National cryptographic algorithm core, data encryption method, device and electronic equipment

By introducing an arbitrator and a key protection module into the national cryptographic algorithm core, multiple national cryptographic algorithms can be run simultaneously and keys can be protected. This solves the problems of low data throughput, low efficiency, and key leakage risk of traditional national cryptographic algorithm cores, and improves security and efficiency.

CN122137552APending Publication Date: 2026-06-02SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
Filing Date
2026-01-30
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Traditional Chinese cryptographic algorithms suffer from low core data throughput, low encryption efficiency, and the risk of key leakage, resulting in low security.

Method used

An arbitrator and a key protection module are introduced. The arbitrator controls the transmission of the initial key and the data to be encrypted according to the preset priority and algorithm channel enable signal. The key protection module generates a key stream for encryption, enabling the simultaneous operation of multiple national cryptographic algorithms and key protection.

Benefits of technology

It improves the data throughput and computational efficiency of the national cryptographic algorithm core, prevents key leakage, and enhances the security of the algorithm core.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137552A_ABST
    Figure CN122137552A_ABST
Patent Text Reader

Abstract

This application discloses a national cryptographic algorithm core, a data encryption method, an apparatus, and an electronic device, relating to the field of data encryption technology. The method includes: transmitting an initial key and data to be encrypted to a control logic module via an arbitrator based on a preset priority and a first enable signal; generating a key stream corresponding to the initial key via a key protection module; and encrypting the data to be encrypted using the key stream via a data encryption module to obtain ciphertext data. This addresses the problems of low data throughput, low encryption efficiency, and the risk of key leakage during data encryption. The national cryptographic algorithm core utilizes an arbitrator to control and sort the initial key and data to be encrypted, enabling all national cryptographic algorithms in the data encryption module to run simultaneously, thus improving the data throughput and computational efficiency of the algorithm core. The key protection module generates a key stream, which is then used to encrypt the data, preventing the actual key used by the algorithm core from being leaked, thereby enhancing the security of the algorithm core.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption technology, specifically to national cryptographic algorithm cores, data encryption methods, devices, and electronic equipment. Background Technology

[0002] Communication technologies have placed higher demands on information security during data transmission. As a result, national cryptographic algorithms such as SM4, SM3, SM2, SM9, and Zu Chongzhi's algorithm have been widely used in the field of information security.

[0003] Currently, traditional Chinese cryptographic algorithm kernels are created based on the aforementioned national cryptographic algorithms and used for data encryption. However, only one national cryptographic algorithm is used for encryption operations at a time within a traditional national cryptographic algorithm kernel, while the others remain in standby mode. This results in low data throughput and low data encryption efficiency. Furthermore, if the key is intercepted before being input into the traditional national cryptographic algorithm kernel, the intercepted key can be used to easily decrypt the ciphertext encrypted by the kernel. Traditional national cryptographic algorithm kernels lack key protection capabilities, posing a risk of key leakage and thus exhibiting low security. Summary of the Invention

[0004] This invention provides a national cryptographic algorithm core, a data encryption method, a device, and an electronic device to solve the problems of low data throughput, low data encryption efficiency, and the risk of key leakage during data encryption.

[0005] In the first aspect, this application provides a national cryptographic algorithm core, which includes: an arbitrator, a control logic module, a key protection module, and a data encryption module;

[0006] The arbitrator is connected to the control logic module and is used to obtain the initial key and the data to be encrypted through the first algorithm channel. According to the preset priority and the first enable signal of the first algorithm channel, the initial key and the data to be encrypted are transmitted to the control logic module. The control logic module is connected to the key protection module and is used to transmit the initial key to the key protection module; The key protection module is used to generate the key stream corresponding to the initial key and transmit the key stream to the control logic module; The control logic module is connected to the data encryption module and is used to transmit the key stream and the data to be encrypted to the data encryption module corresponding to the data to be encrypted, so that the data encryption module can encrypt the data to be encrypted according to the key stream to obtain ciphertext data.

[0007] Secondly, this application provides a data encryption method, which is applied to the national cryptographic algorithm core of the first aspect or any corresponding embodiment thereof, the method comprising: The initial key and the data to be encrypted are obtained through the first algorithm channel. Based on the preset priority and the first enable signal of the first algorithm channel, the arbitration strategy of the data to be encrypted is determined. The arbitration strategy is used to control and sort the initial key and the data to be encrypted. Generate the key stream corresponding to the initial key according to the arbitration strategy; The data to be encrypted is encrypted using the key stream to obtain ciphertext data.

[0008] Thirdly, this application provides a data encryption device, which includes: The arbitration module is used to obtain the initial key and the data to be encrypted through the first algorithm channel, and determine the arbitration strategy of the data to be encrypted according to the preset priority and the first enable signal of the first algorithm channel. The arbitration strategy is used to control and sort the initial key and the data to be encrypted. The key stream generation module is used to generate the key stream corresponding to the initial key according to the arbitration strategy; The encryption module is used to encrypt the data to be encrypted according to the key stream to obtain ciphertext data.

[0009] Fourthly, this application provides an electronic device, including: a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the data encryption method described in the second aspect or any corresponding embodiment.

[0010] Fifthly, this application provides a computer-readable storage medium storing computer instructions for causing a computer to execute the data encryption method described in the second aspect or any corresponding embodiment thereof.

[0011] In a sixth aspect, this application provides a computer program product, including computer instructions for causing a computer to execute the data encryption method described in the second aspect or any corresponding embodiment thereof.

[0012] This application utilizes an arbitrator to obtain an initial key and the data to be encrypted. Based on a preset priority and a first enable signal, the initial key and the data to be encrypted are transmitted to the control logic module. A key protection module then generates a keystream corresponding to the initial key. Finally, a data encryption module encrypts the data to be encrypted using the keystream to obtain ciphertext data. This addresses the problems of low data throughput, low encryption efficiency, and the risk of key leakage during data encryption. The national cryptographic algorithm core employs an arbitration mechanism. The arbitrator controls and sorts the initial key and the data to be encrypted based on a preset priority and the algorithm channel's enable signal, allowing all national cryptographic algorithms in the data encryption module to run simultaneously, thus improving the algorithm core's data throughput and computational efficiency. Furthermore, a key protection mechanism is introduced for the national cryptographic algorithm core. A key protection module generates a keystream, which is then used to encrypt the data, preventing the key actually used by the algorithm core from being leaked and enhancing the algorithm core's security. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in the specific embodiments or related technologies of this application, the drawings used in the description of the specific embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0014] Figure 1 This is a schematic diagram of the structure of a traditional Chinese cryptographic algorithm core according to an embodiment of this application; Figure 2 This is a schematic diagram of the structure of the national cryptographic algorithm core according to an embodiment of this application; Figure 3 This is a schematic diagram of the structure of another national cryptographic algorithm core according to an embodiment of this application; Figure 4 This is a flowchart illustrating a data encryption method according to an embodiment of this application; Figure 5 This is a schematic diagram of the workflow of the national cryptographic algorithm core according to an embodiment of this application; Figure 6 This is a structural block diagram of a data encryption device according to an embodiment of this application; Figure 7 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0015] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0016] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0017] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0018] Chinese cryptographic algorithms such as SM4, SM3, SM2, SM9, and the Zu Chongzhi algorithm (ZUC) can be used for data encryption, decryption, and integrity verification. The rapid development of modern communication technology has placed higher demands on information security during data transmission. Therefore, these Chinese cryptographic algorithms have been widely used in the field of information security. Among them, SM4 is a symmetric encryption algorithm, while SM2 and SM9 are asymmetric encryption algorithms; both can be used for data encryption and decryption. SM2 and SM9 are also frequently used in areas requiring data integrity verification; for example, secure chip startup requires both algorithms to encrypt the data digest to obtain a signature, ensuring information security. SM3 is a hash function algorithm used to verify data integrity, while ZUC is a stream cipher algorithm that can generate stream keys for data encryption, decryption, and integrity verification.

[0019] Currently, the architecture of traditional Chinese cryptographic algorithm cores is as follows: Figure 1 As shown, the key, the data to be processed, and the algorithm core's operating mode are input into the control logic. The control logic then determines the algorithm core's operating mode and selects the corresponding algorithm unit based on that mode. After receiving the start signal, key, and data to be processed from the control logic, the corresponding algorithm unit begins its algorithmic operation and inputs the processed ciphertext or plaintext into the memory, awaiting retrieval and output from the host computer.

[0020] However, traditional Chinese cryptographic algorithm cores suffer from low data throughput and low computational efficiency. Although a traditional Chinese cryptographic algorithm core integrates five algorithms, only one algorithm operates at a time, while the others remain in standby mode. The core only begins receiving commands for the next algorithm after the previous one has finished running. Therefore, traditional Chinese cryptographic algorithm cores have low circuit resource utilization, resulting in low overall data throughput and computational efficiency. Furthermore, traditional Chinese cryptographic algorithm cores have low security. If the key is intercepted before being input into the core, the intercepted key can easily be used to crack the encrypted text. Since traditional Chinese cryptographic algorithm cores lack key protection, they are at risk of key leakage, thus exhibiting low security.

[0021] Based on the above, this application provides a data encryption method that adds an arbitrator and a Zu Chongzhi algorithm unit to the national cryptographic algorithm core. After receiving the key, algorithm mode command, and data to be processed (including the data to be processed and its length) through the algorithm channel, the arbitrator generates an arbitration strategy based on the internally designed priority and the algorithm channel's enable signal. The introduction of the arbitration mechanism enables all algorithms within the national cryptographic algorithm core to work simultaneously, improving the core's data throughput and computational efficiency. The Zu Chongzhi algorithm unit uses the Zu Chongzhi algorithm to generate a Zu Chongzhi keystream with the same length as the key input into the algorithm core. This keystream is used for data encryption to protect the key input into the algorithm core, thus enhancing the security of the national cryptographic algorithm core.

[0022] The specific application environment architecture or specific hardware architecture on which the execution of the data encryption method depends is described here.

[0023] According to the embodiments of this application, a national cryptographic algorithm core is provided. It should be noted that the national cryptographic algorithm core can run on a computer system such as a set of computer-executable instructions, such as a computer or a server, or it can run on an integrated circuit corresponding to the national cryptographic algorithm core.

[0024] This embodiment provides a national cryptographic algorithm core. Figure 2 This is a structural diagram of the national cryptographic algorithm core according to an embodiment of this application, such as... Figure 2 As shown, the core of this national cryptographic algorithm includes: an arbitrator, a control logic module, a key protection module, and a data encryption module; The arbitrator is connected to the control logic module and is used to obtain the initial key and the data to be encrypted through the first algorithm channel. According to the preset priority and the first enable signal of the first algorithm channel, the initial key and the data to be encrypted are transmitted to the control logic module. The control logic module is connected to the key protection module and is used to transmit the initial key to the key protection module; The key protection module is used to generate the key stream corresponding to the initial key and transmit the key stream to the control logic module; The control logic module is connected to the data encryption module and is used to transmit the key stream and the data to be encrypted to the data encryption module corresponding to the data to be encrypted, so that the data encryption module can encrypt the data to be encrypted according to the key stream to obtain ciphertext data.

[0025] Specifically, the arbitrator controls and sorts the encryption requests input to the national cryptographic algorithm core based on the preset priority of its internal design, the enable signal of the algorithm channel in the control logic module, and the algorithm execution signal. The encryption request includes the initial key, the algorithm mode command, and the data to be encrypted (including the data to be encrypted and the data length).

[0026] The data encryption module includes multiple preset algorithm units, such as the SM3, SM4, SM2, SM9, and Zu Chongzhi algorithm units. The SM4 unit is the SM4 algorithm core, used to execute the SM4 algorithm function. The SM3 unit is the SM3 algorithm core, used to execute the SM3 algorithm function. The SM2 unit is the SM2 algorithm core, used to execute the SM2 algorithm function. The SM9 unit is the SM9 algorithm core, used to execute the SM9 algorithm function. The Zu Chongzhi algorithm unit is the Zu Chongzhi algorithm core, used to execute the Zu Chongzhi algorithm function.

[0027] The control logic module is primarily responsible for data interaction with all internal preset algorithm units and for controlling the arbitrator. Upon receiving the initial key, the control logic module treats all input initial keys as keys for the Zu Chongzhi algorithm unit, controls the Zu Chongzhi algorithm unit to generate a Zu Chongzhi flow key of the same length as the input key, and inputs the Zu Chongzhi flow key into the corresponding preset algorithm unit according to the algorithm mode command. The control logic module also controls the arbitrator by raising or lowering the enable signal and algorithm execution signal of the algorithm channel based on the operating status of all preset algorithm units, thereby enabling all preset algorithm units to operate simultaneously.

[0028] The first algorithm channel includes channels corresponding to national cryptographic algorithms such as SM4, SM2, SM9, and Zu Chongzhi's algorithm. Encryption requests can be input through the first algorithm channel for different national cryptographic algorithms.

[0029] The arbitrator is connected to the control logic module. The arbitrator can obtain the initial key and the data to be encrypted through the first algorithm channel. For example, the arbitrator obtains an encryption request through the first algorithm channel, including the initial key, algorithm mode command, and the data to be encrypted (including the data to be encrypted and its length), and then extracts the initial key and the data to be encrypted from the encryption request. The arbitrator has a preset priority, for example: SM4 > SM2 > SM9 > Zu Chongzhi algorithm. If two encryption requests arrive simultaneously, one corresponding to SM4 and the other to SM9, the encryption request corresponding to SM4 is processed first.

[0030] The first enable signal of the first algorithm channel is controlled by the control logic module. Pulling the first enable signal high (i.e., adjusting it to a high level) indicates that the first algorithm channel is available; conversely, pulling it low indicates that the first algorithm channel is unavailable. The arbitrator will transmit the initial key and the data to be encrypted to the control logic module according to the preset priority and the first enable signal of the first algorithm channel. For example, if three encryption requests are received simultaneously, corresponding to SM4, SM2, and SM9 respectively, and the first enable signal of the first algorithm channel corresponding to SM4 is low, while the first enable signals of the first algorithm channels corresponding to SM2 and SM9 are high, the arbitrator will first process the encryption request corresponding to SM2, then the encryption request corresponding to SM9, and only process the encryption request corresponding to SM4 after the first enable signal of the first algorithm channel corresponding to SM4 is adjusted to a low level. During the processing of the encryption requests, the initial key and the data to be encrypted from the encryption request are transmitted to the control logic module.

[0031] This embodiment leverages the high security and uncrackability of the keystream generated by the Zu Chongzhi algorithm. A key protection module is created based on the Zu Chongzhi algorithm, introducing a key protection mechanism that significantly enhances the security of the algorithm core. Furthermore, different national cryptographic algorithms can be used to create key protection modules according to actual needs. The control logic module is connected to the key protection module. The control logic module transmits the initial key to the key protection module, which generates the Zu Chongzhi keystream (i.e., the keystream) corresponding to the initial key based on the Zu Chongzhi algorithm and transmits the keystream to the control logic module.

[0032] The control logic module transmits the key stream and the data to be encrypted to the data encryption module corresponding to the data to be encrypted. The data encryption module encrypts the data to be encrypted according to the key stream and the included national cryptographic algorithm to obtain ciphertext data. For example, if the data to be encrypted corresponds to the SM2 algorithm unit, the SM2 algorithm unit encrypts the data to be encrypted according to the SM2 algorithm and the key stream to obtain ciphertext data.

[0033] Figure 3 This is a schematic diagram of the structure of another national cryptographic algorithm core, such as... Figure 3As shown, the system includes SM4, SM3, SM2, SM9, and ZuChongzhi algorithm units. Each algorithm unit has a corresponding output memory, and after generating ciphertext data, the algorithm unit can output a data ready signal. The arbitrator is connected to the outside world through multiple algorithm channels, including: SM3 algorithm channel, SM4 algorithm channel, SM2 algorithm channel, SM9 algorithm channel, and ZuC algorithm channel.

[0034] The national cryptographic algorithm core provided in this embodiment obtains the initial key and the data to be encrypted through an arbitrator, and transmits the initial key and the data to be encrypted to the control logic module according to a preset priority and a first enable signal. Then, a key protection module generates a key stream corresponding to the initial key. Finally, a data encryption module encrypts the data to be encrypted according to the key stream to obtain ciphertext data. This national cryptographic algorithm core employs an arbitration mechanism, using an arbitrator to control and sort the initial key and the data to be encrypted according to a preset priority and the enable signal of the algorithm channel. This allows all national cryptographic algorithms in the data encryption module to run simultaneously, improving the data throughput and computational efficiency of the algorithm core. Furthermore, a key protection mechanism is introduced for the national cryptographic algorithm core. The key protection module generates a key stream, which is then used to encrypt the data, preventing the key actually used by the algorithm core from being leaked, thus improving the security of the algorithm core. This solves the problems of low data throughput, low data encryption efficiency, and the risk of key leakage during data encryption.

[0035] As an optional embodiment, the national cryptographic algorithm core also includes: a storage module; The data encryption module is connected to the storage module and is used to store ciphertext data in the storage module, adjust the data ready signal to the first level and output the adjusted data ready signal, wherein the adjusted data ready signal is used to represent the generated ciphertext data; The data encryption module is also used to adjust the data ready signal to the second level after the host computer reads the encrypted data from the storage module.

[0036] Specifically, the storage module is a memory with storage function, and a corresponding memory can be set for each preset algorithm unit in the data encryption module, such as... Figure 3 As shown, corresponding output memories are set up for the SM4 algorithm unit, SM3 algorithm unit, SM2 algorithm unit, SM9 algorithm unit and Zu Chongzhi algorithm unit in the data encryption module. The output memories are used to store the output data of the corresponding algorithm unit.

[0037] The data encryption module is connected to the storage module. After completing the calculation, the data encryption module obtains the ciphertext data. The ciphertext data is then stored in the corresponding storage module. The first level represents a high level.

[0038] After the encrypted data is stored, the data encryption module adjusts the data ready signal to the first level and outputs the adjusted data ready signal. This adjusted data ready signal notifies the host computer that encrypted data has been generated and is ready to be read. Adjusting the data ready signal to the first level means pulling the data ready signal high. A high data ready signal indicates that the encrypted data calculation has been completed; a low data ready signal indicates that encrypted data has not been generated or is being calculated.

[0039] After the host computer reads the encrypted data from the storage module, the data encryption module adjusts the data ready signal to the second level, that is, pulls the data ready signal low, and starts the next round of calculation.

[0040] In this embodiment, a corresponding storage module is configured according to the algorithm unit. After the encrypted text is stored, a high signal is pulled to notify the host computer to read it. After reading, the low signal is pulled to start the next round of operation, realizing orderly storage of encrypted text and clear interaction with the host computer, improving data processing efficiency and operation continuity.

[0041] As an optional embodiment, the data encryption module includes: a first preset algorithm unit; An arbitrator is used to acquire the data to be processed through the second algorithm channel, and transmit the data to be processed to the control logic module when the second enable signal of the second algorithm channel is at the first level. The control logic module is connected to the first preset algorithm unit and is used to transmit the data to be processed to the preset algorithm unit; The first preset algorithm unit is used to obtain processing result information based on the preset algorithm and the data to be processed.

[0042] Specifically, the first preset algorithm unit is the SM3 algorithm unit, which is an SM3 algorithm core used to execute the SM3 algorithm function. SM3 is a hash function algorithm, and its function includes verifying the integrity of data. If the algorithm mode command in the input encryption request is the SM3 algorithm, then no initial key needs to be input, the arbitrator does not perform arbitration, and only considers the enable signal of the SM3 algorithm channel. If the enable signal is high, the arbitrator directly inputs the data information to be processed into the control logic.

[0043] The second algorithm channel is the SM3 algorithm channel. The arbitrator obtains the data to be processed through the second algorithm channel, such as data whose integrity needs to be verified. The first level represents a high level, and the second level represents a low level. If the second enable signal of the second algorithm channel is high, it means that the second algorithm channel can be used to input the data to be processed; conversely, if the second enable signal is low, it means that the second algorithm channel cannot be used to input the data to be processed, and the first preset algorithm unit is occupied.

[0044] When the second enable signal of the second algorithm channel is at the first level, the arbitrator does not perform arbitration and directly transmits the data to be processed to the control logic module. The control logic module then directly transmits the received data to be processed to the first preset algorithm unit. The preset algorithm is the SM3 algorithm.

[0045] After receiving the data to be processed, the first preset algorithm unit performs the SM3 algorithm operation on the data and outputs the processing result information. The processing result information may include: the data to be processed is complete, or the data to be processed is incomplete.

[0046] In this embodiment, no initial key is required. When the SM3 algorithm channel is enabled high, the arbitrator can directly transmit the data to be processed without arbitration, quickly perform data integrity verification, simplify the process, accurately reflect the data integrity status, and improve the efficiency of data integrity verification.

[0047] As an optional embodiment, the data encryption module includes: a second preset algorithm unit; The control logic module is connected to the second preset algorithm unit and is also used to adjust the first enable signal and the algorithm running signal corresponding to the second preset algorithm unit to the first level after transmitting the key stream and the data to be encrypted to the second preset algorithm unit. The control logic module is also used to adjust the first enable signal and the algorithm running signal corresponding to the second preset algorithm unit to the second level when it is determined that the data to be encrypted and the ciphertext data have the same data length; The control logic module is also used to adjust the first enable signal to the first level when the falling edge of the data ready signal corresponding to the second preset algorithm unit is detected.

[0048] Specifically, the second preset algorithm unit can be, for example, the SM4 algorithm unit, the SM2 algorithm unit, the SM9 algorithm unit, or the Zu Chongzhi algorithm unit. It should be noted that the second preset algorithm unit cannot be the SM3 algorithm unit. The first level represents a high level, and the second level represents a low level.

[0049] After the control logic module sends the key stream and the data to be encrypted to an algorithm unit other than the SM3 algorithm unit, it pulls the corresponding algorithm channel enable and algorithm execution signals high. For example, the second preset algorithm unit is an algorithm unit other than the SM3 algorithm unit. After transmitting the key stream and the data to be encrypted to the second preset algorithm unit, the control logic module adjusts both the first enable signal and the algorithm execution signal corresponding to the second preset algorithm unit to a first level. Specifically, if the first enable signal is high, it indicates that the first algorithm channel is not occupied; conversely, if the first enable signal is low, it indicates that the first algorithm channel is occupied. If the algorithm execution signal is high, it indicates that the second preset algorithm unit corresponding to the algorithm execution signal is running a preset algorithm and cannot receive new encryption requests; if the algorithm execution signal is low, it indicates that the second preset algorithm unit corresponding to the algorithm execution signal is in an idle state.

[0050] When the control logic module determines that the data to be encrypted has the same length as the ciphertext data calculated by the second preset algorithm unit, it adjusts the first enable signal and the algorithm running signal corresponding to the second preset algorithm unit to the second level, that is, pulls down the algorithm running signal and the first enable signal of the first algorithm channel. At this time, it indicates that the second preset algorithm unit is in an idle state and the first algorithm channel is occupied.

[0051] When the control logic module detects the falling edge of the data ready signal corresponding to the second preset algorithm unit, it adjusts the first enable signal to the first level, that is, pulls up the first enable signal corresponding to the first algorithm channel, indicating that the first algorithm channel is not occupied.

[0052] In this embodiment, by precisely controlling the enable and run signals of non-SM3 algorithm units, and matching the data length and switching the state based on the falling edge of the ready signal, channel conflicts are avoided, the orderly operation is ensured, and the continuity and efficiency of data encryption are improved.

[0053] As an optional embodiment, the arbitrator is used to eliminate the preset priority corresponding to the second preset algorithm unit when the control logic module adjusts the algorithm running signal corresponding to the second preset algorithm unit to the first level. The arbitrator is also used to input the data to be encrypted corresponding to the second preset algorithm unit into the control logic module after removing the preset priority corresponding to the second preset algorithm unit. The arbitrator is also used to re-add the preset priority corresponding to the second preset algorithm unit when the control logic module adjusts the algorithm operation signal corresponding to the second preset algorithm unit to the second level.

[0054] Specifically, the first level represents a high level, and the second level represents a low level. If the algorithm execution signal is high, it indicates that the second preset algorithm unit corresponding to the algorithm execution signal is running a preset algorithm and cannot receive new encryption requests; if the algorithm execution signal is low, it indicates that the second preset algorithm unit corresponding to the algorithm execution signal is in an idle state. It should be noted that the first preset algorithm unit, i.e., the SM3 algorithm unit, does not have an algorithm execution signal.

[0055] When the control logic module adjusts the algorithm operation signal corresponding to the second preset algorithm unit to the first level, the arbitrator indicates that the second preset algorithm unit cannot receive new encryption requests, removes the preset priority corresponding to the second preset algorithm unit, and no longer includes the corresponding algorithm in the priority consideration.

[0056] When the arbitrator removes the preset priority corresponding to the second preset algorithm unit, the data transmission method of the second preset algorithm unit and the SM3 algorithm unit is the same, which is to directly input the corresponding data to be encrypted into the control logic module.

[0057] When the control logic module adjusts the algorithm operation signal corresponding to the second preset algorithm unit to the second level, the arbitrator determines that the second preset algorithm unit is in an idle state, re-adds the preset priority corresponding to the second preset algorithm unit, and controls its input priority.

[0058] In this embodiment, the arbitrator dynamically removes / restores the priority of the second preset algorithm unit based on its running signal, and transmits data directly without arbitration during operation, avoiding channel conflicts, ensuring smooth data transmission, and improving the rationality of algorithm core scheduling and computational efficiency.

[0059] As an optional embodiment, the control logic module is used to, upon receiving the initial key, determine the first intermediate unit in the second preset algorithm unit whose corresponding algorithm running signal is at the second level, and adjust the first enable signal corresponding to the first intermediate unit to the second level; The control logic module is also used to determine, in the second preset algorithm unit, a second intermediate unit that does not correspond to the key stream after the key protection module generates the key stream, and to adjust the first enable signal corresponding to the second intermediate unit to a first level.

[0060] Specifically, once the initial key of an arbitrary algorithm has been input into the control logic module, the control logic module will pull down the enable signal of the algorithm channels other than the "SM3 algorithm channel" and the "algorithm channel whose corresponding algorithm operation signal is high".

[0061] Upon receiving the initial key, the control logic module determines the first intermediate unit within the second preset algorithm unit whose corresponding algorithm execution signal is at the second level. Since the first intermediate unit possesses an algorithm execution signal, it cannot be the SM3 algorithm unit. If the first intermediate unit's algorithm execution signal is low, it is not the SM3 algorithm unit, and its algorithm execution signal is the second level. The module then adjusts the first enable signal corresponding to the first intermediate unit to the second level, i.e., pulls the first enable signal corresponding to the first intermediate unit low.

[0062] After the Zu Chongzhi key stream is generated, the control logic module will pull up the enable signals of all algorithm channels except for the "algorithm channel of the national cryptographic algorithm corresponding to the initial key", excluding the SM3 signal channel. After the key protection module generates the key stream, the control logic module will determine the second intermediate unit that does not correspond to the key stream in the second preset algorithm unit, and adjust the first enable signal corresponding to the second intermediate unit to the first level.

[0063] In this embodiment, the control logic module dynamically adjusts the enable signal of the non-SM3 algorithm unit based on the initial key reception and key stream generation status to avoid channel conflicts during key processing, ensure key stream security, and improve the stability and security of the algorithm core operation.

[0064] As an optional embodiment, the control logic module is used to adjust the second enable signal corresponding to the first preset algorithm unit to a second level when the data length of the determined processing result information is the same as the data length of the data to be processed. The control logic module is also used to adjust the second enable signal to the first level when the falling edge of the data ready signal corresponding to the first preset algorithm unit is detected.

[0065] Specifically, for the first preset algorithm unit, i.e., the SM3 algorithm unit, when the data length of the processing result information obtained after executing the SM3 algorithm is the same as the data length of the data to be processed, the control logic module pulls down the SM3 algorithm channel enable signal, that is, adjusts the second enable signal corresponding to the first preset algorithm unit to the second level. This indicates that the second algorithm channel corresponding to the first preset algorithm unit is occupied.

[0066] When the control logic module detects the falling edge of the data ready signal corresponding to the first preset algorithm unit, it indicates that the host computer has read the processing result information corresponding to the first preset algorithm unit. The task of the first preset algorithm unit is completed, and the next round of calculation can begin. Therefore, the control logic module pulls the SM3 algorithm channel enable signal high, that is, adjusts the second enable signal to the first level. This indicates that the second algorithm channel corresponding to the first preset algorithm unit is in an idle state and can transmit the data to be processed corresponding to the SM3 algorithm.

[0067] In this embodiment, the SM3 algorithm channel enable signal is dynamically adjusted based on the data length matching result and the falling edge of the data ready signal to avoid channel conflicts, ensure orderly operation, and improve the continuity and efficiency of data integrity verification.

[0068] According to the embodiments of this application, a data encryption method embodiment is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be run in the above-mentioned national cryptographic algorithm core, or can be executed in a computer system such as a set of executable instructions, such as a computer, server, etc. Furthermore, although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than that shown here.

[0069] This embodiment provides a data encryption method. Figure 4 This is a flowchart of a data encryption method according to an embodiment of this application, such as... Figure 4 As shown, the process includes the following steps: Step S401: Obtain the initial key and the data to be encrypted through the first algorithm channel. Determine the arbitration strategy for the data to be encrypted based on the preset priority and the first enable signal of the first algorithm channel. The arbitration strategy is used to control and sort the initial key and the data to be encrypted.

[0070] Specifically, the arbitrator is designed with preset priorities, such as SM4 > SM2 > SM9 > Zu Chongzhi's algorithm. If two encryption requests arrive at the same time, one corresponding to SM4 and the other to SM9, the encryption request corresponding to SM4 will be processed first.

[0071] The arbitrator determines the arbitration strategy for the data to be encrypted based on the preset priority and the first enable signal of the first algorithm channel. For example, if three encryption requests are received simultaneously, corresponding to SM4, SM2, and SM9 respectively, and the first enable signal of the first algorithm channel corresponding to SM4 is low, while the first enable signals of the first algorithm channels corresponding to SM2 and SM9 are high, the arbitrator will first process the encryption request corresponding to SM2, then process the encryption request corresponding to SM9, and only process the encryption request corresponding to SM4 after the first enable signal of the first algorithm channel corresponding to SM4 is adjusted to low. When processing the encryption request, the initial key and the data to be encrypted in the encryption request are transmitted to the control logic module.

[0072] Step S402: Generate the key stream corresponding to the initial key according to the arbitration strategy.

[0073] Specifically, through the above arbitration strategy, the initial key and the data to be encrypted are controlled and sorted to determine the transmission order, and the initial key and the data to be encrypted are transmitted to the control logic module according to the transmission order.

[0074] This embodiment leverages the high security and uncrackability of the keystream generated by the Zu Chongzhi algorithm. A key protection module is created based on the Zu Chongzhi algorithm, introducing a key protection mechanism that significantly enhances the security of the algorithm core. Furthermore, different national cryptographic algorithms can be used to create key protection modules according to actual needs. The control logic module is connected to the key protection module. The control logic module transmits the initial key to the key protection module, which generates the Zu Chongzhi keystream (i.e., the keystream) corresponding to the initial key based on the Zu Chongzhi algorithm and transmits the keystream to the control logic module.

[0075] Step S403: Encrypt the data to be encrypted according to the key stream to obtain ciphertext data.

[0076] Specifically, the control logic module transmits the key stream and the data to be encrypted to the data encryption module corresponding to the data to be encrypted. The data encryption module encrypts the data to be encrypted according to the key stream and the included national cryptographic algorithm to obtain ciphertext data. For example, if the data to be encrypted corresponds to the SM2 algorithm unit, the SM2 algorithm unit encrypts the data to be encrypted according to the SM2 algorithm and the key stream to obtain ciphertext data.

[0077] The data encryption method provided in this embodiment employs an arbitration mechanism. An arbitrator controls and sorts the initial key and the data to be encrypted based on preset priorities and algorithm channel enable signals, allowing all national cryptographic algorithms in the data encryption module to run simultaneously, thus improving the data throughput and computational efficiency of the algorithm core. Furthermore, a key protection mechanism is introduced for the national cryptographic algorithm core. A key protection module generates a keystream, which is then used to encrypt the data, preventing the leakage of the key actually used by the algorithm core and enhancing its security. This solves the problems of low data throughput, low data encryption efficiency, and the risk of key leakage during data encryption.

[0078] As an optional embodiment, a workflow for a national cryptographic algorithm core is provided, such as... Figure 5 As shown, the method includes: In step S501, the key, algorithm mode command, and data information to be processed (including the data to be processed and the data length) are input to the arbitrator through the corresponding algorithm channel. The arbitrator inputs the key and data information to be processed for the corresponding algorithm mode into the control logic according to the internally designed priority and the enabling of the algorithm channel.

[0079] In step S502, the control logic sends the key to the Zu Chongzhi algorithm unit. The Zu Chongzhi algorithm unit generates a Zu Chongzhi key stream with the same length as the input key based on the input key, and inputs the key stream into the control logic.

[0080] In step S503, after receiving the key stream, the control logic sends the key stream and the data to be processed to the corresponding algorithm unit for corresponding algorithm operations.

[0081] In step S504, after the corresponding algorithm unit completes the calculation, it sends the calculation result into the corresponding memory, and then outputs a data ready signal to wait for the host computer to read it. After the reading is completed, the data ready signal is pulled low, and the next round of calculation begins.

[0082] In this embodiment, the key, algorithm mode command, and data to be processed (including the data to be processed and its length) are input into the arbitrator through the corresponding algorithm channel. The arbitrator, based on its internally designed priority and the enabling of the algorithm channel, inputs the key and data to be processed for the corresponding algorithm mode into the control logic. The control logic sends the key to the Zu Chongzhi algorithm unit to generate a key stream, and then inputs the key stream into the corresponding algorithm unit for computation and outputs the result. Combining the principle that the key stream generated by the Zu Chongzhi algorithm is highly secure and difficult to crack, the input key is converted into a Zu Chongzhi algorithm stream key, introducing a key protection mechanism for the national cryptographic algorithm core and significantly improving the security of the algorithm core. On the other hand, by using the arbitration mechanism to control the input data stream and the operation of each algorithm unit, the five algorithm units within the national cryptographic algorithm core can work simultaneously, significantly improving the data throughput and computational efficiency of the national cryptographic algorithm core.

[0083] As an optional embodiment, the above step S402 "generating the key stream corresponding to the initial key" may further include steps A1 to A5.

[0084] In this embodiment, based on the above embodiment which only uses Zu Chongzhi's algorithm to generate a single key stream, a dynamic protection system combining security level, key strength, and protection strategy is constructed to solve the problem that the original scheme has fixed key protection strength and cannot adapt to different security requirements of data.

[0085] Step A1: The data to be encrypted is input into the arbitrator through the algorithm channel, simultaneously carrying the L1 / L2 / L3 level identifier issued by the host computer, or the level is automatically determined by the built-in rules of the control logic module (such as identifying sensitive fields).

[0086] In step A2, the control logic module sends the corresponding parameters to the key protection module based on the level identifier or judgment level (L1 uses the default 32 rounds of operation of Zu Chongzhi algorithm, while L2 / L3 are increased to 64 / 128 rounds respectively), and binds the key protection strategy (L2 level adds SM3 verification, L3 registration adds SM2 encapsulation).

[0087] In step A3, the key protection module uses the Zu Chongzhi algorithm to generate a key stream according to the configuration. The L2 level verifies the key integrity through SM3, and the L3 level is encapsulated with the SM2 public key before transmission to ensure the security strength of key streams at different levels. After the key stream is generated, it is directly synchronized to the target algorithm unit (SM4 / SM9, etc.) to avoid key stream leakage.

[0088] In step A4, the control logic module sends the key stream and the data to be encrypted to the data encryption module for encryption. If a level switch, risk warning, or timed update is triggered, the new key stream is switched after the current data is processed, and the old key stream is stopped simultaneously to ensure encryption continuity and key timeliness.

[0089] In step A5, when the main key stream generation fails, the pre-stored backup key stream of the corresponding level is invoked to avoid service interruption. After the new key stream takes effect, the control logic module lowers the enable of the channel corresponding to the old key stream to completely destroy the old key stream and prevent reuse from causing security risks.

[0090] In this embodiment, the generated key stream can achieve precise matching between data security level and key protection, balancing security and efficiency, and adapting to multiple scenario requirements.

[0091] This embodiment also provides a data encryption device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0092] This embodiment provides a data encryption device, such as... Figure 6 As shown, it includes: Arbitration module 601 is used to obtain an initial key and data to be encrypted through a first algorithm channel, and determine an arbitration strategy for the data to be encrypted based on a preset priority and a first enable signal of the first algorithm channel. The arbitration strategy is used to control and sort the initial key and the data to be encrypted. The key stream generation module 602 is used to generate a key stream corresponding to the initial key according to the arbitration strategy; The encryption module 603 is used to encrypt the data to be encrypted according to the key stream to obtain ciphertext data.

[0093] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.

[0094] In this embodiment, the data encryption device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.

[0095] Figure 7This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention.

[0096] The following is a detailed reference. Figure 7 This diagram illustrates a suitable structural schematic for implementing an electronic device according to embodiments of the present invention. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 701, which can perform various appropriate actions and processes based on a program stored in read-only memory (ROM) 702 or a program loaded from memory 708 into random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the electronic device. The processor 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0097] Typically, the following devices can be connected to I / O interface 705: input devices 706 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 707 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 708 including, for example, magnetic tapes, hard disks, etc.; and communication devices 709. Communication device 709 allows electronic devices to exchange data via wireless or wired communication with other devices. Although Figure 7 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.

[0098] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 709, or installed from a memory 708, or installed from a ROM 702. When the computer program is executed by the processor 701, it performs the functions defined in the data encryption method of the embodiments of the present invention.

[0099] Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.

[0100] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the data encryption method shown in the above embodiments is implemented.

[0101] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.

[0102] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A national cryptographic algorithm core, characterized in that, The national cryptographic algorithm core includes: an arbitrator, a control logic module, a key protection module, and a data encryption module; The arbitrator is connected to the control logic module and is used to obtain an initial key and data to be encrypted through a first algorithm channel, and transmit the initial key and data to be encrypted to the control logic module according to a preset priority and a first enable signal of the first algorithm channel. The control logic module is connected to the key protection module and is used to transmit the initial key to the key protection module; The key protection module is used to generate a key stream corresponding to the initial key and transmit the key stream to the control logic module; The control logic module is connected to the data encryption module and is used to transmit the key stream and the data to be encrypted to the data encryption module corresponding to the data to be encrypted, so that the data encryption module encrypts the data to be encrypted according to the key stream to obtain ciphertext data.

2. The national cryptographic algorithm core according to claim 1, characterized in that, The national cryptographic algorithm core also includes: a storage module; The data encryption module is connected to the storage module and is used to store the ciphertext data in the storage module, adjust the data ready signal to a first level and output the adjusted data ready signal, wherein the adjusted data ready signal is used to indicate that the ciphertext data has been generated. The data encryption module is further configured to adjust the data ready signal to a second level after the host computer reads the encrypted data from the storage module.

3. The national cryptographic algorithm core according to claim 1, characterized in that, The data encryption module includes: a first preset algorithm unit; The arbitrator is used to acquire the data to be processed through the second algorithm channel, and transmit the data to be processed to the control logic module when the second enable signal of the second algorithm channel is at the first level. The control logic module is connected to the first preset algorithm unit and is used to transmit the data to be processed to the first preset algorithm unit. The first preset algorithm unit is used to obtain processing result information based on the preset algorithm and the data to be processed.

4. The national cryptographic algorithm core according to claim 2, characterized in that, The data encryption module includes: a second preset algorithm unit; The control logic module is connected to the second preset algorithm unit and is further configured to adjust the first enable signal and the algorithm running signal corresponding to the second preset algorithm unit to the first level after transmitting the key stream and the data to be encrypted to the second preset algorithm unit. The control logic module is further configured to adjust the first enable signal and the algorithm running signal corresponding to the second preset algorithm unit to the second level when it is determined that the data to be encrypted and the ciphertext data have the same data length; The control logic module is further configured to adjust the first enable signal to a first level when a falling edge of the data ready signal corresponding to the second preset algorithm unit is detected.

5. The national cryptographic algorithm core according to claim 4, characterized in that, The arbitrator is used to remove the preset priority corresponding to the second preset algorithm unit when the control logic module adjusts the algorithm running signal corresponding to the second preset algorithm unit to the first level. The arbitrator is also used to input the data to be encrypted corresponding to the second preset algorithm unit into the control logic module after removing the preset priority corresponding to the second preset algorithm unit; The arbitrator is also used to re-add the preset priority corresponding to the second preset algorithm unit when the control logic module adjusts the algorithm running signal corresponding to the second preset algorithm unit to the second level.

6. The national cryptographic algorithm core according to claim 4, characterized in that, The control logic module is used to, upon receiving the initial key, determine a first intermediate unit in the second preset algorithm unit whose corresponding algorithm running signal is at the second level, and adjust the first enable signal corresponding to the first intermediate unit to the second level; The control logic module is further configured to, after the key protection module generates the key stream, determine a second intermediate unit in the second preset algorithm unit that does not correspond to the key stream, and adjust the first enable signal corresponding to the second intermediate unit to a first level.

7. The national cryptographic algorithm core according to claim 3, characterized in that, The control logic module is used to adjust the second enable signal corresponding to the first preset algorithm unit to a second level when it is determined that the data length of the processing result information is the same as the data length of the data to be processed. The control logic module is further configured to adjust the second enable signal to a first level when a falling edge of the data ready signal corresponding to the first preset algorithm unit is detected.

8. A data encryption method, characterized in that, The method is applied to the national cryptographic algorithm core according to any one of claims 1 to 7, and the method includes: An initial key and data to be encrypted are obtained through a first algorithm channel. An arbitration strategy for the data to be encrypted is determined according to a preset priority and a first enable signal of the first algorithm channel. The arbitration strategy is used to control and sort the initial key and the data to be encrypted. Based on the arbitration strategy, a key stream corresponding to the initial key is generated; The data to be encrypted is encrypted using the key stream to obtain ciphertext data.

9. A data encryption device, characterized in that, The device includes: An arbitration module is used to obtain an initial key and data to be encrypted through a first algorithm channel, and determine an arbitration strategy for the data to be encrypted based on a preset priority and a first enable signal of the first algorithm channel. The arbitration strategy is used to control and sort the initial key and the data to be encrypted. A key stream generation module is used to generate a key stream corresponding to the initial key according to the arbitration strategy. An encryption module is used to encrypt the data to be encrypted according to the key stream to obtain ciphertext data.

10. An electronic device, characterized in that, include: The system includes a memory and a processor, which are interconnected. The memory stores computer instructions, and the processor executes the computer instructions to perform the data encryption method of claim 8.