CN112751663B - A data encryption method and device - Google Patents
A data encryption method and device Download PDFInfo
- Publication number
- CN112751663B CN112751663B CN202011641668.6A CN202011641668A CN112751663B CN 112751663 B CN112751663 B CN 112751663B CN 202011641668 A CN202011641668 A CN 202011641668A CN 112751663 B CN112751663 B CN 112751663B
- Authority
- CN
- China
- Prior art keywords
- input data
- path
- data
- encryption
- result
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/0618—Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
- H04L9/0631—Substitution permutation network [SPN], i.e. cipher composed of a number of stages or rounds each involving linear and nonlinear transformations, e.g. AES algorithms
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
- Y02D—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
- Y02D30/00—Reducing energy consumption in communication networks
- Y02D30/50—Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Storage Device Security (AREA)
Abstract
Description
技术领域technical field
本发明涉及数据加密技术领域,尤其涉及一种数据加密方法和装置。The invention relates to the technical field of data encryption, in particular to a data encryption method and device.
背景技术Background technique
当今是信息科技高速发展的时代,互联网正迅速成为各行各业的载体,推动着行业的进步,而物联网作为提高互联网应用的基础媒介以及先驱,大大提高着行业生产和人们生活的效率。它的应用被称为继计算机、互联网之后世界信息产业发展的第三次浪潮,因此,物联网的安全性问题也备受人们关注。Today is the era of rapid development of information technology, the Internet is rapidly becoming the carrier of all walks of life, promoting the progress of the industry, and the Internet of Things, as the basic medium and pioneer of Internet applications, greatly improves the efficiency of industry production and people's lives. Its application is known as the third wave of the development of the world's information industry after computers and the Internet. Therefore, the security of the Internet of Things has also attracted people's attention.
集成电路制造工艺的飞速发展,片上系统SoC应运而生。SoC极大地缩小了系统体积,提高了系统的性能;SoC以其集成度高、体积小、功耗少、可靠性好、产品问世周期短等优点得到了越来越广泛地应用。然而在目前市场有些产品采用软件加密方式,导致数据加密速度慢、周期长,同时还有一些产品加密完全由硬件完成,虽然速度较快,但芯片面积较大、功耗较高,无法满足物联网产品的低功耗要求。同时,几乎市场上绝大多数产品都将密钥保存在非易失性存储器中,从而很容易受到侵入式攻击,导致密钥被复制窃取。这些问题严重制约着物联网的普及和发展,对物联网产品带来极大的安全隐患。With the rapid development of integrated circuit manufacturing technology, SoC came into being. SoC has greatly reduced the size of the system and improved the performance of the system; SoC has been more and more widely used for its advantages of high integration, small size, low power consumption, good reliability, and short product launch cycle. However, some products in the current market use software encryption, resulting in slow data encryption and long cycle times. At the same time, some products are encrypted entirely by hardware. Although the speed is fast, the chip area is large and the power consumption is high, which cannot meet the requirements Low power requirements for networking products. At the same time, almost most of the products on the market store the key in non-volatile memory, which is vulnerable to intrusive attacks, resulting in the key being copied and stolen. These problems seriously restrict the popularization and development of the Internet of Things, and bring great security risks to the products of the Internet of Things.
发明内容Contents of the invention
本发明提供了一种数据加密方法和装置,解决了现有的数据加密方法由于软件缺陷所导致的加密速度较慢,硬件加密所导致的功耗较高以及密钥保存方式导致出现安全隐患的技术问题。The present invention provides a data encryption method and device, which solves the problems of slow encryption speed caused by software defects, high power consumption caused by hardware encryption, and potential safety hazards caused by key storage methods in the existing data encryption method technical problem.
本发明提供的一种数据加密方法,涉及双轨道多米诺逻辑门结构,所述方法包括:A data encryption method provided by the present invention relates to a double-track domino logic gate structure, the method comprising:
接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据;其中,所述四路输入数据包括第一路输入数据、第二路输入数据、第三路输入数据和第四路输入数据;Receive the data to be encrypted input by the user, and divide the data to be encrypted into four input data on average; wherein, the four input data include the first input data, the second input data, the third input data and The fourth input data;
当预置的PC信号为高电平信号时,采用所述第二路输入数据、所述第三路输入数据、所述第四路输入数据与预置的可变轮密钥执行异或运算,得到运算结果;When the preset PC signal is a high-level signal, the XOR operation is performed using the second input data, the third input data, the fourth input data and the preset variable round key , get the operation result;
当所述运算结果有效时,通过所述双轨道多米诺逻辑门结构将所述PC信号转换为低电平信号;When the operation result is valid, the PC signal is converted into a low-level signal through the double-track domino logic gate structure;
根据所述运算结果与所述第一路输入数据,生成第一路加密结果;generating a first encryption result according to the operation result and the first input data;
执行四路输入数据更新操作;Perform four input data update operations;
返回所述接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据的步骤,直至所述四路输入数据更新操作执行32次;Returning to the step of receiving the data to be encrypted input by the user, and dividing the data to be encrypted into four input data on average, until the update operation of the four input data is performed 32 times;
对所述第一路输入数据、所述第二路输入数据、所述第三路输入数据和所述第四路输入数据执行反序变换,得到四路输出数据;performing inverse transformation on the first path of input data, the second path of input data, the third path of input data, and the fourth path of input data to obtain four paths of output data;
将四路所述输出数据进行合并,生成加密数据。Combine the output data of the four channels to generate encrypted data.
可选地,在所述执行四路输入数据更新操作的步骤之后,所述方法还包括:Optionally, after the step of performing the four-way input data update operation, the method further includes:
从预置的轮密钥组中选择与所述可变轮密钥不同的轮密钥作为新的可变轮密钥。A round key different from the variable round key is selected from a preset round key group as a new variable round key.
可选地,所述根据所述运算结果与所述第一路输入数据,生成第一路加密结果的步骤包括:Optionally, the step of generating the first encryption result according to the operation result and the first input data includes:
采用预置的可逆变换算法对所述运算结果执行合成置换操作,生成中间结果;performing a synthetic permutation operation on the operation result by using a preset reversible transformation algorithm to generate an intermediate result;
采用所述中间结果与所述第一路输入数据执行异或运算,生成第一路加密结果。Executing an XOR operation with the intermediate result and the first path of input data to generate a first path of encryption result.
可选地,所述执行四路输入数据更新操作的步骤包括:Optionally, the step of performing the four-way input data update operation includes:
采用所述第二路输入数据更新所述第一路输入数据;updating the first input data by using the second input data;
采用所述第三路输入数据更新所述第二路输入数据;updating the second input data by using the third input data;
采用所述第四路输入数据更新所述第三路输入数据;updating the third input data by using the fourth input data;
采用所述第一路加密结果更新所述第四路输入数据。The fourth path of input data is updated by using the encryption result of the first path.
可选地,在所述当所述运算结果有效时,通过所述双轨道多米诺逻辑门结构将所述PC信号转换为低电平信号的步骤之后,所述方法还包括:Optionally, after the step of converting the PC signal into a low-level signal through the double-track domino logic gate structure when the operation result is valid, the method further includes:
返回所述低电平信号到上一级的双轨道多米诺逻辑门结构,使得所述上一级的双轨道多米诺逻辑门结构所对应的运算结果有效。The low-level signal is returned to the double-track domino logic gate structure of the upper stage, so that the operation result corresponding to the double-track domino logic gate structure of the upper stage is valid.
本发明还提供了一种数据加密装置,涉及双轨道多米诺逻辑门结构,所述装置包括:The present invention also provides a data encryption device, which relates to a double-track domino logic gate structure, and the device includes:
输入数据划分模块,用于接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据;其中,所述四路输入数据包括第一路输入数据、第二路输入数据、第三路输入数据和第四路输入数据;The input data division module is used to receive the data to be encrypted input by the user, and divide the data to be encrypted into four input data on average; wherein, the four input data includes the first input data and the second input data , the third input data and the fourth input data;
运算结果生成模块,用于当预置的PC信号为高电平信号时,采用所述第二路输入数据、所述第三路输入数据、所述第四路输入数据与预置的可变轮密钥执行异或运算,得到运算结果;An operation result generating module, configured to use the second input data, the third input data, the fourth input data and the preset variable input data when the preset PC signal is a high-level signal. The round key performs an XOR operation to obtain the operation result;
低电平信号转换模块,用于当所述运算结果有效时,通过所述双轨道多米诺逻辑门结构将所述PC信号转换为低电平信号;A low-level signal conversion module, configured to convert the PC signal into a low-level signal through the double-track domino logic gate structure when the operation result is valid;
第一路加密结果生成模块,用于根据所述运算结果与所述第一路输入数据,生成第一路加密结果;A first encryption result generating module, configured to generate a first encryption result according to the operation result and the first input data;
数据更新模块,用于执行四路输入数据更新操作;A data update module, configured to perform four input data update operations;
重复执行模块,用于返回所述接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据的步骤,直至所述四路输入数据更新操作执行32次;Repeating the execution module for returning the received data to be encrypted input by the user, and dividing the to-be-encrypted data into four input data on average, until the update operation of the four input data is executed 32 times;
四路输出数据生成模块,用于对所述第一路输入数据、所述第二路输入数据、所述第三路输入数据和所述第四路输入数据执行反序变换,得到四路输出数据;A four-way output data generation module, configured to perform inverse transformation on the first line of input data, the second line of input data, the third line of input data, and the fourth line of input data to obtain four lines of output data;
加密数据生成模块,用于将四路所述输出数据进行合并,生成加密数据。The encrypted data generating module is used to combine the output data of the four channels to generate encrypted data.
可选地,所述装置还包括:Optionally, the device also includes:
轮密钥重选模块,用于从预置的轮密钥组中选择与所述可变轮密钥不同的轮密钥作为新的可变轮密钥。The round key reselection module is used to select a round key different from the variable round key from the preset round key group as a new variable round key.
可选地,所述第一路加密结果生成模块包括:Optionally, the first-way encryption result generation module includes:
中间结果生成子模块,用于采用预置的可逆变换算法对所述运算结果执行合成置换操作,生成中间结果;The intermediate result generation sub-module is used to perform a synthetic permutation operation on the operation result by using a preset reversible transformation algorithm to generate an intermediate result;
第一路加密结果生成子模块,用于采用所述中间结果与所述第一路输入数据执行异或运算,生成第一路加密结果。The first encryption result generation sub-module is used to perform XOR operation with the intermediate result and the first input data to generate the first encryption result.
可选地,所述数据更新模块包括:Optionally, the data update module includes:
第一路输入数据更新子模块,用于采用所述第二路输入数据更新所述第一路输入数据;The first input data updating submodule is used to update the first input data by using the second input data;
第二路输入数据更新子模块,用于采用所述第三路输入数据更新所述第二路输入数据;The second input data update submodule is configured to update the second input data by using the third input data;
第三路输入数据更新子模块,用于采用所述第四路输入数据更新所述第三路输入数据;A third input data updating submodule, configured to use the fourth input data to update the third input data;
第四路输入数据更新子模块,用于采用所述第一路加密结果更新所述第四路输入数据。The fourth input data update sub-module is configured to update the fourth input data by using the first encryption result.
可选地,所述装置还包括:Optionally, the device also includes:
信号返回模块,用于返回所述低电平信号到上一级的双轨道多米诺逻辑门结构,使得所述上一级的双轨道多米诺逻辑门结构所对应的运算结果有效。The signal return module is used to return the low-level signal to the double-track domino logic gate structure of the upper stage, so that the operation result corresponding to the double-track domino logic gate structure of the upper stage is valid.
从以上技术方案可以看出,本发明具有以下优点:As can be seen from the above technical solutions, the present invention has the following advantages:
本发明通过接收用户输入的待加密数据并划分为四路数据,将除第一路数据以外的三路数据与预置的可变轮密钥执行异或运算,得到运算结果;当运算结果有效时,通过双轨道多米诺逻辑门结构将PC信号转换为低电平信号,再根据运算结果与第一路输入数据的异或操作,生成第一路加密结果,执行四路输入数据更新操作,重复31次后,对四路数据执行反序变换,以得到四路输出数据;最后合并四路输出数据以生成加密数据。该方法提高了加密过程的速度,同时由于多米诺逻辑门结构的加入,降低加密功耗,提高加密安全性。In the present invention, by receiving the data to be encrypted input by the user and dividing it into four-way data, the three-way data except the first-way data and the preset variable round key are subjected to XOR operation to obtain the operation result; when the operation result is valid At this time, the PC signal is converted into a low-level signal through the double-track domino logic gate structure, and then the first encryption result is generated according to the XOR operation between the operation result and the first input data, and the four input data update operations are performed, and repeated After 31 times, perform reverse transformation on the four channels of data to obtain four channels of output data; finally combine the four channels of output data to generate encrypted data. The method improves the speed of the encryption process, and at the same time reduces the encryption power consumption and improves the encryption security due to the addition of the domino logic gate structure.
附图说明Description of drawings
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其它的附图。In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings that need to be used in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only These are some embodiments of the present invention. For those skilled in the art, other drawings can also be obtained according to these drawings on the premise of not paying creative efforts.
图1为本发明实施例提供的一种数据加密方法的步骤流程图;Fig. 1 is a flow chart of the steps of a data encryption method provided by an embodiment of the present invention;
图2为本发明实施例中的双轨道多米诺逻辑门的异或结构示意图;2 is a schematic diagram of an XOR structure of a dual-track domino logic gate in an embodiment of the present invention;
图3为本发明实施例中的双轨道多米诺逻辑门的与门结构示意图;Fig. 3 is the AND gate structure schematic diagram of the dual-track domino logic gate in the embodiment of the present invention;
图4为本发明可选实施例提供的一种数据加密方法的步骤流程图;FIG. 4 is a flowchart of steps of a data encryption method provided by an optional embodiment of the present invention;
图5为本发明实施例提供的一种数据加密装置的数据流程图;FIG. 5 is a data flow diagram of a data encryption device provided by an embodiment of the present invention;
图6为本发明实施例提供的一种数据加密装置的结构框图。Fig. 6 is a structural block diagram of a data encryption device provided by an embodiment of the present invention.
具体实施方式detailed description
随着无线区域网标准的推广应用,我国自主设计了SM4对称分组密码算法,该算法加解密速度快,硬件实现简单以及具备一定的安全性,多适用于制作密码芯片,现已大量运用于对金融领域、物联网等重要数据的保护。因此单纯从研究密码算法的结构而判断密码算法的安全性已经远远不够,我们必须还从密码算法的实现角度来考虑运行的速度和功耗设计,这样可以大幅度的改善芯片的质量。因此本发明实施例提供了一种数据加密方法和装置,用于解决现有的数据加密方法由于软件缺陷所导致的加密速度较慢,硬件加密所导致的功耗较高以及密钥保存方式导致出现安全隐患的技术问题。With the popularization and application of wireless area network standards, my country has independently designed the SM4 symmetric block cipher algorithm. This algorithm has fast encryption and decryption speed, simple hardware implementation and certain security. It is mostly suitable for making cryptographic chips, and has been widely used in Protection of important data in the financial field and the Internet of Things. Therefore, it is far from enough to judge the security of cryptographic algorithms simply by studying the structure of cryptographic algorithms. We must also consider the speed of operation and power consumption design from the perspective of cryptographic algorithm implementation, which can greatly improve the quality of chips. Therefore, the embodiment of the present invention provides a data encryption method and device, which are used to solve the problem of slow encryption speed caused by software defects, high power consumption caused by hardware encryption, and problems caused by key storage methods in existing data encryption methods. A technical issue that presents a safety hazard.
为使得本发明的发明目的、特征、优点能够更加的明显和易懂,下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,下面所描述的实施例仅仅是本发明一部分实施例,而非全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其它实施例,都属于本发明保护的范围。In order to make the purpose, features and advantages of the present invention more obvious and understandable, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the following The described embodiments are only some, not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.
请参阅图1,图1为本发明实施例提供的一种数据加密方法的步骤流程图。Please refer to FIG. 1 . FIG. 1 is a flowchart of steps of a data encryption method provided by an embodiment of the present invention.
本发明提供的一种数据加密方法,涉及双轨道多米诺逻辑门结构,所述方法包括:A data encryption method provided by the present invention relates to a double-track domino logic gate structure, the method comprising:
步骤101,接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据;Step 101, receiving the data to be encrypted input by the user, and dividing the data to be encrypted into four input data on average;
其中,所述四路输入数据包括第一路输入数据、第二路输入数据、第三路输入数据和第四路输入数据;Wherein, the four input data include the first input data, the second input data, the third input data and the fourth input data;
步骤102,当预置的PC信号为高电平信号时,采用所述第二路输入数据、所述第三路输入数据、所述第四路输入数据与预置的可变轮密钥执行异或运算,得到运算结果;
步骤103,当所述运算结果有效时,通过所述双轨道多米诺逻辑门结构将所述PC信号转换为低电平信号;
在本发明实施例中,多米诺逻辑门指的是一类在动态逻辑门之间插入静态反向器以避免动态逻辑门直接级联时,产生过早放电的动态电路。由于电路状态变化在级联的各级间依次传播,像多米诺骨牌,所以才被称为多米诺逻辑。而双轨道多米诺逻辑门,指的是在多米诺逻辑门上采用同步双路的形式的设计,以降低硬件资源损耗和功耗。In the embodiment of the present invention, the domino logic gate refers to a type of dynamic circuit in which a static inverter is inserted between the dynamic logic gates to avoid premature discharge when the dynamic logic gates are directly cascaded. It is called domino logic because the circuit state changes are propagated sequentially among the stages of the cascade, like dominoes. The dual-track domino logic gate refers to a design in the form of synchronous dual channels on the domino logic gate to reduce hardware resource consumption and power consumption.
请参阅图2,图2示出了本发明实施例中的双轨道多米诺逻辑门的异或结构示意图,其中包括多个场效应管,PC表示预充电信号,q_t和a_f表示输出信号。当PC信号为0时,输出端q_t和q_f都是为0信号,表示输出信号无效;当PC信号为1时,输出端q_t和q_f都是为1信号,表示输出信号有效。Please refer to FIG. 2 . FIG. 2 shows a schematic diagram of an XOR structure of a dual-track domino logic gate in an embodiment of the present invention, which includes a plurality of field effect transistors, PC represents a precharge signal, and q_t and a_f represent output signals. When the PC signal is 0, both the output terminals q_t and q_f are 0 signals, indicating that the output signal is invalid; when the PC signal is 1, the output terminals q_t and q_f are both 1 signals, indicating that the output signal is valid.
请参阅图3,图3示出了本发明实施例中的双轨道多米诺逻辑门的与门结构示意图,其中包括多个场效应管,PC表示预充电信号,q_t和a_f表示输出信号。当PC信号为0时,输出端q_t和q_f都是为0信号,表示输出信号无效;当PC信号为1时,输出端q_t和q_f都是为1信号,表示输出信号有效。Please refer to FIG. 3 . FIG. 3 shows a schematic diagram of an AND gate structure of a dual-track domino logic gate in an embodiment of the present invention, which includes a plurality of field effect transistors, PC represents a precharge signal, and q_t and a_f represent output signals. When the PC signal is 0, both the output terminals q_t and q_f are 0 signals, indicating that the output signal is invalid; when the PC signal is 1, the output terminals q_t and q_f are both 1 signals, indicating that the output signal is valid.
步骤104,根据所述运算结果与所述第一路输入数据,生成第一路加密结果;
步骤105,执行四路输入数据更新操作;
步骤106,返回所述接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据的步骤,直至所述四路输入数据更新操作执行32次;
步骤107,对所述第一路输入数据、所述第二路输入数据、所述第三路输入数据和所述第四路输入数据执行反序变换,得到四路输出数据;
所述反序变换指的是根据字节流中保存的对象状态及描述信息,通过反序列化重建对象。例如密文C=(Y0,Y1,Y2,Y3)=R(X32.X33,X34,X35)=(X35, X34,X33,X32)。The reverse transformation refers to reconstructing the object through deserialization according to the state and description information of the object stored in the byte stream. For example, the ciphertext C=(Y0, Y1, Y2, Y3)=R(X32.X33, X34, X35)=(X35, X34, X33, X32).
步骤108,将四路所述输出数据进行合并,生成加密数据。
在本发明实施例中,通过接收用户输入的待加密数据并划分为四路数据,将除第一路数据以外的三路数据与预置的可变轮密钥执行异或运算,得到运算结果;当运算结果有效时,通过双轨道多米诺逻辑门结构将PC信号转换为低电平信号,再根据运算结果与第一路输入数据的异或操作,生成第一路加密结果,执行四路输入数据更新操作,重复31次后,对四路数据执行反序变换,以得到四路输出数据;最后合并四路输出数据以生成加密数据。该方法提高了加密过程的速度,同时由于多米诺逻辑门结构的加入,降低加密功耗,提高加密安全性。In the embodiment of the present invention, by receiving the data to be encrypted input by the user and dividing it into four channels of data, the three channels of data except the first channel of data are subjected to XOR operation with the preset variable round key to obtain the operation result ; When the operation result is valid, the PC signal is converted into a low-level signal through the double-track domino logic gate structure, and then the first encryption result is generated according to the XOR operation of the operation result and the first input data, and four input channels are executed. After the data update operation is repeated 31 times, the four channels of data are reversed to obtain four channels of output data; finally, the four channels of output data are combined to generate encrypted data. The method improves the speed of the encryption process, and at the same time reduces the encryption power consumption and improves the encryption security due to the addition of the domino logic gate structure.
请参阅图4,图4为本发明实施例提供的一种数据加密方法的步骤流程图。Please refer to FIG. 4 . FIG. 4 is a flowchart of steps of a data encryption method provided by an embodiment of the present invention.
本发明提供的一种数据加密方法,涉及双轨道多米诺逻辑门结构,所述方法包括:A data encryption method provided by the present invention relates to a double-track domino logic gate structure, the method comprising:
步骤401,接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据;其中,所述四路输入数据包括第一路输入数据、第二路输入数据、第三路输入数据和第四路输入数据;Step 401, receiving the data to be encrypted input by the user, and dividing the data to be encrypted into four input data on average; wherein, the four input data includes the first input data, the second input data, the third input data input data and the fourth input data;
在本发明实施例中,每一轮的数据加密的逻辑门均由信号PC控制,当电路中第一次开始工作时,所有的PC信号必须复位为零一段时间为电路预先充电,然后PC信号转换为高电平,等待有效数据的计算。In the embodiment of the present invention, the logic gates of each round of data encryption are controlled by the signal PC. When the circuit starts to work for the first time, all PC signals must be reset to zero for a period of time to pre-charge the circuit, and then the PC The signal transitions high, awaiting the computation of valid data.
步骤402,当预置的PC信号为高电平信号时,采用所述第二路输入数据、所述第三路输入数据、所述第四路输入数据与预置的可变轮密钥执行异或运算,得到运算结果;
在具体实现中,以第二路输入数据X1、第三路输入数据X2和第四路输入数据X3为例,运算结果X可以通过以下公式进行计算:In a specific implementation, taking the second input data X1, the third input data X2 and the fourth input data X3 as examples, the operation result X can be calculated by the following formula:
其中,rki指的是第i轮的可变轮密钥。where rki refers to the variable round key of the i-th round.
步骤403,当所述运算结果有效时,通过所述双轨道多米诺逻辑门结构将所述PC信号转换为低电平信号;
在本发明实施例中,若运算结果有效时,通过双轨道多米诺逻辑门结构件 PC信号转换为低电平信号,以启动加密进程,对第一路输入数据进行加密。In the embodiment of the present invention, if the operation result is valid, the PC signal of the double-track domino logic gate structure is converted into a low-level signal to start the encryption process and encrypt the first input data.
步骤404,返回所述低电平信号到上一级的双轨道多米诺逻辑门结构,使得所述上一级的双轨道多米诺逻辑门结构所对应的运算结果有效。
在具体实现中,在多个数据需要进行流水线加密时,需要对上一轮电路进行预充电,此时可以将低电平信号返回到上一级双轨道多米诺逻辑门结果,以保证上一级的双轨道多米诺逻辑门结构所对应的运算结果有效。In the specific implementation, when multiple data need to be encrypted in the pipeline, it is necessary to precharge the previous round of circuits. At this time, the low-level signal can be returned to the result of the upper-level double-track domino logic gate to ensure that the upper-level The operation results corresponding to the double-track domino logic gate structure are valid.
步骤405,根据所述运算结果与所述第一路输入数据,生成第一路加密结果;
进一步地,所述步骤405可以包括以下子步骤:Further, the
采用预置的可逆变换算法对所述运算结果执行合成置换操作,生成中间结果;performing a synthetic permutation operation on the operation result by using a preset reversible transformation algorithm to generate an intermediate result;
采用所述中间结果与所述第一路输入数据执行异或运算,生成第一路加密结果。Executing an XOR operation with the intermediate result and the first path of input data to generate a first path of encryption result.
在本发明的一个示例中,采用可逆变换算法对运算结果执行合成置换操作,以得到中间结果,采用中间结果与第一路输入数据进行异或运算,生成第一路加密结果。In an example of the present invention, a reversible transformation algorithm is used to perform a composite permutation operation on the operation result to obtain an intermediate result, and an XOR operation is performed on the intermediate result and the first input data to generate the first encryption result.
其中,可逆变换算法指的是可逆线性变换(invertible linear transformation)亦称非退化线性变换,或满秩线性变换,是一种特殊的线性变换,设V是数域P上的线性空间,σ是V的线性变换,若存在V的变换τ,使στ=τσ=I,其中I为单位变换,则σ称为可逆线性变换,τ称为σ的逆变换,V上的可逆线性变换σ的逆变换仍为V的线性变换,且是惟一的,记为σ-1。Among them, the reversible transformation algorithm refers to the invertible linear transformation (invertible linear transformation), also known as non-degenerate linear transformation, or full-rank linear transformation, which is a special kind of linear transformation. Let V be the linear space on the number field P, and σ be The linear transformation of V, if there is a transformation τ of V, so that στ=τσ=I, where I is the unit transformation, then σ is called a reversible linear transformation, τ is called the inverse transformation of σ, and the reversible linear transformation on V is the inverse of σ The transformation is still the linear transformation of V, and it is unique, denoted as σ -1 .
合成置换操作指的是可逆变换,由一个非线性变换r和线性变换L复合而成的,即T(a)=L(r(a)),a为运算结果。The synthetic permutation operation refers to a reversible transformation, which is composed of a nonlinear transformation r and a linear transformation L, that is, T(a)=L(r(a)), and a is the operation result.
步骤406,执行四路输入数据更新操作;
在本发明实施例中,所述步骤406可以包括以下子步骤:In the embodiment of the present invention, the
采用所述第二路输入数据更新所述第一路输入数据;updating the first input data by using the second input data;
采用所述第三路输入数据更新所述第二路输入数据;updating the second input data by using the third input data;
采用所述第四路输入数据更新所述第三路输入数据;updating the third input data by using the fourth input data;
采用所述第一路加密结果更新所述第四路输入数据。The fourth path of input data is updated by using the encryption result of the first path.
可选地,在所述步骤406之后,所述方法还包括:Optionally, after
从预置的轮密钥组中选择与所述可变轮密钥不同的轮密钥作为新的可变轮密钥。A round key different from the variable round key is selected from a preset round key group as a new variable round key.
在本发明实施例中,加密密钥的长度为128比特,表示为MK=(MK0,MK1,MK2,MK3),其中MKi为32位,可变轮密钥表示为(rk0,rk1,……, rk31),其中rki为32位。可以通过密钥扩展方法:设 以得到 In the embodiment of the present invention, the length of the encryption key is 128 bits, expressed as MK=(MK0, MK1, MK2, MK3), wherein MKi is 32 bits, and the variable round key is expressed as (rk0, rk1,... , rk31), where rki is 32 bits. Can be extended via the key method: set to get
步骤407,返回所述接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据的步骤,直至所述四路输入数据更新操作执行32次;
步骤408,对所述第一路输入数据、所述第二路输入数据、所述第三路输入数据和所述第四路输入数据执行反序变换,得到四路输出数据;
步骤409,将四路所述输出数据进行合并,生成加密数据。
在本发明实施例中,通过接收用户输入的待加密数据并划分为四路数据,将除第一路数据以外的三路数据与预置的可变轮密钥执行异或运算,得到运算结果;当运算结果有效时,通过双轨道多米诺逻辑门结构将PC信号转换为低电平信号,再根据运算结果与第一路输入数据的异或操作,生成第一路加密结果,执行四路输入数据更新操作,重复31次后,对四路数据执行反序变换,以得到四路输出数据;最后合并四路输出数据以生成加密数据。该方法提高了加密过程的速度,同时由于多米诺逻辑门结构的加入,降低加密功耗,提高加密安全性。In the embodiment of the present invention, by receiving the data to be encrypted input by the user and dividing it into four channels of data, the three channels of data except the first channel of data are subjected to XOR operation with the preset variable round key to obtain the operation result ; When the operation result is valid, the PC signal is converted into a low-level signal through the double-track domino logic gate structure, and then the first encryption result is generated according to the XOR operation of the operation result and the first input data, and four input channels are executed. After the data update operation is repeated 31 times, the four channels of data are reversed to obtain four channels of output data; finally, the four channels of output data are combined to generate encrypted data. The method improves the speed of the encryption process, and at the same time reduces the encryption power consumption and improves the encryption security due to the addition of the domino logic gate structure.
请参阅图5,图5示出了本发明实施例的一种数据加密装置的数据流程图。Please refer to FIG. 5 , which shows a data flow chart of a data encryption device according to an embodiment of the present invention.
通过输入128bit的待加密数据Plaintext X,划分为四路输入数据X0、X1、 X2和X3,在进入到Round1后,通过X1、X2、X3与rk1进行异或操作,得到运算结果后通过detect电路(即双路多米诺逻辑门结果)输出PC信号,并执行合成置换操作T后,与X0进行异或操作,生成第一路加密数据,再对每一路输入数据进行更新,将X0作为X4并进行移位,以此类推,直到32轮数据加密过程完成,将四路数据进行反序变化、合并后输出128bit的加密数据Ciphertext Y。By inputting 128bit plaintext X to be encrypted, it is divided into four input data X0, X1, X2 and X3. After entering Round 1 , XOR operation is performed through X1, X2, X3 and rk1, and the operation result is obtained through detect The circuit (that is, the result of the dual-way domino logic gate) outputs the PC signal, and after performing the synthetic replacement operation T, it performs an XOR operation with X0 to generate the first encrypted data, and then updates each input data, using X0 as X4 and Shift, and so on, until the 32-round data encryption process is completed, the four channels of data are changed in reverse order, combined, and the 128-bit encrypted data Ciphertext Y is output.
请参阅图6,图6示出了本发明实施例的一种数据加密装置的结构框图。Please refer to FIG. 6, which shows a structural block diagram of a data encryption device according to an embodiment of the present invention.
本发明还提供了一种数据加密装置,涉及双轨道多米诺逻辑门结构,所述装置包括:The present invention also provides a data encryption device, which relates to a double-track domino logic gate structure, and the device includes:
输入数据划分模块601,用于接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据;其中,所述四路输入数据包括第一路输入数据、第二路输入数据、第三路输入数据和第四路输入数据;The input
运算结果生成模块602,用于当预置的PC信号为高电平信号时,采用所述第二路输入数据、所述第三路输入数据、所述第四路输入数据与预置的可变轮密钥执行异或运算,得到运算结果;The calculation
低电平信号转换模块603,用于当所述运算结果有效时,通过所述双轨道多米诺逻辑门结构将所述PC信号转换为低电平信号;A low-level
第一路加密结果生成模块604,用于根据所述运算结果与所述第一路输入数据,生成第一路加密结果;A first-pass encryption
数据更新模块605,用于执行四路输入数据更新操作;A
重复执行模块606,用于返回所述接收用户输入的待加密数据,并将所述待加密数据平均划分为四路输入数据的步骤,直至所述四路输入数据更新操作执行32次;Repeat the
四路输出数据生成模块607,用于对所述第一路输入数据、所述第二路输入数据、所述第三路输入数据和所述第四路输入数据执行反序变换,得到四路输出数据;The four-way output
加密数据生成模块608,用于将四路所述输出数据进行合并,生成加密数据。The encrypted
可选地,所述装置还包括:Optionally, the device also includes:
轮密钥重选模块,用于从预置的轮密钥组中选择与所述可变轮密钥不同的轮密钥作为新的可变轮密钥。The round key reselection module is used to select a round key different from the variable round key from the preset round key group as a new variable round key.
可选地,所述第一路加密结果生成模块604包括:Optionally, the first-pass encryption
中间结果生成子模块,用于采用预置的可逆变换算法对所述运算结果执行合成置换操作,生成中间结果;The intermediate result generation sub-module is used to perform a synthetic permutation operation on the operation result by using a preset reversible transformation algorithm to generate an intermediate result;
第一路加密结果生成子模块,用于采用所述中间结果与所述第一路输入数据执行异或运算,生成第一路加密结果。The first encryption result generation sub-module is used to perform XOR operation with the intermediate result and the first input data to generate the first encryption result.
可选地,所述数据更新模块605包括:Optionally, the
第一路输入数据更新子模块,用于采用所述第二路输入数据更新所述第一路输入数据;The first input data updating submodule is used to update the first input data by using the second input data;
第二路输入数据更新子模块,用于采用所述第三路输入数据更新所述第二路输入数据;The second input data update submodule is configured to update the second input data by using the third input data;
第三路输入数据更新子模块,用于采用所述第四路输入数据更新所述第三路输入数据;A third input data updating submodule, configured to use the fourth input data to update the third input data;
第四路输入数据更新子模块,用于采用所述第一路加密结果更新所述第四路输入数据。The fourth input data update sub-module is configured to update the fourth input data by using the first encryption result.
可选地,所述装置还包括:Optionally, the device also includes:
信号返回模块,用于返回所述低电平信号到上一级的双轨道多米诺逻辑门结构,使得所述上一级的双轨道多米诺逻辑门结构所对应的运算结果有效。The signal return module is used to return the low-level signal to the double-track domino logic gate structure of the upper stage, so that the operation result corresponding to the double-track domino logic gate structure of the upper stage is valid.
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的装置的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。Those skilled in the art can clearly understand that for the convenience and brevity of the description, the specific working process of the device described above can refer to the corresponding process in the foregoing method embodiment, and details are not repeated here.
在本发明所提供的几个实施例中,应该理解到,所揭露的装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。In the several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or May be integrated into another system, or some features may be ignored, or not implemented. In another point, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or units may be in electrical, mechanical or other forms.
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
另外,在本发明各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, each unit may exist separately physically, or two or more units may be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
以上所述,以上实施例仅用以说明本发明的技术方案,而非对其限制;尽管参照前述实施例对本发明进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本发明各实施例技术方案的精神和范围。As mentioned above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: it can still understand the foregoing The technical solutions recorded in each embodiment are modified, or some of the technical features are replaced equivalently; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims (10)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202011641668.6A CN112751663B (en) | 2020-12-31 | 2020-12-31 | A data encryption method and device |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202011641668.6A CN112751663B (en) | 2020-12-31 | 2020-12-31 | A data encryption method and device |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN112751663A CN112751663A (en) | 2021-05-04 |
| CN112751663B true CN112751663B (en) | 2022-12-23 |
Family
ID=75649393
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN202011641668.6A Active CN112751663B (en) | 2020-12-31 | 2020-12-31 | A data encryption method and device |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN112751663B (en) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103812641A (en) * | 2012-11-07 | 2014-05-21 | 中国科学院微电子研究所 | A System Realizing SM4 Block Symmetric Cipher Algorithm |
| CN108206735A (en) * | 2016-12-16 | 2018-06-26 | 波音公司 | The method and system of password round key is generated by bit mixer |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20160182542A1 (en) * | 2014-12-18 | 2016-06-23 | Stuart Staniford | Denial of service and other resource exhaustion defense and mitigation using transition tracking |
| US20180262525A1 (en) * | 2017-03-09 | 2018-09-13 | General Electric Company | Multi-modal, multi-disciplinary feature discovery to detect cyber threats in electric power grid |
-
2020
- 2020-12-31 CN CN202011641668.6A patent/CN112751663B/en active Active
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103812641A (en) * | 2012-11-07 | 2014-05-21 | 中国科学院微电子研究所 | A System Realizing SM4 Block Symmetric Cipher Algorithm |
| CN108206735A (en) * | 2016-12-16 | 2018-06-26 | 波音公司 | The method and system of password round key is generated by bit mixer |
Also Published As
| Publication number | Publication date |
|---|---|
| CN112751663A (en) | 2021-05-04 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN103973432A (en) | SM4 algorithm encryption unit based on FPGA chip and USB interface chip | |
| CN103152165B (en) | Based on super high-speed A ES processor and its implementation of FPGA | |
| CN110059493B (en) | SKINNY-128-128 encryption algorithm implementation method and system based on coarse-grained reconfigurable computing unit | |
| CN101304312B (en) | Ciphering unit being suitable for compacting instruction set processor | |
| CN114640454B (en) | A Cryptographic System of Post-Quantum Cryptography Crystals Kyber Protocol | |
| CN101848081A (en) | S box and construction method thereof | |
| CN111865560A (en) | An AES cryptographic coprocessor and terminal device | |
| CN102006161A (en) | Nonlinear transformation method for symmetric key encryption and implementation method thereof | |
| KR20100083848A (en) | A packet cipher algorithm based encryption processing method | |
| CN113949504B (en) | High-speed SM4 cryptographic algorithm circuit suitable for mobile device | |
| Aagaard et al. | Hardware design and analysis of the ACE and WAGE ciphers | |
| CN112751663B (en) | A data encryption method and device | |
| CN114826560B (en) | Lightweight block cipher CREF implementation method and system | |
| CN110620587A (en) | Polarization code BP decoding unit based on different data type transmission | |
| CN119299075A (en) | A RISC-V-based SM4 algorithm acceleration calculation method | |
| Haghparast et al. | Design of new reversible quaternary flip-flops | |
| WO2023040595A1 (en) | Chip, and method for generating message authentication code | |
| CN117375802A (en) | Encryption and decryption method and device based on mask protection and storage medium | |
| CN117010031A (en) | Strong physical unclonable function circuit based on closed loop feedback voltage attenuator array | |
| CN120880658B (en) | Hardware implementation device and method compatible with ASCON cryptographic algorithm families | |
| CN112054889B (en) | Method and device for generating message authentication code and computer readable storage medium | |
| Leung et al. | A low power asynchronous GF (2ˆ173) ALU for elliptic curve crypto-processor | |
| CN205540690U (en) | High -speed multi -mode mould adds circuit of operation | |
| CN120729509B (en) | Low-latency hardware acceleration method and system for SM4 symmetric cryptography algorithm | |
| CN110633574A (en) | ECC encryption module for secure transmission in power system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| EE01 | Entry into force of recordation of patent licensing contract | ||
| EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20210504 Contract record no.: X2026980000026 Denomination of invention: A data encryption method and device Granted publication date: 20221223 License type: Common License Record date: 20260109 |




