Encryption and decryption method and device, equipment, medium, program product and chip
By designing a first and a second preset algorithm during the encryption and decryption process, ensuring that their operations correspond one-to-one, and by combining random numbers with an asymmetric key algorithm, constant power consumption is achieved, effectively defending against side-channel attacks and error injection attacks, and improving security and stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING X RING TECHNOLOGY CO LTD
- Filing Date
- 2026-03-13
- Publication Date
- 2026-05-15
AI Technical Summary
Existing technologies struggle to maintain constant power consumption over extended periods, are ineffective against side-channel attacks and fault injection attacks, and suffer from high costs and poor stability due to hardware-based defense designs.
By running the first and second preset algorithms, the computational operations within the preset time range are made to correspond one-to-one, thus achieving constant power consumption. Combined with random number introduction operations and asymmetric key algorithms, side-channel attacks and error injection attacks are defended.
It achieves constant power consumption over a longer period of time, improves security and stability, simplifies logic implementation, reduces optimization costs, and has strong versatility.
Smart Images

Figure CN122053025A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of information security protection, specifically to an encryption / decryption method, apparatus, device, medium, program product, and chip. Background Technology
[0002] In recent years, with the increasing awareness and demand for information security protection, encryption and decryption technologies based on key algorithms have gradually become an important part of chips or terminal devices and have been widely used in many fields. Effective defense against information security attacks needs to be achieved through the deployment, optimization, and hardware design of key algorithms. Summary of the Invention
[0003] To overcome the problems existing in related technologies, this disclosure provides an encryption / decryption method, apparatus, device, medium, program product, and chip.
[0004] According to a first aspect of the present disclosure, an encryption / decryption method is provided, the encryption / decryption method comprising: Run the first preset algorithm and the second preset algorithm to perform the encryption or decryption process and determine the target output information; The first preset algorithm and the second preset algorithm each include multiple alternating first and second operations. Within a preset time range during which both the first preset algorithm and the second preset algorithm are in operation, the start and end times of each first operation of the first preset algorithm are the same as the start and end times of a second operation of the second preset algorithm, and the start and end times of each second operation of the first preset algorithm are the same as the start and end times of a first operation of the second preset algorithm.
[0005] In this embodiment, by running a first preset algorithm and a second preset algorithm to perform an encryption or decryption process and determine the target output information, a guarantee is provided for the security protection of data information. Through the design of the first and second preset algorithms, within a preset time range in which both algorithms are running, the first and second operations of the first preset algorithm correspond one-to-one with the second and first operations of the second preset algorithm, respectively. This ensures that the overall power consumption at each moment within the preset time range is the sum of the power consumption of one first operation and one second operation. This method of controlling power consumption to be constant achieves efficient defense against side-channel attacks and error injection attacks, further improving security and stability. Furthermore, it features simple implementation, low optimization cost, and strong versatility.
[0006] In some embodiments of this disclosure, the runtime of each first operation is the same as the runtime of each second operation.
[0007] In this embodiment, by configuring the runtime of each first operation to be the same as the runtime of each second operation, it is convenient for the first preset algorithm and the second preset algorithm to alternate between the first operation and the second operation, and to ensure that the overall power consumption is constant within the preset time range. This further simplifies the logical implementation of the encryption and decryption method and helps to improve the stability of the encryption and decryption process.
[0008] In some embodiments of this disclosure, the start time of the first preset algorithm and the start time of the second preset algorithm have a preset interval duration; The preset interval duration is the sum of the runtime of N first operations and the runtime of N-1 second operations, where N is a positive integer greater than or equal to 1.
[0009] In this embodiment, by configuring the preset interval between the start time of the first preset algorithm and the start time of the second preset algorithm as the sum of the runtime of N first operations and the runtime of N-1 second operations, it is easier to ensure the constant overall power consumption within the preset time range, further simplifying the logical implementation of the encryption and decryption method and improving the stability of the encryption and decryption process.
[0010] In some embodiments of this disclosure, the first preset algorithm is the same as the second preset algorithm.
[0011] In this embodiment, the first preset algorithm and the second preset algorithm are configured to be the same algorithm, which facilitates the generation, deployment and operation of the first preset algorithm and the second preset algorithm, so as to ensure the constant overall power consumption within the preset time range, and further simplifies the logical implementation and hardware foundation of the encryption and decryption method.
[0012] In some embodiments of this disclosure, both the first preset algorithm and the second preset algorithm further include a first random number introduction operation and a second random number introduction operation, wherein the first random number introduction operation and the second random number introduction operation are used to introduce random numbers into part of the first operation and part of the second operation.
[0013] In this embodiment, by adding a first random number introduction operation and a second random number introduction operation to the first preset algorithm and the second preset algorithm, random numbers can be introduced into a part of the first operation and the second operation to achieve the burying of key information, thereby improving the defense effect against side channel attacks and error injection attacks, and further strengthening the security and risk resistance of the first preset algorithm and the second preset algorithm.
[0014] In some embodiments of this disclosure, the start time of the first random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the start time of the first preset algorithm and the second preset algorithm, respectively, and the end time of the second random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the end time of the first preset algorithm and the second preset algorithm, respectively.
[0015] In this embodiment, the start time of the first random number introduction operation of the first preset algorithm and the second preset algorithm is configured to be the same as the start time of the first preset algorithm and the second preset algorithm, respectively. The end time of the second random number introduction operation of the first preset algorithm and the second preset algorithm is configured to be the same as the end time of the first preset algorithm and the second preset algorithm, respectively. This can bury the key information of the actual operation in the front-end and back-end through the random number introduction operation, which is beneficial to empower the encryption and decryption process from multiple dimensions such as security, efficiency, flexibility and anti-interference.
[0016] In some embodiments of this disclosure, the runtime of the first random number introduction operation and / or the second random number introduction operation is the sum of the runtimes of the first operation and the runtimes of the second operation, where L is a positive integer greater than or equal to 1.
[0017] In this embodiment, the runtime of at least one of the first random number introduction operation and the second random number introduction operation is configured as the sum of the runtime of L first operation operations and the runtime of L second operation operations. This facilitates the control of the start and end times of the first random number introduction operation and the second random number introduction operation, and ensures that the actual operation unaffected by the random number introduction operation is the alternating first operation operation and the second operation operation, thereby ensuring the stability of the encryption and decryption process.
[0018] In some embodiments of this disclosure, determining the target output information includes: Obtain the first encryption / decryption information corresponding to the first preset algorithm and the second encryption / decryption information corresponding to the second preset algorithm; In response to the fact that the first encryption / decryption information and the second encryption / decryption information are the same, the first encryption / decryption information or the second encryption / decryption information is determined as the target output information; In response to the difference between the first encryption / decryption information and the second encryption / decryption information, a warning message is generated, and the warning message is determined as the target output information.
[0019] In this embodiment, by obtaining the first encryption / decryption information corresponding to the first preset algorithm and the second encryption / decryption information corresponding to the second preset algorithm, if the first encryption / decryption information and the second encryption / decryption information are the same, the first encryption / decryption information or the second encryption / decryption information is determined as the target output information. If the first encryption / decryption information and the second encryption / decryption information are different, a warning message is generated and the warning message is determined as the target output information. This enables timely detection of error injection attacks and outputs accurate calculation results or issues warnings based on the detection results, further improving the security of the encryption / decryption process.
[0020] In some embodiments of this disclosure, the first preset algorithm and the second preset algorithm include asymmetric key algorithms.
[0021] In this embodiment, asymmetric key algorithms are used as the first preset algorithm and the second preset algorithm. The encryption and decryption process based on the private key-public key mechanism can be executed through the operation of the first preset algorithm and the second preset algorithm. It has the characteristics of efficient key management, strong security and high adaptability. Furthermore, the defense capability of asymmetric key technology against side-channel attacks and error injection attacks can be enhanced by designing the structural composition of the first preset algorithm and the second preset algorithm and controlling the start and end times.
[0022] In some embodiments of this disclosure, the first operation includes one of modular multiplication and modular squaring, and the second operation includes the other of modular multiplication and modular squaring. or, The first operation includes one of a dot addition operation and a doubling operation, and the second operation includes the other of a dot addition operation and a doubling operation.
[0023] In this embodiment, modular multiplication and modular squaring are used as the first and second operations, respectively, or dot addition or doubling operations are used as the first and second operations. The preset algorithm can be implemented by alternating the first and second operations, thereby ensuring the smooth execution of the encryption and decryption process through the encryption and decryption functions and signature functions corresponding to the preset algorithm. It also facilitates efficient defense against side-channel attacks and error injection attacks with a stable power consumption, further improving security and stability.
[0024] According to a second aspect of the present disclosure, an encryption / decryption apparatus is provided, the encryption / decryption apparatus comprising: The running module is used to run a first preset algorithm and a second preset algorithm to perform an encryption process or a decryption process and determine the target output information; The first preset algorithm and the second preset algorithm each include multiple alternating first and second operations. Within a preset time range during which both the first preset algorithm and the second preset algorithm are in operation, the start and end times of each first operation of the first preset algorithm are the same as the start and end times of a second operation of the second preset algorithm, and the start and end times of each second operation of the first preset algorithm are the same as the start and end times of a first operation of the second preset algorithm.
[0025] In some embodiments of this disclosure, both the first preset algorithm and the second preset algorithm further include a first random number introduction operation and a second random number introduction operation, wherein the first random number introduction operation and the second random number introduction operation are used to introduce random numbers into part of the first operation and part of the second operation.
[0026] In some embodiments of this disclosure, the running module is further configured to: Obtain the first encryption / decryption information corresponding to the first preset algorithm and the second encryption / decryption information corresponding to the second preset algorithm; In response to the fact that the first encryption / decryption information and the second encryption / decryption information are the same, the first encryption / decryption information or the second encryption / decryption information is determined as the target output information; In response to the difference between the first encryption / decryption information and the second encryption / decryption information, a warning message is generated, and the warning message is determined as the target output information.
[0027] In some embodiments of this disclosure, the first preset algorithm and the second preset algorithm include asymmetric key algorithms.
[0028] According to a third aspect of the present disclosure, an electronic device is provided, the electronic device comprising: processor; Memory used to store processor-executable instructions; The processor is configured to perform the encryption / decryption method as described in the first aspect.
[0029] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium is provided, which, when instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to perform the encryption / decryption method as described in the first aspect.
[0030] According to a fifth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the encryption / decryption method as described in the first aspect.
[0031] According to a sixth aspect of the present disclosure, a chip is provided, the chip including a processor and an interface, the processor being configured to read instructions to execute the encryption / decryption method as described in the first aspect.
[0032] The technical solutions provided by the embodiments of this disclosure can include the following beneficial effects: By designing the first preset algorithm and the second preset algorithm, within a preset time range in which both the first preset algorithm and the second preset algorithm are in the running state, the first operation and the second operation of the first preset algorithm correspond one-to-one with the second operation and the first operation of the second preset algorithm, so that the overall power consumption at each moment within the preset time range is the sum of the power consumption of one first operation and one second operation. This achieves efficient defense against side-channel attacks and error injection attacks by controlling the power consumption to be constant, further improving security and stability, and has the characteristics of simple implementation, low optimization cost and strong versatility.
[0033] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0034] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0035] Figure 1 This is a flowchart illustrating an encryption / decryption method according to an exemplary embodiment.
[0036] Figure 2 This is a schematic diagram illustrating an encryption / decryption method according to an exemplary embodiment.
[0037] Figure 3 This is a flowchart illustrating the determination of target output information according to an exemplary embodiment.
[0038] Figure 4 This is a block diagram illustrating an encryption / decryption apparatus according to an exemplary embodiment.
[0039] Figure 5 This is a block diagram of an electronic device according to an exemplary embodiment.
[0040] In the picture: 10 - Operating module; 400 - Electronic device; 402 - Processing component; 404 - Memory; 406 - Power supply component; 408 - Multimedia component; 410 - Audio component; 412 - Input / output interface; 414 - Sensor component; 416 - Communication component; 420 - Processor. Detailed Implementation
[0041] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the invention as detailed in the appended claims.
[0042] In recent years, with the increasing awareness and demand for information security protection, encryption and decryption technologies based on asymmetric key algorithms such as public key cryptography have gradually become an important part of products such as chips or terminal devices, and have been widely used in fields such as finance, payment, Internet of Things, Internet of Vehicles, and cryptocurrency.
[0043] Among related technologies, algorithm-optimized defenses such as masking techniques, randomization, constant-time algorithms, and constant-power algorithms can be used, or hardware-designed defenses such as logic circuits, frequency modulation devices, physical isolation, noise injection, and accelerators can be used, as well as software and hardware collaboration, redundancy checks, or error detection, to defend against the main attack methods at present, such as side channel attacks (SCA) and error injection attacks.
[0044] However, information security protection methods using related technologies can only achieve constant power consumption at specific moments, making it difficult to maintain constant power consumption over a long period of time. Hardware-based constant power consumption involves customized logic units or devices, which are difficult to design and manufacture and have poor stability. Furthermore, it is impossible to achieve simultaneous defense against side-channel attacks and fault injection attacks through a single method.
[0045] Based on this, this disclosure provides an encryption / decryption method. By running a first preset algorithm and a second preset algorithm, an encryption or decryption process is executed, and the target output information is determined, thus providing a guarantee for the security protection of data information. Through the design of the first and second preset algorithms, within a preset time range where both algorithms are running, the first and second operations of the first preset algorithm correspond one-to-one with the second and first operations of the second preset algorithm, respectively. This ensures that the overall power consumption at each moment within the preset time range is the sum of the power consumption of one first operation and one second operation. This achieves efficient defense against side-channel attacks and error injection attacks by controlling power consumption to be constant, further improving security and stability. Furthermore, it features simple implementation, low optimization cost, and strong versatility.
[0046] In one exemplary embodiment, an encryption / decryption method is provided, applied to a chip or terminal device. The chip may include, for example, a secure element or a system-on-a-chip (SoC), and the terminal device may include, for example, a mobile phone, a tablet computer, a smartwatch, etc. (Reference) Figure 1 As shown, the encryption and decryption methods include: S100: Run the first preset algorithm and the second preset algorithm to perform the encryption or decryption process and determine the target output information.
[0047] In step S100, the first preset algorithm and the second preset algorithm are deployed in the core computing unit of the chip or terminal device. The chip or terminal device can run the first preset algorithm and the second preset algorithm to perform the encryption or decryption process for data or information, and determine the corresponding target output information based on the result. The target output information can be used as a tool or result for encryption or decryption, thus providing a guarantee for the security protection of data information.
[0048] For example, the first and second preset algorithms can be the whole or core part of an asymmetric key algorithm. The encryption and decryption processes can include, for example, the generation and use of the key, and the generation of ciphertext and plaintext. The target output information can include, for example, encryption and decryption tools or results such as the key, ciphertext, and plaintext, and can also include warning messages or other prompts indicating that information security has been attacked.
[0049] By designing the structure of the first and second preset algorithms, both algorithms include multiple alternating first and second operations. Specifically, the first and second operations run alternately in both algorithms. The first and second operations are identical in both algorithms. This alternating execution of the first and second operations ensures the functionality of both algorithms, i.e., the execution of the encryption or decryption process. For example, the first and second operations could be modular multiplication and modular squaring, or point addition and point doubling, respectively.
[0050] By controlling the start and end times of the first and second preset algorithms, within a preset time range when both algorithms are running, the start and end times of each first operation of the first preset algorithm are identical to the start and end times of a second operation of the second preset algorithm, and vice versa. In other words, within the overlapping time domains of the first and second preset algorithms, there is a one-to-one correspondence between the first operations of the first preset algorithm and the second operations of the second preset algorithm, and vice versa.
[0051] For example, such as Figure 2 As shown, the algorithm executes a first preset algorithm (Algorithm A) and a second preset algorithm (Algorithm B). Both algorithms include multiple alternating first operations (Operation S) and second operations (Operation M). The start and end times of the first preset algorithm are Tstart1 and Tend1, respectively, and the start and end times of the second preset algorithm are Tstart2 and Tend2, respectively. The preset time range is from Tstart1 to Tend2. Within the preset time range, each first operation of the first preset algorithm has the same start and end time as a second operation of the second preset algorithm. That is, each operation S of Algorithm A is time-aligned with each operation M of Algorithm B, and each second operation of the first preset algorithm has the same start and end time as a first operation of the second preset algorithm.
[0052] In this scenario, at any given moment within a preset time range, a first operation and a second operation are executed. This ensures that the total power consumption of both the first and second preset algorithms at any given moment is the sum of the power consumption of the first and second operations, achieving constant power consumption within the preset time range. By eliminating power consumption fluctuations, the correlation between physical signals and sensitive data is eliminated, preventing attackers from obtaining sensitive data through physical leaks or active interference. This provides highly efficient defense against side-channel attacks and error injection attacks. Compared to power control techniques in other fields, this method achieves long-term constant power consumption covering most of the algorithm's runtime without requiring customized logic units or devices.
[0053] In this embodiment, by running a first preset algorithm and a second preset algorithm to perform an encryption or decryption process and determine the target output information, a guarantee is provided for the security protection of data information. Through the design of the first and second preset algorithms, within a preset time range in which both algorithms are running, the first and second operations of the first preset algorithm correspond one-to-one with the second and first operations of the second preset algorithm, respectively. This ensures that the overall power consumption at each moment within the preset time range is the sum of the power consumption of one first operation and one second operation. This method of controlling power consumption to be constant achieves efficient defense against side-channel attacks and error injection attacks, further improving security and stability. Furthermore, it features simple implementation, low optimization cost, and strong versatility.
[0054] In some embodiments, the runtime of each first operation is the same as the runtime of each second operation.
[0055] By designing the structure of the first and second preset algorithms and controlling the start and end times of each operation, the runtime of each first operation and the runtime of each second operation are the same in the first and second preset algorithms. That is, the first and second preset algorithms are both composed of operations with the same runtime.
[0056] In this case, since both the first preset algorithm and the second preset algorithm include alternating first and second operations, such as Figure 2 As shown, it is only necessary to ensure that the first first operation of the first preset algorithm and the second operation of the second preset algorithm have the same start time, so that within the preset time range, each first operation of the first preset algorithm has the same start time and end time as the second operation of the second preset algorithm, and each second operation of the first preset algorithm has the same start time and end time as the first operation of the second preset algorithm, thereby ensuring the constant overall power consumption within the preset time range.
[0057] In this embodiment, by configuring the runtime of each first operation to be the same as the runtime of each second operation, it is convenient for the first preset algorithm and the second preset algorithm to alternate between the first operation and the second operation, and to ensure that the overall power consumption is constant within the preset time range. This further simplifies the logical implementation of the encryption and decryption method and helps to improve the stability of the encryption and decryption process.
[0058] In some embodiments, the start time of the first preset algorithm and the start time of the second preset algorithm have a preset interval, which is the sum of the runtime of N first operations and the runtime of N-1 second operations, where N is a positive integer greater than or equal to 1.
[0059] By controlling the start times of the first and second preset algorithms, a preset interval is established between the start times of the first and second preset algorithms. This preset interval is equal to the sum of the runtime of N first operations and the runtime of N-1 second operations. For example, as... Figure 2 As shown, there is a preset interval between the start time Tstart1 of the first preset algorithm and the start time Tstart2 of the second preset algorithm. T, when N=1, T is the runtime of the first operation, i.e., operation S. When N=2, T is the sum of the runtimes of two first operations (operation S) and one second operation (operation M).
[0060] In this scenario, since both the first and second preset algorithms include alternating first and second operations, when the start time of the first preset algorithm is reached, the first preset algorithm executes its first first operation, and the second preset algorithm executes its Nth second operation. This ensures that within a preset time range, the first first operation of the first preset algorithm and the Nth second operation of the second preset algorithm share the same start time. This guarantees that within the preset time range, each first operation of the first preset algorithm shares the same start and end time as a second operation of the second preset algorithm, and vice versa, thereby maintaining a constant overall power consumption within the preset time range.
[0061] In this embodiment, by configuring the preset interval between the start time of the first preset algorithm and the start time of the second preset algorithm as the sum of the runtime of N first operations and the runtime of N-1 second operations, it is easier to ensure the constant overall power consumption within the preset time range, further simplifying the logical implementation of the encryption and decryption method and improving the stability of the encryption and decryption process.
[0062] In some embodiments, the first preset algorithm is the same as the second preset algorithm.
[0063] Configuring the first and second preset algorithms to be identical facilitates the design of their structural composition and control of their start and end times. This ensures that the first and second operations have the same operational arrangement and duration within the first and second preset algorithms, thereby maintaining constant overall power consumption within the preset time range. Furthermore, for chips or terminal devices configured with the initial algorithm, the configuration of the first and second preset algorithms can be easily and accurately achieved by copying the initial algorithm, i.e., copying the corresponding circuit.
[0064] In this embodiment, the first preset algorithm and the second preset algorithm are configured to be the same algorithm, which facilitates the generation, deployment and operation of the first preset algorithm and the second preset algorithm, so as to ensure the constant overall power consumption within the preset time range, and further simplifies the logical implementation and hardware foundation of the encryption and decryption method.
[0065] In some embodiments, both the first preset algorithm and the second preset algorithm further include a first random number introduction operation and a second random number introduction operation, wherein the first random number introduction operation and the second random number introduction operation are both used to introduce random numbers into part of the first operation and part of the second operation.
[0066] The first and second preset algorithms further include a first random number introduction operation and a second random number introduction operation. These operations introduce random numbers into a portion of the first and second operations of the first and second preset algorithms, respectively. This masks key information from some of the actual operations, preventing attackers from deducing core secrets by observing the computation process or results. This more effectively defends against side-channel attacks and error injection attacks. For example, the first random number introduction operation can be located at the beginning of the first and second preset algorithms, and the second random number introduction operation can be located at the end of the first and second preset algorithms.
[0067] It should be noted that the power consumption of the first and second random number introduction operations is low and negligible compared to the first and second operation operations. The power consumption generated when running the first and second random number introduction operations will not affect the overall constant power consumption of the first and second preset algorithms.
[0068] In this embodiment, by adding a first random number introduction operation and a second random number introduction operation to the first preset algorithm and the second preset algorithm, random numbers can be introduced into a part of the first operation and the second operation to achieve the burying of key information, thereby improving the defense effect against side channel attacks and error injection attacks, and further strengthening the security and risk resistance of the first preset algorithm and the second preset algorithm.
[0069] In some embodiments, the start time of the first random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the start time of the first preset algorithm and the second preset algorithm, respectively, and the end time of the second random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the end time of the first preset algorithm and the second preset algorithm, respectively.
[0070] The first random number introduction operation of the first preset algorithm and the second preset algorithm have the same start time as the first preset algorithm and the second preset algorithm, respectively, and the second random number introduction operation of the first preset algorithm and the second preset algorithm have the same end time, respectively. The first random number introduction operation can be run after the first preset algorithm and the second preset algorithm have started running to bury key information of the initial operation, and the second random number introduction operation can be run before the first preset algorithm and the second preset algorithm have ended running to bury key information of the final operation.
[0071] For example, such as Figure 2 As shown, the start times of the first random number introduction operation R1 of the first preset algorithm and the second preset algorithm are Tstart1 and Tstart2, respectively, and the end times of the second random number introduction operation R2 of the first preset algorithm and the second preset algorithm are Tend1 and Tend2, respectively. In this case, while ensuring the stable and efficient operation of the computational operations between the first and second random number introduction operations, the algorithm performance can be further optimized, and the security and stability of the encryption and decryption process can be improved.
[0072] In this embodiment, the start time of the first random number introduction operation of the first preset algorithm and the second preset algorithm is configured to be the same as the start time of the first preset algorithm and the second preset algorithm, respectively. The end time of the second random number introduction operation of the first preset algorithm and the second preset algorithm is configured to be the same as the end time of the first preset algorithm and the second preset algorithm, respectively. This can bury the key information of the actual operation in the front-end and back-end through the random number introduction operation, which is beneficial to empower the encryption and decryption process from multiple dimensions such as security, efficiency, flexibility and anti-interference.
[0073] In some embodiments, the runtime of the first random number introduction operation and / or the second random number introduction operation is the sum of the runtimes of the L first operation operations and the runtimes of the L second operation operations, where L is a positive integer greater than or equal to 1.
[0074] The runtime of at least one of the first and second random number introduction operations is configured to be the sum of the runtimes of L first operations and L second operations, such that the first and second random number introduction operations can be aligned in the time domain with one or more sets of first and second operations. For example, L can be 7 to 128.
[0075] In this case, it is convenient to control the start and end times of the first random number introduction operation and the second random number introduction operation according to the start and end times of the first operation and the second operation, so that the first preset algorithm and the second preset algorithm run the first operation when the first random number introduction operation is completed, and run the second random number introduction operation when the second operation is completed, so as to ensure that the actual operation of the first preset algorithm and the second preset algorithm can start with the first operation and end with the second operation.
[0076] In this embodiment, the runtime of at least one of the first random number introduction operation and the second random number introduction operation is configured as the sum of the runtime of L first operation operations and the runtime of L second operation operations. This facilitates the control of the start and end times of the first random number introduction operation and the second random number introduction operation, and ensures that the actual operation unaffected by the random number introduction operation is the alternating first operation operation and the second operation operation, thereby ensuring the stability of the encryption and decryption process.
[0077] In some embodiments, reference Figure 3 As shown, the target output information is determined, including: S210. Obtain the first encryption / decryption information corresponding to the first preset algorithm and the second encryption / decryption information corresponding to the second preset algorithm.
[0078] In step S210, since the first preset algorithm and the second preset algorithm are two independently running algorithms, when the first preset algorithm and the second preset algorithm complete, they can respectively output the corresponding first encryption / decryption information and second encryption / decryption information as the operation results of the first preset algorithm and the second preset algorithm. It can be understood that the first preset algorithm and the second preset algorithm use the same first operation and second operation, and the first operation and the second operation are run alternately in the first preset algorithm and the second preset algorithm. Under the condition of no error injection attack, the first encryption / decryption information and the second encryption / decryption information should be the same.
[0079] S220. In response to the first encryption / decryption information being the same as the second encryption / decryption information, determine the first encryption / decryption information or the second encryption / decryption information as the target output information.
[0080] In step S220, the first decryption information and the second encryption / decryption information are compared. When the first encryption / decryption information and the second encryption / decryption information are the same, it means that the first preset algorithm and the second preset algorithm have not been subjected to error injection attacks during operation. The comparison check result meets the requirements, and the first encryption / decryption information and the second encryption / decryption information are accurate calculation results. Then, either the first encryption / decryption information or the second encryption / decryption information is determined as the target output information and used as the final calculation result.
[0081] S230. In response to the difference between the first encryption / decryption information and the second encryption / decryption information, a warning message is generated and the warning message is determined as the target output information.
[0082] In step S230, when the first encryption / decryption information and the second encryption / decryption information are different, it means that one of the first preset algorithm and the second preset algorithm has been subjected to an error injection attack during operation. The comparison and check results do not meet the requirements, and the first encryption / decryption information or the second encryption / decryption information is an incorrect calculation result. Therefore, the first encryption / decryption information and the second encryption / decryption information are not output. Instead, a corresponding warning message is generated and output as the target output information to warn the outside world about the error injection attack.
[0083] In this embodiment, by obtaining the first encryption / decryption information corresponding to the first preset algorithm and the second encryption / decryption information corresponding to the second preset algorithm, if the first encryption / decryption information and the second encryption / decryption information are the same, the first encryption / decryption information or the second encryption / decryption information is determined as the target output information. If the first encryption / decryption information and the second encryption / decryption information are different, a warning message is generated and the warning message is determined as the target output information. This enables timely detection of error injection attacks and outputs accurate calculation results or issues warnings based on the detection results, further improving the security of the encryption / decryption process.
[0084] In some embodiments, the first preset algorithm and the second preset algorithm include an asymmetric key algorithm.
[0085] The first and second preset algorithms can be asymmetric key algorithms. Asymmetric key algorithms are encryption and decryption techniques based on mathematical principles and are an important pillar of modern cryptography. An asymmetric key algorithm can generate a pair of related but mutually exclusive public and private keys. The public key can be publicly distributed to encrypt data or verify signatures, while the private key is held separately to decrypt data and generate signatures. For example, asymmetric key algorithms may include RSA, ECC, SM2, SM9, or PQC algorithms.
[0086] In this embodiment, asymmetric key algorithms are used as the first preset algorithm and the second preset algorithm. The encryption and decryption process based on the private key-public key mechanism can be executed through the operation of the first preset algorithm and the second preset algorithm. It has the characteristics of efficient key management, strong security and high adaptability. Furthermore, the defense capability of asymmetric key technology against side-channel attacks and error injection attacks can be enhanced by designing the structural composition of the first preset algorithm and the second preset algorithm and controlling the start and end times.
[0087] In some embodiments, the first operation includes one of modular multiplication and modular squaring, and the second operation includes the other of modular multiplication and modular squaring; or, the first operation includes one of dot addition and doubling dot operation, and the second operation includes the other of dot addition and doubling dot operation.
[0088] When the first and second preset algorithms are algorithms such as RSA, the first and second operations can be either modular multiplication or modular squaring, respectively. Modular multiplication refers to multiplying two numbers and then taking the remainder modulo, while modular squaring refers to squaring a number and then taking the remainder modulo. By alternating between modular multiplication and modular squaring operations, the modular exponentiation operation of the RSA algorithm is achieved, thereby realizing the encryption, decryption, and signature functions of the RSA algorithm. In this case, within a preset time range, the modular multiplication operation of the first preset algorithm and the modular squaring operation of the second preset algorithm have the same start and end times.
[0089] When the first and second preset algorithms are ECC or SM2 algorithms, the first and second operations can be either a point addition operation or a point multiplication operation, respectively. A point addition operation is the addition of two non-infinite points on an elliptic curve, while a point multiplication operation is the addition of the same point on an elliptic curve to itself. By alternately performing point addition and point multiplication operations, scalar multiplication of the ECC or SM2 algorithm is achieved, thereby enabling encryption, decryption, and signature functions of the ECC or SM2 algorithm. In this case, within a preset time range, the point addition operation of the first preset algorithm and the point multiplication operation of the second preset algorithm have the same start and end times.
[0090] In this embodiment, modular multiplication and modular squaring are used as the first and second operations, respectively, or dot addition or doubling operations are used as the first and second operations. The preset algorithm can be implemented by alternating the first and second operations, thereby ensuring the smooth execution of the encryption and decryption process through the encryption and decryption functions and signature functions corresponding to the preset algorithm. It also facilitates efficient defense against side-channel attacks and error injection attacks with a stable power consumption, further improving security and stability.
[0091] In one exemplary embodiment, an encryption / decryption apparatus is provided, applied to a chip or terminal device, with reference to... Figure 4 As shown, the encryption / decryption device includes a running module 10, which runs a first preset algorithm and a second preset algorithm to perform an encryption or decryption process and determine the target output information. Each of the first and second preset algorithms includes multiple alternating first and second operations. Within a preset time range during which both the first and second preset algorithms are running, the start and end times of each first operation of the first preset algorithm are the same as the start and end times of a second operation of the second preset algorithm, and vice versa.
[0092] In this embodiment, the running module 10 executes a first preset algorithm and a second preset algorithm to perform an encryption or decryption process and determine the target output information, thus providing a guarantee for the security protection of data information. Through the design of the first and second preset algorithms, within a preset time range when both algorithms are in operation, the first and second operations of the first preset algorithm correspond one-to-one with the second and first operations of the second preset algorithm, respectively. This ensures that the overall power consumption at each moment within the preset time range is the sum of the power consumption of one first operation and one second operation. This method of controlling power consumption to remain constant achieves efficient defense against side-channel attacks and error injection attacks, further improving security and stability. Furthermore, it features simple implementation, low optimization cost, and strong versatility.
[0093] In one embodiment, the runtime of each first operation is the same as the runtime of each second operation.
[0094] In one embodiment, the start time of the first preset algorithm and the start time of the second preset algorithm have a preset interval; the preset interval is the sum of the runtime of N first operations and the runtime of N-1 second operations, where N is a positive integer greater than or equal to 1.
[0095] In one embodiment, the first preset algorithm is the same as the second preset algorithm.
[0096] In one embodiment, both the first preset algorithm and the second preset algorithm further include a first random number introduction operation and a second random number introduction operation, wherein the first random number introduction operation and the second random number introduction operation are both used to introduce random numbers into part of the first operation and part of the second operation.
[0097] In one embodiment, the start time of the first random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the start time of the first preset algorithm and the second preset algorithm, respectively, and the end time of the second random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the end time of the first preset algorithm and the second preset algorithm, respectively.
[0098] In one embodiment, the runtime of the first random number introduction operation and / or the second random number introduction operation is the sum of the runtimes of the L first operation operations and the runtimes of the L second operation operations, where L is a positive integer greater than or equal to 1.
[0099] In one embodiment, the running module 10 is further configured to: obtain first encryption / decryption information corresponding to a first preset algorithm and second encryption / decryption information corresponding to a second preset algorithm; in response to the first encryption / decryption information and the second encryption / decryption information being the same, determine the first encryption / decryption information or the second encryption / decryption information as the target output information; in response to the first encryption / decryption information and the second encryption / decryption information being different, generate a warning message and determine the warning message as the target output information.
[0100] In one embodiment, the first preset algorithm and the second preset algorithm include an asymmetric key algorithm.
[0101] In one embodiment, the first operation includes one of modular multiplication and modular squaring, and the second operation includes the other of modular multiplication and modular squaring; or, the first operation includes one of dot addition and doubling, and the second operation includes the other of dot addition and doubling.
[0102] In one exemplary embodiment, an electronic device is provided, which may include, for example, a mobile phone, a tablet computer, a smartwatch, or other terminal device, and is capable of performing the encryption and decryption methods described above.
[0103] refer to Figure 5 As shown, the electronic device 400 may include one or more of the following components: processing component 402, memory 404, power supply component 406, multimedia component 408, audio component 410, input / output (I / O) interface 412, sensor component 414, and communication component 416.
[0104] Processing component 402 typically controls the overall operation of electronic device 400, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 402 may include one or more processors 420 to execute instructions to perform all or part of the steps of the methods described above. Furthermore, processing component 402 may include one or more modules to facilitate interaction between processing component 402 and other components. For example, processing component 402 may include a multimedia module to facilitate interaction between multimedia component 408 and processing component 402.
[0105] Memory 404 is configured to store various types of data to support the operation of electronic device 400. Examples of such data include instructions for any application or method operating on electronic device 400, contact data, phonebook data, messages, pictures, videos, etc. Memory 404 can be implemented by any type of volatile or non-volatile storage terminal or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0106] Power supply component 406 provides power to various components of electronic device 400. Power supply component 406 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to electronic device 400.
[0107] Multimedia component 408 includes a screen that provides an output interface between electronic device 400 and user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 408 includes a front-facing camera module and / or a rear-facing camera module. When electronic device 400 is in an operating mode, such as shooting mode or video mode, the front-facing camera module and / or rear-facing camera module may receive external multimedia data. Each front-facing camera module and rear-facing camera module may be a fixed optical lens system or have focal length and optical zoom capabilities.
[0108] Audio component 410 is configured to output and / or input audio signals. For example, audio component 410 includes a microphone (MIC) configured to receive external audio signals when electronic device 400 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 404 or transmitted via communication component 416. In some embodiments, audio component 410 also includes a speaker for outputting audio signals.
[0109] I / O interface 412 provides an interface between processing component 402 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.
[0110] Sensor assembly 414 includes one or more sensors for providing state assessments of various aspects of electronic device 400. For example, sensor assembly 414 may receive the on / off state of electronic device 400, the relative positioning of components such as the display and keypad of electronic device 400, changes in position of electronic device 400 or a component of electronic device 400, the presence or absence of user contact with electronic device 400, orientation or acceleration / deceleration of electronic device 400, and temperature changes of electronic device 400. Sensor assembly 414 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 414 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 414 may also include an accelerometer, gyroscope, magnetometer, pressure sensor, or temperature sensor.
[0111] Communication component 416 is configured to facilitate wired or wireless communication between electronic device 400 and other terminals. Electronic device 400 can access wireless networks based on communication standards, such as WiFi, 2G, 3G, 4G, 5G, or combinations thereof. In one exemplary embodiment, communication component 416 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 416 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0112] In an exemplary embodiment, the electronic device 400 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing terminals (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods shown in the above embodiments or combinations thereof.
[0113] In one exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 404 including instructions, which can be executed by a processor 420 of an electronic device 400 to perform the methods shown in the above embodiments or combinations thereof. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage terminal, etc. When the instructions in the storage medium are executed by the processor of the terminal, the terminal is able to perform the methods shown in the above embodiments or combinations thereof.
[0114] In one exemplary embodiment, a computer program product is provided, including a computer program or instructions that, when executed by a processor, implement the method described above.
[0115] In one exemplary embodiment, a chip is provided, including a processor and an interface, the processor being configured to read instructions to execute the method described above.
[0116] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the claims.
[0117] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0118] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this disclosure, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0119] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0120] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. An encryption / decryption method, characterized in that, The encryption / decryption methods include: Run the first preset algorithm and the second preset algorithm to perform the encryption or decryption process and determine the target output information; The first preset algorithm and the second preset algorithm each include multiple alternating first and second operations. Within a preset time range during which both the first preset algorithm and the second preset algorithm are in operation, the start and end times of each first operation of the first preset algorithm are the same as the start and end times of a second operation of the second preset algorithm, and the start and end times of each second operation of the first preset algorithm are the same as the start and end times of a first operation of the second preset algorithm.
2. The encryption / decryption method according to claim 1, characterized in that, The runtime of each of the first operations is the same as the runtime of each of the second operations.
3. The encryption / decryption method according to claim 1, characterized in that, The start time of the first preset algorithm and the start time of the second preset algorithm have a preset interval. The preset interval duration is the sum of the runtime of N first operations and the runtime of N-1 second operations, where N is a positive integer greater than or equal to 1.
4. The encryption / decryption method according to claim 1, characterized in that, The first preset algorithm is the same as the second preset algorithm.
5. The encryption / decryption method according to any one of claims 1 to 4, characterized in that, Both the first preset algorithm and the second preset algorithm further include a first random number introduction operation and a second random number introduction operation. The first random number introduction operation and the second random number introduction operation are used to introduce random numbers into part of the first operation and part of the second operation.
6. The encryption / decryption method according to claim 5, characterized in that, The start time of the first random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the start time of the first preset algorithm and the second preset algorithm, respectively, and the end time of the second random number introduction operation of the first preset algorithm and the second preset algorithm is the same as the end time of the first preset algorithm and the second preset algorithm, respectively.
7. The encryption / decryption method according to claim 6, characterized in that, The runtime of the first random number introduction operation and / or the second random number introduction operation is the sum of the runtimes of the first operation and the runtimes of the second operation, where L is a positive integer greater than or equal to 1.
8. The encryption / decryption method according to any one of claims 1 to 4, characterized in that, The determined target output information includes: Obtain the first encryption / decryption information corresponding to the first preset algorithm and the second encryption / decryption information corresponding to the second preset algorithm; In response to the fact that the first encryption / decryption information and the second encryption / decryption information are the same, the first encryption / decryption information or the second encryption / decryption information is determined as the target output information; In response to the difference between the first encryption / decryption information and the second encryption / decryption information, a warning message is generated, and the warning message is determined as the target output information.
9. The encryption / decryption method according to any one of claims 1 to 4, characterized in that, The first preset algorithm and the second preset algorithm include asymmetric key algorithms.
10. The encryption / decryption method according to claim 9, characterized in that, The first operation includes one of modular multiplication and modular squaring, and the second operation includes the other of modular multiplication and modular squaring. or, The first operation includes one of a dot addition operation and a doubling operation, and the second operation includes the other of a dot addition operation and a doubling operation.
11. An encryption / decryption device, characterized in that, The encryption / decryption device includes: The running module is used to run a first preset algorithm and a second preset algorithm to perform an encryption process or a decryption process and determine the target output information; The first preset algorithm and the second preset algorithm each include multiple alternating first and second operations. Within a preset time range during which both the first preset algorithm and the second preset algorithm are in operation, the start and end times of each first operation of the first preset algorithm are the same as the start and end times of a second operation of the second preset algorithm, and the start and end times of each second operation of the first preset algorithm are the same as the start and end times of a first operation of the second preset algorithm.
12. The encryption / decryption device according to claim 11, characterized in that, Both the first preset algorithm and the second preset algorithm further include a first random number introduction operation and a second random number introduction operation. The first random number introduction operation and the second random number introduction operation are used to introduce random numbers into part of the first operation and part of the second operation.
13. The encryption / decryption device according to claim 11, characterized in that, The operating module is also used for: Obtain the first encryption / decryption information corresponding to the first preset algorithm and the second encryption / decryption information corresponding to the second preset algorithm; In response to the fact that the first encryption / decryption information and the second encryption / decryption information are the same, the first encryption / decryption information or the second encryption / decryption information is determined as the target output information; In response to the difference between the first encryption / decryption information and the second encryption / decryption information, a warning message is generated, and the warning message is determined as the target output information.
14. The encryption / decryption device according to claim 11, characterized in that, The first preset algorithm and the second preset algorithm include asymmetric key algorithms.
15. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store processor-executable instructions; The processor is configured to perform the encryption / decryption method as described in any one of claims 1 to 10.
16. A non-transitory computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the encryption / decryption method as described in any one of claims 1 to 10.
17. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the encryption / decryption method as described in any one of claims 1 to 10.
18. A chip, characterized in that, The chip includes a processor and an interface, the processor being configured to read instructions to execute the encryption / decryption method as described in any one of claims 1 to 10.