ZUC Cipher S1 S-Box Hardware Architecture Using Sub-Field Arithmetic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional implementations of the S1 S-box in the ZUC cipher require significant hardware resources due to the use of a 256-byte lookup table, making them costly and unsuitable for high-speed VLSI circuit designs.
Innovation Solution
A direct mapping method using sub-field arithmetic is employed to represent the S1 S-box as a function of logical equations, replacing the traditional lookup table with a more compact hardware implementation that performs calculations for direct inversion in the Galois field GF(28).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a 256-byte lookup table is used to implement the S1 S-box, then the implementation is fast and easy to implement, but it involves a significant allocation of hardware resources and takes up much physical space
Solution Approach 1:
The patent changes the implementation approach from a static lookup table to a dynamic computational method using sub-field arithmetic. By representing the S1 S-box as a function containing logical equations that perform calculations, the patent transforms the problem from storage-intensive to computation-intensive, significantly reducing the physical space required while maintaining functionality.
Solution Approach 2:
The patent replaces the mechanical lookup table structure with a mathematical computation system based on sub-field arithmetic in Galois fields. This substitution eliminates the need for physical table storage by using algebraic operations (GF(16) arithmetic) to compute the same transformation, thereby reducing hardware resource allocation.
2Ease of operation
If a 256-byte lookup table is used to implement the S1 S-box, then the implementation is fast and easy to implement, but it uses a significant amount of hardware resources and is costly
Solution Approach 1:
The patent changes the implementation paradigm from table-based to equation-based, using sub-field arithmetic to compute S1 S-box values on-the-fly. This approach reduces hardware resource usage by eliminating the need to allocate and manage a 256-byte lookup table, replacing it with compact arithmetic logic that requires significantly fewer resources.
Solution Approach 2:
The patent segments the 8-bit input into two 4-bit parts and performs separate GF(16) arithmetic operations on each segment. This segmentation allows the complex S1 S-box computation to be broken down into simpler, more manageable operations that require fewer hardware resources while maintaining the correct cryptographic transformation.
3Ease of manufacture
If a lookup table method is used for the S1 S-box, then the implementation is simple, but it is not suitable for high speed VLSI circuit designs
Solution Approach 1:
The patent replaces the lookup table mechanism with a computational mechanism based on sub-field arithmetic. This substitution enables high-speed VLSI implementation because arithmetic operations can be performed in parallel and are more suitable for hardware optimization, whereas lookup tables consume excessive area and are less adaptable to high-speed design constraints.
Solution Approach 2:
The patent changes the fundamental approach from storage-oriented to computation-oriented, using logical equations and Galois field arithmetic that are inherently more suitable for high-speed hardware implementation. This allows the S1 S-box to be implemented with optimized logic circuits that can operate at higher speeds while consuming less area.
Data Source
AI summary
Efficient hardware architecture for a S1 S-box for a ZUC cipher is described. One circuit includes a first circuit to map an 8-bit input data of a Galois field GF(256) for a 8-bit data path for a ZUC cipher non-linear function component into 4-bit data paths for the ZUC cipher non-linear function component. The circuit further includes other circuits coupled to the first circuit to execute the 4-bit data paths in GF(162) to determine the inverse of the 8-bit input data for the ZUC cipher non-linear function component in GF(162) and to map the inverse in GF(162) to the Galois field GF(256).


