Complete construction method and system for known MDS matrix in symmetric encryption network, product and storage medium

By using permutation groups and shifts to construct parameter functions in symmetric encryption networks to replace the element multiplication operation of finite fields, the number of parameters of the MDS matrix is ​​expanded, solving the problem of insufficient scale of MDS matrix construction in existing technologies, and improving cryptographic diffusion capability and security.

CN122053039APending Publication Date: 2026-05-15NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
Filing Date
2026-01-06
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing methods for constructing MDS matrices, without altering the structure or implementation costs, struggle to achieve large-scale parameterized construction, resulting in insufficient cryptographic diffusion capabilities and an inability to effectively resist differential and linear analyses.

Method used

By employing the longest periodic cyclic permutation and shift function based on the permutation group, the element multiplication operation in the finite field is replaced, and the mapping relationship of the MDS matrix is ​​constructed, thus expanding the number of parameters of the MDS matrix.

Benefits of technology

Without changing the MDS matrix structure and implementation cost, the number of parameters in the MDS matrix is ​​significantly increased, the resistance to differential and linear analysis of symmetric encryption networks is improved, a larger number of MDS constructions are provided, and dynamic variable diffusion layer design is supported.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122053039A_ABST
    Figure CN122053039A_ABST
Patent Text Reader

Abstract

The invention discloses a complete construction method and system for a known MDS matrix in a symmetric encryption network, a product and a storage medium, belongs to the field of information security, and is used for solving the problems that the dynamic variable diffusion layer design of a cryptographic algorithm cannot be met, and the differential resistance and the linear analysis capability are relatively weak. The method comprises the following steps: extracting a generator of an MDS matrix; on the basis of the shift number of the longest period cyclic permutation sum on the permutation group, a parameter function of the generator is constructed, and when the parameter function is identical transformation and j is equal to 0, the parameter function is identical transformation about the generator; and replacing the element multiplication operation of the MDS matrix in the n-dimensional finite field with the parameter function, n being a positive integer, and updating the mapping relation of MDS transformation in the finite field. According to the method, under the condition that the known MDS matrix structure, elements and implementation cost are not changed, the parameter number scale of the MDS matrix on the existing finite field is enlarged by O (n!) times, and powerful support is provided for dynamic design of a future password extension layer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a complete method, system, product, and storage medium for constructing a known MDS matrix in a symmetric encrypted network. Background Technology

[0002] In symmetric cryptography, the MDS (Maximum Distance Separable codes) matrix is ​​one of the most critical and widely used linear diffusion components. It ensures that every bit of the plaintext and key affects every bit of the ciphertext, thus facilitating the concealment of statistical characteristics of the plaintext. Therefore, the cryptographic properties of the MDS matrix are crucial to the overall security of the algorithm. However, traditional MDS matrices are limited by the constraints of operations within finite fields, which significantly restricts their quantity and combinations. Therefore, achieving the construction of a large number of parameterized complete MDS matrices without altering the known MDS matrix structure, data elements, and implementation costs has become a bottleneck problem limiting current cryptographic applications.

[0003] The cryptographic properties of MDS matrices are primarily the number of differential and linear branches. For classical differential and linear cryptanalysis, the number of branches effectively guarantees diffusion performance, directly determining the number of active S-boxes, and consequently affecting the search for high-probability differential and linear features, thus determining the differential linear security of the cryptographic algorithm. Existing MDS constructions are constrained by factors such as specific structures, element selection, finite field operations, iteration counts, or shift bits, significantly limiting the scale and composability of lightweight MDSs. Therefore, achieving a large-scale, lightweight design of MDSs without altering the known MDS matrix structure, data elements, and implementation costs, and utilizing these lightweight MDS resources, are the two major goals for current cryptographic diffusion MDS composability and nonlinearity.

[0004] It is known that existing MDS construction methods are mostly focused on mathematical methods and structural design, and the implementation cost and the number of MDS obtained are difficult to reach the scale required for dynamic diffusion layers. Summary of the Invention

[0005] The purpose of this invention is to provide a parameterized construction method and apparatus for a known MDS matrix in a symmetric encryption network, addressing all or part of the aforementioned problems, in order to solve the issues of being unable to meet the requirements of dynamically variable diffusion layer design in cryptographic algorithms and having weak resistance to differential and linear analysis.

[0006] The technical solution adopted in this invention is as follows: A complete method for constructing a known MDS matrix in a symmetric cryptographic network, comprising: Extracting generators from the MDS matrix ; Based on permutation groups Longest periodic permutation and shift number Construct the generator Parameterized functions ,when For identity transformation, j =0, the parameter function For the generator Identity transformation; The parameter function Replace the element-wise multiplication operation of the MDS matrix in an n-dimensional finite field, where n is a positive integer, and update the mapping relationship of the MDS transformation in the finite field.

[0007] Furthermore, the parameter function Replacing the element-wise multiplication operation of the MDS matrix in an n-dimensional finite field includes: Construct about the generator Three-variable parameters ,in Describing permutation group The set of longest periodic permutations. Z The range of values ​​is A set; Construct about input variables shift function : ; In the formula, Represents input variables n bits Displacement, Indicates taking The first output of the operation Bit information, ; Based on shift function The MDS transform of the MDS matrix is ​​shifted to update the mapping relationship of the MDS transform. The updated MDS transformation is validated.

[0008] Furthermore, based on the shift function The MDS transformation of the MDS matrix is ​​shifted, including: The setting is based on the input vector adjacent input variables in a pairwise loop The corresponding intermediate variable obtained by XOR operation; Set the output vector Each output variable in , from the input vector Input variables corresponding to the position Input variables for low bits Construct intermediate variables and use shift functions After processing the intermediate variable, it is compared with the input vector. Input variables in other positions Perform an XOR operation.

[0009] Furthermore, based on the shift function The shifting process for the MDS transform of the MDS matrix further includes: Set the longest period of cyclical replacement The initial state is ; Set the longest period of cyclical replacement initial state (i.e., bivariate parameters at j=0) .

[0010] Furthermore, the generator An irreducible polynomial of degree n with a leading coefficient of 1 over a finite field The coefficients obtained by setting the coefficients of the highest term and the constant term to 0.

[0011] Furthermore, the updated MDS transformation is validated, including: Get each of the test finite fields The number of corresponding generators is calculated, and the number of parameters of the MDS formed by the updated MDS transformation on the test finite field is compared with the number of parameters of the MDS transformation corresponding to the MDS matrix.

[0012] The present invention also provides a complete construction system for a known MDS matrix in a symmetric encryption network, comprising a processor and a storage medium storing computer instructions, wherein the processor executes the computer instructions to perform the above-described complete construction method for a known MDS matrix in a symmetric encryption network.

[0013] The present invention also provides a computer program product, including a computer program that, when executed by a processor, performs the above-described complete construction method for a known MDS matrix in a symmetric encryption network.

[0014] The present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, performs the above-described complete construction method for a known MDS matrix in a symmetric encryption network.

[0015] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: (1) The method for completely constructing a known MDS matrix proposed in this invention, without changing the structure, elements, and implementation cost of the known MDS matrix, can completely construct an existing finite field matrix. The number of parameters in the MDS matrix has increased. By combining these methods, the resistance of symmetric encryption to differential and linear analysis can be effectively improved. The constructed MDS matrix has similar efficiency and security to an ideal cyclic MDS matrix.

[0016] (2) Unlike the traditional method of constructing MDS matrices over finite fields, the parameterized MDS matrix based on bit permutation and XOR operation of this invention breaks through the limitations of traditional finite fields, irreducible polynomials and primitive elements, expands the scale of MDS, and maintains the same security performance and implementation cost, realizes the construction and variability of new MDS on a larger scale, and provides strong support for the dynamic design of future cryptographic extension layers. Attached Figure Description

[0017] The present invention will be described by way of example and with reference to the accompanying drawings, wherein: Figure 1 This is a flowchart illustrating the implementation of a complete construction method for a known MDS matrix in a symmetric encryption network. Detailed Implementation

[0018] All features disclosed in this specification, or all steps in all disclosed methods or processes, may be combined in any way, except for mutually exclusive features and / or steps.

[0019] Any feature disclosed in this specification (including any appended claims and abstract) may be replaced by other equivalent or similar features, unless specifically stated otherwise. That is, unless specifically stated otherwise, each feature is merely one example of a series of equivalent or similar features.

[0020] Currently, there are three main categories of MDS matrix design methods: (1) Constructing the MDS matrix based on linear codes: In the cryptography community, the relationship between MDS codes and MDS matrices is often used to construct the MDS matrix. If A is the generator matrix of an MDS code, then the necessary and sufficient condition for A to be an MDS code is that the matrix is... It is an MDS matrix. However, the number of lightweight linear codes currently available is limited, making it difficult to meet the design requirements of symmetric cryptographic algorithms.

[0021] (2) Constructing MDS matrices using special types of mathematical matrices, among which commonly used special types of matrices include cyclic matrices, Hadamad matrices, cyclic matrices, involutional matrices, Cauchy matrices, and Vandermonde matrices. When the matrix dimension is small, the special mathematical structure of cyclic matrices and Hadamad matrices can ensure that the number of different elements in the constructed MDS matrix is ​​as small as possible, while involutional matrices and orthogonal matrices can reduce the resource consumption required in the encryption and decryption process of cryptographic algorithms, but the search space cost is large and it is not easy to expand. When the data volume is large, other methods are needed to construct MDS matrices with larger dimensions. At this time, matrices with certain mathematical properties are generally selected for construction, including Cauchy matrices, Vandermonde matrices, Toeplitz matrices, etc. The constructed MDS has the problem of low hardware implementation efficiency.

[0022] (3) Using LFSR to construct an iterative optimal diffusion layer has high hardware implementation efficiency, but the iterative MDS matrix increases the clock cycle and has the disadvantage of high latency.

[0023] The known methods for constructing MDS mentioned above are mostly focused on mathematical methods and structural design, and the implementation cost and the number of MDS obtained are difficult to reach the scale required for dynamic diffusion layers.

[0024] To address the problems existing in known MDS construction methods in symmetric encryption networks, this application proposes a parameterized construction method, system, product, and storage medium for known MDS matrices in symmetric encryption networks, aiming to meet the requirements of dynamic variable diffusion layer design of cryptographic algorithms and improve their ability to resist differential and linear analysis.

[0025] The theoretical knowledge involved in the parameterized construction method for a known MDS matrix in a symmetric encryption network proposed in this embodiment may include: (1) AES column obfuscation transformation.

[0026] The Advanced Encryption Standard (AES) algorithm uses a 4×4 size with 4 rows of elements. The cyclic matrix A serves as the diffusion layer and participates in the column confusion transformation operation. AES-MDS is defined as the MDS matrix shown in equation (1).

[0027] Equation (1): .

[0028] Define input vector , Represents a 2-element n-dimensional finite field The four elements in the vector. Output vector. The AES-MDS matrix operation (i.e., the MDS operation on the circular matrix A) is as follows: Formal definition: Equation (2): .

[0029] The specific calculation process is shown in equation (3).

[0030] Equation (3):

[0031] Among them, input variables and output variables All are n-bit data. And there are .

[0032] (2) Shift function .

[0033] definition For an n-dimensional finite field An irreducible polynomial of degree n with a leading coefficient of 1 is expressed as: Equation (4): ; In the formula, denoted as the coefficients of each term.

[0034] The shift function is based on Finite field elements The 2x multiplication operation is denoted as .

[0035] In addition, definition The polynomial coefficients obtained by setting the coefficient of the highest term (i.e., the prime minister) and the coefficient of the constant term to 0. Recorded as , That is, the generator of the known MDS matrix.

[0036] (3) MDS matrix.

[0037] Let L be A linear transformation L over a finite field (where m represents the number of elements) is called a linear transformation L when the sum of the number of non-zero input elements and the number of non-zero output elements equals m+1. Under the MDS transformation, if the matrix corresponding to L is M, that is... Then matrix M is an MDS matrix.

[0038] (4) Single-cycle permutation.

[0039] If substitution It satisfies the condition that it contains all elements of the permutation group G, and the permutation... If a permutation cannot be decomposed into several unrelated cycles, and has one and only one cycle, then the permutation is valid. It is called a single-cycle permutation or - Cyclic; a permutation is called a permutation when this single cyclic permutation contains all elements in G. It is the longest periodic permutation or circular permutation, that is, the output of each element from the highest bit is used as the next input (that is, the input to the output is repeated, and the output of the lowest term is the input of the highest term). Its shift number is denoted by j, and its sequential connection constructs a complete permutation containing all elements on G.

[0040] The parameterized construction method for a known MDS matrix in a symmetric encryption network proposed in this application is based on finite fields. Elemental single-cycle permutation Using the shift number j as a parameter, a generalized finite field multiplication tool is constructed, specifically defined as the multiplication operation tool for a known MDS matrix generator. Parameterized functions It replaces the traditional element-multiplication operation in finite fields, thus solving the problem of finite field element-multiplication. This application addresses the complete construction problem of a known MDS matrix. It presents the necessary conditions for constructing an MDS using a generalized finite field multiplication tool, and the traversal of all generators. different j By mapping the parameters of the corresponding MDS matrix, the quantity bound of the complete construction of the MDS matrix is ​​obtained. The finite field is specifically given. The number and instances of MDS (Multi-Level Disk System) complete constructions of cyclic matrices with upper row elements of {2,3,1,1} and Hadamard matrices with first row elements of {2,5,3,1} are presented. The MDS complete construction method proposed in this application, without changing the known MDS matrix structure, elements, or implementation cost, transforms existing finite fields... The number of parameters in the MDS matrix increases. times.

[0041] As an optional implementation, a complete construction method for a known MDS matrix in a symmetric cryptographic network, such as... Figure 1 As shown, it includes: S1. Extract the generators of the MDS matrix. .

[0042] Generator The extraction method has been explained in the previous text, so it will not be repeated here.

[0043] S2, Based on permutation groups Longest periodic permutation and shift number Construct generator Parameterized functions .when For identity transformation, j =0, parameterized function For generators The identity transformation.

[0044] G is about the input variable (2-tuple, length is) (bit) A permutation group G consisting of n bit element positions, the longest periodic permutation set in this permutation group G is denoted as: replacement for Any permutation with the longest period, i.e., any permutation with the longest period.

[0045] S3, Parameterized function Replace the element-wise multiplication of the MDS matrix in an n-dimensional finite field, where n is a positive integer, and update the mapping relationship of the MDS transformation in the finite field. This is achieved through the parameter function. This involves modifying the shift function to achieve parameterization of the MDS matrix through its factorial mapping. Level expansion.

[0046] As an optional implementation, S3 includes the following stages: S31. Constructing about generators Three-variable parameters ,in, Z The range of values ​​is A set of.

[0047] S32. Constructing about the input variables shift function : Equation (5): ; In the formula, Represents input variables n bits Displacement, Indicates taking The first output of the operation Bit information, .

[0048] S33, Based on the shift function The MDS transformation of the MDS matrix is ​​shifted, and the mapping relationship of the MDS transformation is updated.

[0049] In one alternative implementation, this S33 stage is achieved through the following design: Set the output vector Each output variable in , from the input vector Input variables corresponding to the position Input variables for low bits Construct intermediate variables and use shift functions After processing the intermediate variable, it is compared with the input vector. Input variables in other positions Perform an XOR operation.

[0050] For example, using the above Definition, in matrix A of equation (1) Operations, The parameters containing three variables are obtained. The matrix operation on A, denoted as The input vector is The output vector is , respectively For the low-order input variable, four intermediate variables are constructed by cyclically circumferentially connecting the input variables (last and first digits are adjacent): .

[0051] Using shift functions Process these intermediate variables: Equation (6):

[0052] When j=0, then:

[0053] The MDS operation update for matrix A is then: Equation (7):

[0054] Furthermore, for the update of matrix A, i.e., the operation... Set the longest period of cyclical replacement The initial state is That is, the shift value j is 0. Additionally, in the above formula, For intermediate variables Processing results Take the least significant bit for the operation. Set the longest period for cyclic permutation. initial state (Right now Two-variable parameters under ) Thus, the calculation It is a matrix operation on A based on equation (3) performed according to the traditional definition of finite field multiplication, i.e. It is the MDS generator of matrix A The identity transformation.

[0055] S34. Verify the updated MDS transformation.

[0056] As an optional implementation, the S34 phase obtains the test finite field (e.g.) On each The number of corresponding generators, such as in a finite field. The MDS matrix of each irreducible polynomial with a prime coefficient of 1 for each 8th degree has 30 generators. The number of parameters in the MDS formed by the updated MDS transformation over the test finite field is calculated and compared with the number of parameters in the MDS transformation corresponding to the MDS matrix. For example, the MDS matrix used in the diffusion layer of the AES algorithm, in this finite field... Update operation of matrix A The MDS matrix has 5040 × 36 × 8 = 1,451,520 elements, while in traditional methods, the MDS operation on matrix A requires 36 parameters. The method in this application utilizes the finite field... The number of parameters for the operation of matrix A in MDS has been increased by 40320 times.

[0057] Based on the ideas of this application, embodiments of this application also provide a computer program product, which includes a computer program that, when run by a processor, executes the above-described complete construction method for a known MDS matrix in a symmetric encryption network.

[0058] Furthermore, embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, performs the above-described complete construction method for a known MDS matrix in a symmetric encryption network.

[0059] This invention is not limited to the specific embodiments described above. The invention extends to any new feature or combination disclosed in this specification, as well as any new method or process step or combination disclosed herein.

Claims

1. A complete construction method for a known MDS matrix in a symmetric encryption network, characterized in that, include: Extracting generators from the MDS matrix ; Based on permutation groups Longest periodic permutation and shift number Construct the generator Parameterized functions ,when For identity transformation, j =0, the parameter function For the generator Identity transformation; The parameter function Replace the element-wise multiplication operation of the MDS matrix in an n-dimensional finite field, where n is a positive integer, and update the mapping relationship of the MDS transformation in the finite field.

2. The complete construction method for a known MDS matrix in a symmetric encryption network as described in claim 1, characterized in that, The parameter function Replacing the element-wise multiplication operation of the MDS matrix in an n-dimensional finite field includes: Construct about the generator Three-variable parameters ,in Describing permutation group The set of longest periodic permutations. Z The range of values ​​is A set; Construct about input variables shift function : ; In the formula, Represents input variables n bits Displacement, Indicates taking The first output of the operation Bit information, ; Based on shift function The MDS transform of the MDS matrix is ​​shifted to update the mapping relationship of the MDS transform. The updated MDS transformation is validated.

3. The complete construction method for a known MDS matrix in a symmetric encryption network as described in claim 2, characterized in that, Based on shift function The MDS transformation of the MDS matrix is ​​shifted, including: The setting is based on the input vector adjacent input variables in a pairwise loop The corresponding intermediate variable obtained by XOR processing; Set the output vector Each output variable in , from the input vector Input variables corresponding to the position Input variables for low bits Construct intermediate variables and use shift functions After processing the intermediate variable, it is compared with the input vector. Input variables in other positions Perform an XOR operation.

4. The complete construction method for a known MDS matrix in a symmetric encryption network as described in claim 3, characterized in that, Based on shift function The shifting process for the MDS transform of the MDS matrix further includes: Set the longest period of cyclical replacement The initial state is ; Set the longest period of cyclical replacement initial state The two-variable parameters .

5. The complete construction method for a known MDS matrix in a symmetric encryption network as described in any one of claims 1-4, characterized in that, The generator An irreducible polynomial of degree n with a leading coefficient of 1 over a finite field The coefficients obtained by setting the coefficients of the highest term and the constant term to 0.

6. The complete construction method for a known MDS matrix in a symmetric encryption network as described in claim 5, characterized in that, The updated MDS transformation is validated, including: Get each of the test finite fields The number of corresponding generators is calculated, and the number of parameters of the MDS formed by the updated MDS transformation on the test finite field is compared with the number of parameters of the MDS transformation corresponding to the MDS matrix.

7. A complete construction system for a known MDS matrix in a symmetric encryption network, characterized in that, It includes a processor and a storage medium storing computer instructions, the processor executing the computer instructions to perform the complete construction method for a known MDS matrix in a symmetric encryption network as described in any one of claims 1-6.

8. A computer program product, characterized in that, It includes a computer program, which, when executed by a processor, performs the complete construction method for a known MDS matrix in a symmetric cryptographic network as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the complete construction method for a known MDS matrix in a symmetric encryption network as described in any one of claims 1-6.