节点文献

SM4字节切片高性能实现

High Performance Implementation of SM4 Byte Slicing

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 龚子睿郭华陈晨张宇轩关振宇

【Author】 GONG Zirui;GUO Hua;CHEN Chen;ZHANG Yuxuan;GUAN Zhenyu;School of Cyber Science and Technology, Beihang University;State Key Laboratory of Complex & Critical Software Environment(CCSE);

【机构】 北京航空航天大学网络空间安全学院复杂关键软件环境全国重点实验室

【摘要】 SM4是中国自主研发的对称密码算法,目前广泛应用于国家政府部门,但其性能问题制约着算法进一步的推广和应用。在现有S盒研究基础上考虑了线性变换L的结构特点,将计算S盒过程中的仿射变换融合至线性变换中,进而提出了新的SM4函数结构。相比于原始的函数结构,提出的新结构在字节切片的适配性上更优,并基于该新结构提出了一种SM4字节切片优化方法,可降低线性部分的开销、提升指令吞吐率。使用GFNI指令集和AES-NI指令集分别实现本文提出的SM4字节切片优化方法,在消耗的指令条数和指令吞吐率方面均优于采用相同指令集的优化方法。实验结果表明,所提出的优化方法采用GFNI指令集的实现速率最高可达到35 947 Mbps,优于公开文献的最好结果30 026 Mbps。在不支持GFNI的处理器上,优化方法可使用AES-NI指令集实现,可以达到5 410 Mbps,因此具备一定的通用性。

【Abstract】 The SM4 is a symmetric cryptographic algorithm independently developed in China, which is widely applied in national governments, but its performance constrains that the algorithm is further popularized and applied. At present, the optimization of the SM4 efficiency is mainly focused on the S-box with the highest computational cost. Scholars propose theoretical optimization methods such as lookup tables and bit slicing, and cooperating with single instruction multiple data technology to improve the high-performance SM4 encryption. On the basis of the S-box and linear transformation L, the affine transformation of calculating S-box process is combined to linear transformation, and a novel SM4 function structure is proposed. Compared with the original function structure, the proposed structure is superior to compatibility for byte slicing. An optimization method for the SM4 byte slicing based on novel structure is proposed, which reduces the overhead of linear part and increase the instruction throughput. Galois field new instruction(GFNI) and AES new instruction(AES-NI) sets are adopted to respectively implement the SM4 byte slicing optimization method proposed in this paper, the proposed optimization method is better than other optimization methods for the same instruction set in the instruction number and instruction throughput. The experimental results show that the encryption speed of the optimization method achieves up to 35 947 Mbps on the GFNI instruction set, which is better than the maximum result of 30 026 Mbps in public literature. the optimization method adopts the AES-NI instruction set to achieve a speed of 5 410 Mbps on unsupported GFNI processors, so it has certain universality.

【基金】 国家重点研发计划(2021YFB2700200);大学生创新创业训练计划(X202210006242);北京市自然科学基金(4242022);国家自然科学基金(62172025,U2241213)
  • 【文献出处】 网络空间安全科学学报 ,Journal of Cybersecurity , 编辑部邮箱 ,2023年03期
  • 【分类号】TP309.7
  • 【下载频次】11
节点文献中: 

本文链接的文献网络图示:

本文的引文网络