Sixth Encryption Circuit
[0024] 120C: First decryption circuit
[0025] 120D: Second decryption circuit
[0026] 125A, 125B: Multiplexer
[0027] 130A: First Mutex OR Circuit
[0028] 130B: Third Mutex OR Circuit
[0029] 135A: Second Mutex OR Circuit
[0030] 135B: Fourth Mutex OR Circuit
[0031] 305: First Multiplexer
[0032] 310: Multiplication Circuit
[0033] 315: Second Multiplexer Detailed Implementation
[0034] The present invention aims to provide a flash memory controller and block cipher method that can support two different types of block cipher mechanisms using a single multiplier circuit. This can significantly reduce circuit costs.
[0035] Figure 1This is a schematic diagram of a flash memory controller 100 according to an embodiment of the present invention. The flash memory controller 100 is used to couple between a host device 101, such as a personal computer device, and one or more flash memory devices 102, such as NAND flash memory chips / granules. The flash memory controller 100 includes, for example, an encryption circuit 105E, a decryption circuit 105D, and a microcontroller 110, which is coupled to and used to control the encryption circuit 105E and the decryption circuit 105D.
[0036] For encryption operations, the key is parsed as a concatenation of two equal-size key fields, Key1 and Key2. Encryption circuit 105E uses the two keys, Key1 and Key2, to perform block cipher encryption to protect data sent from host device 101 and to be written to a page of flash memory device 102. Encryption circuit 105E supports two different types of encryption mechanisms (e.g., operation / mode). Decryption circuit 105D uses the two corresponding keys, Key1 and Key2, to perform block decipher decryption to obtain correct information from the data read from that page of flash memory device 102. This correct information is then sent to host device 101 if requested by host device 101. Decryption circuit 105D also supports two different types of corresponding decryption mechanisms.
[0037] In practice, the encryption circuit 105E includes a first encryption circuit 115A supporting a first block cipher mechanism, a second encryption circuit 115B supporting a second block cipher mechanism, a third encryption circuit 115C supporting the first block cipher mechanism, a fourth encryption circuit 115D supporting the first block cipher mechanism, a single-multiplexer 125A, a first exclusive-OR (XOR) circuit 130A, and a second exclusive-OR circuit 135A. The first block cipher mechanism is, for example (but not limited to), an XEX-based Tweaked-codebook mode with ciphertext Stealing (hereinafter referred to as XTS-AES) mechanism used for ciphertext stealing and operating in the Advanced Encryption Standard (AES) mode. The AES is a symmetric block cipher standard for encrypting data and is provided and defined by the IEEE Standards Association. The second block cipher mechanism is, for example (but not limited to), a Commercial Cryptography 4 (SM4) mechanism, which is a symmetric block cipher provided by the Chinese National Standard and used in cryptographic algorithms.
[0038] Similarly, the decryption circuit 105D includes a fifth encryption circuit 120A supporting the first block cipher mechanism, a sixth encryption circuit 120B supporting the second block cipher mechanism, a first decryption circuit 120C supporting the first block cipher mechanism, a second decryption circuit 120D supporting the first block cipher mechanism, a single-multiplexer 125B, a third OR circuit 130B, and a fourth OR circuit 135B.
[0039] In this embodiment, the microcontroller 110 sends a mode selection signal Mode to the encryption circuit 105E and the decryption circuit 105D, respectively, to select one mode from two different modes of different block cipher mechanisms. For example, the encryption circuit 105E has two cipher modes, such as a first block cipher mode corresponding to the XTS-AES mechanism and a second block cipher mode corresponding to the SM4 mechanism. The operation of encryption circuits 115A and 115C is associated with the XTS-AES mechanism (i.e., the first block cipher mode), while the operation of encryption circuits 115B and 115D is associated with the SM4 mechanism (i.e., the second block cipher mode). The operation of multiplier 125A and bitwise XOR circuits 130A and 135A is shared by the XTS-AES mechanism (i.e., the first block cipher mode) and the SM4 mechanism (i.e., the second block cipher mode). Similarly, in decryption circuit 105D, the operation of encryption circuit 120A and decryption circuit 120C is associated with the XTS-AES mechanism (i.e., the first block cipher mode), while the operation of encryption circuit 120B and decryption circuit 120D is associated with the SM4 mechanism (i.e., the second block cipher mode). The operation of multiplier 125B, bit mutex circuits 130B and 135B is shared by both the XTS-AES mechanism (i.e., the first block cipher mode) and the SM4 mechanism (i.e., the second block cipher mode).
[0040] For data encryption, the flash memory controller 100 receives a sequence of data units (e.g., sectors) to be written to the flash memory device 102, and this sequence of data units is treated as plaintext data by the encryption circuit 105E. The encryption circuit 105E encrypts the plaintext data into ciphertext data and then writes the ciphertext data into the flash memory device 102 to protect the sequence of data units. For example, P j This refers to a block (i.e., a plaintext block) at the j-th location of the plaintext data sent from the host device 101 and received by the flash memory controller 100. A plaintext block has, for example, a bit length of 128 bits (but is not limited to), while a data unit, for example, a data sector, may include a series of plaintext blocks P0, P1, P2, ..., P... m C jThis refers to the block of ciphertext data ultimately written to flash memory device 102 at the j-th location. This block, for example, is called the ciphertext block at the j-th location and has a bit length of 128 bits, where j is the sequence number of the 128-bit ciphertext data block. Conversely, for data decryption, flash memory controller 100 reads a series of data units from flash memory device 102, and decryption circuit 105D, for example, decrypts the ciphertext data (e.g., the ciphertext block at the j-th location) to generate the plaintext data (i.e., the plaintext block at the j-th location) and transmits the plaintext data requested by host device 101 to host device 101.
[0041] When the microcontroller 110 of the flash memory controller 100 selects the first block cipher mode corresponding to the AES encryption mechanism, the first encryption circuit 115A performs an AES encryption based on the key Key2 in the first block cipher mode to encrypt a subvalue i to generate an encrypted seed value E(Key2,i) of the j-th block to the multiplier 125A, where the seed value i is, for example, the value of 128-bit tweak data. Each sector is assigned a corresponding tweak value i, which is a non-negative integer, and the tweak value can be assigned consecutively. In this case, the encryption circuit 115B corresponding to the SM4 encryption mechanism does not work, that is, its operation is disabled. The multiplier 125A is a Galois field (GF) multiplier, which is a finite field used in cryptography, such as GF(2πf). m The value of 2 represents a prime number in the finite field, where m is a positive integer, for example, equal to 128. The multiplication operation is performed modulo a primitive polynomial of degree 128. The value of α is a GF(2πε₀) of the corresponding polynomial x. 128 ) of the primitive element of GF(2) 128 )corresponding to polynomial x), while α j It is GF(2) 128 The multiplier 125A multiplies the encrypted seed value E(Key2,i) of the j-th block by itself. j Multiply to produce the j-th multiplication result The first mutual exclusion circuit 130A is used for the plaintext block P at position j. j The result of multiplying with the j-th product The first mutual exclusion circuit 130A is for the plaintext block P at the j-th position. j The result of multiplying with the j-th product Perform a first mutually exclusive OR operation to produce a first mutually exclusive OR result. Then, the third encryption circuit 115C, in the first block cipher mode, performs the first mutually exclusive OR operation based on the key Key1. The AES encryption is performed to produce an encrypted mutually exclusive OR result CC = E(Key1,PP) for the block at position j. Then, the second mutually exclusive OR circuit 135A multiplies the encrypted mutually exclusive OR result CC = E(Key1,PP) for the block at position j with the multiplied result of the key. Perform a second mutually exclusive OR operation to produce a second mutually exclusive OR result as the ciphertext block C at position j. j It should be noted that in this case, the fourth encryption circuit 115D corresponding to the SM4 encryption mechanism is also disabled.
[0042] For the second block cipher mode corresponding to the SM4 encryption mechanism, the operation of encryption circuits 115A and 115C is disabled, while the operation of encryption circuits 115B and 115D is enabled. The flash memory controller 100 selects the second block cipher mode corresponding to the SM4 encryption mechanism. In this mode, the second encryption circuit 115B performs SM4 encryption based on key Key2 to encrypt the seed value i, generating an encrypted seed value E(Key2,i) for the j-th block, which is then fed to multiplier 125A. Multiplier 125A multiplies the encrypted seed value E(Key2,i) of the j-th block with α... j The values are multiplied to produce the j-th multiplication result. Mutual exclusion circuit 130A for plaintext block P at position j j The result of multiplying with the j-th product Perform the first mutually exclusive OR operation to produce the first mutually exclusive OR result. Then, the fourth encryption circuit 115D will perform SM4 encryption based on key Key1 in the second block cipher mode to verify the first mutual exclusion or result. Encryption is performed to generate the encrypted mutex OR result CC = E(Key1,PP) of the block at position j. Then, the second mutex OR circuit 135A multiplies the encrypted mutex OR result CC = E(Key1,PP) of the block at position j with the result of the multiplication of the key. Perform a second mutually exclusive OR operation to produce the ciphertext block C at position j. j That is, the multiplier 125A in the encryption circuit 105E is a single multiplier shared by two different types of encryption mechanisms.
[0043] Accordingly, the flash memory controller 100 reads a series of data units (i.e., a sequence of data units), such as sectors, from the flash memory device 102, and these data units are treated as ciphertext data by the decryption circuit 105D. At this time, C j The block of ciphertext data read from flash memory device 102 is the j-th position of the ciphertext data, for example, called the j-th position ciphertext block and has a length of 128 bits, where the value of j is the sequence number of the 128-bit ciphertext block within a data sector.
[0044] For AES decryption, when the flash memory controller 100 selects the first block cipher mode corresponding to the AES decryption mechanism, the fifth encryption circuit 120A in the first block cipher mode performs AES encryption based on the key Key2 to encrypt the seed value i (e.g., a 128-bit adjustment data) to generate an encrypted seed value E(Key2,i) for the j-th block, which is then fed to the multiplier 125B. The multiplier 125B is, for example, GF(2... m The value of 2 is a prime number, and m is a positive integer, such as 128. Multiplier 125B multiplies the encrypted seed value E(Key2,i) of the j-th block by a specific value α. j To produce the j-th multiplication result The third mutual exclusion circuit 130B pairs the ciphertext block C at position j. j The result of multiplying with the j-th product Perform a third mutual exclusion OR operation to produce a third mutual exclusion OR result. Then, the first decryption circuit 120C will perform AES decryption based on the key Key1 in the first block cipher mode to decrypt the third mutex or result. The decrypted mutex OR result PP = D(Key1, CC) of the block at position j is generated. Then, the second mutex OR circuit 135B multiplies the decrypted mutex OR result PP = D(Key1, CC) of the block at position j with the result T = ... Perform a mutual exclusion OR operation to produce a fourth mutual exclusion OR result as the plaintext block P at position j. j It should be noted that in this case, the sixth encryption circuit 120B and the second decryption circuit 120D are disabled.
[0045] For SM4 decryption, the operation of the fifth encryption circuit 120A and the first decryption circuit 120C is disabled, while the operation of the sixth encryption circuit 120B and the second decryption circuit 120D is enabled. Similarly, when the flash memory controller 100 selects the second block cipher mode corresponding to the SM4 decryption mechanism, the sixth encryption circuit 120B in the second block cipher mode performs SM4 encryption based on the key Key2 to encrypt the seed value i (e.g., a 128-bit adjustment data value) to generate an encrypted seed value E(Key2,i) for the j-th block, which is then fed to the multiplier 125B. The multiplier 125B multiplies the encrypted seed value E(Key2,i) of the ciphertext block at the j-th position with α. j Multiply the values to produce a multiplication result at the j-th position. The third mutual exclusion circuit 130B pairs the ciphertext block C at position j. j The result of multiplying with the j-th position Perform a third mutual exclusion OR operation to produce a third mutual exclusion OR result. Then, the second decryption circuit 120D will perform SM4 decryption based on the key Key1 in the second block cipher mode to decrypt the third mutex or result. The decrypted mutex OR result PP = D(Key1, CC) of the block at position j is generated. Then, the fourth mutex OR circuit 135B multiplies the decrypted mutex OR result PP = D(Key1, CC) of the block at position j with the result of the multiplication of the block at position j. Perform a fourth mutual exclusion OR operation to produce the result of the fourth mutual exclusion OR operation as the plaintext block P at position j. j .
[0046] In this way, both AES encryption and SM4 encryption operations require only a single multiplier circuit, and both AES decryption and SM4 decryption operations also require only a single multiplier circuit. This can effectively reduce the cost of the circuit.
[0047] Furthermore, in other embodiments, the encryption circuit 105E and the decryption circuit 105D can be integrated into a single block cipher circuit, which can perform encryption and decryption operations separately. For example (but not limited to), in practice, in one embodiment, the operation of the first decryption circuit 120C and the second decryption circuit 120D can be respectively integrated into the third encryption circuit 115C and the fourth encryption circuit 115D, so that circuits 115C and 115D are configured as circuits with both encryption and decryption functions. The modified encryption circuit 105E can have the same decryption function as the decryption circuit 105D. That is, the decryption circuit 105D can be optional and can be excluded from the flash memory controller 100. Such variations of embodiments also fall within the scope of the present invention.
[0048] Figure 2 According to an embodiment of the present invention Figure 1 The diagram shows the operation of the multiplier 125A. Figure 2 In XEX mode encryption, the multiplier 125A operates on a series of multiplications of the α value itself. For the plaintext block at position j where j is zero (i.e., the plaintext block at position 0), its value α... j =α 0 =1, for example, for a block cipher encryption, because the value α j =α 0 =1, therefore, for example, the operation of the AES encryption circuit 115A in the first block cipher mode is to encrypt the assigned seed value i using the key Key2 to produce the encrypted seed value as the multiplication result T = E(Key2,i) at the 0th position. That is, in this case, the operation of multiplier 125A is bypassed. That is, when generating the multiplication result at the 0th position, multiplier 125A is bypassed, and the encrypted seed value generated in the first block cipher mode or the second block cipher mode can be directly used as the multiplication result at the 0th position. Next, the multiplication result at the 0th position is subjected to a mutual exclusion OR operation with the corresponding plaintext block (i.e., the plaintext block at the 0th position) to produce a first mutual exclusion OR result, and then the first mutual exclusion OR result is encrypted using a block cipher (e.g., by using the key Key1). Figure 1 The AES encryption circuit 115C in the middle is used for encryption to produce an encrypted mutex OR result, which is then multiplied by the result of the multiplication at position 0 (which is the encrypted seed value because α). j =α 0 =1) Perform a mutually exclusive OR operation to produce a second mutually exclusive OR result as the ciphertext block at position 0. That is, for block cipher encryption at position 0, the operation of multiplier 125A can be bypassed.
[0049] For the following plaintext blocks, other block cipher encryption methods will not bypass them. For the plaintext block at position j, where j is 1 (i.e., the plaintext block at position 1), its value α j =α 1 =α, for example, the encrypted seed value E(Key2,i) is generated by encrypting the block cipher at position 0 using the key Key2. This encrypted seed value E(Key2,i) can be passed to multiplier 125A and multiplied by the value α to produce the multiplication result at position 1. The result of multiplication at the first position This first mutually exclusive OR operation is performed with the corresponding plaintext block (i.e., the plaintext block at position 1) to produce the first mutually exclusive OR result. This first mutually exclusive OR result is then encrypted using a block cipher based on key Key1 to produce an encrypted mutually exclusive OR result, which is then multiplied with the result of the first position. Perform a mutual exclusion OR operation to produce the second mutual exclusion OR result as the ciphertext block at the first position.
[0050] Next, for the plaintext block at position j=2 (i.e., the plaintext block at position 2), its value α j =α 2 =α×α, for example, the result of multiplying the first position. It can be transmitted to multiplier 125A to be multiplied again with the value α to produce a second position multiplication result. Should A mutual exclusion OR operation is performed with the corresponding plaintext block (i.e., the plaintext block at the second position) to produce a first mutual exclusion OR result. Then, this first mutual exclusion OR result is encrypted using a block cipher based on key Key1 to produce an encrypted mutual exclusion OR result. This encrypted mutual exclusion OR result is then multiplied with the result of the operation at the second position. A mutual exclusion OR operation is performed to produce the ciphertext block at the second position. In other words, multiplier 125A can directly multiply the result at the (j-1)th position. Multiply by the value α to produce the multiplication result at the j-th position. The operation of multiplier 125B in decryption circuit 105D is similar to that of multiplier 125A in encryption circuit 105E, and will not be described in detail here.
[0051] Figure 3 According to an embodiment of the present invention Figure 1 The circuit diagram of multiplier 125A is shown below. Multiplier 125A includes a first multiplexer 305, a multiplication circuit 310, and a second multiplexer 315. The first multiplexer 305 has a first input section corresponding to "IEEE" and a first input section corresponding to "SM4," while the second multiplexer 315 has a third input section corresponding to "IEEE" and a fourth input section corresponding to "SM4." Multiplication circuit 310 is a GF(2) multiplier used for AES encryption or decryption mechanisms. 128 A multiplier that can be used based on binary arithmetic to multiply two polynomials, for example, multiplying a 128-bit value representing the value α (e.g., 0000…0102) with a 128-bit value representing the encrypted seed value, and then modularly reducing the result to an irreducible polynomial, such as x. 128 +x7 +x 2 +x+1 (but not limited) makes the multiplication result conform to 128 bits. The microcontroller 110 sends the mode selection signal Mode to control the operation of the first multiplexer 305 and the second multiplexer 315.
[0052] To generate the multiplication result at position 0, the operation of multiplier 125A can be bypassed, and the encrypted seed value generated in the first block cipher mode or the second block cipher mode can be directly used as the multiplication result at position 0.
[0053] For producing the multiplication result at the first position, for example, multiplication circuit 310 is a GF(2) for AES encryption / decryption mechanism. 128 The multiplier, and in the first block cipher mode, the first multiplexer 305, according to the mode selection signal Mode sent from the microcontroller 110, can select and output the bit sequence (i.e., the 128 bits from bit 0 to bit 127 used to represent the multiplication result at the 0th position) generated from the first encryption circuit 115A and directly input to the first input portion corresponding to "IEEE" as a series of multiple first output bits (i.e., the first output bit sequence). In this way, in the first block cipher mode, the multiplication circuit 310 can correctly multiply the values of two polynomials, for example, multiplying the 128-bit value representing the value α (e.g., 0000…0102) and the 128-bit value representing the first output bit sequence, to produce a multiplication result bit sequence that conforms to the 128-bit limit. According to the mode selection signal Mode sent from the microcontroller 110, the second multiplexer 315 in the first block cipher mode will directly select the multiplication result bit sequence (that is, the corresponding 128 bits corresponding to "IEEE") as a series of second output bits (i.e., the second output bit sequence), which will be used as the multiplication result of the first position.
[0054] In addition, in the second block cipher mode, for the multiplication result of the first position, the first multiplexer 305 can perform an order-reversed operation on the other bit sequence generated from the second encryption circuit 115B to generate and select the bit sequence corresponding to the reverse order of "SM4" (i.e., bits from bit127 to bit0) as the first output bit sequence. In other words, it generates 128 bits (i.e., bits from bit127 to bit0) by reversing the order of the 128 bits from bit0 to bit127 represented by the multiplication result of the first position generated by the second encryption circuit 115B. Then, the 128 bits (from bit127 to bit0) are input to the second input part of the first multiplexer 305, so that the first multiplexer 305 can select and output the 128 bits corresponding to "SM4" as the sequence of first output bits according to the mode selection signal Mode sent from the microcontroller 110, and output the sequence of first output bits to the multiplication circuit 310.
[0055] Therefore, in the second block cipher mode, the multiplication circuit 310, belonging to the AES encryption / decryption mechanism, still performs the same multiplication operation, that is, multiplying two polynomials, for example, multiplying the 128-bit value representing the value α (e.g., 0000…0102) and the sequence of the first output bits (in this case, the reversed sequence of 128 bits) to produce a sequence of multiple multiplication result bits. Then, the second multiplexer 315 in the second block cipher mode can perform another reverse sorting operation on this sequence of multiple multiplication result bits to produce and select multiple bits of another reversed sequence corresponding to "SM4" as a sequence of multiple second output bits as the multiplication result for the first position. That is, the order of the 128 bits of the multiplication result bits is reversed again to produce the multiplication result for the first position in the SM4 encryption / decryption mechanism.
[0056] Similarly, for generating the multiplication result at the j-th position, when the mode selection signal Mode indicates the first block cipher mode, the first multiplexer 305 can directly select the bit sequence of the multiplication result at the (j-1)-th position as the first output bit sequence. And when the mode selection signal Mode indicates the second block cipher mode, it can perform the reverse sorting operation on the bit sequence of the multiplication result at the (j-1)-th position to generate and select the reversed bit sequence as the first output bit sequence. The multiplication circuit 310 corresponding to the cryptographic operation of the first block cipher mode is used to multiply the first output bit sequence by the bit sequence representing α to generate a multiplication result bit sequence. When the mode selection signal Mode indicates the first block cipher mode, the second multiplexer 315 can directly select the multiplication result bit sequence as the second output bit sequence as the multiplication result at the j-th position. When the mode selection signal Mode indicates the second block cipher mode, it can perform another reverse sorting operation on the multiplication result bit sequence to generate and select the other reversed bit sequence as the second output bit sequence as the multiplication result at the j-th position.
[0057] In this way, even though the multiplication circuit 310 is not originally suitable for the SM4 encryption / decryption mechanism, it can be equivalently applied to the SM4 encryption / decryption mechanism due to the bit order reversal operation and the operation of the two multiplexers 305 and 315. Therefore, a single multiplier 125A can be used for both the SM4 encryption / decryption mechanism and the AES encryption / decryption mechanism. Similarly, a single multiplier 125B can also be used for both the SM4 encryption / decryption mechanism and the AES encryption / decryption mechanism.
[0058] In other embodiments, the microcontroller that sends the mode selection signal Mode may be optional. That is, the multiplier operating in either the first or second block cipher mode can be determined by either a mode selection signal generated by the microcontroller or a mode selection signal recorded in a plaintext block at position 0 of a series of plaintext blocks. Please refer to [reference needed]. Figure 4 and Figure 5 . Figure 4 This is a schematic diagram of a flash memory controller 400 according to another embodiment of the present invention. Figure 5 According to an embodiment of the present invention Figure 4 A circuit diagram of multiplier 425A (or 425B) is shown. Flash memory controller 400 includes encryption circuit 105E, decryption circuit 105D, and a microcontroller 410. In this embodiment, microcontroller 410 is used to assign the aforementioned seed value and is not used to transmit the mode selection signal Mode to encryption circuit 105E and decryption circuit 105D. Figure 4The operation of encryption circuit 105E and decryption circuit 105D in the circuit is similar to that of encryption circuit 105E and decryption circuit 105D in the circuit. Figure 1 The operation of the encryption circuit 105E and decryption circuit 105D in the circuit is related to... Figure 1 The difference lies in that multiplier 425A is used to operate in either the first block cipher mode or the second block cipher mode based on information (i.e., the mode selection signal) recorded in the first plaintext block (i.e., the plaintext block at position 0), while multiplier 425B is used to operate in either the first block cipher mode or the second block cipher mode based on information recorded in the decrypted first ciphertext block (i.e., the ciphertext block at position 0 after decryption). In other words, multipliers 425A and 425B determine whether to use the first block cipher mode or the second block cipher mode for the data in the j-th position block based on information from the data in the 0-th block.
[0059] In this embodiment, since the operation of the multiplier can be bypassed for encryption / decryption of the 0th region, both multipliers 425A and 425B are suitable for the AES or SM4 mechanism. Therefore, the mode selection information or signal can be stored and carried by the plaintext block at the 0th position, or it can be generated by a microcontroller. Multiplier 425A can correctly operate on the plaintext block at the jth position based on the mode selection signal stored in the plaintext block at the 0th position or the mode selection signal generated by a microcontroller, and multiplier 425A can also correctly operate on the plaintext block at the jth position based on either the mode selection signal stored in the ciphertext block at the 0th position after decryption of the plaintext block at the 0th position or the mode selection signal generated by a microcontroller. Other operations are similar and will not be described further for simplicity.
[0060] The above description is only a preferred embodiment of the present invention. All equivalent changes and modifications made in accordance with the claims of the present invention shall be covered by the present invention.
Claims
1. A flash memory controller for coupling between a host device and a flash memory device, comprising: A microcontroller; as well as An encryption circuit, coupled to a microcontroller, includes: A first encryption circuit is used to encrypt a seed value in a first block cipher mode according to a second key to generate an encrypted seed value. A second encryption circuit is used to encrypt the seed value in a second block cipher mode according to a second key to generate an encrypted seed value; A multiplier, coupled to the first encryption circuit and the second encryption circuit, is used to multiply the encrypted seed value generated in the first block cipher mode or the second block cipher mode by a specific value α according to a mode selection signal. j To produce a multiplication result at position j (j-th), where α is a primitive element corresponding to a polynomial of a finite field multiplier; A first mutually exclusive OR circuit, coupled to the multiplier, is used to perform a first mutually exclusive OR operation on the multiplication result of the j-th position and a plaintext block of the j-th position to produce a first mutually exclusive OR result. A data unit sent from the host device and to be written to the flash memory device is received by the flash memory controller and contains a series of plaintext blocks, wherein the series of plaintext blocks includes the plaintext block of the j-th position. A third encryption circuit, coupled to the first mutex circuit, is used to encrypt the first mutex result in the first block cipher mode according to a first key, so as to produce an encrypted mutex result. A fourth encryption circuit, coupled to the first mutex circuit, is used to encrypt the first mutex result in the second block cipher mode according to the first key, so as to produce the encrypted mutex result. as well as A second mutually exclusive OR circuit, coupled to the multiplier, the third encryption circuit, and the fourth encryption circuit, is used to perform a second mutually exclusive OR operation on the multiplication result at the j-th position and the encrypted mutually exclusive OR result generated in the first block cipher mode or the second block cipher mode, so as to generate a second mutually exclusive OR result as a ciphertext block at the j-th position, and the ciphertext block at the j-th position is written to the flash memory device. The multiplier operating in the first block cipher mode or the second block cipher mode is determined by either the mode selection signal generated by the microcontroller or the mode selection signal recorded in the plaintext block at position 0 of the series of plaintext blocks.
2. The flash memory controller as described in claim 1, characterized in that, When the multiplier operates in the first block cipher mode, the first and third encryption circuits are enabled, while the second and fourth encryption circuits are disabled; and when the multiplier operates in the second block cipher mode, the first and third encryption circuits are disabled, while the second and fourth encryption circuits are enabled.
3. The flash memory controller as described in claim 1, characterized in that, The first block cipher mode is associated with the operation of an advanced encryption standard, while the second block cipher mode is associated with a different encryption standard.
4. The flash memory controller as described in claim 1, characterized in that, When a multiplication result at position 0 is generated, the multiplier is bypassed, and the encrypted seed value generated in the first block cipher mode or the second block cipher mode is directly used as the multiplication result at position 0.
5. The flash memory controller as described in claim 4, characterized in that, The multiplier includes: A first multiplexer has a first input section and a second input section, configured to select a bit sequence generated from the first encryption circuit and directly input to the first input section as a first output bit sequence when the mode selection signal indicates the first block cipher mode, and configured to perform an order-reversed operation on another bit sequence generated by the second encryption circuit when the mode selection signal indicates the second block cipher mode, to generate and select an order-reversed sequence of bits as the first output bit sequence; A multiplication circuit, corresponding to a cryptographic operation of the first block cipher mode, is coupled to the first multiplexer for multiplying the first output bit sequence with a bit sequence representing α to produce a multiplied bit sequence; and A second multiplexer, coupled to the multiplication circuit, has a third input section and a fourth input section, for directly selecting the multiplication result bit sequence as a second output bit sequence as the multiplication result of the first position when the mode selection signal indicates the first block cipher mode, and for performing another reverse sorting operation on the multiplication result bit sequence to generate and select another reversed bit sequence as the second output bit sequence as the multiplication result of the first position when the mode selection signal indicates the second block cipher mode.
6. The flash memory controller as described in claim 5, characterized in that, For the product result at position j: When the mode selection signal indicates the first block cipher mode, the first multiplexer directly selects one of the bit sequences of the multiplication result at the (j-1)th position as the first output bit sequence; and when the mode selection signal indicates the second block cipher mode, the first multiplexer performs the reverse sorting operation on the bit sequence of the multiplication result at the (j-1)th position to generate and select the reversed bit sequence as the first output bit sequence. The multiplication circuit corresponding to the cryptographic operation of the first block cipher mode is used to multiply the first output bit sequence with the bit sequence representing α to produce the multiplied result bit sequence; and When the mode selection signal indicates the first block cipher mode, the second multiplexer directly selects the multiplication result bit sequence as the second output bit sequence as the multiplication result at the j-th position. When the mode selection signal indicates the second block cipher mode, the second multiplexer performs another reverse sorting operation on the multiplication result bit sequence to generate and select another reversed bit sequence as the second output bit sequence as the multiplication result at the j-th position.
7. The flash memory controller as described in claim 1, characterized in that, Also includes: A decryption circuit, coupled to the microcontroller, includes: A fifth encryption circuit is used to encrypt the seed value in the first block cipher mode according to the second key to generate the encrypted seed value; A sixth encryption circuit is used to encrypt the seed value in the second block cipher mode according to the second key to generate the encrypted seed value; Another multiplier, coupled to the fifth and sixth encryption circuits, is used to multiply the encrypted seed value generated in the first or second block cipher mode by the specific value α according to the mode selection signal. j Multiply to produce another multiplication result at the j-th position; A third mutual exclusion circuit, coupled to the other multiplier, is used to perform a third mutual exclusion OR operation on the multiplication result of the other j-th position and the ciphertext block of the j-th position to produce a third mutual exclusion OR result. A data unit read from the flash memory device is received by the flash memory controller and contains a sequence of ciphertext blocks, which includes the ciphertext block of the j-th position. A first decryption circuit, coupled to the third mutex circuit, is used to decrypt the third mutex result in the first block cipher mode according to the first key, so as to produce a decrypted mutex result. A second decryption circuit, coupled to the third mutex circuit, is used to decrypt the third mutex result in the second block cipher mode according to the first key, so as to generate the decrypted mutex result; and A fourth mutually exclusive OR circuit, coupled to the other multiplier, the first decryption circuit and the second decryption circuit, is used to perform a fourth mutually exclusive OR operation on the multiplication result of the other j-th position and the decryption mutually exclusive OR result generated in the first block cipher mode or the second block cipher mode, so as to generate a fourth mutually exclusive OR result as the plaintext block of the j-th position, which is decrypted from the ciphertext block of the j-th position and transmitted to the host device; The other multiplier operating in the first block cipher mode or the second block cipher mode is determined by either the mode selection signal generated by the microcontroller or the mode selection signal recorded in a ciphertext block at position 0.
8. A block cipher method for a flash memory controller connected between a host device and a flash memory device, comprising: A first encryption circuit is provided for encrypting a seed value in a first block cipher mode according to a second key to produce an encrypted seed value; A second encryption circuit is provided for encrypting the seed value in a second block cipher mode according to a second key to produce an encrypted seed value; A multiplier is used to multiply the encrypted seed value generated from the first or second block cipher mode by a specific value α according to a mode selection signal. j To produce a multiplication result at position j (j-th), where α is a primitive element corresponding to a polynomial of a finite field multiplier; A first mutually exclusive OR operation is performed on the multiplication result of the j-th position and a plaintext block of the j-th position to produce a first mutually exclusive OR result, wherein one of the data units sent from the host device and to be written to the flash memory device is received by the flash memory controller and contains a series of plaintext blocks, including the plaintext block of the j-th position. A third encryption circuit is provided to encrypt the first mutex or result in the first block cipher mode according to a first key to produce an encrypted mutex or result. A fourth encryption circuit is provided to encrypt the first mutually exclusive or result in the second block cipher mode according to the first key to produce the encrypted mutually exclusive or result. as well as The product of the j-th position and the encrypted mutually exclusive OR result generated in the first block cipher mode or the second block cipher mode are subjected to a second mutually exclusive OR operation to produce a second mutually exclusive OR result as a ciphertext block of the j-th position. The ciphertext block of the j-th position is written to the flash memory device. The multiplier operating in the first block cipher mode or the second block cipher mode is determined by either the mode selection signal generated by a microcontroller controlled by the flash memory or the mode selection signal recorded in the plaintext block at position 0 of the series of plaintext blocks.
9. The block cipher method as described in claim 8, characterized in that, further include: When the multiplier operates in the first block cipher mode, the first encryption circuit and the third encryption circuit are enabled, while the second encryption circuit and the fourth encryption circuit are disabled. as well as When the multiplier operates in the second block cipher mode, the first and third encryption circuits are disabled, while the second and fourth encryption circuits are enabled.
10. The block cipher method as described in claim 8, characterized in that, When a multiplication result at position 0 is generated, the multiplier is bypassed, and the encrypted seed value generated in the first block cipher mode or the second block cipher mode is directly used as the multiplication result at position 0.
11. The block cipher method as described in claim 10, characterized in that, The steps for using this multiplier include: A first multiplexer is provided to select a bit sequence generated from a first encryption circuit and directly input to a first input portion of the first multiplexer as a first output bit sequence when the mode selection signal indicates a first block cipher mode, and to perform an order-reversed operation on another bit sequence generated by a second encryption circuit when the mode selection signal indicates a second block cipher mode, so as to generate and select an order-reversed sequence of bits as the first output bit sequence; Using a multiplication circuit, corresponding to a cryptographic operation of the first block cipher mode, the first output bit sequence is multiplied by a bit sequence representing α to produce a multiplied bit sequence; and A second multiplexer is provided to directly select the multiplication result bit sequence as a second output bit sequence as the multiplication result of a first position when the mode selection signal indicates the first block cipher mode, and to perform another reverse sorting operation on the multiplication result bit sequence to generate and select another reversed bit sequence as the second output bit sequence as the multiplication result of the first position when the mode selection signal indicates the second block cipher mode.
12. The block cipher method as described in claim 11, characterized in that, To generate the multiplication result at the j-th position, the block cipher method further includes: When the mode selection signal indicates the first block cipher mode, the first multiplexer is used to directly select one of the bit sequences of the multiplication result at the (j-1)th position as the first output bit sequence; and when the mode selection signal indicates the second block cipher mode, the first multiplexer is used to perform the reverse sorting operation on the bit sequence of the multiplication result at the (j-1)th position to generate and select the reversed bit sequence as the first output bit sequence. The multiplication circuit corresponding to the cryptographic operation of the first block cipher mode is used to multiply the first output bit sequence with the bit sequence representing α to produce the multiplied bit sequence; and When the mode selection signal indicates the first block cipher mode, the second multiplexer directly selects the multiplication result bit sequence as the second output bit sequence as the multiplication result at the j-th position. When the mode selection signal indicates the second block cipher mode, the second multiplexer performs another reverse sorting operation on the multiplication result bit sequence to generate and select another reversed bit sequence as the second output bit sequence as the multiplication result at the j-th position.
13. The block cipher method as described in claim 8, characterized in that, further include: A fifth encryption circuit is provided to encrypt the seed value in the first block cipher mode according to the second key to generate the encrypted seed value; A sixth encryption circuit is provided to encrypt the seed value in the second block cipher mode according to the second key to generate the encrypted seed value; Using another multiplier, the encrypted seed value generated in the first or second block cipher mode is multiplied by the specific value α according to the mode selection signal. j Multiply to produce another multiplication result at the j-th position; A third mutually exclusive OR operation is performed on the multiplication result of the other j-th position and the ciphertext block of the j-th position to produce a third mutually exclusive OR result. A data unit read from the flash memory device is received by the flash memory controller and contains a sequence of ciphertext blocks, which includes the ciphertext block of the j-th position. A first decryption circuit is provided to decrypt the third mutex result in the first block cipher mode according to the first key, so as to produce a decrypted mutex result; A second decryption circuit is provided to decrypt the third mutex result in the second block cipher mode according to the first key, so as to produce the decrypted mutex result; as well as A fourth mutually exclusive OR operation is performed on the multiplication result of the other j-th position and the decryption mutually exclusive OR result generated in the first block cipher mode or the second block cipher mode to produce a fourth mutually exclusive OR result as the plaintext block of the j-th position. The plaintext block of the j-th position is decrypted from the ciphertext block of the j-th position and transmitted to the host device. The other multiplier operating in the first block cipher mode or the second block cipher mode is determined by either the mode selection signal generated by the microcontroller or the mode selection signal recorded in a ciphertext block at position 0.