Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

47 results about "Round function" patented technology

In topology and in calculus, a round function is a scalar function , over a manifold , whose critical points form one or several connected components, each homeomorphic to the circle , also called critical loops. They are special cases of Morse-Bott functions.

SMBA encryption algorithm side channel attack method based on CPA and related equipment

The invention relates to the technical field of data security, in particular to a CPA-based SMBA encryption algorithm side channel attack method and related equipment, and the method comprises the steps that a collection probe and a programmable oscilloscope are used to collect side channel leakage information when a cryptographic chip runs an SMBA algorithm, and the side channel leakage information comprises a power consumption curve, a current curve or an electromagnetic signal; selecting a result of whitening transformation in a round function of the SMBA encryption algorithm as an intermediate value, calculating the result of whitening transformation in the encryption process for each input data and the assumed encryption sub-key, and constructing an intermediate value set; performing correlation analysis by using the side channel leakage information and the intermediate value set to deduce an encryption sub-key of an SMBA encryption algorithm; the invention provides an effective security assessment means for the practical application of the SMBA encryption algorithm.
Owner:GUANGDONG VOCATIONAL & TECHNICAL COLLEGE

Data encryption device, memory encryption and decryption system and chip

The invention relates to the technical field of data encryption, and discloses a data encryption device, a memory encryption and decryption system and a chip. A password root output end; the key generation circuit is used for generating an n-bit first key and an n-bit second key; the data encryption logic circuit comprises a four-round encryption module, a four-round encryption unit in the four-round encryption module comprises an n-bit interleaver, four columns of 64-bit round function components correspondingly arranged on the two sides of the interleaver and two sub-circuits for encrypting residual data and residual keys, and the four-round encryption unit is connected with an address input end, a password root output end and a key generation circuit. And the four-round encryption module is used for performing alignment processing on the memory access address, performing interleaving encryption processing based on the four-round encryption module according to the n-bit alignment address obtained by the alignment processing, the first key and the second key, and generating an n-bit password root, so that the encryption device encrypts the write data according to the password root, and the decryption device decrypts the read data according to the password root.
Owner:SUZHOU SASAMAI SEMICON CO LTD +2

SM3 and SM4 fusion optimization method and system based on SIMD register

The invention provides an SM3 and SM4 fusion optimization method and system based on an SIMD register, and belongs to the technical field of data encryption and hash optimization. Executing SM3 message extension, writing an extension result into a stack area according to the determined mapping relation, and then reading extension data from the stack area by a compression function according to the mapping relation and executing a previous round operation of the SM3 compression function; reading a parameter pointer address of the SM4 from a stack area, loading a data block to be encrypted into an SIMD register, and performing format conversion from a large end sequence to a small end sequence on data; inserting a round function of the SM4 realized by using an SIMD instruction into a post-set round compression function of the SM3, so that a compression function instruction of the SM3 and a round function instruction of the SM4 are alternately executed, and post-set round calculation after merging is completed; after all round function calculation of the SM3 and the SM4 is completed, the encryption result of the SM4 is stored in the memory, then the parameter pointer of the SM3 is read from the stack area, and the hash result of the SM3 is written in the memory.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

Low-overhead anti-power analysis AES algorithm mask protection method

The invention discloses a low-overhead anti-power analysis AES (advanced encryption standard) algorithm mask protection method. According to the method, two shares of a plaintext and a secret key are received in a clock period 0, ten rounds of round functions are executed from the clock period 0 to the clock period 30, each round needs three clock periods, and two shares of a ciphertext are output in a clock period 31; in the implementation of a round function and key expansion, the calculation of an S box (not including input linear mapping) needs three clock periods; in the third clock period after S box calculation is completed, a round of residual operation (wherein the residual operation of a round function comprises a multiplication module of the S box, S box output linear mapping, row shifting, column confusion and round key addition, and the residual operation of key expansion comprises key word XOR generation of a next round of round key) and the next round of S box input linear mapping calculation are completed at the same time. According to the mask, the side channel security capability of first-order power consumption analysis resistance can be provided for the AES algorithm, and the requirements on random numbers and chip area are remarkably reduced.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

SM4-based efficient authentication encryption method

The invention discloses an efficient authentication encryption method based on SM4. The method comprises the following steps of: 1) initializing and generating an initial vector IV with the length of 128 bits, a secret key K of a national secret SM4 algorithm, a random number N with the length of 128 bits and associated data AD; 2) setting the length l of state updating data in the sponge structure to be 128 bits; 3) designing permutation operation # imgabs0 # 4 based on SM4 rounds of functions, generating S = IVKN in an authentication stage, sequentially executing # imgabs1 # to divide the associated data AD into a plurality of 128-bit data blocks, and performing round transformation on S to obtain a latest state S of fused associated data information; encrypting the plaintext M based on the state S and the key K to obtain a ciphertext C and an authentication tag T; and 5) completing decryption verification in a decryption stage.
Owner:INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES

Symmetric cipher encryption and decryption method and system oriented to ARM (Advanced RISC Machines) architecture

The invention provides an ARM architecture-oriented symmetric cipher encryption and decryption method and system, and relates to the technical field of encryption and decryption, the symmetric cipher adopts a block cipher, the block cipher adopts a round function to perform confusion and diffusion on data blocks in each round of encryption and decryption, and in a linear layer component for realizing diffusion, the data blocks are subjected to encryption and decryption in a byte copying and filling manner. The method comprises the following steps of: filling 8-bit or 16-bit original variables to be calculated to bits required by an ARM (Advanced RISC Machines) architecture, carrying out combined operation of cyclic shift, XOR and bit permutation on the filled variables, and carrying out low-bit extraction on an operation result according to the original bits of the variables to obtain an operation result of the original variables; according to the method, the linear layer efficiency of the small-size symmetric cryptography can be remarkably improved, a new thought and method are provided for lightweight symmetric cryptography algorithm design, and the method is of great significance to cryptography algorithm performance improvement in the Internet of Things and intelligent terminals.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

A method and apparatus for executing a round function

A method performed by a processing unit for determining a round function. A first share and a second share are generated using a current state and an input string. One or more linear operations are separately applied to the first share and the second share. A plurality of functions (which include a masking value from a paired S-box) are further applied to shares of each value input to a non-linear S-box operation to generate S-box output shares. The S-box output shares are then compressed to generate shares of the processed state. The round function may be a part of a sponge algorithm and the round function forms at least part of an absorbing phase. The method may be used to generate one of: a salted hash, a message authentication code, a pseudorandom number or a cipher. The round function may be one of: Keccak , PRINCE, Midori, LED, or SKINNY. The one or more linear operations may be θ, ρ, and π, and the S-box operation may be ꭓ. It is claimed that the first register 21 may be removed without loss of security as the compressor 28 won’t leak information in subsequent round transformations.
Owner:PQSHIELD LTD

Sequence password security analysis method for composite structure

The invention relates to the technical field of information security, in particular to a sequential cipher security analysis method for a composite structure, which comprises the following steps of: acquiring round function parameters of a target cipher algorithm, nonlinear component definition and a key scheduling rule, and generating a standardized configuration data set; dividing the complete algorithm into a plurality of independent low wheel structures along the boundary of the nonlinear component according to the wheel function parameters, and constructing a directed graph data model containing state transition constraints to compress a state space; calling a password component vulnerability feature library to quantify a sub-structure active S box distribution abnormal value and a linear diffusion layer vulnerability path, and generating a risk weight priority ranking list; and inputting the state sequence data into the target application environment simulation platform, and generating a reproducible vulnerability report when the output deviation exceeds a security threshold. Through hierarchical compression, risk guidance and multi-environment verification, the technical defect of insufficient path coverage of a high-round-number lightweight algorithm in a resource-limited scene is solved.
Owner:UNIV OF SCI & TECH OF CHINA

Data encryption device and memory encryption and decryption system, chip

The application relates to the technical field of data encryption, and discloses a data encryption device, a memory encryption and decryption system and a chip. The device comprises an address input end, a password root output end, a key generation circuit for generating a first key and a second key with n bits, and a data encryption logic circuit comprising a four-round encryption module. Four-round encryption units in the four-round encryption module comprise an interleaver with n bits, four 64-bit round function components arranged on both sides of the interleaver, and two sub-circuits for encrypting residual data and residual keys. The data encryption logic circuit is connected with the address input end, the password root output end and the key generation circuit, is used for performing alignment processing on a memory access address, and performs interleaving encryption processing on the n-bit aligned address, the first key and the second key obtained through the alignment processing on the basis of the four-round encryption module to generate a password root with n bits. The encryption device is used for encrypting write data on the basis of the password root, and the decryption device is used for decrypting read data on the basis of the password root.
Owner:SUZHOU SASAMAI SEMICON CO LTD +2

High-performance block cipher construction method and device, electronic equipment and storage medium

The application discloses a high-performance block cipher construction method and device, electronic equipment and a storage medium, wherein the method comprises: an encryption process: using a preset round function generation algorithm to encrypt plaintext to obtain ciphertext, wherein a round key in the preset round function generation algorithm is obtained by performing position permutation on 32 positions in units of 4 bits through a 128-bit key scheduling algorithm; and a decryption process: decrypting the ciphertext through a decryption algorithm to obtain the plaintext. Thus, the problem that the existing block cipher algorithm has high resource occupation when hardware is efficiently implemented, and has low software implementation efficiency is solved.
Owner:TSINGHUA UNIVERSITY

Identity authentication and key distribution method and system based on white-box cryptographic algorithm

The application discloses an identity authentication and key distribution method and system based on a white-box cryptographic algorithm, and the method comprises the following steps: a communication initiator generates an identity authentication token by using randomly selected white-box code and sends the token to a key management center; a session key distribution token sent by the key management center is received, the session key distribution token is generated by the key management center after the identity authentication token is verified to be correct, and the session key distribution token comprises a target round function generated based on a randomly selected session key; the communication initiator refreshes the reference code stored locally by using the target round function and the white-box code stored locally, and generates a communication session white-box cryptographic algorithm; the communication initiator sends the communication session white-box cryptographic algorithm and the session key distribution token to a communication responder for encrypted communication; and the application reduces the resource consumption of white-box code transmission and switching in the whole identity authentication and key distribution process while ensuring security.
Owner:CHINA TELECOM QUANTUM TECH CO LTD

Anti-attack block cipher encryption method for multi-scene application

The application relates to an anti-attack block cipher encryption method for multi-scene application. A group of random numbers generated by a random number module is pre-stored in a register, two groups of round functions are designed to simultaneously encrypt plaintext, irrelevant data is encrypted by using an irrelevant key to interfere with the power consumption curve of the current chip when the plaintext is correctly encrypted, so that the power consumption curve obtained by an attacker contains irrelevant power consumption, the difficulty of power consumption curve analysis is increased, and a random pseudo round is inserted in the 10 rounds of normal operation to prevent a fault injection attack; when there is no attacker, the two groups of round functions are simultaneously used to simultaneously encrypt two groups of plaintext, and the encryption speed is improved.
Owner:NO 47 INST OF CHINA ELECTRONICS TECH GRP

Password period evaluation method and device based on SH structure

The invention discloses a password period evaluation method and device based on an SH structure. The method comprises the steps of obtaining a to-be-evaluated cryptographic algorithm; converting the input of the cryptographic algorithm into a plaintext mode and constructing a structural model of the cryptographic algorithm; inputting the plaintext mode into a structure model of the cryptographic algorithm, and performing round function iteration operation to obtain the periodic function round number, independent variables, parameters and output variables of the cryptographic algorithm; constructing a periodic function, verifying the correctness of the constructed periodic function, judging whether the round number of the periodic function is greater than one half of the whole round of the to-be-evaluated cryptographic algorithm under the correct condition, and if yes, determining that the evaluation result of the to-be-evaluated cryptographic algorithm is safe under the quantum model; and if not, determining that the evaluation result of the cryptographic algorithm to be evaluated is unsafe under the quantum model. The design method is simple and easy to realize on software and hardware platforms, and has the advantage of high efficiency.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Block chain anti-quantum hash calculation method and system based on modulo 30 shrinkage residual coefficient prime number

The invention discloses a block chain anti-quantum hash calculation method and system based on modulo 30 shrinkage residual coefficient prime numbers, and belongs to the technical field of block chain security. The method comprises the steps of obtaining to-be-processed block chain data; constructing a prime number replacement function P30 and a modulo 30 confusion function M30 based on a modulo 30 simplified residual system Z30 * = {1, 7, 11, 13, 17, 19, 23, 29}, and performing modulo 30 congruence replacement on a special number 1 in Z30 by adopting a prime number 31 to form a modulo 30 congruence prime number set of Z30; the method comprises the following steps: embedding an M30 function into a core compression round function of an SHA256 algorithm, and constructing an improved Hash algorithm Mod30SHA256; and performing hash operation on the block chain data by using a Mod30SHA256 algorithm to generate a 256-bit hash value, and writing the 256-bit hash value into the block chain. According to the method, a number-theory confusion layer of a modular 30 shrinkage residual system is introduced, and a double diffusion mechanism of number-theory confusion and bit operation confusion is constructed, so that the quantum attack resistance of the Hash algorithm is effectively improved, the operation efficiency basically equivalent to that of SHA256 is kept, the method is seamlessly compatible with an existing block chain architecture, a core structure and a consensus mechanism of a block chain do not need to be modified, and the method is easy to implement. And smooth upgrading can be realized through direct deployment, and a lightweight anti-quantum hash solution is provided for the block chain system.
Owner:刘诗章 +1

Block cipher algorithm architecture, algorithm calling method and device and electronic equipment

The invention relates to a block cipher algorithm architecture, an algorithm calling method and device and electronic equipment. The algorithm architecture comprises a quantum security layer which is used for taking a quantum true random number generator as a key entropy source and generating an unpredictable initialization vector and a dynamic key seed based on a quantum optical effect; the hybrid encryption layer is used for encrypting a session key by adopting a hybrid encryption mechanism of post quantum cryptography and SM4 and using a public key algorithm based on lattice cryptography, generating a master key through an anti-quantum algorithm, and generating a sub-key sequence in combination with an SM4 round key expansion algorithm; the core algorithm layer is used for optimizing a round function, dynamically generating an S-box replacement table based on quantum random numbers through an implicit coding technology of dynamic S-box generation and white-box protection, carrying out implicit coding on XOR and shift operations in the round function and injecting redundant noise data; and the protocol adaptation layer is used for integrating a dynamic defense protocol. The encryption security can be improved, and the algorithm efficiency can be remarkably improved.
Owner:CHINA MOBILE INTERNET CO LTD +1

A Block Cipher Design and Automated Security Assessment Assistance System

The present invention discloses a block cipher design and automated security assessment auxiliary system, including a front-end and a back-end. The front-end is designed based on the RESTful architecture, including a user interface, a FastAPI and a verification module; the back-end includes a component function system, a solver call module, an STP solver and a data parsing module. The method of the present invention receives the basic data and round function description passed in by the user at the front-end, uses the parsing method to link the basic description of the user-defined encryption algorithm with each module, uses the background script file to automatically generate the CVC language file, and uses the STP solver to complete the automatic search and modular implementation of different attack modes; it realizes the security assessment of the encryption algorithm designed by the user and returns the assessment result report. At present, there is no automated analysis tool that can both effectively analyze the block encryption algorithm and reduce the ability requirements for the user. The present invention fills this gap.
Owner:HANGZHOU DIANZI UNIV

SIMD register-based sm3 and sm4 fusion optimization method and system

The application provides an SM3 and SM4 fusion optimization method and system based on a SIMD register, belongs to the technical field of data encryption and hash optimization, and comprises: a required stack area; performing SM3 message expansion, writing an expansion result into the stack area according to a determined mapping relationship, then a compression function reads expansion data from the stack area according to the mapping relationship and performs a preset round operation of an SM3 compression function; reading an SM4 parameter pointer address from the stack area, loading a data block to be encrypted into a SIMD register, and performing format conversion of big-endian sequence to little-endian sequence on the data; inserting a round function of SM4 realized by using a SIMD instruction into a post-set round compression function of SM3, so that the compression function instruction of SM3 and the round function instruction of SM4 are alternately executed to complete post-set round calculation after merging; after all round function calculation of SM3 and SM4 is completed, the encryption result of SM4 is stored back into a memory, then an SM3 parameter pointer is read from the stack area, and the hash result of SM3 is written back into the memory.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

A method and related apparatus for SHA-3 lightweight hardware implementation

This application discloses a lightweight hardware implementation method and related apparatus for SHA-3, belonging to the field of post-quantum cryptography. The lightweight hardware implementation method of this application includes initializing a state matrix and absorbing input data into the state matrix; initiating a round function calculation process: when the current round number is less than or equal to a preset round number, reading target data from the state matrix and sequentially performing write-back operations of θ transformation, χ transformation, ι transformation, fused ρ transformation, and π transformation on the target data to obtain the transformed state matrix; when the current round number is greater than the preset round number, calculating and outputting the hash result based on the transformed state matrix. Using this application helps reduce the consumption of logical and storage resources.
Owner:NANJING UNIV OF AERONAUTICS & ASTRONAUTICS

Encryption method and system based on computer-aided proof security

The invention relates to the technical field of cryptography, and provides an encryption method and system based on computer-aided proof security, and the method comprises the steps: carrying out the parametric modeling of an EGFN structure, constructing a constraint condition based on a differential cryptographic analysis framework, and carrying out the optimization of the constraint condition through an SMT constraint solver; calculating the minimum number of rounds of complete diffusion of all rounds of functions of a certain round of the EGFN structure during encryption inquiry and the minimum number of rounds of complete diffusion of all rounds of functions of a certain round of the EGFN structure during decryption inquiry; constructing a coefficient matrix of the ciphertext output by the EGFN structure about a round function, and calculating the minimum round number when the coefficient matrix of the ciphertext output by the EGFN structure about the round function reaches a full rank during encryption inquiry through a linear algebraic calculation tool; and when the EGFN structure meets the security, encrypting the plaintext through the EGFN structure to obtain a ciphertext. And the encryption speed and security are improved.
Owner:SHANDONG UNIV

Encryption authentication method based on hash function and Feistel structure

The invention relates to the technical field of information security, and provides an encryption authentication method based on a hash function and a Feistel structure, the encryption authentication method comprises an encryption authentication algorithm and a decryption verification algorithm, the encryption authentication method is realized by taking the Feistel structure as a password structure, selecting a hash function as a round function of the Feistel structure, and instantiating the round function into a hash function. According to the invention, encryption and decryption and message integrity verification can be carried out. The plaintext length and the secret key length are selectable, and the method is high in universality, good in expansibility, low in error code diffusion and high in safety. The method can be widely applied to wireless communication environments such as satellite internet and internet of things.
Owner:SPACE STAR TECH CO LTD +1

A method and apparatus for executing a round function

A method performed by a processing unit for determining a round function is provided. The round function applies one or more linear operations and applies a non-linear S- box operation implemented by a plurality of S-boxes. The method generates a first share and a second share using a current state and an input string. The method separately applies the one or more linear operations to the first share and the second share. The method further applies a plurality of functions, which include a masking value from a paired S-box, to shares of each value input to the non-linear S-box operation to generate S-box output shares. The method compresses the S-box output shares to generate shares of the processed state.
Owner:PQSHIELD LTD

Linear path automatic analysis method and system oriented to ARX type cryptographic algorithm

The invention relates to the technical field of cryptographic analysis, and discloses an automatic linear path analysis method and system for an ARX type cryptographic algorithm, and the method comprises the following steps: constructing a round function, configuring a linear analysis target, and selecting a search strategy; performing linear mask initialization on the round function, and establishing an association relationship between inter-round mask variables; generating local linear mask propagation expressions based on the linear approximation characteristic of each basic operation unit, combining the local linear mask propagation expressions into a global linear approximation model, and calculating a correlation expression of a linear path; executing a search strategy on the global linear approximation model; converting the global linear approximation model and the search strategy into constraint description and solving the constraint description; according to the method, the modeling complexity of linear analysis is reduced through visual modeling and selection of the path search strategy, and automation of the linear path search process is achieved.
Owner:HANGZHOU DIANZI UNIV

Implementation method of improved algorithm SAFE for ROCCA algorithm

The present application is directed to the security problem of ROCCA algorithm and the low-efficiency implementation problem of the algorithm in the resource-restricted embedded environment, and provides an implementation method of an improved algorithm SAFE for the ROCCA algorithm in the ARM Cortex series embedded microprocessor environment.The SAFE round function adopts the components of the AES twice iteration, so that the SAFE can be efficiently implemented based on the semi-fixed slice in the resource-restricted embedded device; and in order to improve the security of the algorithm, the SAFE algorithm improves the structure of the ROCCA algorithm, on the one hand, adds two sets of operations of the key XOR initialization and the key XOR generation tag, and on the other hand, makes corresponding modifications to the initialization, the encryption plaintext and the generation tag part of the ROCCA algorithm.Compared with the ROCCA, the SAFE can better resist the key recovery attack, the state recovery attack and the differential attack, and has better security.
Owner:GUILIN UNIV OF ELECTRONIC TECH

A Differential Fault Attack Method for Lightweight Authentication Encryption Algorithms

This invention discloses a lightweight authentication encryption algorithm differential fault attack method, relating to the fields of cryptography and information security technology; it initializes the AEGIS encryption algorithm and injects a random single-bit fault, with plaintext P as input. i The method involves encrypting the AEGIS encryption algorithm after initialization to generate correct and incorrect ciphertexts and obtaining their output difference. The output difference between the correct and incorrect ciphertexts is then XORed, and the location of the fault is determined using the XOR result. Byte state recovery is then performed based on the XOR result, and the word state recovery process is repeated. Finally, the inverse round function formula and encryption formula are applied to restore the complete internal state. This invention employs a lightweight authentication encryption algorithm differential fault attack method, which can efficiently extract key features from complex high-dimensional time-series data and accurately identify potential fault modes.
Owner:HENAN UNIV OF SCI & TECH

Encryption method for enhancing security of ARX structure cryptographic component

The invention discloses an encryption method for enhancing security of an ARX structure cryptographic component, data is encrypted by using an encryption algorithm, the cryptographic component in the encryption algorithm is a Feistel-based cryptographic component of an ARX structure, and the encryption method is characterized in that round functions used for iterative computation in the ARX structure are Rc (x, y) = (S beta (x + S alpha y) + S alpha y + c), S beta (x + S alpha y) + S alpha y + c), S beta (x + S alpha y) + S alpha y + c), S beta (x + S alpha y) + S alpha y + c), S beta (x + S alpha y) + S alpha y + c) and S beta (x + S alpha y) + S alpha y + c), the data processing method of the round function Rc (x, y) comprises the following steps: 1) dividing input data into two halves (mL, mR), and initializing (x, y) = (mL, mR); 2) performing multiple rounds of iteration on (x, y), and updating an internal state (x, y) <-Rc (x, y) during each round of iteration; and 3) generating two pieces of confused data (zL, zR) = (x, y) according to the internal state (x, y) output after final iterative updating in the step 2). According to the method, the safety is enhanced, the calculation efficiency is improved, and better safety and efficiency balance is realized.
Owner:UNIV OF CHINESE ACAD OF SCI

An edge medical emergency signal encryption processing method based on a racing dormancy strategy

This invention discloses an edge medical emergency signal encryption processing method based on a race-sleep strategy, relating to information security technology and embedded hardware acceleration technology. The method includes the following steps: S1, real-time monitoring of the number K of physiological data blocks to be encrypted in the data input buffer; S2, comparing the number K of data blocks with a preset minimum start threshold, and generating a global wake-up pulse when K ≥ 0; S3, responding to the global wake-up pulse, causing the fully expanded pipeline layer to transition from a sleep state to a full-speed running state, and sequentially injecting K data blocks into the fully expanded pipeline layer for encryption processing. This invention originates from the fully expanded architecture, which eliminates iterative feedback loops and, in conjunction with a deep pipeline, cuts off critical paths. By spatially instantiating R round function units, it achieves the output of a complete ciphertext block per clock cycle, improving throughput while reducing power consumption.
Owner:NANTONG UNIV

Method, device and equipment for implementing block cipher algorithm

This application discloses a method, apparatus, and device for implementing a block cipher algorithm. The method comprises: mapping acquired first plaintext data and a first-round key into a composite domain to obtain second plaintext data and a second-round key, respectively. The first plaintext data and the first-round key are data in a finite field of the block cipher algorithm, and the first-round key is a key generated using an initial key through a key expansion algorithm. An isomorphic relationship exists between the composite domain and the finite field of the block cipher algorithm; in the composite domain, calculating a round function included in the block cipher algorithm based on the second plaintext data and the second-round key to obtain first ciphertext data; de-mapping the first ciphertext data back into the finite field of the block cipher algorithm to obtain second ciphertext data; and outputting the second ciphertext data. This method can improve the versatility of block cipher algorithm implementations.
Owner:ALIBABA (CHINA) CO LTD

Construction method and device of block cipher round function, electronic equipment and storage medium

The application discloses a construction method and device of a block cipher round function, electronic equipment and a storage medium, wherein the method comprises the following steps: performing bit-by-bit exclusive or whitening of a key generation round function initial state on a plaintext block; replacing 32 S-box units of the round function one by one by using an S-box with multiple bits; performing bit grouping on the replaced round function, performing exclusive or on the bit grouping with a multi-bit constant, and performing position permutation on 32 positions of the round function as an S-box unit, so that there is no 9-round impossible differential based on the iteration of the round function, and there is also no 9-round effective differential route; multiplying each column of an intermediate state matrix of the round function by a preset matrix from the left to perform column mixing, and performing bit-by-bit exclusive or on the round function after the column mixing and a round key; and obtaining a final state of the round function after multiple iterations. Thus, the problems of high resource occupation in the hardware efficient implementation of the existing block cipher algorithm and low software implementation efficiency are solved.
Owner:TSINGHUA UNIVERSITY

Dynamic variable block cipher algorithm implementation method and device

The invention provides a dynamic variable block cipher algorithm implementation method and device. The method comprises the following steps: transmitting a plaintext to a register or a cache; grouping the plaintexts; an SPN structure is adopted, and a dynamic cryptographic algorithm based on parameter control is constructed and used for plaintext encryption and ciphertext decryption; the round function of the dynamic cryptographic algorithm is composed of a key adding layer, a parameter control layer and a static diffusion layer; the parameter control layer sets a second type parameter control layer between two first type parameter control layers, and a branch coupling structure is formed by nesting and combining the second type parameter control layer and the two first type parameter control layers; the round function of the dynamic cryptographic algorithm comprises an encryption round function and a decryption round function; and performing multiple rounds of encryption iteration on the initially input plaintext to complete plaintext encryption. According to the method, by designing a branch coupling structure with the parameter control layer comprising three dynamic layers, the structural analysis resistance of the algorithm and the algorithm iteration efficiency are improved, the method has wider applicability, and the actual information encryption requirement can be better met.
Owner:KAIYUAN INTERNATIONAL MATHEMATICS RESEARCH INSTITUTE

A method for implementing SM4 algorithm mask on a DSP chip to resist power analysis

The application relates to a SM4 algorithm mask implementation method for resisting power consumption analysis on a DSP chip, which comprises the following steps: obtaining plaintext data to be encrypted and an initial round key; generating a first random mask equal to the length of the plaintext data, and performing a first mask operation on the plaintext data by using the first random mask to obtain first mask state data; for the multi-round iteration encryption structure of the SM4 algorithm, in each round of encryption operation, a second random mask is generated based on the current round key; the first mask state data and the second random mask are input into an arithmetic logic unit of the DSP chip to execute a round function F which is subjected to mask conversion, wherein the round function F comprises a nonlinear transformation T and a linear transformation L; in the nonlinear transformation T, a pre-constructed and stored S-box lookup table which is subjected to mask processing is called, and the input data and the output data of the S-box lookup table which is subjected to mask processing are both covered by masks; the DSP implementation SM4 mask of the application is resistant to power consumption, is safe and efficient, and has better hardware adaptability.
Owner:SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD