Key scheduler for encryption apparatus using data encryption standard algorithm
Abstract
A key scheduler for an encryption apparatus using a DESencryption algorithm is disclosed. The key schedulerincludes:a first permutation choice unit for permuting a 56-bit block;a first register for storing left 28 bits amongthe 56-bit block from the first permutation choice unit inaccordance with a clock signal;a second register for storingright 28 bits among the 56-bit block from the firstpermutation choice unit in accordance with the clock signal;a first and a second shift units for shifting the 28-bitblocks stored in the first and the second registers to theleft by a first predetermined number of bits and outputtingshifted 28-bit blocks to the first and the second registersrespectively; a second permutation choice unit for permutingthe 28 bits stored in the first and the second registers,therdby generating a first subkey; a third and a fourth shiftunets, each for shifting the 28 bits stored in the first andthe second registers to left by a second predetermined numberof bits; and a therd permutation choice unite for permutingthe 28 bits stored in the third and the fourth shifters,thereby generating a second subkey.
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
6 claims: 2 independent, 4 dependent
- 1522698 申請專利範圍 ι· 一種使用DES加密演算法沾石令牯罢+ +过 也/、·#古的加也、裝置之主排程器,其中 該主排程器包括: ~ 一第一排列選擇單元,其用以排列5 6 -位元區塊; 一第一暫存器,其用以根據時序信號儲存第一排列選 擇單元的56 -位元鑰匙區塊其中的左側28-位元; 一第二暫存器,其用以根據時序信號儲存第一排列選 擇單元的56-位元鑰匙區塊其中的右侧28_位元; 一第一和一第二轉移單元,其用以將儲存在第一和第 二暫存器的28 -位元區塊以第一預定位元數轉移至左 側’並將轉移的2 8 -位元分別輸出至第一和第二暫存 器; 一第二排列選擇單元,其用以排列儲存在第一和第二 暫存器的28-位元,並藉此產生第一子鑰匙; 一第三和一第四轉移單元,其皆用以將儲存在第一和 第二暫存器的2 8 -位元以第二預定位元數轉移至左側; 以及 一第三排列選擇單元,其用以排列儲存在第三和第四 轉移器的28-位元,並藉此產生第二子鑰匙。 2_如申請專利範圍第1項之主排程器,其中該第二預定位 元數為1或2。 3·如申請專利範圍第2項之主排程器,其中該第三排列選 擇單元是由配線完成。 4· 一種使用DES加密演算法的加密裝置之主排程器,其中 該主排程器包括: -22- 本紙張尺度適用中國國家標準(CNS) Α4規格(210 X 297公釐) 522698 A BCD w 穴川Μ j 1儿7〇區塊; 一第一暫存器,其用以根據時序信號儲存第一排列$ 擇單元的5 6 -位元鑰匙區塊其中的左側2 8 _位元; 1 第一暫存器,其用以根據時序信號儲存第一 擇單元的56 -位元鑰匙區塊其中的右側28_位元; 第一和一第二轉移單元,其用以將儲存在第一 二暫存器的28-位元區塊以第一預定位元數轉移至〆 ,,並將轉移的28-位元分別輸出至第一和第二暫^ 〇s , -第二排列選擇單元,其用以排列儲存在第 _ 暫存器的28 -位元,並藉此產生第一子鑰匙; 一 -第三和四轉移單元,其皆用以將儲存在第 第二暫存器的28-位元以第二預定位元數 以及 々W, -第三排列選擇單元,其用以排列儲存在第 轉移器的28-位元,並藉此產生第二子鑰匙。 弟西 5. 如申請專利範圍第4項之主排程器, 元數為丨或2。 〃中该第二預定位 6. 如申請專利範圍第5項之主排程器, βσ ,、甲孩弟二排列撰 擇早元是由配線路完成。 、 -23-
125 paragraphs, as filed
Master scheduler for encryption devices using data encryption standard algorithms
Other objects and functions described above and in the present invention will become more apparent from the detailed description of the preferred embodiments illustrated in the appended claims
Figure 1 shows a block diagram of a general DES architecture;
Figure 2 shows a block diagram of the main scheduler that generates the subkeys;
3 is a block diagram showing an encryption function unit and an S-Box arrangement unit in a general DES architecture;
Figure 4 shows a block diagram of the DES architecture using the expanded loop encryption functional unit;
5A and 5B are block diagrams showing a combinational logic unit of an unfolded loop encryption function unit;
Figure 6 shows a block diagram of the expansion loop encryption function unit;
Figure 7 shows a block diagram of a conventional master scheduler with two key schedule units;
Figure 8 shows a block diagram of a main scheduler in accordance with an embodiment of the present invention;
Figure 9 shows a block diagram of a main scheduler in accordance with another embodiment of the present invention;
Figure 10 illustrates a timing diagram of a main scheduler operation in accordance with the present invention;
Figure 11 shows a block diagram of a DES architecture using macros and time-division multiplexed functional units in accordance with the present invention;
Figure 12 is a block diagram showing the DES architecture of a macros pipeline and an unrolled loop wafer functional unit in accordance with the present invention;
Figure 13 shows a timing diagram of a DES architecture operation using a macro pipeline and an unrolled loop encryption functional unit;
Figure 14 shows a timing diagram of the effects of a DES architecture using a macro pipeline in accordance with the present invention.
Scope of invention
The present invention relates to the main scheduler of the encryption device; and, in particular, to the main scheduler of the 8-cycle encryption device using the data encryption standard algorithm.
Prior art description
The DES (Data Encryption Standard) algorithm draws more attention in environments where the network is widely used. In particular, DES is widely used in Internet security applications, remote access servers, wired data machines, or satellite data machines.
DES is basically a 64-bit block cipher with 64-bit block output and input, where 56-bit is used for encryption and decryption, and the remaining 8-bit is used for parity checking. The DES receives the 64-bit plain text block and outputs the 64-bit encrypted text generated by the 64-bit plain text block and the 56-bit key.
In one main technique, DES is implemented by arranging (P-Box), substituting (S-Box), and master scheduler to generate subkeys.
Data encryption is internally implemented in this way to recur 16 loop operations with an initial arrangement (IP) of the input portion and an inverse initial arrangement of the output portion (IP) <sup>-1</sup> ) Construction.
Figure 1 shows a block diagram of a general DES architecture.
Referring to FIG. 1, the general DES architecture includes an initial ranking unit 110, a DES encryption unit 120, and a reverse initial alignment unit 130.
In the DES encryption unit 120, the 64-bit plain text block area under the IP unit is divided into two blocks, which are respectively registered as the left first register (L). <sub>0</sub> ) and the first scratchpad on the right side (R <sub>0</sub> ). At each cycle, the 32-bit data is registered in the left register, and the right register is subjected to product transformation and block conversion. The inverse initial alignment unit 130 performs an inverse initial alignment (IP) for the 64-bit data of the 16-cycle computation transformation. <sup>-1</sup> ) and output an encrypted text block.
The basic operation unit 120 includes a plurality of encryption function units 121 and a mutually exclusive OR (X-OR) unit 122.
Registered on the right first register (L <sub>0</sub> The 32-bit data is the subkey of the main scheduler by the encryption function unit f12l (K) <sub>1</sub> Encrypted, and the encrypted 32-bit data will be in mutual exclusion or unit 122 and registered in the first scratchpad on the left (L) <sub>0</sub> The 32-bit data is mutually exclusive or computed. Mutually exclusive or 32-bit data of unit 122 is registered in the right register (R) <sub>1</sub> ), while registering on the right first register (R <sub>0</sub> 32-bit data, will be in the next cycle in the left register (L <sub>1</sub> ) Exchange and registration, called "single loop operation". In the DES architecture, 16 loop operations are performed back by a single loop operation.
The 16-cycle operation can be expressed by equations (1) and (2).
L <sub>i</sub> =R <sub>I-1</sub> I=1,2,...16 (1)R <sub>i</sub> =L <sub>I-1</sub> f(R <sub>I-1</sub> , K <sub>i</sub> ) i = 1, 2, ... 16 (2) Figure 2 shows a block diagram of a conventional master scheduler that generates a subkey.
Referring to FIG. 2, the conventional main scheduler includes a first permutation selection (PC1) unit 200, first and second transfer units 220, 230, and a second permutation selection (PC2) unit 240.
The first permutation selection (PC1) unit 200 performs an arrangement of 56-bit key data. The arranged 56-bit key data will be split into two 28-bit blocks, and the block will be registered in the scratchpad C. <sub>0</sub> And D <sub>0</sub> . Each transfer unit 220 and 230 is transferred to register in C <sub>i</sub> And D <sub>i</sub> Corresponding 28-bit of (i=0,1,...,15). The transfer key data block will be registered in the next cycle of the scratchpad C <sub>i+1</sub> And D <sub>i+l</sub> . The second permutation selection (PC2) unit 240 performs registration in the register C <sub>i</sub> And D <sub>i</sub> The 28-bit block is arranged and outputs a 48-bit subkey K <sub>i</sub> 。
During the 16 cycle operation, C <sub>i</sub> And D <sub>i</sub> The key data block will be transferred in a 28-bit manner, so it is registered in C. <sub>0</sub> , D <sub>0</sub> Data size and C <sub>16</sub> , D <sub>16</sub> The size of the data is the same.
Figure 3 shows a detailed block diagram of the cryptographic functional unit and the S-BOX permutation unit in the general DES architecture.
Referring to FIG. 3, the encryption function f includes an expansion arrangement unit 310, a mutually exclusive (XOR) unit 320, an S-Box arrangement unit 330, a P-Box arrangement unit 340, and an XOR mutual exclusion unit 350.
The expansion permutation unit 310 performs expansion of the 32-bit data (R(R) from the right register registering the 32-bit text block. <sub>I-1</sub> )) to output 48-bit data.
The XOR exclusive OR unit 320 is in the 48-bit data from the extended permutation unit 310 and the sub-key from the main scheduler (K <sub>i</sub> Execute a mutex or operation on it.
The S-Box arranging unit 330 performs substitution on the 48-bit data from the XOR mutex or unit 320 to output 32-bit data.
The P-Box arranging unit 340 performs arranging on the 32-bit material from the P-Box arranging unit 330.
The XOR Mutually Exclusive OR unit 350 is in the 32-bit data from the P-Box arranging unit 340 and the 32-bit data from the left register (L ( <sub>I-1</sub> )) Perform a mutual exclusion or operation.
The main scheduler includes a first permutation selection (PC1) unit 360, two transfer units 370, 380, and a second permutation selection (PC2) unit 380. Each of the transfer units 160 and 170 respectively transfers the corresponding 28-bit, that is, half of the 56-bit key data.
The PC2 unit 390 receives two blocks from the transfer unit 160, 170 to compress it into sub-keys.
Specifically, the S-Box arranging unit 330 includes eight S-Boxes for receiving 48-bit data and outputting 32-bit data. That is to say, the 48-bit data block will be divided into 8 6-bit data, and each 6-bit data will be applied to the corresponding 8 S-Boxes in the S-Box array unit, and each S- Box outputs 4-bit data. Therefore, the 48-bit data will be arranged as 32-bit data. The S-Box arranging unit 330 requires a memory such as a programmable logic array (PLA) or a read-only memory (ROM) because it employs look-up table technology. Since each S-Box input 6-bit outputs only 4-bits, a 64x4 memory capacity is required, and the S-Box arrangement unit 330 requires 8 x 64 x 4 memory capacity. Therefore, the S-Box arranging unit 130 occupies a relatively large area in the wafer.
To perform a conventional DES algorithm that recursively the same operation 16 times, one loop operation is called a basic arithmetic unit, and the DES architecture is executed by 16 basic arithmetic units. However, an expansion loop architecture in which one of the 2 to 16 cycle operations is used as the basic operation unit will be introduced and received more attention. Expanding the loop architecture can effectively reduce the time difference, combine the operations of the basic unit to reduce the slack time between the basic units, and use the boundary optimization combination to reduce the size of the wafer. Because the unrolled loop architecture operates two loop operations in a single timing cycle, encryption can be performed in eight timing cycles. However, two S-Box array units are required, taking up most of the area of the chip.
Figure 4 shows a block diagram of a traditional DES architecture using expanded loop encryption.
Referring to FIG. 4, a conventional DES architecture using an unrolled loop architecture includes an initial permutation unit 400, multiplexers 410 and 420, combinational logic units 430 and 440, registers 450 and 460, and a final permutation unit 470.
The initial arrangement unit 400 can arrange data and key blocks. The multiplexer 410 selects the data block of the initial arranging unit 400, or the data block fed back by the register 450. The multiplexer 420 selects the key block of the initial arrangement unit 400, or the key block that is fed back by the register 450. The combinational logic unit 430 performs an odd number of cyclic encryption operations on the data block and the key block of the multiplexers 410, 420. Combinational logic unit 440 performs an even number of cyclic encryption operations on the data block and the key block of combinational logic unit 430. The registers 450 and 460 store the data block and the key block of the combinational logic unit 440, respectively. The last ranking unit 470 generates an encrypted text block from the data block of the scratchpad 450.
5A and 5B are block diagrams showing the combined logic unit of the unfolded loop encryption function unit.
Referring to FIGS. 5A and 5B, the unfolding loop encryption function unit includes the combination logic unit of FIG. 4, which is a circuit that performs two DES algorithm loop operations. In terms of a timing loop, the main scheduler generates two subkeys K <sub>m</sub> And K <sub>n</sub> , expand the loop encryption function unit using the key K <sub>m</sub> And K <sub>n</sub> , performing two loop operations of the DES algorithm, the algorithm has two encryption functions (XOR) unit f <sub>m</sub> , f <sub>n</sub> And two mutually exclusive or arithmetic units. In other words, the expansion loop encryption function unit receives two subkeys K <sub>m</sub> And K <sub>n</sub> , output data block from scratchpads A and B, and calculate the result R at the next timing <sub>C</sub> And R <sub>D</sub> Output to the corresponding scratchpad.
Figure 6 shows a detailed block diagram of the unfolded loop encryption function unit.
Referring to Figure 6, the expand loop encryption function unit contains two encryption function units. The encryption function unit includes an expansion arrangement unit 610, mutually exclusive or (X-OR) units 620 and 650, an S-Box arrangement unit 630, and a P-Box arrangement unit 640.
Register R <sub>B</sub> 32-bit data block R <sub>B</sub> The expansion is performed by the expansion permutation unit 610 into a 48-bit block. The 48-bit block is mutually exclusive by X-OR or the subkey K of the unit 620 and the main scheduler <sub>m</sub> Perform a mutually exclusive X-ORed or operation. The 48-bit data block is stored by the S-Box array unit 630 and replaced with a 32-bit data block. The 32-bit data blocks of the S-Box arranging unit 630 are arranged by the P-Box arranging unit 640. The 32-bit data of the P-Box arranging unit 640 is mutually exclusive or the unit 650 and the register R <sub>A</sub> The 32-bit block is mutually exclusive X-ORed OR operation, and the 32-bit data block of the mutually exclusive X-OR or unit 650 is stored in the scratchpad R <sub>C</sub> . The expand loop encryption function unit contains one more encryption function, has the same components as above, and outputs another 32-bit data block to the scratchpad R. <sub>D</sub> 。
If the 32-bit data block R <sub>2i-3</sub> , R <sub>2i-2</sub> Stored in scratchpads A, B, the main scheduler provides two subkeys K <sub>2i-1</sub> , K <sub>2i</sub> , in a time series loop, the 32-bit data block R is computed by equations (3) and (4). <sub>2i-1</sub> , R <sub>2i</sub> 。
R <sub>2i-</sub> 1=R <sub>2i-3</sub> f(R <sub>2i-2</sub> , K <sub>2i-1</sub> )i=1,2,...8 (3)R <sub>2i</sub> =R <sub>2i-2</sub> f(R <sub>2i-1</sub> , K <sub>2i</sub> i = 1, 2, ... 8 (4) Figure 7 shows a block diagram of a conventional master scheduler with two key schedule units.
Referring to FIG. 7, the main scheduler includes two key scheduling units, each of which has a first arrangement selection unit 700, two registers 710 and 720, transfer units 730 and 740, and a second arrangement selection. Unit 750.
In the first key scheduling unit, the first schedule selection unit 700 performs the arrangement of the 56-bit key data. Each register (C <sub>m</sub> ) 710 and (D <sub>m</sub> ) 720 stores 28-bit, which is half of the 56-bit key data, in response to timing (CLK). Transfer units 730 and 740 transfer the corresponding 28-bit key data from the scratchpad, respectively, by a predetermined number of bits, such as 2, 3, or 4 bits. The second arrangement selection unit 750 is from the scratchpad (C <sub>m</sub> ) 710 and (D <sub>m</sub> 720 receives two 28-bit key blocks and generates a subkey K <sub>m</sub> . The second key scheduling unit contains the same components and generates a subkey K <sub>n</sub> 。
In terms of eight cycles, the first and second key scheduling units respectively generate subkeys K <sub>2i-1</sub> And K <sub>2i</sub> . In other words, the first key scheduling unit transfers the key block by a predetermined number of bits for eight timing periods, such as 2, 3 or 4 bits, so the total accumulated transfer bit number is 4, 8, 12, 15, 19, 23 and 27. The second key scheduling unit transfers the key block eight timing periods by 2, 3 or 4 bits, so the total accumulated transfer bit numbers are 2, 6, 10, 14, 17, 21, 25 and 28.
Figure 2 shows the master scheduler that generates the subkeys in one sequence cycle, consisting of two registers and two shifters. The master scheduler that generates two subkeys in one timing cycle as described above requires four. A scratchpad and four transferers take up most of the area of the wafer. Therefore, the encryption device is enlarged due to the register and the transfer device.
Summary of invention
Accordingly, it is an object of the present invention to provide a small main scheduler.
According to an aspect of the present invention, a device for using a DES encryption algorithm is provided with a main scheduler, the scheduler comprising: a first arrangement selection unit for arranging 56-bit blocks; a buffer for storing a left 28-bit of the 56-bit block from the first arrangement selection unit according to the timing signal; a second register for storing the 56-bit from the first arrangement selection unit according to the timing signal a 28-bit right side of the metablock; a first and a second transfer unit for transferring the 28-bit block stored in the first and second registers to the left side by the first predetermined-bit number And outputting the 28-bit block to the first and second registers respectively; and a second arrangement selecting unit for arranging the 28-bit blocks stored in the first and second registers, The first sub-key is generated; a third and a fourth transfer unit are configured to transfer the 28-bits stored in the first and second registers to the left side by the second predetermined number of bits; and A three-array selection unit for arranging the 28-bits stored in the third and fourth diverters, thereby generating a second sub-key.
Simple illustration
Other objects and functions described above and in the present invention will become more apparent from the detailed description of the preferred embodiments illustrated in the appended claims
Figure 1 shows a block diagram of a general DES architecture;
Figure 2 shows a block diagram of the main scheduler that generates the subkeys;
3 is a block diagram showing an encryption function unit and an S-Box arrangement unit in a general DES architecture;
Figure 4 shows a block diagram of the DES architecture using the expanded loop encryption functional unit;
5A and 5B are block diagrams showing a combinational logic unit of an unfolded loop encryption function unit;
Figure 6 shows a block diagram of the expansion loop encryption function unit;
Figure 7 shows a block diagram of a conventional master scheduler with two key schedule units;
Figure 8 shows a block diagram of a main scheduler in accordance with an embodiment of the present invention;
Figure 9 shows a block diagram of a main scheduler in accordance with another embodiment of the present invention;
Figure 10 illustrates a timing diagram of a main scheduler operation in accordance with the present invention;
Figure 11 shows a block diagram of a DES architecture using macros and time-division multiplexed functional units in accordance with the present invention;
Figure 12 is a block diagram showing the DES architecture of a macros pipeline and an unrolled loop wafer functional unit in accordance with the present invention;
Figure 13 shows a timing diagram of a DES architecture operation using a macro pipeline and an unrolled loop encryption functional unit;
Figure 14 shows a timing diagram of the effects of a DES architecture using a macro pipeline in accordance with the present invention.
Preferred embodiment of the invention
Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the accompanying drawings.
Figure 8 shows a block diagram of a main scheduler having a key scheduling unit in accordance with an embodiment of the present invention.
Referring to FIG. 8, the main scheduler includes a first permutation selection (PC1) unit 800, two registers 810 and 820, four transfer units 830, 840, 860, 870 and two second permutation options (PC2). Units 850, 880.
The first permutation selection unit 800 performs an arrangement of 56-bit key data blocks. Each register (C <sub>m</sub> , D <sub>m</sub> 810 and 820 store the left and right 28-bits, which are half of the 56-bit key data, and respond to the timing (CLK). The transfer units 830 and 840 transfer the corresponding 28-bit key data from the registers 810 and 820, respectively, by a predetermined number of bits, such as 2, 3 or 4 bits. The second arrangement selection unit 850 is from the scratchpad (C <sub>m</sub> , D <sub>m</sub> ) 810 and 820 receive two 28-bit key blocks and generate subkey K <sub>m</sub> . Transfer units 860 and 870 transfer the corresponding 28-bit key data blocks from registers 810 and 820, respectively, by a predetermined number of bits, such as 1 or 2 bits. The second permutation selection unit 850 receives two 28-bit key blocks from the transfer units 860 and 870, and generates a sub-key K <sub>n</sub> 。
In terms of eight cycles, the main scheduler uses the key scheduling unit to calculate the subkey K in the ith cycle. <sub>2i-1</sub> . Register (C <sub>m</sub> , D <sub>m</sub> 810 and 820 receive and store the initial key from the first arrangement selection unit 800 or the key block transferred from the transfer unit 830, 840 in the next timing cycle. In each cycle, the transfer unit is in the predetermined number of bits S <sub>m</sub> For example, 3, 4, 4, 3, 4, 4, 4, 2 (1) transfer key blocks.
As shown in Figure 8, in the ith cycle, to obtain the subkey K <sub>2i-1</sub> TS <sub>m</sub> Total number of transfer bits and get subkey K <sub>2i</sub> TS <sub>n</sub> The relationship between the total number of transfer bits is: TS <sub>n</sub> -TS <sub>m</sub> =D <sub>m</sub> 。
The table in Figure 8 illustrates the number of bits transferred by the transfer units 830 and 840 in each iteration.
In the first cycle (P <sub>0</sub> ), TS <sub>n</sub> And TS <sub>m</sub> Between D <sub>m</sub> The difference is 1. In the eighth cycle (P <sub>7</sub> ), when storing a new initial key, D <sub>m</sub> The difference is 0, and the difference is 1 when recursing the plain text block using the same key. In other cycles (P <sub>1</sub> To P <sub>6</sub> ), D <sub>m</sub> The difference is 2. Using the additional two diverters 860, 870 and the second permutation selection unit 880, which is done by wiring, the main scheduler calculates the subkey K in the ith cycle <sub>2i-1</sub> And K <sub>2i</sub> And output K <sub>m</sub> And K <sub>n</sub> 。
Figure 9 shows a block diagram of a main scheduler having a key scheduling unit in accordance with another embodiment of the present invention.
Referring to FIG. 9, the main scheduler includes a first permutation selection (PC1) unit 900, two registers 910 and 920, four transfer units 930, 940, 960, 970 and two second permutation options (PC2). Units 950, 980.
The first permutation selection unit 900 performs an arrangement of 56-bit key data blocks. Each register (C <sub>n</sub> , D <sub>n</sub> 910 and 920 store 28-bit, which is half of the 56-bit key block, in response to timing (CLK). Each of the transfer units 930 and 940 transfers the corresponding 28-bit key block from the scratchpad by a predetermined number of bits, such as 2, 3 or 4-bit. The second permutation selection list (PC2) element 950 is from the scratchpad (C <sub>n</sub> , D <sub>n</sub> ) 910 and 920 receive two 28-bit key blocks and generate subkey K <sub>n</sub> . Each of the transfer units 960 and 970 transfers the corresponding 28-bit key block from the registers 910 and 920, respectively, by a predetermined number of bits, such as 2, 3 or 4-bit. The second permutation selection (PC2) unit 950 receives two 28-bit key blocks from the diverters 960 and 970 and generates a subkey K <sub>m</sub> 。
The main scheduler of FIG. 9 calculates the subkey K using the second key scheduling unit of FIG. 7 at the ith cycle. <sub>2i</sub> . As shown in Figure 9, in the ith cycle, to obtain the subkey K <sub>2i-1</sub> TS <sub>m</sub> Total number of transfer bits and get subkey K <sub>2i</sub> TS <sub>n</sub> The relationship between the total number of transfer bits is: TS <sub>m</sub> -TS <sub>n</sub> =D <sub>n</sub> 。
In the first cycle (P <sub>0</sub> ) and the eighth cycle (P <sub>7</sub> ), D <sub>n</sub> The difference is -1. In other cycles (P <sub>1</sub> To P <sub>6</sub> ), D <sub>n</sub> The difference is -2. Using the additional two right side deflectors 960, 970 and the second permutation selection unit 980, which is done by wiring, the main scheduler calculates the subkey K in the ith cycle <sub>2i</sub> And K <sub>2i-1</sub> And output K <sub>n</sub> And K <sub>m</sub> 。
Figure 10 illustrates the timing diagram of the main scheduler operation.
Please refer to Figure 10, K <sub>m</sub> And K <sub>n</sub> The number of subkey accesses representing the 8-cycle DES architecture. TS <sub>m</sub> And TS <sub>n</sub> Represents the number of transition-bits of the initial key block after the first permutation selection unit (PC1). S <sub>m</sub> And S <sub>n</sub> Represents each cycle (P <sub>i</sub> ) transfer - the number of bits to get TS <sub>m</sub> And TS <sub>n</sub> Total transfer - the number of bits.
The procedure for generating the subkey will be explained.
In the first cycle (P <sub>0</sub> ) because TS <sub>m</sub> And TS <sub>n</sub> 1, 2, respectively, to generate the subkey K by transferring the initial key block one and two bits from PC1. <sub>1</sub> And K <sub>2</sub> And arrange the transferred blocks through PC2.
In the second cycle (P <sub>1</sub> ) because TS <sub>m</sub> And TS <sub>n</sub> 4, 6, respectively, for generating subkey K <sub>3</sub> And K <sub>4</sub> Each transfer unit transfers the key block stored in the corresponding register to the left 3 (= 4-1) and 4 (= 6 - 2) bits.
In the third cycle (P <sub>2</sub> ) because TS <sub>m</sub> And TS <sub>n</sub> 8 and 10 respectively, for generating subkey K <sub>5</sub> And K <sub>6</sub> Each transfer unit transfers the key blocks stored in the corresponding register to the left 4 (= 8-4) and 4 (= 10-6) - bits, respectively.
In each cycle (P <sub>i</sub> ), the key block stored in the corresponding register is transferred to the left side S <sub>m</sub> And S <sub>n</sub> - bit in the eighth cycle (P <sub>7</sub> ), the key block transfers TS separately <sub>m</sub> =27 and TS <sub>n</sub> = 28 (=0) bits. Then, in order to return to the first loop, such as TS <sub>m</sub> =1 and TS <sub>n</sub> =2, then S <sub>m</sub> And S <sub>n</sub> Should be 2 respectively.
In general, in many cases, there are many data blocks that need to be encrypted compared to a given key. At this point, using a pipelined structure can promote encryption performance. The pipelines used in the DES architecture can be divided into micro pipelines and macro pipelines according to the application hierarchy.
The data input rate of the DES encryption unit is determined by the speed of the entire encryption system, not the speed of the DES encryption unit. In the case where the DES architecture is used for the network, the macro pipeline is determined by the modulation rate of the modulator, the demodulator, and the speed of the external servo microprocessor.
In general, the data input/output rate of the DES encryption unit is low. Since the data is moved by a byte (8-bit) outside the DES encryption unit, and the DES encryption unit performs encryption processing of the 64-bit data block and outputs the encrypted 64-bit data block, Need to input the scratchpad and output register. In order to reduce the input/output latency, the encryption apparatus of the present invention uses a macro pipeline including input processing (first stage), DES operation processing (second stage), and output processing (third stage). The period of the macro pipeline is determined according to the maximum time of data input, DES operation, and data output. When the data input, DES operation and data output time are the same, the macro pipeline structure has the greatest effect in reducing the waiting time.
Figure 11 is a block diagram showing the DES architecture using the macro pipeline and the time division multiplexing encryption functional unit of the present invention.
Referring to Figure 11, the macro pipeline contains three phases. In phase 1, the input data stream is divided into eight 8-bit blocks, and each of the four 8-bit blocks is sequentially input, collected, and stored in the left input buffer register (IBR(L)) 1110 and the right input. Buffer register (IBR(R)) 1120. Step 2: Each 32-bit data block of the left and right input buffer registers is selectively input to the first and second encryption function units, and encrypted for 8 cycles. In phase three, each 32-bit data block is divided into four 8-bit blocks, through the left output buffer register (OBR(L)) 1140 and the right output buffer register (OBR(R)). 1150, output in 8-bit block.
The time division multiplexing encryption function unit receives 32-bit blocks from the registers A0 and B0, and receives the subkey K from the main scheduler. <sub>A</sub> And K <sub>B</sub> . The encryption function unit f is used during the first half of the first sequence <sub>A</sub> In the second half of the cycle, the encryption function unit f is used. <sub>8</sub> . In other words, the multiplexed time-sharing encryption unit from the scratchpad A0 and the subkey K <sub>A</sub> Receiving a 32-bit data block, and by registering the array unit, the exclusive XOR or unit, the S-Box array unit, and the P-Box array unit, the register A0 and the sub-key K <sub>A</sub> Performs the encryption function and outputs the 32-bit block of the result of the encryption function. Similarly, the time division multiplexing function unit from the scratchpad B0 and the subkey K <sub>B</sub> The 32-bit block is received, and the result of the encryption function operation is output.
In the present invention, two sub-keys K can be generated in one timing cycle. <sub>2i-1</sub> And K <sub>2i</sub> The main scheduler can be used for the 8-cycle DES architecture using the time-sharing multiplex function unit.
Figure 12 is a block diagram showing the DES architecture using the macro pipeline and the unrolled loop encryption functional unit of the present invention.
Referring to Figure 12, the macro pipeline contains three phases. In phase 1, the input data stream is divided into eight 8-bit blocks, and each of the four 8-bit blocks is sequentially input, collected, and stored in the left input buffer register (IBR(L)) 1210 and the right input. Buffer register (IBR(R)) 1220. In phase two, each 32-bit data block of the left and right input buffer registers is encrypted by the expansion loop encryption function unit for 8 cycles. In phase three, each 32-bit data block is divided into four 8-bit blocks, through the left output buffer register (OBR(L)) 1260 and the right output buffer register (OBR(R)). 1270, output in 8-bit block.
In the present invention, two sub-keys K can be generated in one timing cycle. <sub>2i-1</sub> And K <sub>2i</sub> The main scheduler (i = 1, 2, ..., 8) can be used for the 8-cycle DES architecture using the time division multiplexing encryption function unit and the expansion loop encryption function unit.
A conventional master scheduler with two key schedule units, containing four registers that store the initial key block transfer results, occupying a significant area of the wafer.
In the ith cycle, to obtain the subkey K <sub>2i-1</sub> And K <sub>2i</sub> The total number of transfer bits of the initial key block is 1 or 2 bits. The primary scheduler of Figures 8 and 9 can be implemented using one of the key scheduling units of Figure 7. The main scheduler of Figures 8 and 9 utilizes two additional transfer units and an arrangement selection unit (PC2) for obtaining the subkey K <sub>2i-1</sub> And K <sub>2i</sub> Key block to calculate another pair of keys K <sub>2i</sub> And K <sub>2i-1</sub> . Since the total number of transfer bits is not 0 (= 28), in order to avoid the use of the first key schedule unit by the main scheduler of Fig. 8, an additional device is required when storing the initial key. Therefore, the main scheduler of Fig. 8 is larger than the main scheduler of Fig. 9 using only the second key scheduling unit. Because the expansion loop encryption function uses the subkey K <sub>2i-1</sub> Start the encryption function operation, the main scheduler of Figure 9 uses the right shifter to get the subkey K <sub>2i-1</sub> Some of the limit value paths are larger than the main scheduler of FIG.
Figure 13 shows a timing diagram of a DES architecture operation using a macro pipeline and an unrolled loop encryption functional unit.
Referring to Figure 13, the DES architecture sequentially receives the initial arrangement of plain text (y <sub>0</sub> ,z <sub>0</sub> ), (a <sub>0</sub> ,b <sub>0</sub> ), (c <sub>0</sub> ,d <sub>0</sub> ), calculate z <sub>i</sub> ,b <sub>i</sub> ,d <sub>i</sub> (i=1,2,......,16) and calculate (z <sub>16</sub> ,z <sub>15</sub> ), (b <sub>16</sub> ,b <sub>15</sub> ), (d <sub>16</sub> ,d <sub>15</sub> )。
For the sake of explanation, only from (a <sub>0</sub> ,b <sub>0</sub> ) calculate bi and output (b <sub>16</sub> ,b <sub>15</sub> ). After the initial arrangement, the 64-bit plain text is split into two 32-bit blocks a <sub>0</sub> And b <sub>0</sub> . In other words, a <sub>0</sub> =L <sub>0</sub> =R <sub>-1</sub> And b <sub>0</sub> =R <sub>0</sub> . DES encryption unit calculates the value b <sub>1</sub> ,b <sub>2</sub> ,.........,b <sub>16</sub> (b <sub>i</sub> =R <sub>i</sub> ). Calculation b <sub>i</sub> Previously, the subkey K was provided by the main scheduler. <sub>i</sub> Give the encryption function unit.
At t <sub>0</sub> For the first eight cycles, the data entered per bit-bit is collected in the Input Buffer Register (IBR). In [t <sub>0</sub> -t <sub>2</sub> ], the left buffer register (IBR(L)) maintains a <sub>0</sub> , the right buffer register (IBR(R)) maintains b <sub>0</sub> . At the next sequence, each input buffer register collects a tuple of plain text blocks c <sub>0</sub> And d <sub>0</sub> . After eight timing cycles, [t <sub>16</sub> -t <sub>18</sub> Between, input buffer register maintains c <sub>0</sub> And d <sub>0</sub> 。
Output buffer register (OBR) at t <sub>1</sub> Loaded by A0 and B0 <sub>16</sub> And z <sub>15</sub> And at t <sub>1</sub> The bitwise tuple outputs eight rows of inversely arranged data blocks. z <sub>16</sub> And z <sub>15</sub> The data block is maintained at OBR, loaded in t <sub>17</sub> Buffers A and B b <sub>16</sub> And b <sub>1</sub> 5, and maintain eight cycles, while the inverse initial arrangement data from t <sub>17</sub> Bitwise tuple output.
Registered in the input buffer register (IBR) a <sub>0</sub> And b <sub>0</sub> Can be in [t <sub>0</sub> -t <sub>2</sub> ] Inter-access, expand loop encryption to take advantage of the sub-key K of the main scheduler <sub>1</sub> And K <sub>2</sub> In [t <sub>0</sub> -t <sub>2</sub> Calculation, b <sub>1</sub> And b <sub>2</sub> Can be stored in t <sub>2</sub> Registers A and B.
Because registered in B of A and B <sub>1</sub> , b2 can be in [t <sub>2</sub> -t <sub>4</sub> ] Inter-access, expand loop encryption to take advantage of the sub-key K of the main scheduler <sub>3</sub> And K <sub>4</sub> In [t <sub>2</sub> -t <sub>4</sub> Calculation, b <sub>3</sub> And b <sub>4</sub> Can be stored in t <sub>4</sub> Registers A and B.
b <sub>1</sub> And b <sub>2</sub> Is by t <sub>0</sub> Start the calculation, then b <sub>2</sub> ,b <sub>3</sub> ,...,b <sub>15</sub> Each is calculated and stored in the corresponding scratchpad. After eight timings, b <sub>15</sub> And b <sub>16</sub> Stored in t <sub>16</sub> Registers A and B, thus terminating a <sub>0</sub> And b <sub>0</sub> DES operation. At the same time, c <sub>0</sub> And d <sub>0</sub> At t <sub>16</sub> Perform DES operations.
Figure 14 shows a timing diagram of the effects of a DES architecture using a macro pipeline in accordance with the present invention.
Please refer to FIG. 14, which shows the performance comparison results of the 8-cycle pipeline DES architecture and the 16-cycle DES architecture. The wait time represents the timing period necessary to input a plain text block to output an encrypted text block through DES encryption. The total processing power represents a plain text block that is encrypted in one timing cycle.
If the traditional 16-cycle DES architecture does not use a macro pipeline, because the input processing and output processing require 8 timing cycles, respectively, and the DES encryption processing requires 16 timing cycles, a new plain text block can be input every 32 timing cycles. In this case, the wait time is 32 and the total processing power is 1/32.
If a 2-stage macro pipeline is introduced in the input and output processing, the waiting time is 32 as described above, but the input and output processing of the encrypted data is performed simultaneously. Therefore, a new plain text block can be entered every 24 timing cycles with a total processing power of 124.
If a 3-stage macro pipeline is introduced in the input processing, DES encryption processing, and output processing, since the eight timing cycles are idle in the input and output processing, respectively, the waiting time is 40, which is larger than the above, but the total processing The ability is 1/l6. In other words, a new plain text block can be entered and encrypted every 16 timing cycles. Eight cycles of input processing, DES encryption processing, and output processing are performed using the DES architecture of the expansion loop encryption function unit and the time division multiplexing encryption function unit. If a 3-phase macro pipeline is introduced in the DES architecture using the expansion loop encryption function unit and the time division multiplexing encryption function unit, the waiting time is 24, and the total processing capacity is 18, which can be input every 8 timing cycles. Encrypt a new plain text block.
Using a master scheduler with a key scheduling unit reduces the encryption device and thereby reduces the cost of the encryption device.
Although the preferred embodiment of the present invention has been disclosed for the purpose of illustration, the invention may be .
8 members in 5 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 20000032451 | Republic of Korea | A | |
| 20000032451 | – | – | – |
| KR20000032451 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| KR20010111784A | Republic of Korea | A | |
| JP2002040933A | Japan | A | |
| US2002018562A1 | United States of America | A1 | |
| GB2367462A | United Kingdom | A | |
| TW522698BThis record | Taiwan Province of China | B | |
| KR100377172B1 | Republic of Korea | B1 | |
| GB2367462B | United Kingdom | B | |
| US7123720B2 | United States of America | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A | |
| Issue of patent certificate for granted invention patentGrantedGD4A | GD4A |
Numbers
- Publication
- 522698
- Publication, DOCDB
- 522698
- Publication, EPODOC
- TW522698B
- Application
- 90117895
- Application, DOCDB
- 90117895
- Application, EPODOC
- TW20010117895
Titles5
- Chinese
- 使用資料加密標準演算法之加密裝置之主排程器
- English
- KEY SCHEDULER FOR ENCRYPTIONAPPARATUS USING DATA ENCRYPTIONSTANDARD ALGORITHM
- English
- Key scheduler for encryption apparatus using data encryption standard algorithm
- Unlabeled
- 使用資料加密標準演算法之加密裝置之主排程器
- Unlabeled
- Master scheduler for encryption devices using data encryption standard algorithms
Classification
- CPC, 5
- H04L9/0625
- H04L9/06
- H04L2209/122
- H04L2209/125
- H04L2209/24
- IPC, 2
- G09C1 00
- H04L9 06