SM4CCM encryption device

By using ZYNQ chip and FPGA to implement hardware encryption modules in the SM4_CCM encryption device, and using a 6-level pipeline structure and RAM to implement S-boxes, the problem of low performance of SM4_CCM algorithm software in the prior art is solved, and higher encryption performance and resource consumption are achieved.

CN222850937UActive Publication Date: 2025-05-09YUNNAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202323370628.4
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2023-12-11
Publication Date
2025-05-09
Estimated Expiration
2033-12-11

AI Technical Summary

Technical Problem

In the prior art, the software implementation of the SM4_CCM algorithm has problems such as computation-intensive, high memory resource consumption and low performance.

Method used

A SM4_CCM encryption device is designed, using a ZYNQ chip, which includes an ARM processor, DDR3 memory and a hardware encryption module. The hardware encryption module is implemented using FPGA, including an SM4 encryption core structure, and an S box is implemented using a 6-level pipeline structure and RAM in the wheel.

Benefits of technology

It greatly reduces the logical resource consumption required for encryption computing, improves the maximum operating frequency and throughput, and achieves higher encryption performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN222850937U_ABST
    Figure CN222850937U_ABST
Patent Text Reader

Abstract

The utility model discloses an SM4CCM encryption device, and relates to the technical field of information security, and the device comprises a ZYNQ chip; the ZYNQ chip comprises an ARM processor, a DDR3 memory and a hardware encryption module which are connected in sequence; the hardware encryption module is realized by adopting an FPGA (Field Programmable Gate Array) and comprises an SM4 encryption core structure; the SM4 encryption core structure is an in-wheel six-level assembly line structure. According to the utility model, the encryption performance is higher, and the logic resource consumption required for realizing the SM4CCM algorithm is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The utility model relates to the technical field of information security, in particular to an SM4_CCM encryption device. Background Art

[0002] With the rapid development of artificial intelligence and 5G, a large amount of sensitive data containing privacy is generated and transmitted. In order to ensure the security of data, most data is encrypted using encryption algorithms before transmission. In this scenario, providing high-speed encryption for a large amount of data that needs to be encrypted has become a bottleneck for data transmission.

[0003] The SM4 algorithm is a commercial encryption algorithm released by the China Cryptography Administration and is widely used in China's data encryption field. However, symmetric encryption alone cannot guarantee the authenticity and integrity of data and is vulnerable to replay attacks and tampering attacks. SM4_CCM, as an authenticated encryption algorithm, can simultaneously ensure the confidentiality, integrity, and source authenticity of data. It has been introduced by RFC 8898 and is widely used.

[0004] In the prior art, SM4_CCM is a computationally intensive algorithm, and its software implementation has the problems of high memory resource consumption and low performance. Utility Model Content

[0005] The utility model aims to provide an SM4_CCM encryption device, which has higher encryption performance and reduces the consumption of logic resources required to implement the SM4_CCM algorithm.

[0006] To achieve the above purpose, the utility model provides the following solutions:

[0007] An SM4_CCM encryption device, comprising: a ZYNQ chip; the ZYNQ chip comprises an ARM processor, a DDR3 memory and a hardware encryption module connected in sequence;

[0008] The hardware encryption module is implemented by FPGA; the hardware encryption module includes: an SM4 encryption core structure; the SM4 encryption core structure is an intra-wheel 6-stage pipeline structure.

[0009] Optionally, the device further includes: an interface module; the interface module is connected to the ZYNQ chip.

[0010] Optionally, the ZYNQ chip further includes: a data bus; the DDR3 memory is connected to the hardware encryption module via the data bus.

[0011] Optionally, the SM4 encryption core structure includes: 2 XOR modules, 1 nonlinear transformation module, 1 cyclic shift module and 5 registers; the nonlinear transformation module includes: 4 S boxes.

[0012] Optionally, the S-box is implemented using RAM.

[0013] Optionally, the SM4 encryption core structure also includes: a control state machine, a register, a multiplexer and a counter.

[0014] Optionally, the interface module includes an onboard wired Ethernet interface.

[0015] According to the specific embodiments provided by the utility model, the utility model discloses the following technical effects:

[0016] The utility model discloses an SM4_CCM encryption device, which includes: a ZYNQ chip; the ZYNQ chip includes an ARM processor, a DDR3 memory and a hardware encryption module connected in sequence; the hardware encryption module is implemented by FPGA; the hardware encryption module includes: an SM4 encryption core structure; the SM4 encryption core structure includes: 2 XOR modules, 1 nonlinear transformation module, 1 circular shift module and 5 registers; the nonlinear transformation module includes: 4 S boxes. The SM4 encryption core structure in the utility model is implemented by using a 6-stage pipeline structure within the wheel. Compared with the prior art that uses a circular structure and an external pipeline to implement the SM4 encryption core, the consumption of logic resources required for the implementation of encryption operations is greatly reduced, and it has a higher maximum operating frequency and throughput; the S box is implemented by using RAM resources, and compared with the S box implemented by using a lookup table, the consumption of logic resources required for the implementation of nonlinear transformation is avoided. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the embodiments of the utility model or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the utility model. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0018] Figure 1 A schematic diagram of the structure of the SM4_CCM encryption device provided by an embodiment of the utility model;

[0019] Figure 2 It is a schematic diagram of the hardware encryption module structure;

[0020] Figure 3 This is a schematic diagram of the SM4 encryption core structure. DETAILED DESCRIPTION

[0021] The following will be combined with the drawings in the embodiments of the utility model to clearly and completely describe the technical solutions in the embodiments of the utility model. Obviously, the described embodiments are only part of the embodiments of the utility model, not all of the embodiments. Based on the embodiments in the utility model, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the utility model.

[0022] The utility model aims to provide an SM4_CCM encryption device, aiming to improve encryption performance and reduce the consumption of logic resources required to implement the SM4_CCM algorithm.

[0023] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0024] Figure 1 A schematic diagram of the structure of the SM4_CCM encryption device provided in an embodiment of the utility model. Figure 2 Figure 1 is a schematic diagram of the hardware encryption module structure. Figure 1 and Figure 2 As shown, the SM4_CCM encryption device in this embodiment includes: a ZYNQ chip; the ZYNQ chip includes an ARM processor, a DDR3 memory and a hardware encryption module connected in sequence.

[0025] Specifically, the ARM processor may be any existing ARM processor (such as ARM Cortex-A9 and ARM Cortex-A53) that can implement the following five functions.

[0026] (1) The control interface module receives the data to be encrypted and sends the encrypted data.

[0027] (2) The length of the data to be encrypted is checked, and then the initial vector IV, additional data and plaintext data are generated after padding and grouping, and then written into the DDR3 memory.

[0028] (3) Before encryption or when the ARM processor is idle, the ARM processor can prepare the round key required for the next encryption in advance and write it to the DDR3 memory, which does not affect the work of the hardware encryption module and is conducive to improving encryption efficiency.

[0029] (4) The ARM processor generates control information before encryption and writes it to the DDR3 memory.

[0030] (5) The ARM processor detects the status information of the hardware encryption module through the data bus.

[0031] The DDR3 memory is used to store the data to be encrypted, the encrypted data, and the control information generated by the ARM processor.

[0032] The hardware encryption module is implemented by using a Field-Programmable Gate Array (FPGA); the hardware encryption module includes: an SM4 encryption core structure.

[0033] Specifically, FPGA includes but is not limited to ZYNQ's FPGA.

[0034] like Figure 3 As shown, the SM4 encryption core structure is a 6-stage pipeline structure within a round. The SM4 encryption core structure includes: 2 XOR modules, 1 nonlinear transformation module, 1 circular shift module and 5 registers; the nonlinear transformation module includes: 4 S boxes.

[0035] Specifically, the working process of the SM4 encryption core structure is as follows:

[0036] 1) Cycle 1: Data packet 1 is written to register 1.

[0037] 2) Cycle 2: Data packet 1 completes XOR operation, and the result is written into register 2. Data packet 2 is written into register 1.

[0038] 3) Cycle 3: Data group 1 completes nonlinear transformation and the result is written into the RAM output register. Data group 2 completes XOR operation and the result is written into register 2. Data group 3 is written into register 1.

[0039] 4) Cycle 4: Data packet 1 is written from the RAM output register to register 3, and subsequent data packets are calculated and written to the next register in sequence. Data packet 4 is written to register 1.

[0040] 5) Cycle 5: Data packet 1 completes the cyclic shift and the result is written into register 4. Subsequent data packets complete the operation in sequence and are written into the next register. Data packet 5 is written into register 1.

[0041] 6) Cycle 6: Data packet 1 completes the XOR operation, and the result is written into register 5. Subsequent data packets complete the operation in sequence and are written into the next register. Data packet 6 is written into register 1.

[0042] At this point, data group 1 completes the first round of the process. SM4 encryption requires 32 rounds of iterative operations. After the 7th cycle, register 1 writes the round output of data group 1. After 192 cycles, data group 1 completes 32 rounds of iterative operations, and the SM4 encryption core outputs the encryption result. Registers 1-5 and the RAM output register implement a 6-stage pipeline. The SM4 encryption core can process up to 6 groups of data in parallel.

[0043] As an optional implementation, the S-box is implemented using RAM, and the RAM output register is enabled.

[0044] As an optional implementation, the SM4 encryption core structure also includes: a control state machine, a register, a multiplexer and a counter.

[0045] Specifically, the control state machine is implemented using a Mealy-type state machine. After receiving the control information, the overall process of SM4_CCM is started; the register is used to store the data required for encryption, the intermediate data generated during the encryption process, and the working status information of the hardware encryption module; the counter is used to generate the count value required for the CCM mode operation; the SM4 encryption core is called by the control state machine to perform the actual operation process of SM4 encryption. After the encryption is completed, the hardware encryption module writes the encrypted data to the DDR3 memory through the data bus.

[0046] As an optional implementation, the device also includes: an interface module; the interface module is connected to the ZYNQ chip.

[0047] As an optional implementation, the interface module includes an onboard wired Ethernet interface.

[0048] Specifically, the onboard wired Ethernet interface supports TCP / IP communication protocol, is connected to a terminal that requires data encryption, and is used to receive data to be encrypted and send encrypted data.

[0049] As an optional implementation, the ZYNQ chip also includes: a data bus; the DDR3 memory is connected to the hardware encryption module via the data bus.

[0050] Specifically, the data bus is an AXI-Lite bus, which implements data interaction between the DDR3 memory and the hardware encryption module.

[0051] The working process of the SM4_CCM encryption device in the utility model is as follows:

[0052] 1) The ARM processor controls the interface module to receive the data and key to be encrypted from the terminal and write them into the DDR3 memory.

[0053] 2) The ARM processor generates control information for controlling the hardware encryption module and writes it into the DDR3 memory. The control information is an enable signal for the hardware encryption module.

[0054] 3) The ARM processor performs length detection on the data to be encrypted, and then performs padding and grouping to generate the initial vector IV, additional data and plaintext data grouping, and writes them into the DDR3 memory.

[0055] 4) The ARM processor generates a round key based on the key and writes it into the DDR3 memory.

[0056] 5) The hardware encryption module reads the control information, round keys and data packets in the DDR3 memory through the data bus.

[0057] 6) The hardware encryption module performs the actual operation process of SM4_CCM on the data group and writes the operation result to the DDR3 memory through the data bus, and generates the status information of the hardware encryption module after the encryption is completed.

[0058] 7) The ARM processor controls the communication module to read the ciphertext packets in the DDR3 memory and sends the ciphertext packets to the terminal through the interface module using the TCP / IP protocol.

[0059] Beneficial effects of the utility model:

[0060] 1. The SM4 encryption core inside the hardware encryption module of the utility model is implemented by using a 6-stage pipeline structure within the wheel. Compared with the prior art that uses a loop structure and an external pipeline to implement the SM4 encryption core, it greatly reduces the consumption of logical resources required for encryption operations and has a higher maximum operating frequency and throughput; it uses RAM resources to implement the S-box, which avoids the consumption of logical resources required to implement nonlinear transformations compared to the use of a lookup table to implement the S-box; it uses a 6-stage pipeline encryption module, which can encrypt 6 groups of data at a time, greatly improving encryption performance compared to the traditional loop structure. Encryption using the utility model's SM4_CCM encryption device has higher encryption performance than the SM4_CCM software implementation in the prior art, and reduces the consumption of logical resources required for hardware implementation of the SM4_CCM algorithm.

[0061] 2. The interface module of the utility model includes a limited Ethernet interface and supports the TCP / IP communication protocol, ensuring the stable and reliable transmission of ciphertext data and message verification code data after encryption. It is widely applicable to terminals that support the TCP / IP communication protocol. The utility model can be widely used in fields that require secure data transmission, such as network communications and the Internet of Things.

[0062] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0063] This article uses specific examples to illustrate the principle and implementation of the utility model. The above examples are only used to help understand the device and its core idea of ​​the utility model. At the same time, for those skilled in the art, according to the idea of ​​the utility model, there will be changes in the specific implementation and application scope. In summary, the content of this specification should not be understood as limiting the utility model.

Claims

1. An SM4_CCM encryption device, characterized in that: The device comprises: a ZYNQ chip; the ZYNQ chip comprises an ARM processor, a DDR3 memory and a hardware encryption module connected in sequence; The hardware encryption module is implemented by FPGA; the hardware encryption module includes: an SM4 encryption core structure; the SM4 encryption core structure is an intra-wheel 6-stage pipeline structure.

2. The SM4_CCM encryption device according to claim 1, characterized in that: The device also includes: an interface module; the interface module is connected to the ZYNQ chip.

3. The SM4_CCM encryption device according to claim 1, characterized in that: The ZYNQ chip also includes: a data bus; the DDR3 memory is connected to the hardware encryption module via the data bus.

4. The SM4_CCM encryption device according to claim 1, characterized in that: The SM4 encryption core structure includes: 2 XOR modules, 1 nonlinear transformation module, 1 cyclic shift module and 5 registers; the nonlinear transformation module includes: 4 S boxes.

5. The SM4_CCM encryption device according to claim 4, characterized in that: The S box is implemented using RAM.

6. The SM4_CCM encryption device according to claim 4, characterized in that: The SM4 encryption core structure also includes: a control state machine, a register, a multiplexer and a counter.

7. The SM4_CCM encryption device according to claim 2, characterized in that: The interface module includes an onboard wired Ethernet interface.