Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

60 results about "Round function" patented technology

In topology and in calculus, a round function is a scalar function , over a manifold , whose critical points form one or several connected components, each homeomorphic to the circle , also called critical loops. They are special cases of Morse-Bott functions.

Flash encryption method for security chip, security chip and electronic equipment

The invention provides a flash encryption method for a security chip, the security chip and electronic equipment, and belongs to the field of digital security, the security chip comprises two flash encryption modules which are connected in parallel, the first flash encryption module carries out encryption and decryption processing on target data of which the values are all '1', and the second flash encryption module carries out encryption and decryption processing on other target data; each flash encryption module is used for encrypting and decrypting target data by using a Feistel structure; dividing the target data into a preset number of groups, encrypting each group by using different round functions, and performing nonlinear transformation on each round function by using different S boxes; and each flash encryption module scrambles the address based on a preset scrambling formula, and stores the encrypted ciphertext based on a scrambling result. The encryption delay can be reduced, the encryption strength is enhanced, and the software and hardware communication cost is reduced.
Owner:CHINA MOBILE M2M +2

SIMON encryption and decryption hardware acceleration system and method based on Loongson soft core

The invention provides an SIMON encryption and decryption hardware acceleration system and method based on a Loongson soft core, and the system comprises a LoongArch processor soft core which is used for control, task scheduling and data interaction with external equipment; the SIMON encryption / decryption coprocessor module is used for executing an SIMON lightweight block encryption algorithm, completing key expansion and round function calculation and realizing encryption and decryption functions; the SRAM module is used for caching an original text, a ciphertext and intermediate data generated in the encryption and decryption process and supporting efficient data access; and the AXI bus interface module is used for high-speed data interaction between the SIMON encryption / decryption coprocessor module and the processor core and between the SIMON encryption / decryption coprocessor module and the SRAM module, and supports burst read-write operation. The method has high efficiency, flexibility and low power consumption, and can be widely applied to data encryption and transmission scenes of an embedded system and Internet of Things equipment.
Owner:NANTONG UNIV

SMBA encryption algorithm side channel attack method based on CPA and related equipment

The invention relates to the technical field of data security, in particular to a CPA-based SMBA encryption algorithm side channel attack method and related equipment, and the method comprises the steps that a collection probe and a programmable oscilloscope are used to collect side channel leakage information when a cryptographic chip runs an SMBA algorithm, and the side channel leakage information comprises a power consumption curve, a current curve or an electromagnetic signal; selecting a result of whitening transformation in a round function of the SMBA encryption algorithm as an intermediate value, calculating the result of whitening transformation in the encryption process for each input data and the assumed encryption sub-key, and constructing an intermediate value set; performing correlation analysis by using the side channel leakage information and the intermediate value set to deduce an encryption sub-key of an SMBA encryption algorithm; the invention provides an effective security assessment means for the practical application of the SMBA encryption algorithm.
Owner:GUANGDONG VOCATIONAL & TECHNICAL COLLEGE

Data encryption device, memory encryption and decryption system and chip

The invention relates to the technical field of data encryption, and discloses a data encryption device, a memory encryption and decryption system and a chip. A password root output end; the key generation circuit is used for generating an n-bit first key and an n-bit second key; the data encryption logic circuit comprises a four-round encryption module, a four-round encryption unit in the four-round encryption module comprises an n-bit interleaver, four columns of 64-bit round function components correspondingly arranged on the two sides of the interleaver and two sub-circuits for encrypting residual data and residual keys, and the four-round encryption unit is connected with an address input end, a password root output end and a key generation circuit. And the four-round encryption module is used for performing alignment processing on the memory access address, performing interleaving encryption processing based on the four-round encryption module according to the n-bit alignment address obtained by the alignment processing, the first key and the second key, and generating an n-bit password root, so that the encryption device encrypts the write data according to the password root, and the decryption device decrypts the read data according to the password root.
Owner:SUZHOU SASAMAI SEMICON CO LTD +2

SM3 and SM4 fusion optimization method and system based on SIMD register

The invention provides an SM3 and SM4 fusion optimization method and system based on an SIMD register, and belongs to the technical field of data encryption and hash optimization. Executing SM3 message extension, writing an extension result into a stack area according to the determined mapping relation, and then reading extension data from the stack area by a compression function according to the mapping relation and executing a previous round operation of the SM3 compression function; reading a parameter pointer address of the SM4 from a stack area, loading a data block to be encrypted into an SIMD register, and performing format conversion from a large end sequence to a small end sequence on data; inserting a round function of the SM4 realized by using an SIMD instruction into a post-set round compression function of the SM3, so that a compression function instruction of the SM3 and a round function instruction of the SM4 are alternately executed, and post-set round calculation after merging is completed; after all round function calculation of the SM3 and the SM4 is completed, the encryption result of the SM4 is stored in the memory, then the parameter pointer of the SM3 is read from the stack area, and the hash result of the SM3 is written in the memory.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

Low-overhead anti-power analysis AES algorithm mask protection method

The invention discloses a low-overhead anti-power analysis AES (advanced encryption standard) algorithm mask protection method. According to the method, two shares of a plaintext and a secret key are received in a clock period 0, ten rounds of round functions are executed from the clock period 0 to the clock period 30, each round needs three clock periods, and two shares of a ciphertext are output in a clock period 31; in the implementation of a round function and key expansion, the calculation of an S box (not including input linear mapping) needs three clock periods; in the third clock period after S box calculation is completed, a round of residual operation (wherein the residual operation of a round function comprises a multiplication module of the S box, S box output linear mapping, row shifting, column confusion and round key addition, and the residual operation of key expansion comprises key word XOR generation of a next round of round key) and the next round of S box input linear mapping calculation are completed at the same time. According to the mask, the side channel security capability of first-order power consumption analysis resistance can be provided for the AES algorithm, and the requirements on random numbers and chip area are remarkably reduced.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

SM4-based efficient authentication encryption method

The invention discloses an efficient authentication encryption method based on SM4. The method comprises the following steps of: 1) initializing and generating an initial vector IV with the length of 128 bits, a secret key K of a national secret SM4 algorithm, a random number N with the length of 128 bits and associated data AD; 2) setting the length l of state updating data in the sponge structure to be 128 bits; 3) designing permutation operation # imgabs0 # 4 based on SM4 rounds of functions, generating S = IVKN in an authentication stage, sequentially executing # imgabs1 # to divide the associated data AD into a plurality of 128-bit data blocks, and performing round transformation on S to obtain a latest state S of fused associated data information; encrypting the plaintext M based on the state S and the key K to obtain a ciphertext C and an authentication tag T; and 5) completing decryption verification in a decryption stage.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

National cryptographic algorithm acceleration system based on Numba just-in-time compiling technology

The invention relates to the technical field of national cryptographic algorithm acceleration, and discloses a national cryptographic algorithm acceleration system based on a Numba just-in-time compiling technology. The numerical calculation mode reconstruction module is used for performing numerical calculation mode reconstruction on SM2 elliptic curve scalar multiplication, SM3 message extension round function, SM4 nonlinear transformation and ZUC flow generation logic contained in the national cryptographic algorithm core calculation module by utilizing an LLVM compiling chain of Numba, and converting an interpretively executed Python code into an optimized machine code adaptive to hardware; key function compiling acceleration is achieved through a (at) njit decorator, hot spot operation is dynamically recognized through compiling scheduling, and a differential instruction optimization strategy is loaded; the platform shows multiple technical advantages: on the development efficiency level, by presetting a standardized acceleration module library and an automatic compiling tool chain, the integration complexity of a national cryptographic algorithm is greatly reduced; in the aspect of operation performance, the compilation optimization depth is better than that of a general interpreter acceleration scheme; in the aspect of safety controllability, the mathematical theory basis of the national cryptographic algorithm is completely reserved, and hidden risks possibly introduced by black box type hardware acceleration are avoided.
Owner:SOUTHWEST PETROLEUM UNIV

Symmetric cipher encryption and decryption method and system oriented to ARM (Advanced RISC Machines) architecture

The invention provides an ARM architecture-oriented symmetric cipher encryption and decryption method and system, and relates to the technical field of encryption and decryption, the symmetric cipher adopts a block cipher, the block cipher adopts a round function to perform confusion and diffusion on data blocks in each round of encryption and decryption, and in a linear layer component for realizing diffusion, the data blocks are subjected to encryption and decryption in a byte copying and filling manner. The method comprises the following steps of: filling 8-bit or 16-bit original variables to be calculated to bits required by an ARM (Advanced RISC Machines) architecture, carrying out combined operation of cyclic shift, XOR and bit permutation on the filled variables, and carrying out low-bit extraction on an operation result according to the original bits of the variables to obtain an operation result of the original variables; according to the method, the linear layer efficiency of the small-size symmetric cryptography can be remarkably improved, a new thought and method are provided for lightweight symmetric cryptography algorithm design, and the method is of great significance to cryptography algorithm performance improvement in the Internet of Things and intelligent terminals.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

A method and apparatus for executing a round function

A method performed by a processing unit for determining a round function. A first share and a second share are generated using a current state and an input string. One or more linear operations are separately applied to the first share and the second share. A plurality of functions (which include a masking value from a paired S-box) are further applied to shares of each value input to a non-linear S-box operation to generate S-box output shares. The S-box output shares are then compressed to generate shares of the processed state. The round function may be a part of a sponge algorithm and the round function forms at least part of an absorbing phase. The method may be used to generate one of: a salted hash, a message authentication code, a pseudorandom number or a cipher. The round function may be one of: Keccak , PRINCE, Midori, LED, or SKINNY. The one or more linear operations may be θ, ρ, and π, and the S-box operation may be ꭓ. It is claimed that the first register 21 may be removed without loss of security as the compressor 28 won’t leak information in subsequent round transformations.
Owner:PQSHIELD LTD

Sequence password security analysis method for composite structure

The invention relates to the technical field of information security, in particular to a sequential cipher security analysis method for a composite structure, which comprises the following steps of: acquiring round function parameters of a target cipher algorithm, nonlinear component definition and a key scheduling rule, and generating a standardized configuration data set; dividing the complete algorithm into a plurality of independent low wheel structures along the boundary of the nonlinear component according to the wheel function parameters, and constructing a directed graph data model containing state transition constraints to compress a state space; calling a password component vulnerability feature library to quantify a sub-structure active S box distribution abnormal value and a linear diffusion layer vulnerability path, and generating a risk weight priority ranking list; and inputting the state sequence data into the target application environment simulation platform, and generating a reproducible vulnerability report when the output deviation exceeds a security threshold. Through hierarchical compression, risk guidance and multi-environment verification, the technical defect of insufficient path coverage of a high-round-number lightweight algorithm in a resource-limited scene is solved.
Owner:UNIV OF SCI & TECH OF CHINA

Data encryption device and memory encryption and decryption system, chip

The application relates to the technical field of data encryption, and discloses a data encryption device, a memory encryption and decryption system and a chip. The device comprises an address input end, a password root output end, a key generation circuit for generating a first key and a second key with n bits, and a data encryption logic circuit comprising a four-round encryption module. Four-round encryption units in the four-round encryption module comprise an interleaver with n bits, four 64-bit round function components arranged on both sides of the interleaver, and two sub-circuits for encrypting residual data and residual keys. The data encryption logic circuit is connected with the address input end, the password root output end and the key generation circuit, is used for performing alignment processing on a memory access address, and performs interleaving encryption processing on the n-bit aligned address, the first key and the second key obtained through the alignment processing on the basis of the four-round encryption module to generate a password root with n bits. The encryption device is used for encrypting write data on the basis of the password root, and the decryption device is used for decrypting read data on the basis of the password root.
Owner:SUZHOU SASAMAI SEMICON CO LTD +2

High-performance block cipher construction method and device, electronic equipment and storage medium

The application discloses a high-performance block cipher construction method and device, electronic equipment and a storage medium, wherein the method comprises: an encryption process: using a preset round function generation algorithm to encrypt plaintext to obtain ciphertext, wherein a round key in the preset round function generation algorithm is obtained by performing position permutation on 32 positions in units of 4 bits through a 128-bit key scheduling algorithm; and a decryption process: decrypting the ciphertext through a decryption algorithm to obtain the plaintext. Thus, the problem that the existing block cipher algorithm has high resource occupation when hardware is efficiently implemented, and has low software implementation efficiency is solved.
Owner:TSINGHUA UNIVERSITY

Identity authentication and key distribution method and system based on white-box cryptographic algorithm

The application discloses an identity authentication and key distribution method and system based on a white-box cryptographic algorithm, and the method comprises the following steps: a communication initiator generates an identity authentication token by using randomly selected white-box code and sends the token to a key management center; a session key distribution token sent by the key management center is received, the session key distribution token is generated by the key management center after the identity authentication token is verified to be correct, and the session key distribution token comprises a target round function generated based on a randomly selected session key; the communication initiator refreshes the reference code stored locally by using the target round function and the white-box code stored locally, and generates a communication session white-box cryptographic algorithm; the communication initiator sends the communication session white-box cryptographic algorithm and the session key distribution token to a communication responder for encrypted communication; and the application reduces the resource consumption of white-box code transmission and switching in the whole identity authentication and key distribution process while ensuring security.
Owner:CHINA TELECOM QUANTUM TECH CO LTD

Anti-attack block cipher encryption method for multi-scene application

The application relates to an anti-attack block cipher encryption method for multi-scene application. A group of random numbers generated by a random number module is pre-stored in a register, two groups of round functions are designed to simultaneously encrypt plaintext, irrelevant data is encrypted by using an irrelevant key to interfere with the power consumption curve of the current chip when the plaintext is correctly encrypted, so that the power consumption curve obtained by an attacker contains irrelevant power consumption, the difficulty of power consumption curve analysis is increased, and a random pseudo round is inserted in the 10 rounds of normal operation to prevent a fault injection attack; when there is no attacker, the two groups of round functions are simultaneously used to simultaneously encrypt two groups of plaintext, and the encryption speed is improved.
Owner:NO 47 INST OF CHINA ELECTRONICS TECH GRP

Password period evaluation method and device based on SH structure

The invention discloses a password period evaluation method and device based on an SH structure. The method comprises the steps of obtaining a to-be-evaluated cryptographic algorithm; converting the input of the cryptographic algorithm into a plaintext mode and constructing a structural model of the cryptographic algorithm; inputting the plaintext mode into a structure model of the cryptographic algorithm, and performing round function iteration operation to obtain the periodic function round number, independent variables, parameters and output variables of the cryptographic algorithm; constructing a periodic function, verifying the correctness of the constructed periodic function, judging whether the round number of the periodic function is greater than one half of the whole round of the to-be-evaluated cryptographic algorithm under the correct condition, and if yes, determining that the evaluation result of the to-be-evaluated cryptographic algorithm is safe under the quantum model; and if not, determining that the evaluation result of the cryptographic algorithm to be evaluated is unsafe under the quantum model. The design method is simple and easy to realize on software and hardware platforms, and has the advantage of high efficiency.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Block chain anti-quantum hash calculation method and system based on modulo 30 shrinkage residual coefficient prime number

The invention discloses a block chain anti-quantum hash calculation method and system based on modulo 30 shrinkage residual coefficient prime numbers, and belongs to the technical field of block chain security. The method comprises the steps of obtaining to-be-processed block chain data; constructing a prime number replacement function P30 and a modulo 30 confusion function M30 based on a modulo 30 simplified residual system Z30 * = {1, 7, 11, 13, 17, 19, 23, 29}, and performing modulo 30 congruence replacement on a special number 1 in Z30 by adopting a prime number 31 to form a modulo 30 congruence prime number set of Z30; the method comprises the following steps: embedding an M30 function into a core compression round function of an SHA256 algorithm, and constructing an improved Hash algorithm Mod30SHA256; and performing hash operation on the block chain data by using a Mod30SHA256 algorithm to generate a 256-bit hash value, and writing the 256-bit hash value into the block chain. According to the method, a number-theory confusion layer of a modular 30 shrinkage residual system is introduced, and a double diffusion mechanism of number-theory confusion and bit operation confusion is constructed, so that the quantum attack resistance of the Hash algorithm is effectively improved, the operation efficiency basically equivalent to that of SHA256 is kept, the method is seamlessly compatible with an existing block chain architecture, a core structure and a consensus mechanism of a block chain do not need to be modified, and the method is easy to implement. And smooth upgrading can be realized through direct deployment, and a lightweight anti-quantum hash solution is provided for the block chain system.
Owner:刘诗章 +1

Block cipher algorithm architecture, algorithm calling method and device and electronic equipment

The invention relates to a block cipher algorithm architecture, an algorithm calling method and device and electronic equipment. The algorithm architecture comprises a quantum security layer which is used for taking a quantum true random number generator as a key entropy source and generating an unpredictable initialization vector and a dynamic key seed based on a quantum optical effect; the hybrid encryption layer is used for encrypting a session key by adopting a hybrid encryption mechanism of post quantum cryptography and SM4 and using a public key algorithm based on lattice cryptography, generating a master key through an anti-quantum algorithm, and generating a sub-key sequence in combination with an SM4 round key expansion algorithm; the core algorithm layer is used for optimizing a round function, dynamically generating an S-box replacement table based on quantum random numbers through an implicit coding technology of dynamic S-box generation and white-box protection, carrying out implicit coding on XOR and shift operations in the round function and injecting redundant noise data; and the protocol adaptation layer is used for integrating a dynamic defense protocol. The encryption security can be improved, and the algorithm efficiency can be remarkably improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

A Block Cipher Design and Automated Security Assessment Assistance System

The present invention discloses a block cipher design and automated security assessment auxiliary system, including a front-end and a back-end. The front-end is designed based on the RESTful architecture, including a user interface, a FastAPI and a verification module; the back-end includes a component function system, a solver call module, an STP solver and a data parsing module. The method of the present invention receives the basic data and round function description passed in by the user at the front-end, uses the parsing method to link the basic description of the user-defined encryption algorithm with each module, uses the background script file to automatically generate the CVC language file, and uses the STP solver to complete the automatic search and modular implementation of different attack modes; it realizes the security assessment of the encryption algorithm designed by the user and returns the assessment result report. At present, there is no automated analysis tool that can both effectively analyze the block encryption algorithm and reduce the ability requirements for the user. The present invention fills this gap.
Owner:HANGZHOU DIANZI UNIV

SIMD register-based sm3 and sm4 fusion optimization method and system

The application provides an SM3 and SM4 fusion optimization method and system based on a SIMD register, belongs to the technical field of data encryption and hash optimization, and comprises: a required stack area; performing SM3 message expansion, writing an expansion result into the stack area according to a determined mapping relationship, then a compression function reads expansion data from the stack area according to the mapping relationship and performs a preset round operation of an SM3 compression function; reading an SM4 parameter pointer address from the stack area, loading a data block to be encrypted into a SIMD register, and performing format conversion of big-endian sequence to little-endian sequence on the data; inserting a round function of SM4 realized by using a SIMD instruction into a post-set round compression function of SM3, so that the compression function instruction of SM3 and the round function instruction of SM4 are alternately executed to complete post-set round calculation after merging; after all round function calculation of SM3 and SM4 is completed, the encryption result of SM4 is stored back into a memory, then an SM3 parameter pointer is read from the stack area, and the hash result of SM3 is written back into the memory.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

A method and related apparatus for SHA-3 lightweight hardware implementation

This application discloses a lightweight hardware implementation method and related apparatus for SHA-3, belonging to the field of post-quantum cryptography. The lightweight hardware implementation method of this application includes initializing a state matrix and absorbing input data into the state matrix; initiating a round function calculation process: when the current round number is less than or equal to a preset round number, reading target data from the state matrix and sequentially performing write-back operations of θ transformation, χ transformation, ι transformation, fused ρ transformation, and π transformation on the target data to obtain the transformed state matrix; when the current round number is greater than the preset round number, calculating and outputting the hash result based on the transformed state matrix. Using this application helps reduce the consumption of logical and storage resources.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Encryption method and system based on computer-aided proof security

The invention relates to the technical field of cryptography, and provides an encryption method and system based on computer-aided proof security, and the method comprises the steps: carrying out the parametric modeling of an EGFN structure, constructing a constraint condition based on a differential cryptographic analysis framework, and carrying out the optimization of the constraint condition through an SMT constraint solver; calculating the minimum number of rounds of complete diffusion of all rounds of functions of a certain round of the EGFN structure during encryption inquiry and the minimum number of rounds of complete diffusion of all rounds of functions of a certain round of the EGFN structure during decryption inquiry; constructing a coefficient matrix of the ciphertext output by the EGFN structure about a round function, and calculating the minimum round number when the coefficient matrix of the ciphertext output by the EGFN structure about the round function reaches a full rank during encryption inquiry through a linear algebraic calculation tool; and when the EGFN structure meets the security, encrypting the plaintext through the EGFN structure to obtain a ciphertext. And the encryption speed and security are improved.
Owner:SHANDONG UNIV

A Table-Lookup Threshold Implementation Method for PRESENT Encryption and Decryption

The present invention discloses a look-up table type threshold implementation method for PRESENT encryption and decryption, belonging to the field of cryptographic hardware design. The present invention includes an input selection layer, a first layer of round function, a second layer of round function, a third layer of round function, a fourth layer of round function, and a fifth layer of round function; first, based on the secondary decomposition of the S-box in the encryption part, the secondary decomposition derivation of the S-box inverse is carried out; then the threshold implementation of the non-linear function F in the decryption part is derived. ‑1 Based on the S-box decomposition in the encryption part, the present invention gives the inverse decomposition of the S-box in the decryption part, and also gives the look-up table type encryption and decryption threshold implementation method, which is applicable to the application scenarios that require both encryption and decryption for two-way operations; this method can be applied to various hardware platforms such as FPGA and ASIC to implement PRESENT.
Owner:NANJING UNIV OF SCI & TECH

Encryption authentication method based on hash function and Feistel structure

The invention relates to the technical field of information security, and provides an encryption authentication method based on a hash function and a Feistel structure, the encryption authentication method comprises an encryption authentication algorithm and a decryption verification algorithm, the encryption authentication method is realized by taking the Feistel structure as a password structure, selecting a hash function as a round function of the Feistel structure, and instantiating the round function into a hash function. According to the invention, encryption and decryption and message integrity verification can be carried out. The plaintext length and the secret key length are selectable, and the method is high in universality, good in expansibility, low in error code diffusion and high in safety. The method can be widely applied to wireless communication environments such as satellite internet and internet of things.
Owner:SPACE STAR TECH CO LTD +1

Data Encryption Method and System Based on Chaotic Block Cipher

The present invention provides a data encryption method and system based on chaotic block cipher, which relates to the technical field of data encryption. The method includes: receiving plaintext data input by a user; dividing the plaintext data into multiple groups and inputting them into a round function for encryption operation to obtain corresponding ciphertext data; wherein, a chaotic sequence is used to dynamically construct an S-box, system parameters and fixed parameters; in each round of encryption process, the constructed S-box is called to participate in data permutation, and the round key determined by the system parameters and fixed parameters is called to encrypt multiple groups of the plaintext data to generate the next-round grouped data. In this way, the chaotic sequence is used to dynamically construct the S-box in the non-linear structure part and the system parameters and fixed parameters in the linear structure part to securely encrypt the plaintext data, reduce the risk of being broken during data transmission, and improve the security of information transmission.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES)

A method and apparatus for executing a round function

A method performed by a processing unit for determining a round function is provided. The round function applies one or more linear operations and applies a non-linear S- box operation implemented by a plurality of S-boxes. The method generates a first share and a second share using a current state and an input string. The method separately applies the one or more linear operations to the first share and the second share. The method further applies a plurality of functions, which include a masking value from a paired S-box, to shares of each value input to the non-linear S-box operation to generate S-box output shares. The method compresses the S-box output shares to generate shares of the processed state.
Owner:PQSHIELD LTD

Linear path automatic analysis method and system oriented to ARX type cryptographic algorithm

The invention relates to the technical field of cryptographic analysis, and discloses an automatic linear path analysis method and system for an ARX type cryptographic algorithm, and the method comprises the following steps: constructing a round function, configuring a linear analysis target, and selecting a search strategy; performing linear mask initialization on the round function, and establishing an association relationship between inter-round mask variables; generating local linear mask propagation expressions based on the linear approximation characteristic of each basic operation unit, combining the local linear mask propagation expressions into a global linear approximation model, and calculating a correlation expression of a linear path; executing a search strategy on the global linear approximation model; converting the global linear approximation model and the search strategy into constraint description and solving the constraint description; according to the method, the modeling complexity of linear analysis is reduced through visual modeling and selection of the path search strategy, and automation of the linear path search process is achieved.
Owner:HANGZHOU DIANZI UNIV

Implementation method of improved algorithm SAFE for ROCCA algorithm

The present application is directed to the security problem of ROCCA algorithm and the low-efficiency implementation problem of the algorithm in the resource-restricted embedded environment, and provides an implementation method of an improved algorithm SAFE for the ROCCA algorithm in the ARM Cortex series embedded microprocessor environment.The SAFE round function adopts the components of the AES twice iteration, so that the SAFE can be efficiently implemented based on the semi-fixed slice in the resource-restricted embedded device; and in order to improve the security of the algorithm, the SAFE algorithm improves the structure of the ROCCA algorithm, on the one hand, adds two sets of operations of the key XOR initialization and the key XOR generation tag, and on the other hand, makes corresponding modifications to the initialization, the encryption plaintext and the generation tag part of the ROCCA algorithm.Compared with the ROCCA, the SAFE can better resist the key recovery attack, the state recovery attack and the differential attack, and has better security.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Multi-modal complex data format-reserved encrypted storage method based on national cryptographic algorithm

The invention relates to a multi-modal complex data format-preserving encryption storage method based on a national cryptographic algorithm, which comprises the following steps: a data preprocessing and structure improvement mechanism: classifying and segmenting multi-modal complex data, and optimizing a round function of the multi-modal complex data in combination with balanced and unbalanced Feistel structures; a national cryptographic algorithm fusion mechanism: improving SM3 and SM4 national cryptographic algorithms, combining the SM3 and SM4 national cryptographic algorithms with round operation of a Feistel structure, and performing optimization processing; and a data retaining format encryption storage mechanism: based on the processing mechanism, performing retaining format encryption storage processing of data transformation, iterative encryption, data organization and key management on the multi-modal complex data. By the adoption of the multi-mode complex data retaining format encryption storage method based on the national secret algorithm, the original format and structural features of data are effectively retained in the encryption process, and the encryption performance is remarkably improved while the data security is guaranteed; the problem that the data format is not well reserved when the multi-mode complex data is processed by the existing encryption technology is effectively solved.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY

Coprocessor and computer equipment

A coprocessor and computer equipment are applied to symmetric encryption calculation, and the coprocessor comprises an instruction decoding module, a key expansion module and a round function calculation module. The instruction decoding module is used for receiving an instruction sent by the central processing unit and decoding the instruction; the key expansion module comprises a first linear transformation unit, a nonlinear transformation unit and a second linear transformation unit which are connected in sequence, and is used for executing round key calculation operation; the signal provided by the encryption type register represents the type of the symmetric encryption calculation; the round function calculation module comprises a plurality of calculation units, and each calculation unit comprises a plurality of sub-calculation units; and in round function calculation of each round, each calculation unit is used for selecting the sub-calculation units with the required number corresponding to the encryption type according to the signal provided by the encryption type register to perform encryption calculation on the message words participating in the current round so as to obtain the ciphertext of the current round.
Owner:CHONGQING XINLIANXIN INTELLIGENT TECHNOLOGY CO LTD