提出一种专用指令集安全处理器的架构设计和VLSI实现方法,取得了高效的密码运算能力及良好的硬件结构和指令集可扩展性.通过分析对称密码算法和散列算法特点,本文基于低成本RISC结构,提出并行查找表与特殊算术逻辑单元相结合的架构设计方法,并以包含密码学专用指令的指令集与其对应,使密码算法程序代码密度紧凑、执行效率高.本设计可执行SMS4、AES、SHA-1等算法,并提出一种安全存储方法,提高安全处理器系统的抗攻击能力.
An architecture design and VLSI implementation method of application specific instruction set security processor is presented in this paper. The processor in this paper has the advantage of efficient cryptographic computing power as well as excellent extensibility for both hardware architecture and instruction set. Based on thorough analysis of characteristics of symmetric-key and hash algorithms, an architectural design method of combining parallel on-chip lookup tables with special arithmetic logic unit is proposed and implemented by low-cost three-stage pipeline RISC architecture. Dedicated cryptographic instructions are introduced into the 16-bit length reduced instruction set to obtain low code density and high performance of cryptographic processing. Chinese wireless local area network block cipher standard SMS4, NIST encryption standard AES and prevalent hash function SHA-1 are implemented in this processor. A method for secure storage of round key is also proposed and the capacity of resisting to software attack is enhanced for the entire security processor system.