A communication device software encryption method based on hardware information
Patent Information
- Application Number
- CN202611307615.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-27
- Publication Date
- 2026-09-25
AI Technical Summary
[0005]为了解决通信设备软件易遭逆向分析和非法克隆、加密结构单一抗差分能力不足的技术问题,本发明提供了一种基于硬件信息的通信设备软件加密方法,包括:
本发明通过将硬件特征数据划分为三个独立分段并分别参与加密的不同环节,使加密强度与设备硬件深度绑定,提升了通信设备软件的加密强度与安全性;利用第一硬件特征分段结合密码学哈希函数与线性探测法构建混合基数向量,降低了位置索引冲突,生成具有设备唯一性的加密参量;基于第二硬件特征分段完成非均匀数据分割,结合多态加密变换、混合基数变换以及依奇偶性交替执行的伽罗瓦域乘法与循环移位异或运算,提升了密文数据的混淆度与抗逆向分析能力。
Smart Images

Figure CN122824401A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of software encryption technology, and in particular to a software encryption method for communication devices based on hardware information. Background Technology
[0002] The software running inside communication equipment carries critical business logic, confidential communication protocols, and a large amount of sensitive data, making it a core asset for maintaining equipment operation. Because communication equipment is typically deployed in open environments, its software systems are inevitably exposed to increasingly severe cybersecurity threats. Malicious attackers often use reverse engineering, static code analysis, dynamic debugging and tracing, and illegal cloning to steal core algorithms or tamper with software control flows. To protect communication equipment software and ensure the stable operation of communication networks, software encryption technology has become a crucial line of defense in building equipment security boundaries.
[0003] Traditional software encryption methods rely on independent external key management or pre-defined conventional encryption algorithms for data protection. These static protection mechanisms are relatively vulnerable to advanced attacks. To enhance software protection and achieve collaborative security between software and hardware, incorporating the device's own hardware characteristics into the encryption process and binding the software to a specific hardware platform has become an important direction in the fields of tamper-proofing and anti-cloning. However, existing solutions often limit their utilization of hardware characteristic data to simple hash derivation or basic key generation, failing to explore the role of hardware characteristics in controlling non-uniform data distribution and polymorphic cryptographic transformations. This results in insufficient randomness and resistance to deduction in encryption strategies.
[0004] Furthermore, current encryption processes often employ fixed data segmentation mechanisms and homogeneous mathematical transformations, resulting in limited correlation, nonlinear obfuscation, and spatial permutation strength between ciphertexts. In practical deployments, attackers have found that they can align ciphertexts based on constant data block boundaries and apply differential comparisons. This simplistic encryption logic remains vulnerable to overall decryption when facing advanced cryptanalysis techniques, differential attacks, and reverse engineering tools. Therefore, how to integrate hardware features from multiple dimensions to construct a software encryption process with high obfuscation capabilities, nonlinear characteristics, and resistance to analysis, thereby alleviating the problems of communication equipment software being susceptible to reverse engineering and illegal cloning, and the simplistic encryption structure lacking resistance to differential attacks, is a key issue that needs to be addressed in the field of communication security. Summary of the Invention
[0005] To address the technical problems of communication equipment software being vulnerable to reverse engineering and illegal cloning, and the insufficient resistance to differential attacks due to simple encryption structures, this invention provides a communication equipment software encryption method based on hardware information, comprising:
[0006] S1. Read the processor serial number, motherboard universal unique identifier, and network card media access control address of the communication device, and concatenate them end to end in a fixed byte order to form a 256-bit binary hardware feature data. Extract bits 1 to 88 sequentially and concatenate them end to end to generate the first hardware feature segment. Extract bits 89 to 172 sequentially and concatenate them continuously to generate the second hardware feature segment. Extract bits 173 to 256 sequentially and concatenate them continuously to generate the third hardware feature segment. Divide the first hardware feature segment into multiple sub-segments. Apply a cryptographic hash function to generate a hash digest for each sub-segment. Use the first part of the hash digest as the base value and the second part as the position index to construct a hybrid base vector. S2. Initialize the pseudo-random number generator using the second hardware feature segment as the seed, divide the information to be encrypted into multiple data blocks according to the length of its output numerical sequence, perform data-dependent polymorphic encryption transformation on each data block to obtain intermediate ciphertext, perform mixed radix transformation on the intermediate ciphertext to generate a set of numbers, and switch between Galois field multiplication and cyclic shift XOR operation for processing according to the parity of the number position index. S3. Utilize the third hardware feature to segment and generate an orthogonal permutation matrix. Perform bit-level permutation operations on the overall ciphertext stream obtained by concatenating the permuted ciphertext segments. Construct an invertible finite state automaton to perform a replacement operation on the permuted overall ciphertext stream to generate encrypted information.
[0007] This invention divides hardware feature data into three independent segments, which are used for hybrid radix vector construction, non-uniform data segmentation, and orthogonal permutation matrix generation, respectively. This binds the encryption process to the device hardware, making it difficult for parties without the same hardware features to reproduce the encryption parameters. The first hardware feature segment constructs a hybrid radix vector using a cryptographic hash function and linear probing, reducing position index collisions while retaining all radix values. The non-uniform segmentation and block-by-block polymorphic transformation controlled by the second hardware feature segment, combined with Galois field multiplication and cyclic shift XOR operations applied alternately according to the parity of the position index, makes the ciphertext block boundaries unpredictable. The orthogonal permutation matrix generated by the third hardware feature segment completes bit-level rearrangement, and a reversible finite state automaton applies non-linear replacements, disrupting the statistical distribution of the original code and improving the communication device software's resistance to reverse engineering and illegal cloning.
[0008] The 256-bit hardware feature data is divided into three functionally independent segments of 88, 84, and 84 bits, so that the radix vector, pseudo-random segmentation, and permutation matrix each use non-overlapping hardware bit sources, avoiding the reuse of the same bit by multiple stages and thus weakening the independence of each stage. The bit allocation of 88, 84, and 84 bits mentioned above is determined by the number of bits required by each of the three functional stages: the first hardware feature segment needs to be divided into 8 sub-segments of equal length, which is the same as the length of the mixed radix vector constant, so its bit count is an integer multiple of 8, with 88 bits corresponding to 11 bits for each sub-segment; the third hardware feature segment needs to be evenly divided into 12 bit substrings of equal length, which is the same as the dimension of the orthogonal permutation matrix, so its bit count is an integer multiple of 12, with 84 bits corresponding to 7 bits for each substring, and the integer values of each substring falling between 0 and 127 after conversion; the second hardware feature segment is only used as the seed for the pseudo-random number generator and is not subject to the above division relationship, so the remaining 84 bits from the 256 bits are taken, and zeros are padded at the end to form a 128-bit initialization seed sequence. If the number of bits in the first hardware feature segment is not an integer multiple of the length of the mixed radix vector constant, or the number of bits in the third hardware feature segment is not an integer multiple of the dimension of the orthogonal permutation matrix, then the corresponding segment cannot be divided into 8 sub-segments of equal length or evenly divided into 12 bit substrings of equal length, and the parameter configuration of the corresponding link will not be valid.
[0009] Preferably, the step of constructing a hybrid radix vector using the first part of the hash digest as the base value and the second part of the hash digest as the position index includes: dividing the first hardware feature segment into 8 sub-segments of equal length; performing hash calculation on each sub-segment to obtain 8 corresponding hash digests; extracting the first 16 bits of each hash digest and converting them into the first decimal integer; taking the modulo of a preset upper limit constant of the radix interval and adding a base offset constant to obtain the base value; extracting the last 8 bits of each hash digest and converting them into the second decimal integer; taking the modulo of a preset hybrid radix vector length constant to obtain the position index; storing the base value in the element position pointed to by the position index; and when the position index conflicts, extending to the next free position in the index increment direction for storage.
[0010] The base value falling into a fixed interval is obtained by taking the modulo of the first 16 bits of the hash digest and adding an offset, and the position index is obtained by taking the modulo of the last 8 bits. The collision items are stored sequentially by linear probing, so that each base value is greater than 1 and does not exceed the single byte limit, ensuring that subsequent division with remainder can be performed normally and all base values are preserved.
[0011] Preferably, the step of dividing the information to be encrypted into multiple data blocks based on the output numerical sequence as the length includes: using the second hardware feature segmentation as the seed of the pseudo-random number generator to generate a pseudo-random integer stream with uniform distribution characteristics; setting a minimum length threshold and a maximum length threshold for the data blocks; mapping each integer in the pseudo-random integer stream to a closed interval between the minimum length threshold and the maximum length threshold through modulo and offset operations to generate a length sequence; and sequentially extracting data of the corresponding number of bits from the information to be encrypted according to the values in the length sequence to generate multiple data blocks. The non-uniform segmentation, controlled by hardware random features, makes the ciphertext block boundaries vary depending on the device, making it difficult for attackers to perform differential comparisons based on constant block boundaries.
[0012] Preferably, the step of performing a mixed radix transformation on the intermediate ciphertext to generate a set of numbers includes: converting the intermediate ciphertext into a large integer, performing continuous iterative division operations with remainders using the radix values in the mixed radix vector as divisors, using the quotient obtained from the previous division as the dividend in each iteration, cyclically extracting the next radix value from the mixed radix vector as the divisor, recording the remainders obtained in each operation, and arranging all remainders in the order of calculation to form a set of numbers.
[0013] After converting the data block into a large integer, a continuous division with remainder is performed by iteratively taking the divisor from the mixed radix vector. This results in a remainder sequence whose values are constrained by the radix of each round, allowing the ciphertext data to break away from the fixed base representation of the original bytes and increasing the difficulty of reverse derivation.
[0014] Preferably, the arithmetic operation of switching between Galois field multiplication and cyclic shift XOR operation to process the parity of the numerical position index includes: obtaining a cyclic key stream from the system-preset master key through key derivation expansion; traversing a set of numbers; when the position index of the number is odd, aligning the bit width of the number to the predefined Galois field dimension and performing Galois field multiplication with the corresponding part of the cyclic key stream; when the position index is even, performing a cyclic shift XOR operation with the corresponding part of the cyclic key stream; and converting all the processed numbers into binary sequences of a preset fixed bit width and concatenating them to generate a permutation ciphertext segment.
[0015] Preferably, the step of generating an orthogonal permutation matrix using the third hardware feature segmentation and performing a bit-level permutation operation on the overall ciphertext stream obtained by concatenating the permuted ciphertext segments includes: dividing the third hardware feature segmentation into multiple bit substrings of equal length, converting each bit substring into a corresponding integer value to generate a sorted sequence, performing a row swap operation on a preset identity matrix according to the sorted sequence to generate a full-rank orthogonal permutation matrix, dividing the overall ciphertext stream into vectors with the same dimension as the orthogonal permutation matrix, and multiplying them sequentially with the orthogonal permutation matrix to complete the bit-level permutation operation.
[0016] The row permutation of the identity matrix is applied to the sorting result of the third hardware feature segmentation to construct a full-rank and invertible orthogonal permutation matrix, so that the bit position shift covers the entire vector rather than being limited to a fixed offset, thus destroying the positional correlation of the original ciphertext stream.
[0017] Preferably, the construction of the reversible finite state automaton to perform a substitution operation on the permuted overall ciphertext stream includes: extracting the sorted sequence obtained when generating the orthogonal permutation matrix, perturbing the preset space by combining the multiplicative inverse operation on the Galois field to generate an internal state space, establishing a reversible finite state automaton with a one-to-one correspondence between the input and output, inputting the overall ciphertext stream that has completed the bit-level permutation operation into the reversible finite state automaton with a fixed byte length, looking up the table according to the current state and the input byte to output the replacement byte and trigger a state jump, and outputting the encrypted information after traversal processing.
[0018] Preferably, the step of performing data-dependent polymorphic encryption transformation on each data block to obtain intermediate ciphertext includes: calculating the hash value of each data block as a data-dependent feature vector, performing a bitwise XOR mixing operation between the data-dependent feature vector and the system-preset master key to generate a subkey for the data block, using the subkey to perform symmetric encryption processing on the data block, outputting the intermediate ciphertext corresponding to the data block, and storing the data-dependent feature vector in the encryption / decryption header structure for reproducing the subkey during decryption.
[0019] By XORing the hash value of the data block with the master key, different subkeys are derived for each block, so that the same plaintext fragment can be obtained with different ciphertexts in different positions, and the encryption transformation is polymorphic according to the data content.
[0020] Preferably, the method further includes a decryption step: acquiring the same hardware feature data as during encryption and dividing it into three segments; reconstructing the mixed radix vector, length sequence, and orthogonal permutation matrix; inputting the encrypted information into the inverse mapping of the reversible finite state automaton to undo the substitution operation; dividing the output data stream into equal-length vectors and multiplying them with the inverse matrix of the orthogonal permutation matrix to restore the concatenated permutation ciphertext segment; truncating the permutation ciphertext segment into numbers according to a preset fixed bit width; performing Galois field multiplication inverse operation on numbers with odd position indices according to the parity of the position indices; performing inverse cyclic shift XOR operation on numbers with even position indices to restore the remainder sequence; performing continuous multiplication and accumulation operations on the remainder sequence with the radix value to reconstruct the large integer; restoring the large integer into data blocks according to the length sequence and then concatenating them in order to obtain the plaintext information.
[0021] The technical solution of the present invention has the following beneficial technical effects: This invention improves the encryption strength and security of communication equipment software by dividing hardware feature data into three independent segments, each participating in different encryption stages. This deeply binds encryption strength to the device hardware. The invention also utilizes the first hardware feature segment combined with cryptographic hash functions and linear probing to construct a hybrid radix vector, reducing position index collisions and generating device-unique encryption parameters. Furthermore, the invention completes non-uniform data segmentation based on the second hardware feature segment, and combines polymorphic encryption transformation, hybrid radix transformation, and alternating parity Galois field multiplication and cyclic shift XOR operations to enhance the obfuscation level and resistance to reverse engineering of the ciphertext data.
[0022] Furthermore, by using the third hardware feature to generate an orthogonal permutation matrix in segments to perform bit-level permutations on the entire ciphertext stream, and applying nonlinear replacements by an invertible finite state automaton, the statistical regularity of the data is disrupted, thereby improving the overall anti-cracking level of the encrypted information. Attached Figure Description
[0023] Figure 1 A flowchart of a software encryption method for communication devices based on hardware information; Figure 2 A schematic diagram showing the regions segmented for hardware feature data; Figure 3 A comparative diagram showing the number of days required for reverse analysis of each test set. Detailed Implementation
[0024] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments.
[0025] Reference Figure 1 A software encryption method for communication devices based on hardware information includes steps S1 to S3, which are described in detail below.
[0026] S1. Extract hardware features and construct a hybrid cardinality vector.
[0027] The hardware feature data is acquired and divided into a first hardware feature segment, a second hardware feature segment, and a third hardware feature segment. The first hardware feature segment is further divided into multiple sub-segments. A cryptographic hash function is applied to generate a hash digest for each sub-segment. A hybrid radix vector is constructed using the first part of the hash digest as the radix and the second part as the position index.
[0028] The processor serial number, motherboard unique identifier, and network card media access control address of the underlying communication device are read and concatenated end-to-end in fixed byte order to form binary raw hardware feature data, with a length of 256 bits. Three consecutive bit streams are extracted using bitmasking and logical shifting performed within the CPU's high-speed register: bits 1 to 88 form the first hardware feature segment, used to generate the mixed radix vector; bits 89 to 172 form the second hardware feature segment, used for initializing the pseudo-random number generator; and bits 173 to 256 form the third hardware feature segment, used to construct the orthogonal permutation matrix. The entire bit-by-bit segmentation is completed within the register, referencing... Figure 2 This reduces the persistent residue of hardware feature data on the disk and ensures the memory security of hardware feature data. For example, in other implementations, the start and end positions of the bits in each segment can be redefined, provided that the number of bits in the first hardware feature segment is an integer multiple of the length of the mixed radix vector and the number of bits in the third hardware feature segment is an integer multiple of the dimension of the orthogonal permutation matrix, as long as the decryption end uses the same partitioning rules.
[0029] After obtaining the first hardware feature segment, it is divided into 8 sub-segments of equal length, each 11 bits long. Each sub-segment is padded with 21 zeros at the high-order bits to make it 32 bits. These sub-segments are then independently processed by the cryptographic hash function, outputting 8 hash digests of 256 bits each. By padded with zeros at each point to align the bit width, even short sub-segments that are less than a hash input block can still be processed by the same hash engine, thus allowing the 8 sub-segments to share the same hash caliber.
[0030] The first part of each hash digest is used as the base value, and the second part is used as the position index to construct a mixed base vector of length 8. The base value is determined as follows: the first 16 bits of the hash digest are truncated and converted into the first unsigned decimal integer in big-endian order, with a value range of 0 to 65535. This value is then modulo a preset upper limit constant of the base interval and added to a base offset constant. In this embodiment, the upper limit constant of the base interval is 245, and the base offset constant is 11. Therefore, the base value stably falls within the range of 11 to 255. The lower bound of this range is determined by the base offset constant, and the upper bound is determined by the sum of the upper limit constant of the base interval and the base offset constant. This ensures that each base value is greater than 1, guaranteeing that subsequent division with remainder can be performed normally without exceeding the single-byte limit for unified storage. Taking a sub-segment as an example, if the hexadecimal value of the first 16 bits of its hash digest is 0x1A2B, which is 6699 in decimal, taking 6699 modulo 245 gives 84. Adding the offset of 11, the radix value corresponding to this sub-segment is 95. The position index is determined as follows: the last 8 bits of the hash digest are truncated and converted into an unsigned second decimal integer, with a value range of 0 to 255. The value is then moduloed by a preset mixed radix vector length constant. In this embodiment, the mixed radix vector length constant is 8, so the position index falls between 0 and 7.
[0031] Initialize a one-dimensional array of length 8, containing only empty markers, as the mixed radix vector to be constructed. Iterate through the 8 radix values and their corresponding indices, writing the radix value to the element position pointed to by the index in the array. When an array position pointed to by a certain index is already occupied by a previous radix value, a position index conflict is determined and handled using linear probing: increment the current position index by one and take the modulo of the array length 8 to obtain a new position index. If the new position is still occupied, continue incrementing and taking the modulo to probe forward until the first empty marker position is located and the radix value is written. For example, if the calculated position index of a radix value is 3 and index 3 is already occupied, then check index 4, index 5, and so on, until an empty position is found and stored. After processing all 8 sub-segments, a fully filled mixed radix vector with no empty positions is obtained. The linear probing approach, rather than discarding conflicting items, is used to ensure that all 8 radix values are retained in the vector, avoiding radix loss due to hash collisions, which would weaken the reversibility of subsequent transformations.
[0032] S2. Non-uniformly divide the data blocks and perform polymorphic transformation.
[0033] The pseudo-random number generator is initialized using the second hardware feature segment as a seed. The information to be encrypted is divided into multiple data blocks according to the length of the output numerical sequence. Data-dependent polymorphic encryption transformation is performed on each data block to obtain intermediate ciphertext. A mixed radix transformation is performed on the intermediate ciphertext to generate a set of numbers. Arithmetic operations are switched between Galois field multiplication and cyclic shift XOR operation according to the parity of the number position index.
[0034] The second hardware feature, with a length of 84 bits, is segmented and padded with 44 zero bits at the end to reconstruct a 128-bit initialization seed sequence. This seed sequence is then injected into a pseudo-random number generator, outputting a continuous 32-bit pseudo-random integer stream with uniform distribution. To strike a balance between encryption obfuscation and processor efficiency, a minimum data block length threshold of 128 bits and a maximum threshold of 512 bits are pre-set. Too small a threshold would cause a surge in the number of data blocks, hindering processor efficiency; too large a threshold would stabilize the statistical characteristics within a single block, reducing the disruption to the original code distribution caused by non-uniform segmentation. Therefore, the above range is chosen as a compromise. For each integer in the pseudo-random integer stream... The modulo and offset operations are used to map the data to the aforementioned closed interval, and the mapping relationship is as follows: ; In the formula, The segmentation length obtained after mapping. The current integer in the pseudo-random integer stream is the modulo term, which constrains the discrete pseudo-random number to the interval span, and the offset term shifts the result as a whole to a position with the minimum length threshold as the lower bound. When it increases The corresponding changes occur within the closed interval. When taking any value All values do not exceed the range of 128 to 512, and each segment length falls within a preset threshold. This generates a continuously extending length sequence in memory, for example, the sequence values are 144, 312, 256, and 508 respectively.
[0035] A read offset pointer is maintained, initially pointing to the base address of the software code's memory image. Data of the corresponding number of bits is sequentially extracted from the information to be encrypted according to the length sequence. Taking the example sequence above, the first round reads 144 bits from the starting position as a data block, and the pointer moves forward 144 bits; the second round continues to extract 312 bits to form the next data block, and so on until the entire binary stream of the information to be encrypted is consumed. If the number of available bits remaining during the last read is less than the currently allocated length, the remaining bits are packaged into the last data block and padded at the end according to standard padding rules. This non-uniform partitioning, relying on the random characteristics of hardware, changes the inherent statistical distribution structure of the native code and the instruction cycle patterns relied upon by reverse engineering tools. It should be noted that if a fixed-length partitioning is used instead of non-uniform partitioning, attackers can align the ciphertext based on constant block boundaries and apply differential comparisons, leading to a simple ciphertext structure that is vulnerable to differential attacks. Therefore, non-uniform partitioning is a necessary step to maintain the unpredictability of ciphertext block boundaries.
[0036] For each data block, a data-dependent polymorphic encryption transformation is first performed to obtain intermediate ciphertext. The hash value of the data block itself is calculated as a data-dependent feature vector. This feature vector is then XORed with a pre-set master key to generate a subkey for the data block. This subkey is then used to perform symmetric encryption on the data block, outputting the corresponding intermediate ciphertext. Because the hash value of each data block varies depending on its content, the subkey differs from block to block. The same plaintext fragment will yield different ciphertexts in different positions. This process makes the encryption transformation polymorphic according to the data content.
[0037] The system's pre-set master key also serves as the source for deriving the circular key stream required for subsequent arithmetic operations. Using the pre-set master key as input to the key derivation function, a 256-bit circular key stream is output after key derivation expansion. The circular key used for subsequent parity arithmetic operations is derived from this circular key stream; when traversing a set of numbers, the corresponding bytes are extracted sequentially according to their position index. Using the same master key to uniformly derive subkeys and the circular key stream ensures that the encryption end and the decryption end, which possesses the same hardware characteristics and pre-set master key, can reproduce the same circular key stream, thereby guaranteeing that parity arithmetic operations can be reversed.
[0038] After obtaining the intermediate ciphertext, perform a mixed radix transformation on it to generate a set of numbers. Then convert the intermediate ciphertext to a large integer in big-endian byte order. Using the base values in the mixed base vector as divisors, perform successive iterative division operations with remainders: the first round uses... Divide by the first base value to obtain the quotient and remainder. Record the remainder as the first element of this group of numbers. In the next round, use the quotient from the previous round as the dividend, and cyclically extract the next base value from the mixed base vector as the divisor to obtain a new quotient and remainder. This process continues until all eight base values are exhausted and the current quotient is still not zero. The vector read pointer is then reset and reused cyclically from the first base value until the quotient equals zero, at which point the process stops. Arrange the remainders from each round in the order of calculation to form a group of numbers, denoted as . By performing the above iteration on a large integer corresponding to an intermediate ciphertext of length 312 bits using the base value of 95 in this embodiment, a series of remainders whose values are constrained by the base values of each round can be obtained.
[0039] Iterate through the group of numbers, indexed by the current number's position. Parity selection arithmetic operations. When position index When the number is odd, it is bit-width aligned to match the predefined Galois field dimension, that is, the high-order bits are padded with zeros to make it 8 bits to match. Then, Galois field multiplication is performed with the corresponding part of the preset cyclic key. In this embodiment, the irreducible polynomial is taken as... The circular key is derived from the circular key stream pre-set by the system master key, and the corresponding bytes are extracted according to position. This multiplication causes local diffusion within a finite field. When the position index... When the number is even, a cyclic shift XOR operation is performed on the corresponding part of the loop key. This involves first cyclically shifting the binary string of the number 3 bits to the left in an 8-bit register to shuffle the bitwise order, and then performing a bitwise XOR with the corresponding byte of the loop key. All processed numbers are then converted into 8-bit binary sequences of a preset fixed width and concatenated sequentially to generate the permutation ciphertext segment corresponding to the data block. Distributing two types of arithmetic operations based on parity is because a single operation results in a homogeneous distribution across the ciphertext positions, making it easy to model bit by bit. Alternating between finite field multiplication and cyclic shift XOR ensures that the confusion patterns of adjacent positions are different.
[0040] S3. Generate the permutation matrix and complete the nonlinear replacement.
[0041] The orthogonal permutation matrix is generated by segmenting the third hardware feature. Bit-level permutation operation is performed on the overall ciphertext stream obtained by concatenating the permuted ciphertext segments. An invertible finite state automaton is then constructed to perform a replacement operation on the permuted overall ciphertext stream to generate encrypted information.
[0042] Extract an 84-bit third hardware feature segment from memory and evenly divide it into 12 substrings of fixed length 7 bits. Convert each substring into an unsigned integer value between 0 and 127, generating a sorted sequence of 12 integer elements. For example, the memory representation might be 45, 12, 108, 33, etc. This sorted sequence also serves as a pseudo-random sequence for subsequent construction of a finite state automaton. Initialize a 12×12 binary identity matrix. Rearrange the sorted sequence in ascending order using a sorting algorithm. Whenever two elements in the sequence are swapped due to size comparison, a swap is simultaneously performed on the corresponding row of the identity matrix. By reproducing the swapping trajectory of the sorting process, construct a... A 12×12 orthogonal permutation matrix with a non-zero, full-rank, and inverse matrix is generated by classifying the row determinants, and the sorted sequence is retained for use in state-space perturbation. This transforms the hardware characteristics into a set of deterministic row swapping actions, binding the permutation matrix to the device hardware one by one.
[0043] The data blocks obtained after the aforementioned parity arithmetic operations are concatenated end-to-end according to their original cutting order to form a continuous ciphertext stream. The total bit length of the ciphertext stream is calculated. If this length is not divisible by 12, the remainder obtained by subtracting the length from 12 and taking the modulo 12 is used as the number of bits to be padded. A corresponding number of zero bits are appended to the end for alignment padding, making the total length a multiple of 12. The aligned ciphertext stream is then divided into multiple Boolean column vectors, each consisting of 12 bits. These vectors are then sequentially processed with an orthogonal permutation matrix. Intra-domain multiplication rearranges the bits of the entire ciphertext stream without changing the ciphertext bit width. Using an orthogonal permutation matrix for left multiplication instead of simple shifting allows the bit position shifts to cover the entire vector rather than being limited to a fixed offset, thus breaking down the positional dependencies of the original ciphertext stream.
[0044] After the bit-level permutation is completed, the sorted sequence retained during the generation of the orthogonal permutation matrix is taken as a pseudo-random sequence. This sequence, combined with the multiplicative inverse operation over the Galois finite field, is used to perturb the preset space, generating the internal state space. The algorithm iterates through all single-byte elements from 0 to 255, calculating the multiplicative inverse of each non-zero element to introduce nonlinear properties. Numerical values are sequentially extracted from the pseudo-random sequence and mapped to 8-bit binary masks. Bit-level affine transformations are then performed on each multiplicative inverse using these masks. Through a combination of finite-field nonlinear operations and hardware perturbations, a 256-dimensional internal state space with nonlinear characteristics is obtained. Based on this, a reversible finite state automaton with 256 independent stable state nodes and a one-to-one correspondence between inputs and outputs is constructed. This automaton maintains a state transition lookup table and a data replacement lookup table in memory, ensuring a one-to-one correspondence between the in-degree and out-degree of each state to satisfy the reversibility condition.
[0045] The entire ciphertext stream, after completing bit-level substitution operations, is input into a reversible finite state automaton in fixed byte units (8 bits each). The automaton uses the current state node and the input byte for joint addressing in the transition table. It then looks up a replacement byte from the substitution lookup table of the current node, overwrites the original byte with this replacement byte, and triggers a state transition to the next node to process subsequent bytes. After traversing the entire ciphertext stream byte by byte to complete all substitutions, the processed fixed-length byte data stream is written to a new program file. An encryption / decryption header structure is added to the beginning of the file data segment. This header structure records the basic configuration of the three hardware feature segments and the byte length table of each ciphertext segment arranged in concatenated order. The file stream handle is closed, generating encrypted information that can be deployed and distributed to communication devices.
[0046] Accordingly, during decryption, the same 256-bit hardware feature data as during encryption is obtained and divided into three segments according to the same rules. The mixed radix vector, pseudo-random length sequence and orthogonal permutation matrix are reconstructed and their inverse matrices are obtained, as well as the inverse mapping table of the invertible finite state automaton. First, the byte length table of each permutation ciphertext segment is read from the encryption / decryption header structure. Then, the encrypted information is input into a reverse-configured finite state automaton to undo the nonlinear substitution. The output data stream is divided into equal-length vectors and multiplied with the inverse of the orthogonal permutation matrix to restore the bit-level permutation, resulting in a concatenated sequence of permutation ciphertext segments. The concatenated sequence is then divided into permutation ciphertext segments according to the byte length table. Each permutation ciphertext segment is sequentially truncated and converted into numbers according to a preset fixed bit width. The Galois field multiplication inverse operation is performed on numbers with odd positions according to the parity of the position index, and the inverse cyclic shift XOR operation is performed on numbers with even positions to recover the remainder sequence. The remainder sequence is then reconstructed using a continuous multiplication and accumulation operation from low to high using the base value to obtain the intermediate ciphertext corresponding to each data block. These intermediate ciphertexts are then concatenated in order to obtain the plaintext information.
[0047] To verify the effectiveness of the above encryption method, a 50MB binary file of the core business code of a communication device was selected as the test object. An enterprise-grade Linux system was deployed and run on a communication node server equipped with a multi-core processor and 64GB of memory. Four test sets were set up: a standard pattern reference set without hardware feature cutting and state machine replacement; a cut length removal set that removed pseudo-random length cutting and replaced it with a constant 256-bit segmentation; an operator confusion set that degraded Galois field multiplication and cyclic shift to ordinary XOR; and a mixed multi-overlay set that included all the above processing steps. The Shannon information entropy (a measure of randomness), the number of days required for brute-force cracking and reverse analysis by a third-party security laboratory, and the computation time for processing each megabyte of plaintext were used as evaluation metrics. The information entropy measured by the standard pattern reference set was 7.9892, with a reverse engineering time of 9 days and a processing time of 410 microseconds; the information entropy measured by the removed cut length group was 7.9941, with a reverse engineering time of 21 days and a processing time of 465 microseconds; the information entropy measured by the operator confusion group was 7.9928, with a reverse engineering time of 16 days and a processing time of 430 microseconds; and the information entropy measured by the mixed multiple overlay group was 7.9997, with a reverse engineering time of 62 days and a processing time of 498 microseconds. Figure 3 As shown in the figure, the introduction of non-uniform segmentation and alternating arithmetic operations brings the ciphertext information entropy close to the theoretical upper limit of a single byte, significantly increasing the time required for reverse engineering relative to the reference set, while the processing time for a single megabyte only increases slightly.
[0048] It should be noted that those skilled in the art can make various modifications and improvements without departing from the inventive concept, and these all fall within the scope of protection of this invention. Therefore, the scope of protection of this patent should be determined by the appended claims.
Claims
1. A software encryption method for communication devices based on hardware information, characterized in that, include: S1. Read the processor serial number, motherboard universal unique identifier, and network card media access control address of the communication device, and concatenate them end to end in a fixed byte order to form a 256-bit binary hardware feature data. Extract bits 1 to 88 sequentially and concatenate them end to end to generate the first hardware feature segment. Extract bits 89 to 172 sequentially and concatenate them continuously to generate the second hardware feature segment. Extract bits 173 to 256 sequentially and concatenate them continuously to generate the third hardware feature segment. Divide the first hardware feature segment into multiple sub-segments. Apply a cryptographic hash function to generate a hash digest for each sub-segment. Use the first part of the hash digest as the base value and the second part as the position index to construct a hybrid base vector. S2. Initialize the pseudo-random number generator using the second hardware feature segment as the seed, divide the information to be encrypted into multiple data blocks according to the length of its output numerical sequence, perform data-dependent polymorphic encryption transformation on each data block to obtain intermediate ciphertext, perform mixed radix transformation on the intermediate ciphertext to generate a set of numbers, and switch between Galois field multiplication and cyclic shift XOR operation for processing according to the parity of the number position index. S3. Utilize the third hardware feature to segment and generate an orthogonal permutation matrix. Perform bit-level permutation operations on the overall ciphertext stream obtained by concatenating the permuted ciphertext segments. Construct an invertible finite state automaton to perform a replacement operation on the permuted overall ciphertext stream to generate encrypted information.
2. The software encryption method for communication devices based on hardware information according to claim 1, characterized in that, The method of constructing a hybrid radix vector using the first part of the hash digest as the radix and the second part as the position index includes: dividing the first hardware feature segment into 8 sub-segments of equal length; performing hash calculation on each sub-segment to obtain 8 corresponding hash digests; extracting the first 16 bits of each hash digest and converting them into the first decimal integer; taking the modulo of a preset radix interval upper limit constant and adding a base offset constant to obtain the radix value; extracting the last 8 bits of each hash digest and converting them into the second decimal integer; taking the modulo of a preset hybrid radix vector length constant to obtain the position index; storing the radix value in the element position pointed to by the position index; and when the position index conflicts, extending to the next free position in the index increment direction for storage.
3. The software encryption method for communication devices based on hardware information according to claim 1, characterized in that, The step of dividing the information to be encrypted into multiple data blocks according to the length of the output numerical sequence includes: using the second hardware feature segmentation as the seed of the pseudo-random number generator to generate a pseudo-random integer stream with uniform distribution characteristics; setting a minimum length threshold and a maximum length threshold for the data blocks; mapping each integer in the pseudo-random integer stream to a closed interval between the minimum length threshold and the maximum length threshold through modulo and offset operations to generate a length sequence; and sequentially extracting data of the corresponding number of bits from the information to be encrypted according to the values in the length sequence to generate multiple data blocks.
4. The software encryption method for communication devices based on hardware information according to claim 1, characterized in that, The step of performing a mixed radix transformation on the intermediate ciphertext to generate a set of numbers includes: converting the intermediate ciphertext into a large integer; performing continuous iterative division with remainders using the radix values in the mixed radix vector as divisors; using the quotient obtained from the previous division as the dividend in each iteration; cyclically extracting the next radix value from the mixed radix vector as the divisor; recording the remainders obtained in each operation; and arranging all remainders in the order of calculation to form a set of numbers.
5. The software encryption method for communication devices based on hardware information according to claim 4, characterized in that, The parity of the numerical position index is processed by switching between Galois field multiplication and cyclic shift XOR operation, which includes: obtaining a cyclic key stream from the system's preset master key through key derivation expansion; traversing a set of numbers; when the position index of the number is odd, aligning the bit width of the number to the predefined Galois field dimension and performing Galois field multiplication with the corresponding part of the cyclic key stream; when the position index is even, performing a cyclic shift XOR operation with the corresponding part of the cyclic key stream; and converting all the processed numbers into binary sequences of preset fixed bit width and concatenating them to generate a permutation ciphertext segment.
6. The software encryption method for communication devices based on hardware information according to claim 1, characterized in that, The step of generating an orthogonal permutation matrix using the third hardware feature segmentation and performing a bit-level permutation operation on the overall ciphertext stream obtained by concatenating the permuted ciphertext segments includes: dividing the third hardware feature segmentation into multiple bit substrings of equal length, converting each bit substring into a corresponding integer value to generate a sorted sequence, performing a row swap operation on a preset identity matrix according to the sorted sequence to generate a full-rank orthogonal permutation matrix, dividing the overall ciphertext stream into vectors with the same dimension as the orthogonal permutation matrix, and multiplying them sequentially with the orthogonal permutation matrix to complete the bit-level permutation operation.
7. The software encryption method for communication devices based on hardware information according to claim 6, characterized in that, The construction of the reversible finite state automaton to perform a replacement operation on the permuted overall ciphertext stream includes: extracting the sorted sequence obtained when generating the orthogonal permutation matrix; perturbing the preset space by combining the multiplicative inverse operation on the Galois field to generate an internal state space; establishing a reversible finite state automaton with a one-to-one correspondence between input and output; inputting the overall ciphertext stream that has completed the bit-level permutation operation into the reversible finite state automaton with a fixed byte length; looking up the table according to the current state and the input byte to output the replacement byte and trigger a state jump; and outputting the encrypted information after traversal processing.
8. The software encryption method for communication devices based on hardware information according to claim 1, characterized in that, The process of performing data-dependent polymorphic encryption transformation on each data block to obtain intermediate ciphertext includes: calculating the hash value of each data block as a data-dependent feature vector; performing a bitwise XOR operation on the data-dependent feature vector and the system-preset master key to generate a subkey for the data block; using the subkey to perform symmetric encryption on the data block; outputting the intermediate ciphertext corresponding to the data block; and storing the data-dependent feature vector in the encryption / decryption header structure for reproducing the subkey during decryption.
9. A software encryption method for communication devices based on hardware information according to claim 1, characterized in that, The decryption steps also include: acquiring the same hardware feature data as during encryption and dividing it into three segments; reconstructing the mixed radix vector, length sequence, and orthogonal permutation matrix; inputting the encrypted information into the inverse mapping of the reversible finite state automaton to undo the substitution operation; dividing the output data stream into equal-length vectors and multiplying them with the inverse of the orthogonal permutation matrix to restore the concatenated permutation ciphertext segments; truncating the permutation ciphertext segments according to a preset fixed bit width and converting them into numbers; performing Galois field multiplication inverse operation on numbers with odd positions according to the parity of the position index, and performing inverse cyclic shift XOR operation on numbers with even positions to restore the remainder sequence; performing continuous multiplication and accumulation operations on the remainder sequence with the radix value to reconstruct large integers; restoring the large integers into data blocks according to the length sequence and then concatenating them in order to obtain the plaintext information.