Method and device for determining processing parameters for rounding multiplication circuit and modulo multiplication circuit

By using the mapping relationship between the low-bit transformation matrix and the high-bit transformation matrix, the parameter conversion is performed using the anti-angle mapping matrix S, which solves the problem of high parameter configuration cost of rounding multiplication and modular multiplication circuits, and improves the efficiency of modular multiplication operation.

CN120371259APending Publication Date: 2025-07-25ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510404879.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the performance optimization of the modular multiplication operation in encrypted calculations is difficult to effectively improve, especially the parameter configuration cost of rounding multiplication and modular multiplication circuits is relatively high.

Method used

By converting the mapping matrix between the low-bit transformation matrix and the high-bit transformation matrix, the processing parameters of the rounding multiplication and modulus multiplication circuit are determined, and the mapping matrix S in the form of an opposing angle is used to achieve a fast mapping of the low-bit transformation matrix to the high-bit transformation matrix, avoiding the process of searching for determining the low-bit and high-bit transformation matrix respectively.

Benefits of technology

The parameter configuration cost of the modular multiplication and rounding multiplication circuit is saved, and the efficiency of the modular multiplication operation is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371259A_ABST
    Figure CN120371259A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a method and a device for determining processing parameters for a rounding multiplication circuit and a modulo multiplication circuit. The method for determining the processing parameters of the rounding multiplication circuit comprises the steps that a low-order transformation matrix used for modular multiplication is obtained, the target modulus of the modular multiplication is k-th power of r, when the low-order transformation matrix is used for applying combined operation to multiplier segments of two multipliers, the operation result shows a low-order partial segment of a product, and the lower-order partial segment of the product is k-th power of r; wherein the multiplier segment is determined by dividing a multiplier into k segments with a cardinal number of r. Secondly, target transformation is conducted on the low-order transformation matrix through a mapping matrix in an inverse diagonal form, a high-order transformation matrix used for rounding multiplication is obtained, rounding multiplication is conducted on a target modulus, and when the high-order transformation matrix is used for applying the combined operation to a multiplier segment, an operation result shows a high-order part segment of a product; the high-order transformation matrix is used as a processing parameter of the rounding multiplication circuit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of this specification relate to the field of hardware design for encrypted computing, and in particular, to methods and apparatuses for determining processing parameters for a rounding multiplication circuit and a modulo multiplication circuit. Background Art

[0002] With the continuous improvement of people's awareness of data security and privacy protection, privacy computing, as a new type of secure computing mode, is gradually becoming one of the mainstream methods for data processing and analysis. Privacy computing realizes the protection of data privacy and security by directly computing on encrypted or anonymized data without exposing the original data, and has broad application prospects. Currently, privacy computing technology has been widely applied in fields such as artificial intelligence, finance, and healthcare, and has become an important supporting technology for the future digital society.

[0003] Privacy computing relies on the use of various encryption algorithms, including RSA encryption algorithm, elliptic curve ECC encryption algorithm, homomorphic encryption algorithm, and so on. In particular, the homomorphic encryption algorithm has become one of the mainstream technologies in the field of privacy computing, and can perform various common computing operations in the encrypted state while ensuring the correctness of the results and the privacy of the data. Among the above various encryption algorithms, the arithmetic operations are often carried out in a certain modulo space, and the modulo multiplication operation, as a basic operation and primitive, has an important impact on the performance of encrypted computing. Currently, some hardware solutions have been proposed to accelerate the performance of the modulo multiplication operation.

[0004] There is a need for an improved solution to further optimize the implementation process of the basic arithmetic operations related to encrypted computing. Summary of the Invention

[0005] One or more embodiments of this specification describe a method and an apparatus for determining processing parameters for a rounding multiplication circuit and a modulo multiplication circuit, which can save the cost of parameter design and configuration for the modulo multiplication circuit and the rounding multiplication circuit.

[0006] According to a first aspect, a method for determining processing parameters of a rounding multiplication circuit is provided, including:

[0007] Obtain a low-order transformation matrix for modulo multiplication, where the target modulus of the modulo multiplication is the k-th power of r. When the low-order transformation matrix is used to perform a combined operation on the multiplier segments of two multipliers, the operation result shows the low-order part segment of the product, and the multiplier segments are determined by dividing the multiplier into k segments with a radix of r;

[0008] Using a mapping matrix in anti-diagonal form, perform a target transformation on the low-order transformation matrix to obtain a high-order transformation matrix for rounding multiplication, where the rounding multiplication is rounded for the target modulus, and when the high-order transformation matrix is used to apply the combined operation to the multiplier fragments, the operation result shows the high-order part fragment of the product; the high-order transformation matrix is used as the processing parameter of the rounding multiplication circuit.

[0009] In one embodiment, obtaining the low-order transformation matrix for modular multiplication includes: reading, from the configuration parameters of the modular multiplication circuit, the low-order transformation matrix corresponding to the base r and the number of terms k.

[0010] According to one implementation, the low-order transformation matrix includes a low-order evaluation matrix and a low-order interpolation matrix; the high-order transformation matrix includes a high-order evaluation matrix and a high-order interpolation matrix; the combined operation includes: respectively using the high-order / low-order evaluation matrix to act on the first vector formed by the multiplier fragments of the first multiplier and the second vector formed by the multiplier fragments of the second multiplier, multiplying the two obtained vectors bit by bit to obtain an intermediate vector; multiplying the intermediate vector by the high-order / low-order interpolation matrix.

[0011] Further, in one embodiment, performing a target transformation on the low-order transformation matrix includes: right multiplying the mapping matrix to the low-order evaluation matrix as the high-order evaluation matrix; left multiplying the mapping matrix to the low-order interpolation matrix as the high-order interpolation matrix.

[0012] In one example, the elements at the anti-diagonal positions in the mapping matrix are all 1.

[0013] In a preferred embodiment, any element in the low-order evaluation matrix and the high-order evaluation matrix is selected from 0, 1, and -1.

[0014] According to one embodiment, the above method further includes using the obtained high-order transformation matrix as the processing parameter corresponding to the base r and the number of terms k to configure the parameters of the rounding multiplication circuit.

[0015] In one example, the aforementioned modular multiplication circuit and the rounding multiplication circuit are sub-circuits in a modular multiplication circuit.

[0016] According to a second aspect, a method for determining the processing parameter of a modular multiplication circuit is provided, including:

[0017] Obtain a high-order transformation matrix for rounding multiplication, where the target integer for the rounding multiplication is the kth power of r, and when the high-order transformation matrix is used to apply a combined operation to the multiplier fragments of two multipliers, the operation result shows the high-order part fragment of the product, where the multiplier fragments are determined by dividing the multiplier into k fragments with a base of r;

[0018] Using a mapping matrix in anti-diagonal form, perform a target transformation on the high-order transformation matrix to obtain a low-order transformation matrix for modulo multiplication, where the modulo multiplication is modulo with respect to the target integer, and when the low-order transformation matrix is used to apply the combined operation to the multiplier fragments, the operation result shows the low-order partial fragment of the product; the low-order transformation matrix is used as the processing parameter of the modulo multiplication circuit.

[0019] According to a third aspect, there is provided an apparatus for determining the processing parameter of a rounding multiplication circuit, including:

[0020] A first acquisition unit configured to acquire a low-order transformation matrix for modulo multiplication, where the target modulus of the modulo multiplication is the k-th power of r, and when the low-order transformation matrix is used to apply a combined operation to the multiplier fragments of two multipliers, the operation result shows the low-order partial fragment of the product, where the multiplier fragments are determined by dividing the multiplier into k fragments with a radix of r;

[0021] A first transformation unit configured to use a mapping matrix in anti-diagonal form to perform a target transformation on the low-order transformation matrix to obtain a high-order transformation matrix for rounding multiplication, where the rounding multiplication is rounding with respect to the target modulus, and when the high-order transformation matrix is used to apply the combined operation to the multiplier fragments, the operation result shows the high-order partial fragment of the product; the high-order transformation matrix is used as the processing parameter of the rounding multiplication circuit.

[0022] According to a fourth aspect, there is provided an apparatus for determining the processing parameter of a modulo multiplication circuit, including:

[0023] A second acquisition unit configured to acquire a high-order transformation matrix for rounding multiplication, where the target integer of the rounding multiplication is the k-th power of r, and when the high-order transformation matrix is used to apply a combined operation to the multiplier fragments of two multipliers, the operation result shows the high-order partial fragment of the product, where the multiplier fragments are determined by dividing the multiplier into k fragments with a radix of r;

[0024] A second transformation unit configured to use a mapping matrix in anti-diagonal form to perform a target transformation on the high-order transformation matrix to obtain a low-order transformation matrix for modulo multiplication, where the modulo multiplication is modulo with respect to the target integer, and when the low-order transformation matrix is used to apply the combined operation to the multiplier fragments, the operation result shows the low-order partial fragment of the product; the low-order transformation matrix is used as the processing parameter of the modulo multiplication circuit.

[0025] According to a fifth aspect, there is provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed in a computer, the computer is made to execute the method described in the first aspect or the second aspect.

[0026] According to a sixth aspect, a computing device is provided, including a memory and a processor. It is characterized in that executable code is stored in the memory, and when the processor executes the executable code, the method of the first aspect or the second aspect is implemented.

[0027] In the embodiments of this specification, through a mapping matrix, a mapping transformation of a high-order transformation matrix for a rounding multiplication circuit and a low-order transformation matrix for a modulo multiplication circuit is realized. When the low-order transformation matrix is calculated and determined, the high-order transformation matrix can be quickly obtained through the mapping operation of the mapping matrix and configured into the rounding multiplication circuit. Or vice versa, when the high-order transformation matrix is calculated and determined, the low-order transformation matrix can be quickly obtained through the mapping operation of the mapping matrix and configured into the modulo multiplication circuit. In this way, it is not necessary to separately search and determine the low-order transformation matrix and the high-order transformation matrix, saving the cost of parameter configuration for the modulo multiplication circuit and the rounding multiplication circuit. Description of the Drawings

[0028] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0029] Figure 1 Illustrates the algorithm process of modular multiplication using Barrett modular reduction;

[0030] Figure 2 Illustrates the schematic diagram of the principle of the 2-term Schoolbook algorithm;

[0031] Figure 3 Illustrates the schematic diagram of the number of bits during the operation;

[0032] Figure 4 Illustrates the schematic diagram of a modular multiplication circuit according to an embodiment;

[0033] Figure 5 Illustrates the flowchart of the method for determining the processing parameters of a rounding multiplication circuit according to an embodiment;

[0034] Figure 6 Illustrates the flowchart of the method for determining the processing parameters of a modulo multiplication circuit according to an embodiment;

[0035] Figure 7 Illustrates the schematic diagram of parameter transformation in the embodiment;

[0036] Figure 8 Illustrates the schematic diagram of the structure of a rounding multiplication parameter determination device according to an embodiment;

[0037] Figure 9 The structural schematic diagram of a modulo multiplication parameter determination device according to an embodiment is shown. Detailed implementation manners

[0038] The solution provided in this specification will be described below with reference to the accompanying drawings.

[0039] To achieve privacy computing, various encryption algorithms are adopted. In particular, homomorphic encryption has become one of the mainstream technologies in the field of privacy computing because it can perform corresponding mathematical calculations on data in an encrypted state. The operations of homomorphic encryption involve a large number of four arithmetic operations under modulo. The main difficulty of modulo operation lies in that division calculation is involved in the process of calculating the quotient value, and the implementation cost of division is relatively high. For this reason, the Barrett reduction algorithm is proposed. This algorithm achieves an effect similar to division through multiplication and shift operations, thereby improving the efficiency of modulo operation.

[0040] Modulo multiplication is a commonly used operation in encryption systems, that is, after multiplying two integers X and Y, a modulo operation is performed on a modulus M, that is, X * Y mod M. Modulo multiplication can be implemented by a hardware circuit using the Barrett reduction idea.

[0041] Figure 1 The algorithm process of performing modulo multiplication using Barrett modulo reduction is shown. As Figure 1 shown, the inputs of this algorithm include the multiplicands X, Y, the modulus M, and the pre-computed value μ corresponding to the modulus M. It is assumed here that both the multiplicands X and Y are not greater than the modulus M corresponding to the modulo space. And the value range of this modulus M can be expressed as [2 β-1 , 2 N ), where β is a very small constant, for example, 2; N is the maximum bit width supported by the system. In this way, the modulus M can take various values within the bit width N acceptable to the system. The parameters α and t involved in the pre-computed value can be set as needed. Specifically, α and β can be appropriately set so that the Z generated in the 4th line of the algorithm is within the range of [0, 2M), so that in lines 5-6, at most one correction operation is required.

[0042] It can be seen that in the algorithm process of performing modulo multiplication using Barrett reduction, the following operations are relatively high-cost core operations: (1) Conventional multiplication calculation, such as the calculation X * Y shown in the 1st line of the algorithm; (2) Rounding multiplication calculation, that is, calculating the truncated rounding result of the product of two numbers multiplied with respect to the target value in the form of a power of 2, such as the calculation shown in the 3rd line of the algorithm where Denote floor division; (3) Modulo multiplication calculation, that is, calculate the modulo result of the product of two numbers multiplied with respect to the target value in the form of a power of 2. For example, the calculation involved in the 4th row of multiplication is qM mod 2 N+1 .

[0043] Without loss of generality, conventional multiplication can be denoted as AB, and floor multiplication can be denoted as Denote modulo multiplication as AB mod r k , where r = 2 m , and where Denote ceiling division. That is, divide the target value in the form of a power of 2 (when applied to the Figure 1 algorithm, here N may be different from the bit width corresponding to the modulus M) into k segments, each segment with a bit width of m and a base of r for each segment.

[0044] To accelerate the modular multiplication operation, the operation processes and calculation circuits of the above-mentioned conventional multiplication, floor multiplication, and modulo multiplication can be optimized and improved respectively.

[0045] For conventional multiplication, the Karatsuba algorithm can be used for acceleration. According to the k-term Karatsuba algorithm, first divide the multiplier A (and multiplier B) with a bit width of N into k segments, or k words. The bit width of each segment A i is Thus, the multiplier A can be denoted as where r = 2 m is the base for each segment, and A i = A[(i + 1)m - 1:im].

[0046] Thus, the product result C of AB can be calculated by the following formula:

[0047]

[0048] Taking k = 2 as an example, the process of calculating the product C using the Schoolbook algorithm is shown in the following formula:

[0049] C = AB = A1B1r 2 +(A1B0 + A0B1)r + A0B0 (2)

[0050] Figure 2 Shows the schematic diagram of the principle of the 2-term Schoolbook algorithm.

[0051] It can be found that if strictly following the calculation process of formula (2), calculate A i B jTo calculate the sum again, 4 multiplication operations are required. However, for the second term in formula (2), what matters is the product sum A1B0 + A0B1, rather than the individual products. To this end, the product sum can be restored through the following formula:

[0052] A0B1 + A1B0 = -(A0 - A1)(B0 - B1) + A1B1 + A0B0 (3)

[0053] Since formula (3) can reuse the results of A1B1 and A0B0, by calculating the second term in formula (2) using formula (3), the number of multiplication operations required in the calculation process of formula (2) can be reduced to 3 times, thus achieving the optimization of the Karatsuba algorithm.

[0054] Still taking k = 2 as an example, the optimization process of the Karatsuba algorithm can be divided into three stages: the evaluation stage, the multiplication stage, and the interpolation stage. In the preparatory process, the multiplier can be represented as a vector composed of individual multiplier segments (or words), called the multiplier vector. For example, in the case of k = 2, the two multipliers can be represented as the multiplier vectors: A = [A0, A1] T , B = [B0, B1] T .

[0055] In the evaluation stage, the evaluation matrix E is applied to the multiplier vector to obtain the corresponding generated vector. The elements in the generated vector are combinations of multiplier segments and are used as the basis for subsequent multiplications. For example, when k = 2, the 2nd-order evaluation matrix E (2) can take the following form:

[0056]

[0057] Applying this evaluation matrix to the multiplier vector corresponding to multiplier A, the generated vector e corresponding to multiplier A can be obtained as follows A :

[0058]

[0059] Similarly, the generated vector corresponding to multiplier B can also be obtained.

[0060] Then, in the multiplication stage, the generated vector e A corresponding to multiplier A and the generated vector e B corresponding to multiplier B are multiplied bit by bit to obtain the intermediate vector, that is: e = e A ⊙ e B , where ⊙ is the Hadamard operator, representing bit-by-bit multiplication. In the case of k = 2, the obtained intermediate vector e is as follows:

[0061]

[0062] Next, in the interpolation stage, multiply the intermediate vector by the interpolation matrix I, and the resulting vector shows each segment of the product result. In the example where k = 2, the second-order interpolation matrix I (2) can take the following form:

[0063]

[0064] Thus, the resulting vector is shown as follows:

[0065]

[0066] The base vector R = [r 0 , r 1 , r 2 T can be applied to the above result vector, that is, calculate R T ·C, so as to recover the value of the product result C.

[0067] Combining the above three stages, the product calculation process under the k-term Karatsuba algorithm can be summarized as follows:

[0068] C = Karatsuba(A, B) = R T ·I (k) ·((E (k) ·A) ⊙ (E (k) ·B)) (9)

[0069] According to formula (9), pre-construct the transformation matrix under the k-term Karatsuba algorithm, including the evaluation matrix E (k) and the interpolation matrix I (k) . Use the evaluation matrix E (k) to act on the vector composed of the multiplier segments of the multiplier A and the vector composed of the multiplier segments of the multiplier B respectively, multiply the two resulting vectors bit by bit to obtain an intermediate vector; then multiply the intermediate vector by the interpolation matrix I (k) . The resulting vector C thus obtained shows each segment of the product.

[0070] In practice, the construction of the evaluation matrix E (k) and the interpolation matrix I (k) is not unique, and different matrix forms may bring different computational costs, such as different numbers of multiplications.

[0071] The above optimization idea based on the k-term Karatsuba algorithm can also be applied to rounding multiplication and modular multiplication AB mod r k .

[0072] ​It can be understood that according to formula (1), in the k-term Karatsuba algorithm, the product C of AB contains segments from C0 to C 2k-2 The segment subscripts correspond to the orders of r. For the modulo multiplication AB mod r k The segments in the product C with orders higher than k have no influence on the result. Therefore, only the product segments of the low-order part within the k-th order need to be considered. For this purpose, the idea of implementing the k-term Karatsuba algorithm using the transformation matrix can be referred to, and the low-order transformation matrix is constructed. Through similar operations, the low-order part C L in the product result is obtained. Specifically, the low-order k-term Karatsuba algorithm for modulo multiplication can be implemented as follows:

[0073]

[0074] where R L = [r 0 , r 1 , …, r k-1 T .

[0075] Then take the modulus of C L with respect to r k . It can be seen that the process of obtaining the low-order product part using the low-order transformation matrix is similar to the process of implementing conventional multiplication: the low-order evaluation matrix acts on the vector composed of the multiplier segments of the multiplier A and the vector composed of the multiplier segments of the multiplier B respectively, and the two obtained vectors are multiplied bit by bit to obtain the intermediate vector e L ; then multiply this intermediate vector e by the low-order interpolation matrix L . The resulting result vector C L shows the low-order part of the product.

[0076] Still taking k = 2 as an example to describe an example process. In this example, the low-order evaluation matrix and the low-order interpolation matrix can take the following forms respectively:

[0077]

[0078] In this way, the obtained result is:

[0079]

[0080] In the form of formula (11) can further simplify the circuit calculation because in the subsequent calculation of C L with respect to r 2 ​When taking the modulus, e L,1 and e L,2 only the last m bits in the terms need to be considered, that is, only e L,1 mod r and e L,2 mod r need to be considered. Its principle can be illustrated by the digit diagram of Figure 3 .

[0081] It can be understood that r = 2 m is the base or size of a segment, and m is the bit width of a segment. Any e L,i is obtained by multiplying the additive combination of the multiplier segment A i and the additive combination of the multiplier segment B j . The maximum bit width of each additive combination is m + 1 (carry may occur during addition). Therefore, the maximum bit width of e L,i is 2m + 2, slightly exceeding the size of two segments. As shown in Figure 3 , e L,i r is obtained by shifting e L,i one segment to the left. When calculating C L mod r 2 , the part exceeding the size of r 2 has no impact on the result. As shown by the shaded part in the figure, only the white part falling within the range of r 2 has an impact on the result. It can be seen that only the last m bits of e L,i r fall within the range of r 2 .

[0082] Therefore, the modulus of C L can be calculated as:

[0083] C L mod r 2 = e L,0 (r + 1)+(e L,1 mod r)r-(e L,2 mod r)r mod r 2 (13)

[0084] Since only the last m bits of e L,1 and e L,2 need to be considered, their calculation can be implemented by a half - multiplication circuit. The half - multiplication circuit includes a high - order half - multiplication circuit that only calculates the high - order part and a low - order half - multiplication circuit that only calculates the low - order part. In formula (13), the low - order half - multiplication circuit can be used to calculate e L,1 and e L,2 , to obtain e L,1 mod r and e L,2mod r. Compared with the full multiplication circuit that calculates all digits, the half multiplication circuit can save circuit area and calculation cost. The calculation cost of the half multiplication circuit can be considered as 0.5 times of the full multiplication calculation. Correspondingly, by calculating the modular multiplication through formula (13), only the calculation cost of 1 + 2 * 0.5 = 2 full multiplication operations is required. Compared with the 3 multiplications of the 2-term Karatsuba algorithm for realizing conventional multiplication, the cost is further reduced.

[0085] In contrast to modular multiplication, for integer multiplication , the segments in the product C with orders lower than k have no influence on the result, so only the product segments of the high-order part with orders above k need to be considered. For this purpose, similarly referring to the idea of using the transformation matrix (E (k) , I (k) ) to implement the k-term Karatsuba algorithm, a high-order transformation matrix is constructed Through similar operations, the high-order part in the product result is obtained, that is, the high-order product result C U . Specifically, the high-order k-term Karatsuba algorithm for modular multiplication can be implemented as follows:

[0086]

[0087] where R U = [r k-1 , r k , …, r 2k-2 T .

[0088] Then, the quotient of C U divided by r k is calculated through a shift operation. It can be seen that the process of obtaining the high-order product result using the high-order transformation matrix is similar to the process of implementing conventional multiplication: the high-order evaluation matrix is respectively applied to the vector composed of the multiplier segments of the multiplier A and the vector composed of the multiplier segments of the multiplier B, and the two obtained vectors are multiplied bit by bit to obtain the intermediate vector e U ; then the high-order interpolation matrix is multiplied by this intermediate vector e U , and the resulting result vector C U shows the high-order part of the product.

[0089] Similar to optimizing modular multiplication using an appropriate form of , the process of integer multiplication can also be optimized by using an appropriate form of the high-order transformation matrix , including using a high-order half multiplication circuit to calculate partial product terms, thereby reducing the calculation cost.

[0090] In practice, to reduce the search scope, preferably, the elements in the high / low evaluation matrix are constrained to 0, 1, and -1. The interpolation matrix is generated according to the corresponding evaluation matrix and may contain other values.

[0091] Figure 4 A schematic diagram showing a modular multiplication circuit according to an embodiment, which uses the idea of the k-term Karatsuba algorithm to implement Figure 1 the calculation process of modular multiplication by Barrett reduction. As Figure 4 shown, the modular multiplication circuit includes a circuit 11 for regular multiplication, a circuit 12 for rounding multiplication, and a circuit 13 for modular multiplication. Specifically, the inputs of circuit 11 include the multiplicands X and Y. In this circuit, using the evaluation matrix E (k) as the circuit parameter, addition operations are respectively performed on the multiplier segments corresponding to the multiplicands X and Y to obtain the generated vectors e A and e B for each element in. After compression and combination of the generated vectors, using the interpolation matrix I (k) as the parameter, the result T of XY multiplication as shown in the Figure 1 algorithm can be obtained.

[0092] Circuit 12 implements rounding multiplication using the KaratsubaUpper algorithm shown in formula (14). The inputs of circuit 12 include the pre-computed value μ and T obtained by shifting T H (as shown in the second line of the Figure 1 algorithm). In this circuit 12, using the aforementioned high-order evaluation matrix as the circuit parameter, addition operations and corresponding encoding operations are respectively performed on the multiplier segments of the two inputs. After compression and combination of the generated vectors, using the high-order interpolation matrix as the parameter for combination and compression, the rounding multiplication result shown in the third line of the algorithm

[0093] Circuit 13 implements modular multiplication using the KaratsubaLower algorithm shown in formula (10). The inputs of circuit 13 include the modulus M and q output by circuit 12. In this circuit 13, using the aforementioned low-order bit evaluation matrix as the circuit parameter, addition operations and corresponding encoding operations are respectively performed on the multiplier segments of the two inputs. After compression and combination of the generated vectors, using the low-order interpolation matrix as the parameter for combination and compression, the modular multiplication result qM mod 2 N+1 can be obtained.

[0094] Finally, combining this modular multiplication result with T obtained by processing T L(Can be achieved by truncation or shifting). Through basic circuit operations such as shifting and addition, the final modular multiplication result Z can be obtained.

[0095] In other embodiments, circuits 12 and 13 can also be independent circuits dedicated to performing rounding multiplication and modular multiplication.

[0096] It can be understood that the operation of circuit 12 depends on the circuit configuration with the transformation matrix as circuit parameters, and the operation of circuit 13 depends on the circuit configuration with the transformation matrix as circuit parameters. For the same order k, the form of the transformation matrix satisfying the forms of formulas (10) and (14) is not unique. Different forms of transformation matrices can optimize the circuit calculation process to varying degrees. A better form of the transformation matrix, such as the form of formula (11) can adopt more half-multiplication circuits to optimize the circuit calculation and reduce the calculation cost.

[0097] Therefore, exploring a better form of the transformation matrix becomes a direction for optimizing the circuit calculation of modular multiplication / rounding multiplication. When k takes a small value, the dimension of the transformation matrix is limited and the search space is not large; while when k gradually increases, the search space increases exponentially, bringing great difficulties to the determination of the transformation matrix and the configuration of the circuit. In particular, in the case where both modular multiplication and rounding multiplication need to be performed (such as Figure 4 in the modular multiplication circuit), determining and configuring the corresponding transformation matrices for the modular multiplication circuit and the rounding multiplication circuit respectively requires a large amount of calculation cost.

[0098] Through in-depth research, the inventors found that there is a one-to-one mapping relationship between the low-order transformation matrix and the high-order transformation matrix. And through certain mapping operations, the conversion between the low-order transformation matrix and the high-order transformation matrix can be carried out. In this way, when the low-order transformation matrix is determined, the corresponding high-order transformation matrix can be obtained through the mapping operation, and vice versa, thus saving the cost of parameter configuration for the modular multiplication circuit and the rounding multiplication circuit.

[0099] Next, the principle and process of the above mapping operation will be described first.

[0100] According to an embodiment, an anti-diagonal form mapping matrix S can be defined. Preferably, the elements on the anti-diagonal of the mapping matrix S are all 1, and the other elements are all 0. Specifically, the mapping matrix S is as follows:

[0101]

[0102] It can be understood that the inverse matrix S of the above mapping matrix S-1 for itself, because:

[0103]

[0104] Using the above mapping matrix S, define a function f:

[0105] f(E, I) = (E·S, S·I) (17)

[0106] According to formula (17), the input of function f includes the evaluation matrix E and the interpolation matrix I. The function operations include right-multiplying the evaluation matrix E by the mapping matrix S as the transformed evaluation matrix, and left-multiplying the interpolation matrix I by the mapping matrix S as the transformed interpolation matrix.

[0107] It can be easily proved that function f is an invertible function, because:

[0108] f(f(E, I)) = (E·S·S, S·S·I) = (E, I) (18)

[0109] The following demonstrates that when the low-order transformation matrix is input into the above function f, the obtained transformation result can be used as the high-order transformation matrix For this purpose, a transformation multiplier vector A′ = S·A can be calculated first, as shown below:

[0110]

[0111] It can be seen that the transformation multiplier vector A′ actually reverses the order of the elements of the original multiplier vector A. Therefore, the following relationship holds between the two:

[0112] A′ i = A k-1-i (20)

[0113] Next, the low-order transformation matrix can be applied to the transformation multiplier vectors A′ and B′ to calculate the corresponding transformation result vector C L ′:

[0114]

[0115] where

[0116] It can be seen that the transformation result vector C L ′ is composed of the result segments C k-1 , C k , …, C 2k-2 and can be expressed as the mapping matrix S and the high-order result vector C U = [C k-1 , Ck , …, C 2k-2 T The product of:

[0117]

[0118] Thus, the high-order product result can be calculated as follows:

[0119]

[0120] By comparing formula (23) with formula (14), it can be determined that: acts as the high-order interpolation matrix and acts as the high-order evaluation matrix From this, it can be concluded that by inputting the low-order transformation matrix into the above function f, the obtained transformation result can be used as the high-order transformation matrix

[0121] Similarly, it can be correspondingly demonstrated that when the high-order transformation matrix is input into the above function f, the obtained transformation result can be used as the low-order transformation matrix

[0122] The low-order transformation matrix and the high-order transformation matrix that conform to the above function f relationship can be called having an associated correspondence relationship. The following proves that the low-order transformation matrix and the high-order transformation matrix consume the same number of half multiplications and full multiplications.

[0123] Observing the low-order interpolation matrix it can be found that if only the last row element in the i-th column of this matrix is not 0 (the other rows are all 0), then this column will generate the target term e L in the low-order result vector C L,i r k-1 , and this target term is equivalent to e L mod r k in the subsequent modulo operation C L,i mod r, that is, only the last m bits need to be considered. Therefore, this target term can be implemented by a half multiplication circuit.

[0124] It has been proven that there is a mapping relationship defined by the function f between the low-order transformation matrix and the high-order transformation matrix , so there is:

[0125]

[0126] That is, the high-order interpolation matrix ​is obtained by reversing the order of the rows of the low-order interpolation matrix . Thus, if only the last row element in the i-th column of the low-order interpolation matrix is non-zero, it means that only the first row element in the i-th column of the high-order interpolation matrix is non-zero. Then this column will generate the target term e U in the high-order result vector C U,i r k-1 . This target term is equivalent to e U / r in the subsequent rounding and shifting operation C k , that is, only the first m bits need to be considered. Therefore, this target term can be implemented by a semi-multiplication circuit U,i .

[0127] It can be concluded therefrom that the low-order transformation matrix and the high-order transformation matrix with an associated correspondence consume the same number of semi-multiplications and full multiplications. This means that if a low-order transformation matrix with a relatively optimal cost is determined through search in the matrix space, then the high-order transformation matrix obtained through the function f transformation must also be of relatively optimal cost, and vice versa

[0128] . Based on the above research, a method and apparatus for determining the processing parameters of a rounding multiplication circuit and the processing parameters of a modular multiplication circuit are proposed

[0129] Figure 5 FIG. shows a flowchart of a method for determining the processing parameters of a rounding multiplication circuit according to an embodiment. This method can be executed by any circuit, device, platform with computing and processing capabilities. As Figure 5 shown, this method includes the following steps

[0130] In step 52, obtain a low-order transformation matrix for modular multiplication, where the target modulus of the modular multiplication is the k-th power of r; wherein, when using the low-order transformation matrix to perform a combined operation on the multiplier segments of two multipliers, the operation result shows the low-order part segment of the product, and the multiplier segments are determined by dividing the multiplier into k segments with a radix of r

[0131] It can be understood that the low-order transformation matrix is the configuration parameter of the modular multiplication circuit for calculating the modular multiplication AB mod r k , and specifically may include a low-order evaluation matrix and a low-order interpolation matrix . The modular multiplication circuit can use this low-order transformation matrix to perform a combined operation on the multiplier segments of two multipliers to obtain an operation result C L showing the low-order part segment. As described above, this combined operation may include using the low-order evaluation matrix The first vector composed of the multiplier segments of the first multiplier and the second vector composed of the multiplier segments of the second multiplier are multiplied in pairs to obtain an intermediate vector e L ; Multiply the intermediate vector e by the low-order interpolation matrix L to obtain the result vector C showing the low-order partial segments L .

[0132] Here, it is assumed that an appropriate low-order transformation matrix has been determined through pre-computation for the modular multiplication circuit. In one embodiment, the low-order transformation matrix has been configured in the modular multiplication circuit as a circuit processing parameter. At this time, in step 52, the low-order transformation matrix corresponding to the base r and the number of terms k can be read from the configuration parameters of the modular multiplication circuit. In another case, in step 52, the determined low-order transformation matrix can also be read from the computing device that calculates the low-order transformation matrix.

[0133] Next, in step 54, the foregoing low-order transformation matrix is subjected to a target transformation using the mapping matrix S in anti-diagonal form to obtain a high-order transformation matrix for integer multiplication, where the integer multiplication is performed for the foregoing target modulus r k and the obtained high-order transformation matrix is used as a processing parameter of the integer multiplication circuit. When the foregoing combined operation is applied to the multiplier segments, the operation result shows the high-order partial segments of the product.

[0134] Specifically, the high-order transformation matrix is a configuration parameter of the integer multiplication circuit for calculating integer multiplication and may specifically include a high-order evaluation matrix and a high-order interpolation matrix The integer multiplication circuit can use the foregoing high-order transformation matrix to apply the foregoing combined operation to the multiplier segments of the two multipliers to obtain an operation result C showing the high-order partial segments U . As described above, the combined operation may include using the high-order evaluation matrix to act on the first vector composed of the multiplier segments of the first multiplier and the second vector composed of the multiplier segments of the second multiplier respectively, multiplying the two obtained vectors in pairs to obtain an intermediate vector e U ; multiplying the intermediate vector e by the high-order interpolation matrix U to obtain the result vector C showing the high-order partial segments U .

[0135] In one embodiment, the process of subjecting the low-order transformation matrix to a target transformation using the mapping matrix S may include right-multiplying the mapping matrix S by the low-order evaluation matrix as the high-order evaluation matrix and the low-order interpolation matrix Left-multiply the mapping matrix S, which serves as the high-order interpolation matrix

[0136] As described above, the forms of the low-order transformation matrix and the high-order transformation matrix that satisfy relations (10) and (14) are not unique. In some forms, the matrices may contain integer elements with multiple values. Preferably, however, any element in the low-order evaluation matrix and the high-order evaluation matrix is selected from 0, 1, and -1 to simplify the calculation process.

[0137] In a preferred embodiment, the elements at the anti-diagonal positions in the mapping matrix S are all 1, and the remaining positions are all 0. In some embodiments, the elements at the anti-diagonal positions in the mapping matrix S can take an integer p. In this case, after applying the mapping matrix to the target matrix to be transformed, each element in the result can be divided by p to eliminate the influence.

[0138] Optionally, after step 52, the obtained high-order transformation matrix can be used as the processing parameter corresponding to the bit width r and the number of terms k to configure the parameters of the rounding multiplication circuit.

[0139] In one embodiment, the above-mentioned rounding multiplication circuit and modulo multiplication circuit are sub-circuits in the modular multiplication circuit. For example, they can respectively correspond to Figure 4 Circuit 12 and circuit 13 in the modular multiplication circuit shown. In other embodiments, the rounding multiplication circuit and the modulo multiplication circuit can also be independent circuits dedicated to performing rounding multiplication operations and modulo multiplication operations respectively.

[0140] Corresponding to Figure 5 Shown is Figure 6 A flowchart of a method for determining the processing parameters of a modulo multiplication circuit according to an embodiment. This method can be executed by any circuit, device, or platform with computing and processing capabilities. As Figure 6 shown, the method includes the following steps.

[0141] In step 62, obtain the high-order transformation matrix for rounding multiplication, where the target integer for the rounding multiplication is the k-th power of r; wherein, when using the high-order transformation matrix to perform a combined operation on the multiplier segments of two multipliers, the operation result shows the high-order part segment of the product, and the multiplier segments are determined by dividing the multiplier into k segments with a radix of r.

[0142] Next, in step 64, use the mapping matrix S in anti-diagonal form to perform a target transformation on the aforementioned high-order transformation matrix to obtain the low-order transformation matrix for modulo multiplication, where this modulo multiplication is for the aforementioned target integer r kPerform modulo operation, and the obtained low-order transformation matrix is used as the processing parameter of the modulo multiplication circuit. When the foregoing combined operation is applied to the multiplier segment, the operation result shows the low-order part segment of the product.

[0143] Specifically, the high-order transformation matrix includes a high-order evaluation matrix and a high-order interpolation matrix The low-order transformation matrix includes a low-order evaluation matrix and a low-order interpolation matrix The process of performing target transformation on the high-order transformation matrix using the mapping matrix S may include multiplying the high-order evaluation matrix right by the mapping matrix S as the low-order evaluation matrix Multiplying the low-order interpolation matrix left by the mapping matrix S as the high-order interpolation matrix

[0144] For the description of the rounding multiplication circuit, the modulo multiplication circuit, the high-order transformation matrix, the low-order transformation matrix, and the combined operation process, reference can be made to the foregoing description in conjunction with Figure 5 and will not be repeated here.

[0145] Figure 7 A schematic diagram showing the parameter transformation in the embodiment is shown. Figure 7 As shown, the modulo multiplication circuit 71 uses the low-order transformation matrix as the circuit parameter to perform the modulo multiplication AB mod r k The rounding multiplication circuit 72 uses the high-order transformation matrix as the circuit parameter to perform the rounding multiplication According to the embodiments of the present specification, the mapping transformation between the high-order transformation matrix and the low-order transformation matrix can be realized through the mapping matrix S. When the low-order transformation matrix is calculated and determined, the high-order transformation matrix can be quickly obtained through the mapping operation of the mapping matrix S and configured into the rounding multiplication circuit. Or vice versa, when the high-order transformation matrix is calculated and determined, the low-order transformation matrix can be quickly obtained through the mapping operation of the mapping matrix S and configured into the modulo multiplication circuit. In this way, there is no need to separately search and determine the low-order transformation matrix and the high-order transformation matrix, saving the cost of parameter configuration for the modulo multiplication circuit and the rounding multiplication circuit.

[0146] According to an embodiment of another aspect, a device for determining the processing parameter of a rounding multiplication circuit is provided. Figure 8The structural schematic diagram of a rounding multiplication parameter determination device according to an embodiment is shown. This device can be deployed in any device, platform, or device cluster with data storage, computing, and processing capabilities. As Figure 8 shown, the rounding multiplication parameter determination device 800 includes:

[0147] A first acquisition unit 82, configured to acquire a low-order transformation matrix for modular multiplication, where the target modulus of the modular multiplication is the k-th power of r. When a combined operation is applied to the multiplier segments of two multipliers using the low-order transformation matrix, the operation result shows the low-order partial segment of the product, and the multiplier segments are determined by dividing the multiplier into k segments with a radix of r;

[0148] A first transformation unit 84, configured to perform a target transformation on the low-order transformation matrix using an anti-diagonal form mapping matrix to obtain a high-order transformation matrix for rounding multiplication. The rounding multiplication is rounded with respect to the target modulus, and when the combined operation is applied to the multiplier segments using the high-order transformation matrix, the operation result shows the high-order partial segment of the product; the high-order transformation matrix is used as the processing parameter of the rounding multiplication circuit.

[0149] According to an embodiment of another aspect, a device for determining the processing parameter of a modular multiplication circuit is provided. Figure 9 The structural schematic diagram of a modular multiplication parameter determination device according to an embodiment is shown. This device can be deployed in any device, platform, or device cluster with data storage, computing, and processing capabilities. As Figure 9 shown, the modular multiplication parameter determination device 900 includes:

[0150] A second acquisition unit 92, configured to acquire a high-order transformation matrix for rounding multiplication, where the target integer of the rounding multiplication is the k-th power of r. When a combined operation is applied to the multiplier segments of two multipliers using the high-order transformation matrix, the operation result shows the high-order partial segment of the product, and the multiplier segments are determined by dividing the multiplier into k segments with a radix of r;

[0151] A second transformation unit 94, configured to perform a target transformation on the high-order transformation matrix using an anti-diagonal form mapping matrix to obtain a low-order transformation matrix for modular multiplication. The modular multiplication is modulo with respect to the target integer, and when the combined operation is applied to the multiplier segments using the low-order transformation matrix, the operation result shows the low-order partial segment of the product; the low-order transformation matrix is used as the processing parameter of the modular multiplication circuit.

[0152] The implementation manners of each unit in the above device can be referred to in combination with the description of the method embodiments. Through the above device, it is possible to convert between the processing parameters of the modulo multiplication circuit and the processing parameters of the rounding multiplication circuit, saving the cost of parameter configuration for the modulo multiplication circuit and the rounding multiplication circuit.

[0153] According to an embodiment of another aspect, there is also provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed in a computer, the computer is made to execute the method described in combination with Figure 5 and / or Figure 6 .

[0154] According to an embodiment of still another aspect, there is also provided a computing device, including a memory and a processor. An executable code is stored in the memory. When the processor executes the executable code, the method described in combination with Figure 5 and / or Figure 6 is implemented.

[0155] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the present invention can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium.

[0156] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for determining processing parameters of a rounding multiplication circuit, comprising: Obtaining a low-order transformation matrix for modular multiplication, where the target modulus of the modular multiplication is the k-th power of r. When a combined operation is applied to multiplier segments of two multipliers using the low-order transformation matrix, the operation result shows the low-order partial segment of the product, and the multiplier segments are determined by dividing a multiplier into k segments with a radix of r; Using a mapping matrix in anti-diagonal form to perform a target transformation on the low-order transformation matrix to obtain a high-order transformation matrix for rounding multiplication. The rounding multiplication is rounded with respect to the target modulus. When the combined operation is applied to the multiplier segments using the high-order transformation matrix, the operation result shows the high-order partial segment of the product; the high-order transformation matrix is used as a processing parameter of the rounding multiplication circuit.

2. The method according to claim 1, wherein, Obtaining a low-order transformation matrix for modular multiplication includes: Reading, from the configuration parameters of the modular multiplication circuit, the low-order transformation matrix corresponding to the radix r and the number of terms k.

3. The method according to claim 1, wherein The low-order transformation matrix includes a low-order evaluation matrix and a low-order interpolation matrix; The high-order transformation matrix includes a high-order evaluation matrix and a high-order interpolation matrix; The combined operation includes: Using the high / low-order evaluation matrix to act on a first vector composed of multiplier segments of a first multiplier and a second vector composed of multiplier segments of a second multiplier respectively, multiplying the two obtained vectors bit by bit to obtain an intermediate vector; Multiplying the intermediate vector by the high / low-order interpolation matrix.

4. The method according to claim 3, wherein, Performing a target transformation on the low-order transformation matrix includes: Right-multiplying the mapping matrix by the low-order evaluation matrix as the high-order evaluation matrix; Left-multiplying the mapping matrix by the low-order interpolation matrix as the high-order interpolation matrix.

5. The method according to claim 1, wherein, The elements at the anti-diagonal positions in the mapping matrix are all 1.

6. The method according to claim 3, wherein Any element in the low-order evaluation matrix and the high-order evaluation matrix is selected from 0, 1, and -1.

7. The method according to claim 1, further comprising configuring the parameters of the rounding multiplication circuit by using the high-order transformation matrix as the processing parameter corresponding to the radix r and the number of terms k.

8. The method according to claim 7, wherein, The low-order transformation matrix is obtained from the configuration parameters of the modular multiplication circuit; the modular multiplication circuit and the rounding multiplication circuit are sub-circuits in a modular multiplication circuit.

9. A method for determining processing parameters of a modular multiplication circuit, comprising: Obtaining a high-order transformation matrix for rounding multiplication, where the target integer of the rounding multiplication is the k-th power of r. When a combined operation is applied to multiplier segments of two multipliers using the high-order transformation matrix, the operation result shows the high-order partial segment of the product, and the multiplier segments are determined by dividing a multiplier into k segments with a radix of r; Using a mapping matrix in anti-diagonal form to perform a target transformation on the high-order transformation matrix to obtain a low-order transformation matrix for modular multiplication. The modular multiplication is modulo with respect to the target integer. When the combined operation is applied to the multiplier segments using the low-order transformation matrix, the operation result shows the low-order partial segment of the product; the low-order transformation matrix is used as a processing parameter of the modular multiplication circuit.

10. The method according to claim 9, wherein, Obtain a high-order transformation matrix for rounding multiplication, including: Read the high-order transformation matrix corresponding to the radix r and the number of terms k from the configuration parameters of the rounding multiplication circuit.

11. The method according to claim 9, wherein, The low-order transformation matrix includes a low-order evaluation matrix and a low-order interpolation matrix; The high-order transformation matrix includes a high-order evaluation matrix and a high-order interpolation matrix; The combined operation includes: Use the high-order / low-order evaluation matrices to act on the first vector formed by the multiplier segments of the first multiplier and the second vector formed by the multiplier segments of the second multiplier respectively, multiply the two obtained vectors bit by bit to obtain an intermediate vector; Multiply the intermediate vector by the high-order / low-order interpolation matrix.

12. The method according to claim 11, wherein, Perform a target transformation on the high-order transformation matrix, including: Right-multiply the high-order evaluation matrix by the mapping matrix to serve as the low-order evaluation matrix; Left-multiply the high-order interpolation matrix by the mapping matrix to serve as the low-order interpolation matrix.

13. An apparatus for determining the processing parameters of a rounding multiplication circuit, including: A first obtaining unit configured to obtain a low-order transformation matrix for modulo multiplication, where the target modulus of the modulo multiplication is the k-th power of r. When a combined operation is applied to the multiplier segments of two multipliers using the low-order transformation matrix, the operation result shows the low-order partial segment of the product, where the multiplier segments are determined by dividing the multiplier into k segments with a radix of r; A first transformation unit configured to perform a target transformation on the low-order transformation matrix using a mapping matrix in anti-diagonal form to obtain a high-order transformation matrix for rounding multiplication, where the rounding multiplication is rounded with respect to the target modulus, and when the combined operation is applied to the multiplier segments using the high-order transformation matrix, the operation result shows the high-order partial segment of the product; the high-order transformation matrix is used as the processing parameter of the rounding multiplication circuit.

14. An apparatus for determining the processing parameters of a modulo multiplication circuit, including: A second obtaining unit configured to obtain a high-order transformation matrix for rounding multiplication, where the target integer of the rounding multiplication is the k-th power of r. When a combined operation is applied to the multiplier segments of two multipliers using the high-order transformation matrix, the operation result shows the high-order partial segment of the product, where the multiplier segments are determined by dividing the multiplier into k segments with a radix of r; A second transformation unit configured to perform a target transformation on the high-order transformation matrix using a mapping matrix in anti-diagonal form to obtain a low-order transformation matrix for modulo multiplication, where the modulo multiplication is modulo with respect to the target integer, and when the combined operation is applied to the multiplier segments using the low-order transformation matrix, the operation result shows the low-order partial segment of the product; the low-order transformation matrix is used as the processing parameter of the modulo multiplication circuit.

15. A computing device, comprising a memory and a processor, characterized in that, The memory stores executable code, and when the processor executes the executable code, the method described in any one of claims 1-12 is implemented.

Citation Information

Cited By

  • RRAM-based polynomial modular multiplication acceleration method and accelerator, electronic equipment and storage medium

    CN120832961A