Logic gate-based data processing method and apparatus

By using a three-input logic gate in the symmetric encryption algorithm and optimizing the encoding method, the problem of low computational efficiency in the existing technology is solved, and the number of logic gates is reduced while the computational efficiency is improved.

WO2026066944A1PCT designated stage Publication Date: 2026-04-02HUAWEI TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-02
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing symmetric encryption algorithms based on logic gates are computationally inefficient and highly complex.

Method used

Three-input logic gates are used to replace the traditional two-input logic gates. The S-box structure is optimized through a specific encoding method to reduce the number of logic gates and improve computational efficiency.

Benefits of technology

While ensuring functionality, the number of logic gates in the S-box was reduced, thus improving the computational efficiency of the symmetric encryption algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025118559_02042026_PF_FP_ABST
    Figure CN2025118559_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and provides a logic gate-based data processing method and apparatus. The method comprises: acquiring input data, the input data belonging to a finite field; and processing the input data by means of an S-box, wherein the S-box is used for a symmetric encryption algorithm, the S-box comprises multiple logic gates, and the multiple logic gates include three input logic gates. The method in the embodiments of the present application can improve the computation efficiency of symmetric encryption algorithms.
Need to check novelty before this filing date? Find Prior Art

Description

Data processing method and device based on logic gate

[0001] The present application claims priority to the Chinese patent application No. 202411338641.8, filed on September 24, 2024, and entitled "Data processing method and device based on logic gate", the whole content of which is incorporated herein by reference. TECHNICAL FIELD

[0002] The present application relates to the field of communication technology, in particular to a data processing method and device based on logic gate. BACKGROUND

[0003] Symmetric encryption algorithm has the advantages of high strength, high speed and easy implementation. With the development of communication technology, the data in the network shows a trend of mass, and the security in the process of data transmission and communication can be improved by using symmetric encryption algorithm.

[0004] Symmetric encryption algorithm can be implemented by logic circuit (or Boolean circuit), for example, logic gate can be used to construct symmetric encryption algorithm. However, the existing symmetric encryption algorithm based on logic gate is relatively complex and has low calculation efficiency. SUMMARY

[0005] The present application provides a data processing method and device based on logic gate, which can improve the calculation efficiency of symmetric encryption algorithm.

[0006] In a first aspect, a data processing method based on logic gate is provided, the method comprising:

[0007] obtaining input data, the input data belonging to a finite field; processing the input data by an S-box, wherein the S-box is used for symmetric encryption algorithm, the S-box comprises a plurality of logic gates, and the plurality of logic gates comprises a three-input logic gate.

[0008] In the embodiments of the present application, the S-box comprises a three-input logic gate, the three-input logic gate can process three input data, and can realize the function or effect of more than one two-input logic gate. The operation time of each logic gate is relatively fixed, so the number of logic gates in the S-box can be reduced under the premise of ensuring the overall function or effect of the S-box, thereby improving the calculation efficiency of the symmetric encryption algorithm.

[0009] In some possible implementation manners, the operation corresponding to the three-input logic gate comprises encoding three input data of the three-input logic gate according to a first type of encoding manner, and the first type of encoding manner is used to enable the three-input logic gate to process the three input data.

[0010] In the embodiment of the present application, the first type of encoding mode is used to enable the three-input logic gate to process the three input data, and according to the first type of encoding mode and the three input data of the three-input logic gate, the S-box can support the three-input logic gate, the number of logic gates in the S-box can be reduced, and thus the calculation efficiency of the symmetric encryption algorithm can be improved.

[0011] In some possible implementation ways, the three-input logic gate comprises a first logic gate, the first logic gate is configured to perform an exclusive OR operation on three input data of the first logic gate, and the first type of encoding mode comprises a first encoding mode corresponding to the first logic gate.

[0012] In the embodiment of the present application, the first type of encoding mode comprises the first encoding mode corresponding to the first logic gate, the S-box can support the exclusive OR operation on the three input data by one logic gate, the diversity of the types of logic gates in the S-box can be improved, and thus the implementation (or construction) of the S-box can be facilitated.

[0013] In some possible implementation ways, the first encoding mode satisfies the following formula:

[0014] wherein t represents a modulus of a finite field to which the first data belongs, the first data is determined according to the three input data of the first logic gate, x is a positive integer, and the value range of x is 0 to t-1, is a bottom symbol.

[0015] In the embodiment of the present application, by using the first encoding mode, the exclusive OR operation on the three input data by the first logic gate is facilitated, the number of logic gates in the S-box can be reduced, and thus the calculation efficiency of the symmetric encryption algorithm can be improved.

[0016] In some possible implementation ways, the three-input logic gate comprises a second logic gate, the second logic gate is configured to perform an AND operation on three input data of the second logic gate, and the first type of encoding mode comprises a second encoding mode corresponding to the second logic gate.

[0017] In the embodiment of the present application, the first type of encoding mode comprises the second encoding mode corresponding to the second logic gate, the S-box can support the AND operation on the three input data by one logic gate, the diversity of the types of logic gates in the S-box can be improved, and thus the implementation (or construction) of the S-box can be facilitated.

[0018] In some possible implementation ways, the second encoding mode satisfies the following formula:

[0019] wherein t represents a modulus of a finite field to which the second data belongs, the second data is determined according to three input data of the second logic gate, x is a positive integer, and a value range of x is 0 to t-1, is a bottom symbol.

[0020] In the embodiment of the present application, the second encoding manner is used to facilitate the second logic gate to perform XOR operation on the three input data, which helps to reduce the number of logic gates in the S-box, thereby helping to improve the calculation efficiency of the symmetric encryption algorithm.

[0021] In some possible implementation manners, the three-input logic gate includes a third logic gate, the third logic gate is used to output 1 when the number of 1s in input data of the third logic gate exceeds half, and output 0 when the number of 1s in the input data of the third logic gate does not exceed half, and the first type of encoding manner includes a third encoding manner corresponding to the third logic gate.

[0022] In the embodiment of the present application, the first type of encoding manner includes the third encoding manner corresponding to the third logic gate, which can enable the S-box to support implementation of outputting 1 when the number of 1s in input data of a logic gate exceeds half and outputting 0 when the number of 1s in the input data of the logic gate does not exceed half through one logic gate, and can improve the diversity of logic gate types in the S-box, thereby helping to implement (or construct) the S-box.

[0023] In some possible implementation manners, the third encoding manner satisfies the following formula:

[0024] wherein t represents a modulus of a finite field to which the third data belongs, the third data is determined according to three input data of the third logic gate, x is a positive integer, and a value range of x is 0 to t-1, is a bottom symbol.

[0025] In the embodiment of the present application, the first encoding manner is used to facilitate the third logic gate to output 1 when the number of 1s in input data of the third logic gate exceeds half and output 0 when the number of 1s in the input data of the third logic gate does not exceed half, which helps to reduce the number of logic gates in the S-box, thereby helping to improve the calculation efficiency of the symmetric encryption algorithm.

[0026] In some possible implementation manners, the plurality of logic gates includes a two-input logic gate, and an operation corresponding to the two-input logic gate includes encoding two input data of the two-input logic gate according to a fourth encoding manner.

[0027] In some possible implementation manners, the fourth encoding manner satisfies the following formula:

[0028] wherein t represents a modulus of a finite field to which the fourth data belongs, the fourth data is determined according to two input data of the two-input logic gate, x is a positive integer, and a value range of x is 0 to t-1, is a bottom symbol.

[0029] In the embodiments of the present application, the fourth encoding manner facilitates the two-input logic gate to process the two input data, helps to reduce the number of logic gates in the S-box, and thus helps to improve the calculation efficiency of the symmetric encryption algorithm.

[0030] In some possible implementation manners, the two-input logic gate includes a fourth logic gate and / or a fifth logic gate, the fourth logic gate is configured to perform an exclusive OR operation on two input data of the fourth logic gate, and the fifth logic gate is configured to perform an AND operation on two input data of the fifth logic gate.

[0031] In some possible implementation manners, the input data is ciphertext data obtained after homomorphic encryption.

[0032] In a second aspect, a data processing apparatus is provided, which can be used in a communication apparatus, can be the communication apparatus, can be a device (for example, a chip, or a chip system, or a circuit, or a processor) in the communication apparatus, or can be a device capable of being used in combination with the communication apparatus, and can also be a logic module or software capable of implementing all or part of the communication apparatus.

[0033] The data processing apparatus includes a module corresponding to each of the methods / operations / steps / actions described in the first aspect or any possible implementation manner of the first aspect, which can be a hardware circuit, can be software, or can be a combination of hardware circuit and software.

[0034] In a third aspect, a data processing apparatus is provided, which includes a processor and a memory, the processor is coupled to the memory, and the memory is used to store a computer program (which can also be referred to as code or instruction), the computer program is executed by the processor, so that the apparatus executes the method in the first aspect or any possible implementation manner of the first aspect.

[0035] In some possible implementation manners, the apparatus further includes a memory coupled to the processor.

[0036] In some possible implementation manners, the processor is one or more, and / or the memory is one or more.

[0037] In some possible implementation manners, the memory can be integrated with the processor, or the memory is arranged separately from the processor.

[0038] In a fourth aspect, a computer readable storage medium is provided, and the computer readable storage medium has stored thereon a computer program (which can also be referred to as code or instructions) that, when run on a computer, causes the computer to perform the method according to any one of the aspects or any possible implementation thereof.

[0039] In a fifth aspect, a computer program product is provided, and the computer program product includes a computer program (which can also be referred to as code or instructions) that, when run on a computer, causes the computer to perform the method according to any one of the aspects or any possible implementation thereof.

[0040] In a sixth aspect, a chip is provided, and the chip includes a processor and a memory, and the memory is configured to store a computer program (which can also be referred to as code or instructions), and the processor is configured to invoke and run the computer program stored in the memory, so that a device or equipment installed with the chip performs the method according to any one of the aspects or any possible implementation thereof. BRIEF DESCRIPTION OF DRAWINGS

[0041] FIG. 1 is a schematic block diagram of a wireless communication system suitable for use in the present application.

[0042] FIG. 2 is a schematic diagram of a homomorphic encryption process in an embodiment of the present application.

[0043] FIG. 3 is a schematic diagram of homomorphic key generation in an embodiment of the present application.

[0044] FIG. 4 is a schematic diagram of homomorphic encryption in an embodiment of the present application.

[0045] FIG. 5 is a schematic diagram of homomorphic decryption in an embodiment of the present application.

[0046] FIG. 6 is a schematic diagram of homomorphic computation in an embodiment of the present application.

[0047] FIG. 7 is a schematic diagram of a homomorphic key scheme in an embodiment of the present application.

[0048] FIG. 8 is a schematic diagram of a noise principle in homomorphic encryption in an embodiment of the present application.

[0049] FIG. 9 is a schematic diagram of a bootstrap process in an embodiment of the present application.

[0050] FIG. 10 is a schematic flowchart of rekeying through an AES algorithm in an embodiment of the present application.

[0051] FIG. 11 is a schematic flowchart of a logic gate-based data processing method provided in an embodiment of the present application.

[0052] FIG. 12 is a schematic structural diagram of a data processing apparatus according to another embodiment of the present application.

[0053] FIG. 13 is a schematic structural diagram of an apparatus according to an embodiment of the present application. DETAILED DESCRIPTION

[0054] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.

[0055] In the description of the present application, unless otherwise specified, " / " represents that the objects before and after the " / " are in an "or" relationship, for example, A / B can represent A or B; "and / or" in the present application is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. In addition, in the description of the present application, unless otherwise specified, "multiple" means two or more than two. "At least one of the following" or the like means any combination of the items, including any combination of single item or multiple items. For example, at least one of a, b, or c can represent: a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, and c can be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, "first", "second", and the like are used to distinguish the same items or similar items with basically the same function and effect. Those skilled in the art can understand that "first", "second", and the like do not limit the quantity and execution order, and "first", "second", and the like do not necessarily mean different. It should be understood that "in the case of", "if", "when", "if", and the like in the present application can be replaced.

[0056] The technical solutions of the embodiments of the present application can be applied to various scenarios using the advanced encryption standard (AES) algorithm for encryption, for example, can be applied to a wireless communication system, and can also be applied to any other scenario or system that needs to use the AES algorithm.

[0057] The wireless communication system of the embodiments of the present application can be various wireless communication systems, for example, a 5th generation (5G) system or new radio (NR), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), a satellite, and the like, a non-terrestrial communication system, a communication system integrating terrestrial and non-terrestrial communications, and the like. The technical solutions provided in the present application can also be applied to future communication systems.

[0058] The technical solutions of the embodiments of the present application are described in detail below with the wireless communication system as an example. The wireless communication system applicable to the embodiments of the present application is introduced below in conjunction with FIG. 1.

[0059] FIG. 1 is a schematic architecture diagram of a wireless communication system applicable to the embodiments of the present application. The wireless communication system 100 can include a terminal device, a data network (DN), and an operator part.

[0060] The terminal device can refer to a user equipment (UE), a station, an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, a remote terminal, a mobile terminal (MT), a user terminal, a terminal (or terminal device), a wireless communication device, a user agent, or a user device, etc., or a device used to provide voice or data connectivity to a user, and can also be an Internet of Things device, for example, the terminal device includes a handheld device with wireless connection function, a vehicle-mounted device, etc., which is not limited in the embodiments of the present application. The terminal device in the embodiments of the present application can be a mobile phone, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a large screen, a vehicle-mounted device (for example, a car, a bicycle, an electric vehicle, an airplane, a ship, a train, a high-speed rail, etc.), a wearable device (for example, a smart watch, a smart bracelet, a pedometer, smart glasses, etc.), a machine type communication (MTC) terminal device, a terminal device in a 5G network, or a terminal device in a future evolved public land mobile network (PLMN), etc., which is not limited in the embodiments of the present application.The terminal device in the embodiments of the present application can also be a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a virtual reality (VR) device, an augmented reality (AR) device, a smart point of sale (POS) machine, a customer-premises equipment (CPE), a light UE, a reduced capability UE (RedCap UE), a wireless terminal in industrial control, a smart home device (for example, a refrigerator, a television, an air conditioner, an electricity meter, etc.), a smart robot, a mechanical arm, a plant device, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a flight device (for example, a smart robot, a hot air balloon, a drone, an airplane), etc. The terminal device can also be a vehicle device, for example, a whole vehicle device, a vehicle-mounted module, a vehicle-mounted chip, an on board unit (OBU) or a telematics box (T-BOX), etc. The terminal device can also be other devices with terminal functions, for example, the terminal device can also be a device in device to device (D2D) communication.

[0061] In some embodiments, the terminal device can be used to act as a base station. Optionally, the terminal device can act as a scheduling entity to provide a sidelink signal between terminal devices in vehicle to everything (V2X) or device to device (D2D) communication, etc. For example, a cellular phone and a car can communicate using the sidelink signal, or a cellular phone and a smart home device can also communicate using the sidelink signal without relaying the communication signal through the base station.

[0062] The operator part can include one or more of the following network elements:

[0063] Network Slice Selection Function (NSSF), Authentication Server Function (AUSF) network element, Network Exposure Function (NEF) network element, Policy Control Function (PCF) network element, Unified Data Management (UDM) network element, Unified Data Repository (UDR), Network Repository Function (NRF) network element, Application Function (AF) network element, Access and Mobility Management Function (AMF) network element, Session Management Function (SMF) network element, Network Data Analytics Function (NWDAF) network element, Service Communication Proxy (SCP) network element, Network Slice Admission Control Function (NSACF) network element, Radio Access Network (RAN) (may be RAN or AN, denoted as (R)AN in FIG. 1), and User Plane Function (UPF) network element, etc.

[0064] The radio access network can also be referred to as a network device, a base station (BS), and the like, and is used to access the terminal device to the wireless network. For example, the radio access network can be a NodeB (NodeB), an evolved NodeB (eNodeB), a next generation NodeB (gNB) in a 5G mobile communication system, a transmission reception point (TRP), an access point (AP), a radio access network in a non-terrestrial network (NTN) system (such as a satellite), a base station in a future mobile communication system, or an access node (AP) in a WiFi system, a wireless controller in a cloud radio access network (CRAN) scenario, a relay station, an access point, a vehicle-mounted device, a wearable device, a radio access network in other future evolved communication systems, and the like.

[0065] In some embodiments, a terminal device can be assisted by multiple RAN nodes to implement wireless access, and different RAN nodes can respectively implement part of the functions of a base station. For example, a RAN node can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can also be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna processing unit (AAU), or a remote radio head (RRH). In different systems, the CU (or CU-CP and CU-UP), DU or RU can also have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (ORAN) system, the CU can also be referred to as an open CU (O-CU), the DU can also be referred to as an open DU (O-DU), the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. Any one of the CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module. It should be understood that the specific technology and specific equipment form of the wireless access network are not limited in this application.

[0066] In some embodiments, the wireless access network can be fixed or mobile, and the embodiments of this application do not limit this. For example, a helicopter or a drone can be configured as a mobile wireless access network, and one or more cells can move according to the position of the mobile wireless access network. In other examples, a helicopter or a drone can be configured to serve as a device that communicates with another wireless access network.

[0067] In some embodiments, the wireless access network can be deployed on land or in the air, and the embodiments of this application do not limit this. For example, the wireless access network can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on the water surface; and can also be deployed on aircraft, balloons and satellites in the air.

[0068] In the embodiments of the present application, the terminal device or the radio access network can include a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and a memory (also known as main memory). The operating system can be any one or more computer operating systems that implement business processing through processes. The application layer includes applications such as browsers, address books, word processing software, instant messaging software, etc. Moreover, the embodiments of the present application do not particularly limit the specific structure of the execution subject of the method provided by the embodiments of the present application, as long as the execution subject can communicate according to the method provided by the embodiments of the present application by running a program in which the code of the method provided by the embodiments of the present application is recorded.

[0069] In the above operator network, the part other than the radio access network can be referred to as a core network part. The core network part can include a control plane (CP) network element and a user plane (UP) network element. Among them, the user plane network element can include a UPF, and the control plane network element can include an AMF, an SMF, a PCF, an AF, and a NEF.

[0070] The following describes each network element of the core network part.

[0071] The AF network element is similar to an application server, which interacts with other core network control plane network elements and provides service services. The AF network element can exist for different application services and can be owned by an operator or a trusted third party.

[0072] The PCF network element supports a unified policy framework to manage network behavior and provides policy rules to network entities for implementation and execution.

[0073] The UDM network element is responsible for the management of user identification, subscription data, authentication data, and the registration management of service network elements of users.

[0074] The UPF network element is a module for processing data in the core network, and the main functions are: routing and forwarding of data from the base station to the network, quality of service (QoS) control, charging information statistics, etc.

[0075] The AMF network element is responsible for UE identity authentication, authentication, registration, mobility management, and connection management functions, for example, the AMF can interact with the RAN and the UE through the N2 and N1 interfaces to complete registration, session establishment, mobility management, and other functions.

[0076] The SMF network element is mainly responsible for session management, management of user (protocol data unit, PDU) session creation, deletion, maintenance of PDU session context and user plane forwarding pipe information, allocation of addresses for terminals, management of various channels between terminals and the core network, for example, the SMF can control the UPF through the N4 interface.

[0077] The user plane function (UPF) entity is mainly responsible for data packet routing and forwarding, serving as a session anchor, serving as an uplink classifier to support routing traffic flows to a local data network, serving as a branching point to support multi-homed PDU sessions, and the like.

[0078] The NWDAF network element can be responsible for security-related analysis. It should be noted that the security analysis function here can also be performed by other network elements, and the embodiments of the present application do not limit this.

[0079] The data network (DN) is, for example, an operator service, Internet access, or a third-party service.

[0080] The devices, network elements or entities in the present application can be replaced with each other in some scenarios.

[0081] In the architecture shown in FIG. 1, the communication interfaces between some network elements are indicated, as follows:

[0082] The N1 interface is the interface between the terminal device and the core network control plane, used to transmit non-access stratum (NAS) signaling.

[0083] The N2 interface is the communication interface between the radio access network and the core network control plane.

[0084] The N3 interface is the communication interface between the radio access network and the core network user plane network element UPF, used to transmit user data.

[0085] The N4 interface is the communication interface between the control plane session management network element SMF and the user plane network element UPF, used for policy configuration of the UPF and the like.

[0086] The N6 interface is the communication interface between the core network user plane network element UPF and the DN.

[0087] It can be understood that FIG. 1 exemplarily shows an architecture diagram of a communication system to which the method provided in the embodiments of the present application is applicable. The communication system to which the method provided in the embodiments of the present application is applicable can include other network elements or network entities, which are not limited in the embodiments of the present application.

[0088] With the development of communication technology, the data in the communication system shows a trend of mass, and the security of the data has been paid more and more attention. The symmetric encryption algorithm has the advantages of high strength, high speed and easy implementation, and the security in the process of data transmission and communication can be effectively improved through the symmetric encryption algorithm. For example, the advanced encryption standard (AES) is a kind of symmetric encryption algorithm with high security, and the technical solutions in the embodiments of the present application are introduced by taking the AES algorithm as an example in the subsequent embodiments.

[0089] For example, the data transmission between communication devices needs to use the transport layer security (TLS) and the internet protocol security (IPSEC), and the AES algorithm can be used in the TLS and the IPSEC; the wireless air interface in the wireless communication system also uses the AES algorithm for encryption; the security and privacy of the homomorphic encryption (HE) data can be used in the wireless communication system, and the AES algorithm can also be used for ciphertext conversion (which can also be referred to as conversion, such as AES encryption of the homomorphic ciphertext) in the homomorphic ciphertext calculation.

[0090] The application of the AES algorithm in the communication system is introduced below by taking the homomorphic ciphertext calculation using the AES algorithm as an example.

[0091] The homomorphic encryption (HE) is a kind of privacy compute algorithm, which can realize data processing under the premise of protecting the security and privacy of the data, therefore, the homomorphic encryption can be used in the communication system to improve the security and privacy of the data.

[0092] For example, as shown in FIG. 2, the plaintext data can be homomorphic encrypted to obtain the ciphertext data, and the ciphertext data (which can be referred to as ciphertext) can be homomorphic calculated to obtain the ciphertext result, at this time, the result obtained by homomorphic decryption of the ciphertext calculation result is consistent with the plaintext calculation result obtained by directly calculating the plaintext data (which can be referred to as plaintext), so that the processing of the plaintext data can be realized under the premise of protecting the security and privacy of the data.

[0093] The homomorphic encryption algorithm HE=(HE.Keygen, HE.Enc, HE.Dec, HE.Eval) can include key generation, homomorphic encryption, homomorphic decryption, and homomorphic evaluation. The four algorithms are described in detail below (n in the following formula is a security parameter).

[0094] (1) Key generation: (pk, evk, sk) <- HE.Keygen(1 n )

[0095] wherein pk is an output public key (public key, pk) and can be used as a homomorphic encryption key (encryption key) K enc , i.e., K enc =pk; evk can be used as a homomorphic evaluation key (evaluation key) K eval , i.e., K eval =evk, and the homomorphic evaluation key can also be referred to as a homomorphic computation key; and sk is a secret key (Secret Key, sk) and can be used as a homomorphic decryption key (decryption key) K dec , i.e., K dec =sk.

[0096] As shown in FIG. 3, the homomorphic key generator can input or generate key material and generate an encryption key, a decryption key, and a computation key through a key generator.

[0097] (2) Homomorphic encryption: c <- HE.Enc pk (m)

[0098] wherein m is plaintext data, m∈{0,1}, and c is ciphertext data.

[0099] As shown in FIG. 4, the homomorphic encryption party can use the homomorphic encryption key K enc =pk to encrypt plaintext data m∈{0,1} of a single bit into ciphertext data c.

[0100] (3) Homomorphic decryption: m <- HE.Dec sk (c)

[0101] As shown in FIG. 5, the homomorphic decryption party can use the homomorphic decryption key K dec =sk to decrypt the ciphertext data c to recover the plaintext data m∈{0,1}.

[0102] (4) Homomorphic evaluation (also referred to as homomorphic computation): cf ←HE.Eval evk (f,c1,…,c l )

[0103] where c1,…,c l are ciphertext data, f is a homomorphic computation function, f:{0,1} l →{0,1}, c f is a ciphertext computation result, and l is a positive integer.

[0104] As shown in FIG. 6, a homomorphic computation party (which can be referred to as HEcalc or HEeval) can perform homomorphic computation on input ciphertext data c1,…,c l , homomorphic computation key K eval =evk, and homomorphic computation function f:{0,1} l →{0,1} to obtain ciphertext result c f .

[0105] where the homomorphic computation function can be implemented by an arithmetic circuit with an addition gate and a multiplication gate on a finite field (GF can represent a finite field, and GF is the abbreviation of Galois Field, the inventor Evariste Galois). For example, homomorphic computation HE.Eval can be decomposed into multiple basic operators, such as homomorphic addition c add ←HE.Add evk (c1,c2) and homomorphic multiplication c mult ←HE.Mult evk (c1,c2).

[0106] A complete homomorphic encryption scheme HE=(HE.Keygen,HE.Enc,HE.Dec,HE.Eval) can be as shown in FIG. 7. Where the ciphertext computation result is equivalent to the plaintext computation result after decryption, that is, Dec Kdec (f(Enc Kenc (m1),Enc Kenc (m2),…,Enc Kenc (m l )))=f(m1,…,m l ). The homomorphic encryption key K enc , the homomorphic computation key K eval , and the homomorphic decryption key K dec generated by the homomorphic key generation party A can be respectively distributed to the homomorphic encryption party B, the homomorphic computation party C, and the homomorphic decryption party D.

[0107] In a homomorphic encryption task, multiple homomorphic encryptors can encrypt data from different sources, multiple homomorphic computing parties can perform homomorphic computing circuits, and single-hop or multi-hop homomorphic computing parties can be included. There can also be multiple homomorphic decryptors in a homomorphic encryption task, and the decryption results can be provided to multiple data users. Depending on the key deployment, the homomorphic decryptor and the data user can be the same or different entities. Full homomorphic encryption can be asymmetric public key encryption or symmetric encryption, as long as the ciphertext has certain algebraic structure. The keys of multiple homomorphic encryptors in a homomorphic encryption task can be the same or different.

[0108] Full homomorphic encryption (FHE) is a commonly used homomorphic encryption algorithm. Full homomorphic encryption is usually based on lattice construction, and its security is basically the fault-tolerant learning problem (LWE) or the ring error learning (R-LWE) problem in lattice cryptography. In 2005, Regev first proposed the LWE fault-tolerant learning problem, which has become a widely used cryptographic basis in lattice cryptography. The random vector The positive integer n is the vector dimension, q is the ciphertext modulus, and the set Z q represents a finite field, and the set is a uniformly distributed random matrix, and N>n. The noise e∈χ N The noise distribution χ=χ(n) is a set of distributions on Z, and the noise χ=χ(n) can satisfy a discrete Gaussian distribution, and the upper limit of the noise can be set to satisfy |χ|≤B. Then the homomorphic encrypted ciphertext can be c=(a,b), where, as shown in FIG. 8, b=[A·s+m+e] q , m is the plaintext data to be encrypted.

[0109] As can be seen from FIG. 8, a small random “noise” component e is added in the full homomorphic encryption process. Homomorphic computing on ciphertext data will cause the noise to grow, and when multiple ciphertext data are superimposed and homomorphic computing is performed, the noise included in each ciphertext will be superimposed and expanded. In particular, the noise growth caused by homomorphic multiplication can reach an exponential level, and cross terms of noise multiplied by ciphertext data can occur. When the noise is within a controllable range, the decryption algorithm can easily restore the plaintext data from the ciphertext data. If only simple calculations are performed on the ciphertext, the superimposed noise is still within an acceptable range. As shown in FIG. 9, if the ciphertext calculation is too complex, the noise range will exceed the critical value, and once the noise range exceeds the critical value, the original plaintext data will be completely covered, resulting in a failed homomorphic decryption.

[0110] In Gentry's paper in 2009, a very important concept called bootstrapping is mentioned. Bootstrapping is a special processing technique for ciphertext, as shown in FIG. 9, through which a ciphertext data with noise close to the critical value can be "refreshed" into a new ciphertext data with very low noise. The main method of bootstrapping is to encrypt a high-noise ciphertext data into another homomorphic ciphertext data using a new key k2 At the same time, the old key k1 can also be encrypted into ciphertext using the new key k2 that is, the bootstrapping key (BSK); then the homomorphic computing party computes the corresponding homomorphic decryption circuit through homomorphic computation decrypt the ciphertext in the inner layer to plaintext, and obtain a new low-noise FHE ciphertext under a new key It can be seen that the bootstrapping process is encryption and decryption based on ciphertext data, and therefore can also be called conversion ciphertext or conversion (i.e., processing of ciphertext).

[0111] The above new key k2 can also be called a bootstrapping key. As a kind of homomorphic computing key, the bootstrapping key needs to be generated by the key generation party and distributed to the homomorphic computing party. In addition to the bootstrapping key, there is another kind of homomorphic computing key, which is the key switching key (KSK). Taking the single-party key R-LWE homomorphic encryption scheme as an example, suppose the ciphertext corresponding to the key is Homomorphically compute two ciphertexts ct and ct ′ multiplication The corresponding key is After ciphertext multiplication, not only the ciphertext size is inflated, but also the key appears exponential cross terms. After each ciphertext computation, a relinearization key (i.e., a key switching key) is needed to convert the ciphertext product into a new ciphertext with the same dimension as the original ciphertext and eliminate the cross terms of the corresponding key, and then enter the next layer of circuit computation.

[0112] AES algorithm can be used for encryption and decryption operations in the state of homomorphic ciphertext (i.e., ciphertext data obtained by homomorphic encryption), that is, AES encryption and decryption operations can be superimposed in the state of homomorphic ciphertext. This process can also be understood as conversion of homomorphic ciphertext.

[0113] As shown in FIG. 10, the conversion process can include the following steps:

[0114] Step 1, upload: the user can encrypt the user data using the AES algorithm, encrypt the AES key using the FHE algorithm, and upload the FHE-encrypted AES key and the AES-encrypted ciphertext data to the cloud platform.

[0115] Step 2, FHE encryption (FHE Enc): in the FHE algorithm, input the FHE-encrypted AES key and the AES-encrypted ciphertext data, and perform FHE encryption on them, output the FHE-encrypted and AES-encrypted ciphertext data.

[0116] Step 3, AES decryption under FHE (AES dec under FHE): input the FHE-encrypted and AES-encrypted ciphertext data and the FHE-encrypted AES key, perform AES decryption calculation under the FHE state, and generate FHE ciphertext data.

[0117] Step 4, FHE calculation (FHE compute): perform FHE calculation on the FHE ciphertext data to obtain the FHE calculation result.

[0118] Step 5, return and decrypt: return the FHE calculation result to the user, and perform FHE decryption by the user.

[0119] As described above, the homomorphic ciphertext state can superimpose AES encryption and decryption operations, so the ciphertext data obtained after homomorphic encryption can be bootstrapped using the AES algorithm to avoid the range of noise in the ciphertext data exceeding the critical value.

[0120] The AES algorithm includes four operations: SubBytes, ShiftRows, MixColumns, and AddRoundKey. The AES algorithm includes the following features: 1) each step of the decryption algorithm corresponds to the inverse operation of the encryption algorithm, that is, the operations of each step of the encryption algorithm and the decryption algorithm are inverse; 2) the order of all operations of encryption and decryption is exactly opposite. These features can ensure the correctness of the AES algorithm. The key of each round in encryption and decryption is obtained by key expansion algorithm from the seed key. In the AES algorithm, 16-byte plaintext, ciphertext, and round key can be represented as a 4x4 matrix.

[0121] The main function of byte substitution is to map one byte to another using the S-box, which is fixed in AES. The S-box provides confusion for the cryptographic algorithm, and the inverse S-box is needed during decryption. The inverse S-box can be obtained by inverse transformation of the S-box. Detailed construction methods for the S-box and inverse S-box can be found in existing technologies and will not be elaborated here.

[0122] The S-box and inverse S-box are both 16x16 matrices, completing an 8-bit input to 8-bit output mapping. The high 4 bits of the input S-box are used as row indices, and the low 4 bits are used as column indices. Assuming the input byte value is a = a7a6a5a4a3a2a1a0, the output value is S[a7a6a5a4][a3a2a1a0]. The transformation of the inverse S-box is similar.

[0123] For example: byte 00000000 B The value after S-box transformation is (S[0][0]=)63 H Then, the transformed result can be passed through the inverse S-box to obtain the value before the replacement. -1 [6][3]=)00 H Where S represents the S-box transformation, S -1 This represents the inverse S-box transformation.

[0124] After byte substitution via the S-box, other steps in the AES algorithm can be executed sequentially, such as row shifting, column obfuscation, and round key addition.

[0125] Currently, the AES algorithm can be implemented using logic circuits (or Boolean circuits). For example, the AES algorithm can be constructed using logic gates (or simply gates).

[0126] For example, the logic gate form of the S-box in a feasible implementation of the AES algorithm may include the following parts:

[0127] The first part (containing 23 logic gates) is the linear part. The inputs are x0, x1, x2, x3, x4, x5, x6, x7, and the outputs are x7, y1, ..., y1. 21 x7,y1,......,y 21 As input for the next part.

[0128] The logic gates in the first part of the S-box can be represented as shown in Table 1 below:

[0129] Table 1. Logic gate forms of the first part of the S-box.

[0130] In Table 1 above, "+" represents the XOR operation.

[0131] The second part (containing 62 logic gates) is a nonlinear part, the input is x7, y1,..., y 21 , and the output is z0,..., z 17 . z0,..., z 17 is the input of the next part.

[0132] The logic gate form of the second part in the S-box can be shown in Table 2 as follows:

[0133] Table 2 Logic gate form of the second part in the S-box

[0134] In the above Table 2, "X" represents logical AND operation.

[0135] The third part (containing 30 logic gates) is a linear part, the input is z0,..., z 17 , and the output is s0, s1, s2, s3, s4, s5, s6, s7. s0, s1, s2, s3, s4, s5, s6, s7 is the output of the overall S-box.

[0136] The logic gate form of the third part in the S-box can be shown in Table 3 as follows:

[0137] Table 3 Logic gate form of the third part in the S-box

[0138] In the above Table 2, "XNOR" represents the exclusive OR operation. Among them, the exclusive OR operation can be regarded as first performing the exclusive OR operation, and then performing the NOT operation on the result of the exclusive OR operation.

[0139] The above method requires a total of 23+62+30=115 logic gates to realize the S-box part.

[0140] Similarly, there is also a method of realizing the S-box part by 113 logic gates. The input of the S-box realized by 113 logic gates is x0, x1, x2, x3, x4, x5, x6, x7, and the output is s0, s1, s2, s3, s4, s5, s6, s7, which can be shown in Table 4 as follows:

[0141] Table 4 S-box realized by 113 logic gates

[0142] As can be seen, the S-box constructed in the above embodiment contains a large number of logic gates, and the operation time of each logic gate is relatively fixed. More logic gates will affect the calculation efficiency of the symmetric encryption algorithm.

[0143] To solve one or more of the above technical problems, the present application proposes a data processing method and device based on a logic gate. It should be noted that the technical solutions in the embodiments of the present application are applicable to various symmetric encryption algorithms. The data processing method based on a logic gate in the embodiments of the present application will be described in detail below with reference to FIG. 11.

[0144] FIG. 11 is a schematic flowchart of a data processing method based on a logic gate according to an embodiment of the present application. The method 1100 shown in FIG. 11 can be applied to a communication device or a component (such as a processor, a chip, a chip system, a circuit, or a functional module) in the communication device. The communication device can be a terminal device or a network device (such as an access network device, a core network device, or another device).

[0145] The method 1100 shown in FIG. 11 can include steps S1110 and S1120, which are specifically as follows.

[0146] S1110, obtaining input data.

[0147] The input data can be ciphertext data obtained after homomorphic encryption, can be data transmitted between communication devices through TLS and IPSEC, or can be data transmitted between a terminal device and an access network device through a wireless air interface.

[0148] In some embodiments, the input data can belong to a finite field. If the data to be encrypted belongs to another data field, the data to be encrypted needs to be converted to the finite field; or if the finite field to which the data to be encrypted belongs is different from the finite field supported by the symmetric algorithm (such as the finite field to which the data input into the AES algorithm belongs), the data to be encrypted needs to be converted to the finite field supported by the symmetric algorithm. For example, the finite field to which the data to be encrypted belongs is GF(2 8), and the finite field supported by the symmetric algorithm is GF(2 4). In this case, the encrypted data needs to be converted from GF(2 8) to GF(2 4).

[0149] For example, the input data is ciphertext data obtained after homomorphic encryption. The input data can be obtained through the following homomorphic encryption formula:

[0150] where c represents the ciphertext data (i.e., the input data) obtained after homomorphic encryption, and are vectors, represents a key, represents an inner product of and , m represents plaintext data, e represents noise, n is a positive integer, n represents the dimension of the vector, Δ=q / p, q represents a ciphertext modulus, p represents a plaintext modulus, and GF(q) represents a finite field with a modulus of q.

[0151] In some embodiments, if homomorphic decryption needs to be performed on the ciphertext data obtained after the homomorphic encryption, the following formula can be used:

[0152] where Des(c, s) represents the plaintext data obtained after the homomorphic decryption, represents the nearest integer (either rounding up or rounding down) to the value, and mod represents the modulus.

[0153] For ease of description, in subsequent embodiments, the input data is taken as an example of the ciphertext data obtained after the homomorphic encryption.

[0154] S1120, processing the input data through an S-box.

[0155] The S-box can be used in a symmetric encryption algorithm. Alternatively, the symmetric encryption algorithm can be an AES algorithm, a ZUC (zuc cipher) algorithm, a snow 5G algorithm, or the like.

[0156] Alternatively, the S-box can be used to implement byte substitution in the AES algorithm. For example, processing the input data through the S-box can be understood as performing byte substitution on the input data through the S-box.

[0157] In some embodiments, the S-box can include a plurality of logic gates. The plurality of logic gates can include one or more three-input logic gates and one or more two-input logic gates. The three-input logic gate can refer to a logic gate that performs a logical operation on three input data, and the two-input logic gate can refer to a logic gate that performs a logical operation on two input data.

[0158] The S-box in the present application can include a plurality of types of three-input logic gates.

[0159] For example, the three-input logic gate in the S-box can include a first logic gate, which can be used to perform an exclusive OR operation on three input data of the first logic gate. The first logic gate can be represented by XOR3.

[0160] For another example, the three-input logic gate in the S-box can include a second logic gate, which can be used to perform an AND operation on three input data of the second logic gate. The second logic gate can be represented by AND3.

[0161] For yet another example, the three-input logic gate in the S-box can include a third logic gate, which can be used to output 1 when the number of 1s in the input data of the third logic gate exceeds half, and output 0 when the number of 1s in the input data of the third logic gate does not exceed half. The third logic gate can be represented by MAJ.

[0162] Optionally, other three-input logic gates can also be included in the S-boxes in the present application, which are not limited in the embodiments of the present application.

[0163] In the present embodiment, the three-input logic gate can be constructed by various methods.

[0164] In some embodiments, the three-input logic gate corresponding to a specific two-input logic gate in the S-box can be determined by constructing a satisfiability (SAT) solver, so that the obtained three-input logic gate can achieve the same function or effect as the specific two-input logic gate.

[0165] For example, the partial logic gates in the second part of the S-box shown in Table 2 above are as shown in Table 5 below:

[0166] Table 5 Partial logic gates in the second part of the S-box

[0167] In Table 5 above, a total of 16 logic gates are included, and this part of the logic gates has four external inputs, t 21 , t 22 , t 23 , t 24 , and four external outputs, t 29 , t 33 , t 37 , t 40 .

[0168] The SAT solver can solve the following 9 steps, and the functions of the 16 logic gates in Table 5 above can be achieved through the 9 steps. The 9 steps have four external inputs, x0, x1, x2, x3, and four external outputs, y0, y1, y2, y3.

[0169] The 9 steps are as follows:

[0170] Step (1) t0 = q0*q1 + q0 + q1 + 1 (where q0 = x1, q1 = x3)

[0171] Step (2) t1 = q3*q4 + q3*q5 + q4*q5 (where q3 = x0, q4 = x1, q5 = t0)

[0172] Step (3) t2 = q6*q7 + q6*q8 + q7*q8 (where q6 = x0, q7 = 0, q8 = x2)

[0173] Step (4) t3 = q9*q 10 + q9*q11 + q 10 * q 11 (where q9=x2, q 10 =x3, q 11 =t0)

[0174] Step (5) t4=q 12 + q 13 + q 14 (where q 12 =x3, q 13 =t2, q 14 =t3)

[0175] Step (6) t5=q 15 + q 16 + q 17 (where q 15 =x1, q 16 =t1, q 17 =t2)

[0176] Step (7) t6=q 18 + q 19 + q 20 (where q 18 =x1, q 19 =x3, q 20 =t2)

[0177] Step (8) t8=q 21 * q 22 + q 21 * q 23 + q 22 * q 23 (where q 21 =x0, q 22 =x1, q 23 =t6)

[0178] Step (9) t9=q 24 * q 25 + q 24 * q 26 + q 25 * q 26 (where q 24 =x2, q 25 =x3, q 26 =t6)

[0179] The output obtained through the above 9 steps is:

[0180] y0=t4

[0181] y1=t8

[0182] y2=t5

[0183] y3=t7

[0184] The above 9 steps can be implemented by logic gates, as follows:

[0185] Step (1) corresponds to the logic gate t0=NOR(q0, q1)

[0186] Step (2) corresponds to the logic gate t1=MAJ(q3, q4, q5)

[0187] Step (3) corresponds to the logic gate t2=MAJ(q6, q7, q8)

[0188] Step (4) corresponds to the logic gate t3=MAJ(q9, q 10 , q 11 )

[0189] Step (5) corresponds to the logic gate t4=XOR3(q 12 , q 13 , q 14 )

[0190] Step (6) corresponds to the logic gate t5=XOR3(q 15 , q 16 , q 17 )

[0191] Step (7) corresponds to the logic gate t6=XOR3(q 18 , q 19 , q 20 )

[0192] Step (8) corresponds to the logic gate t7=MAJ(q 21 , q 22 , q 23 )

[0193] Step (9) corresponds to the logic gate t8=MAJ(q 24 , q 25 , q 26 )

[0194] At this time, the above 9 logic gates can be used to replace the above 16 logic gates in Table 5. In this way, the number of logic gates in the S-box can be reduced (a total of 16-9=7 logic gates are reduced), so that the calculation efficiency of the symmetric encryption algorithm can be improved.

[0195] In some embodiments, a three-input logic gate can also be determined by merging multiple two-input logic gates, such that the merged three-input logic gate can achieve the same function or effect as the multiple two-input logic gates.

[0196] For example, the fifth logic gate t0=x1+x2 in Table 4 above and the sixteenth logic gate y 10 = y 15 +t0, and the twenty-first logic gate y 16 =t0+y 11 may be merged to obtain a new logic gate y 10 =y 15 +x1+x2, and y 16 =x1+x2+y 11 , and the original fifth logic gate is deleted. In this way, the number of logic gates in the S-box can be reduced (equivalent to merging 3 logic gates into 2 logic gates), thereby improving the calculation efficiency of the symmetric encryption algorithm.

[0197] For the S-box containing 113 logic gates in Table 4 above, the number of logic gates can be reduced to 96 by the above-mentioned merging method (a total of 113-96=17 logic gates are reduced), which can greatly improve the calculation efficiency of the symmetric encryption algorithm. Specifically, it can be as shown in Table 6 below:

[0198] Table 6 S-box containing 96 logic gates obtained by merging

[0199] Wherein, the logic gate with the strikethrough "─" in the text indicates that the logic gate has been deleted, for example, "t0=x1+x2" indicates that the logic gate "t0=x1+x2" has been deleted; "¬" represents the NOT operation, in Table 5 above, the XOR operation is realized by first performing the XOR operation, and then performing the NOT operation on the result of the XOR operation, for example, "¬(z (z 12 +tc 13 +tc 14 )" represents the XOR operation of z 12 , tc 13 and tc 14 .

[0200] In some embodiments, the operation corresponding to the three-input logic gate can include encoding the three input data of the three-input logic gate according to a first type of encoding manner. Wherein, the first type of encoding manner can be used to enable the three-input logic gate to process the three input data.

[0201] Optionally, different types of three-input logic gates can correspond to different encoding manners.

[0202] For example, the first type of encoding manner can include a first encoding manner corresponding to the first logic gate, and the first encoding manner can satisfy the following formula:

[0203] wherein t represents a modulus of a finite field to which the first data belongs, the first data can be determined according to three input data of the first logic gate, x is a positive integer, and the value range of x is 0 to t-1, is a bottom symbol.

[0204] For another example, the first type of encoding manner can include a second encoding manner corresponding to the second logic gate, and the second encoding manner can satisfy the following formula:

[0205] wherein t represents a modulus of a finite field to which the second data belongs, the second data can be determined according to three input data of the second logic gate, x is a positive integer, and the value range of x is 0 to t-1, is a bottom symbol.

[0206] For another example, the first type of encoding manner can include a third encoding manner corresponding to the third logic gate, and the third encoding manner can satisfy the following formula:

[0207] wherein t represents a modulus of a finite field to which the third data belongs, the third data can be determined according to three input data of the third logic gate, x is a positive integer, and the value range of x is 0 to t-1, is a bottom symbol.

[0208] In some embodiments, the operation corresponding to the two-input logic gate can include encoding two input data of the two-input logic gate according to a fourth encoding manner.

[0209] For example, the fourth encoding manner can satisfy the following formula:

[0210] wherein t represents a modulus of a finite field to which the fourth data belongs, the fourth data can be determined according to two input data of the two-input logic gate, x is a positive integer, and the value range of x is 0 to t-1, is a bottom symbol.

[0211] Optionally, the two-input logic gate can include a fourth logic gate and / or a fifth logic gate. The fourth logic gate can be used to perform an exclusive or operation on two input data of the fourth logic gate, that is, the fourth logic gate is an exclusive or gate, and the fifth logic gate can be used to perform an and operation on two input data of the fifth logic gate, that is, the fifth logic gate is an and gate.

[0212] The operations corresponding to the logical gates mentioned in the above embodiments (operations corresponding to three-input logical gates and operations corresponding to two-input logical gates) are described in detail as follows.

[0213] Taking the first logical gate y 14 in Table 6 as an example, assuming that x3 and x5 are ciphertext data obtained after homomorphic encryption, The operation corresponding to the logical gate can specifically include the following:

[0214] First, x3 and x5 are added to obtain c, that is,

[0215] Next, h is calculated based on c, wherein K represents a key. h is determined according to the input data of the logical gate, that is, the first data, the second data, the third data or the fourth data mentioned in the above embodiments.

[0216] Then, h is substituted into the following formula to calculate f(h), and f(h) is the output of the logical gate. The calculation formula is specifically as follows:

[0217] wherein t represents the modulus of the finite field to which h belongs, a is a positive integer, the value range of a is 0 to t-1, and i is a positive integer, the value range of i is 0 to t-1.

[0218] The above embodiments take two-input logical gates as examples. If it is a three-input logical gate, three input data need to be added in the first step. For example, for the 16th logical gate y 10 in Table 6, assuming that 15 +x1+x2, y First, y 15 , x1 and x2 are added to obtain c, that is,

[0219] The DRaM() in the above formula is the encoding mode mentioned in the above embodiments. For example, if it is the first logical gate, the DRaM() in the above formula is the first encoding mode DRaM1(x) in the above embodiments; if it is the second logical gate, the DRaM() in the above formula is the second encoding mode DRaM2(x) in the above embodiments; if it is the third logical gate, the DRaM() in the above formula is the third encoding mode DRaM3(x) in the above embodiments; if it is the fourth logical gate or the fifth logical gate, the DRaM() in the above formula is the fourth encoding mode DRaM4(x) in the above embodiments.

[0220] In the embodiments of the present application, the S-box includes a three-input logic gate, the three-input logic gate can process three input data, and can realize a function or effect greater than that of a two-input logic gate. Since the operation time of each logic gate is relatively fixed, the number of logic gates in the S-box can be reduced while the overall function or effect of the S-box is guaranteed, thereby improving the calculation efficiency of the symmetric encryption algorithm.

[0221] The method embodiments of the present application are described in detail above in combination with FIG. 1 to FIG. 11, and the device embodiments of the present application are described in detail below in combination with FIG. 12 and FIG. 13. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.

[0222] FIG. 12 is a schematic structural diagram of a data processing device according to an embodiment of the present application. The data processing device 1200 shown in FIG. 12 can be used in the communication device in the foregoing embodiments. The data processing device 1200 can be the communication device, a device (for example, a processor, a chip, a chip system, a circuit, or a functional module) in the communication device, or a device capable of being used in combination with the communication device, and can also be a logic module or software capable of realizing all or part of the communication device.

[0223] As shown in FIG. 12, the data processing device 1200 includes an obtaining unit 1210 and a processing unit 1220, which are specifically as follows.

[0224] The obtaining unit 1210 is configured to obtain input data, and the input data belongs to a finite field.

[0225] The processing unit 1220 is configured to process the input data by using an S-box, wherein the S-box is used in a symmetric encryption algorithm, and the S-box includes a plurality of logic gates, and the plurality of logic gates include a three-input logic gate.

[0226] In some possible implementation manners, the operation corresponding to the three-input logic gate includes encoding three input data of the three-input logic gate according to a first type of encoding manner, and the first type of encoding manner is used to enable the three-input logic gate to process the three input data.

[0227] In some possible implementation manners, the three-input logic gate includes a first logic gate, the first logic gate is configured to perform an exclusive-OR operation on three input data of the first logic gate, and the first type of encoding manner includes a first encoding manner corresponding to the first logic gate.

[0228] In some possible implementation manners, the first encoding manner satisfies the following formula:

[0229] wherein t represents a modulus of a finite field to which the first data belongs, the first data is determined according to three input data of the first logic gate, x is a positive integer, and a value range of x is 0 to t-1, is a bottom symbol.

[0230] In some possible implementation manners, the three-input logic gate comprises a second logic gate, the second logic gate is configured to perform an AND operation on three input data of the second logic gate, and the first encoding manner comprises a second encoding manner corresponding to the second logic gate.

[0231] In some possible implementation manners, the second encoding manner satisfies the following formula:

[0232] wherein t represents a modulus of a finite field to which the second data belongs, the second data is determined according to three input data of the second logic gate, x is a positive integer, and a value range of x is 0 to t-1, is a bottom symbol.

[0233] In some possible implementation manners, the three-input logic gate comprises a third logic gate, the third logic gate is configured to output 1 when a number of 1s in input data of the third logic gate exceeds half, and output 0 when the number of 1s in the input data of the third logic gate does not exceed half, and the first encoding manner comprises a third encoding manner corresponding to the third logic gate.

[0234] In some possible implementation manners, the third encoding manner satisfies the following formula:

[0235] wherein t represents a modulus of a finite field to which the third data belongs, the third data is determined according to three input data of the third logic gate, x is a positive integer, and a value range of x is 0 to t-1, is a bottom symbol.

[0236] In some possible implementation manners, the plurality of logic gates comprises a two-input logic gate, and an operation corresponding to the two-input logic gate comprises encoding two input data of the two-input logic gate according to a fourth encoding manner.

[0237] In some possible implementation manners, the fourth encoding manner satisfies the following formula:

[0238] wherein t represents a modulus of a finite field to which the fourth data belongs, the fourth data is determined according to two input data of the two-input logic gate, x is a positive integer, and a value range of x is 0 to t-1, is a bottom symbol.

[0239] In some possible implementation manners, the two-input logic gate comprises a fourth logic gate and / or a fifth logic gate, the fourth logic gate is configured to perform an exclusive-OR operation on two input data of the fourth logic gate, and the fifth logic gate is configured to perform an AND operation on two input data of the fifth logic gate.

[0240] In some possible implementation manners, the input data is ciphertext data obtained after homomorphic encryption.

[0241] FIG. 13 is a schematic structural diagram of an apparatus provided by an embodiment of the present application. The dashed line in FIG. 13 indicates that the unit or module is optional. The apparatus 1300 can be used to implement the method described in the foregoing method embodiments. The apparatus 1300 can be a chip or a data processing apparatus.

[0242] The apparatus 1300 can include one or more processors 1310. The processor 1310 can support the apparatus 1300 to implement the method described in the foregoing method embodiments. The processor 1310 can be a general-purpose processor or a dedicated processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general-purpose processors, microprocessor units (MPUs), microcontroller units (MCUs), graphics processing units (GPUs), artificial intelligence processors (AI processors) or neural network processors (NPU), digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0243] The apparatus 1300 can further include one or more memories 1320. The memories 1320 store programs that can be executed by the processor 1310, so that the processor 1310 performs the methods described in the foregoing method embodiments. The memories 1320 can be independent of the processor 1310 or integrated in the processor 1310. In embodiments of the present application, the memories 1320 can include, but are not limited to, a cache, a read-only memory (ROM), a random access memory (RAM), a synchronous dynamic random access memory (SDRAM), a hard disk drive (HDD), or a solid-state drive (SSD), an erasable programmable ROM (EPROM), or a compact disc read-only memory (CD-ROM), and the like.

[0244] The apparatus 1300 can further include a transceiver 1330. The processor 1310 can communicate with other devices or chips through the transceiver 1330. For example, the processor 1310 can perform data transceiving with other devices or chips through the transceiver 1330.

[0245] It should be noted that the information interaction, execution process, and the like between the above apparatuses / units, since based on the same concept as the method embodiments of the present application, the specific functions and the technical effects brought by them can be referred to the method embodiments part, and will not be repeated here.

[0246] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual applications, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the apparatus is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit or module in the embodiments can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific names of each functional unit or module are only for easy distinction, and do not limit the protection scope of the present application. The specific working process of the unit or module in the system can refer to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0247] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program. When the computer program is run on a computer, the computer is caused to implement the steps in the above various method embodiments.

[0248] The embodiment of the present application further provides a computer program product, which comprises a computer program. When the computer program is run on a computer, the computer is caused to implement the steps in the above various method embodiments.

[0249] The embodiment of the present application further provides a chip, which comprises a processor and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that a device or equipment (such as a data processing device) installed with the chip executes the steps in the above various method embodiments.

[0250] The integrated unit, if realized in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the embodiment of the present application realizes all or part of the processes in the above method embodiments, which can be completed by a computer program instructing related hardware. The computer program can be stored in a computer readable storage medium, and the computer program can realize the steps in the above various method embodiments when executed by a processor. The computer program comprises computer program code, which can be in the form of source code, object code, executable file or some intermediate form. The computer readable storage medium at least includes any entity or device capable of carrying the computer program code to a device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium. For example, U disk, mobile hard disk, magnetic disk or optical disk, etc. In some possible implementation manners, the computer readable storage medium can not be an electrical carrier signal and a telecommunication signal.

[0251] In the above embodiments, the description of each embodiment has its own focus, and the parts not described or recorded in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0252] Those skilled in the art can understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0253] In the embodiments provided by the present application, it should be understood that the disclosed apparatuses / devices and methods can be implemented in other manners. For example, the embodiments of the apparatuses / devices described above are merely schematic; for example, the division of the modules or units is merely logical function division; an actual implementation can be another division manner, for example, multiple units or components can be combined or integrated into another system, or some characteristics can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.

[0254] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.

[0255] The above-described embodiments are merely used to illustrate the technical solutions of the present application, rather than limit them; even though the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: the technical solutions recorded in the foregoing embodiments can still be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A data processing method based on logic gates, characterized in that, The method comprises: obtaining input data, wherein the input data belongs to a finite field; processing the input data through an S-box, wherein the S-box is used for a symmetric encryption algorithm, and the S-box comprises a plurality of logic gates, and the plurality of logic gates comprise a three-input logic gate.

2. The method of claim 1, wherein, The operation corresponding to the three-input logic gate comprises encoding three input data of the three-input logic gate according to a first type of encoding mode, and the first type of encoding mode is used to enable the three-input logic gate to process the three input data.

3. The method of claim 2, wherein, The three-input logic gate comprises a first logic gate, and the first logic gate is used to perform an exclusive or operation on three input data of the first logic gate, and the first type of encoding mode comprises a first encoding mode corresponding to the first logic gate.

4. The method of claim 3, wherein, The first encoding mode satisfies the following equation: wherein t represents a modulus of a finite field to which the first data belongs, the first data is determined according to three input data of the first logic gate, x is a positive integer, and a value range of x is 0 to t-1, The bottom symbol is taken.

5. The method according to any one of claims 2 to 4, characterized in that, The three-input logic gate comprises a second logic gate, and the second logic gate is used to perform an and operation on three input data of the second logic gate, and the first type of encoding mode comprises a second encoding mode corresponding to the second logic gate.

6. The method of claim 5, wherein, The second encoding mode satisfies the following equation: wherein t represents a modulus of a finite field to which the second data belongs, the second data is determined according to three input data of the second logic gate, x is a positive integer, and a value range of x is 0 to t-1, The bottom symbol is taken.

7. The method according to any one of claims 2 to 6, characterized in that, The three-input logic gate comprises a third logic gate, and the third logic gate is used to output 1 when the number of 1s in the input data of the third logic gate exceeds half, and output 0 when the number of 1s in the input data of the third logic gate does not exceed half, and the first type of encoding mode comprises a third encoding mode corresponding to the third logic gate.

8. The method of claim 7, wherein, The third encoding mode satisfies the following equation: wherein t represents a modulus of a finite field to which the third data belongs, the third data is determined according to three input data of the third logic gate, x is a positive integer, and the value range of x is 0 to t-1, The bottom symbol is taken.

9. The method according to any one of claims 1 to 8, characterized in that, The plurality of logic gates comprise a two-input logic gate, and the operation corresponding to the two-input logic gate comprises encoding two input data of the two-input logic gate according to a fourth encoding mode.

10. The method of claim 9, wherein, The fourth encoding mode satisfies the following equation: wherein t represents a modulus of a finite field to which the fourth data belongs, the fourth data is determined according to two input data of the two-input logic gate, x is a positive integer, and a value range of x is 0 to t-1, The bottom symbol is taken.

11. The method according to claim 9 or 10, characterized in that, The two-input logic gate comprises a fourth logic gate and / or a fifth logic gate, the fourth logic gate is used to perform an exclusive or operation on two input data of the fourth logic gate, and the fifth logic gate is used to perform an and operation on two input data of the fifth logic gate.

12. The method according to any one of claims 1 to 11, characterized in that, The input data is ciphertext data obtained after homomorphic encryption.

13. A data processing apparatus, characterized by: The method comprises: A module or unit for performing the method of any one of claims 1 to 12.

14. A data processing apparatus, characterized by: The method comprises: A processor and a memory, the processor is coupled with the memory, and the memory is used to store a computer program, and the computer program is executed by the processor to enable the device to perform the method of any one of claims 1 to 12.

15. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and when the computer program runs on a computer, the computer executes the method of any one of claims 1 to 12.

16. A computer program product, characterised in that, The method comprises: A computer program, when the computer program runs on a computer, the computer executes the method of any one of claims 1 to 12.

17. A chip, characterized by The method comprises: A processor and a memory, the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the device or equipment installed with the chip executes the method of any one of claims 1 to 12.