Method, device and chip for number-theory transformation
By setting the rotation factor to multiple subsets and performing predetermined combined calculations, the problem of high storage demand in traditional number theory transformation is solved, and the optimization of storage space and computing performance is achieved.
Patent Information
- Application Number
- CN202510491001.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-08-05
AI Technical Summary
In the traditional number theory transformation method, the storage demand for rotation factors is high, resulting in low computing efficiency and difficult to meet the high-performance computing needs.
The rotation factor is set to multiple subsets, and the required rotation factor is generated by a predetermined combination of the sub-rotation factor, reducing the storage amount while keeping the calculation efficiency unaffected.
Without affecting the computing efficiency, the storage requirements of rotation factors are significantly reduced, and the storage space and computing performance are optimized.
Smart Images

Figure CN120429533A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer digital operations, and more specifically, to a method, device and chip for number theory transformation. Background Art
[0002] With the advancement of quantum computing technology, traditional public-key cryptography faces severe security challenges, driving research on security solutions and other related technologies into the post-quantum cryptography era. Lattice-based cryptographic schemes, such as Dilithium and Aigis, are considered the most promising post-quantum cryptographic algorithms for public-key encryption and digital signatures due to their high security and fast computational speed. The computational bottleneck of lattice cryptographic schemes is polynomial multiplication. Traditional computational methods are inefficient, so most research uses number theoretic transforms (NTTs) to implement polynomial multiplication, thereby reducing computational complexity.
[0003] For example, in the definition of Z q [X] / (X 256 +1) polynomial f(x)=a0+a1x+a2x 2 +…+a 255 x 255 When calculating the multiplication of polynomials on the ring, number theory transformations are often used. And, and, expressed by coefficients (a0, a1, ..., a 255 ) to the interpolation point expression (f(ω 1 ),f(ω 3 ),…f(ω 511 )) is the transformation operation (NTT), correspondingly, (f(ω 1 ),f(ω 3 ),…f(ω 511 )) to (a0,a1,…,a 255 ) process is the inverse transform operation (invNTT). That is, the number theory transform is an algorithm for fast polynomial multiplication over a finite field, and the rotation factor plays a key role in the number theory transform operation, which is similar to the complex unity root in the fast Fourier transform (FFT). For example, take 256 different interpolation points (ω 1 ,ω 3 ,ω 5 ,…,ω 511 ), where ω satisfies ω 512 =1modq, where ω p (p=1,3,5,…,511) are called rotation factors.
[0004] Figure 1 The figure shows a schematic diagram of an existing device for number theory transformation. Figure 1As shown, the existing apparatus for number theory transformation includes an operation unit for performing a transformation operation (NTT) and an inverse transformation operation (invNTT) and a unit for storing a rotation factor (ω p ) of the rotation factor memory. Each time a transform operation (NTT) or an inverse transform operation (invNTT) is performed, the operation unit obtains the corresponding rotation factor (ω p ) for operation.
[0005] Specifically, in specific application scenarios and parameter selections, when the degree of the polynomial being processed or the data size necessitates a predetermined number of different twiddle factors to complete NTT and invNTT calculations, it is necessary to store these twiddle factors. Furthermore, these twiddle factors are typically pre-calculated and stored in the circuit's memory unit for rapid access and use during NTT and invNTT calculations, thereby improving computational efficiency.
[0006] On the other hand, the number theory transformation method can also be improved by improving the calculation and storage mechanism of the rotation factors. Summary of the Invention
[0007] To address the above technical issues, the present application is proposed. Embodiments of the present application provide a method, device, and chip for number-theoretic transformations, which reduce storage requirements without compromising computational efficiency by storing twiddle factors as multiple subsets and generating twiddle factors for transform and inverse transform operations using predetermined combinations of sub-twiddle factors in the subsets.
[0008] According to one aspect of the present application, a method for number theoretic transformation is provided, comprising: setting and storing at least two sub-rotation factor sets having a predetermined number for a rotation factor set used for a transformation operation and an inverse transformation operation of the number theoretic transformation, wherein the sum of the predetermined number of sub-rotation factors in the sub-rotation factor sets is less than the number of rotation factors in the rotation factor set; and generating each rotation factor in the rotation factor set by a predetermined combination calculation of the sub-rotation factors in the at least two sub-rotation factor sets, wherein a first calculation time for the transformation operation or the inverse transformation operation of the number theoretic transformation is greater than or equal to a second calculation time for the predetermined combination calculation.
[0009] In the above method for number theory transformation, the at least two sub-rotation factor sets include a first sub-rotation factor set and a second sub-rotation factor set, and the rotation factor is represented by ω p , the first sub-twist factor in the first sub-twist factor set is ω x , the second sub-twist factor in the second sub-twist factor set is ω y, and the predetermined combination is calculated as ω p =ω x ×ω y , where × is a modular multiplication operation.
[0010] In the above method for number theory transformation, p = m × n, and m ≥ n, m ≥ 2, n ≥ 2, then x = m × 0, m × 1, ..., m × (n-1), y = 0, 1, ..., n-1.
[0011] In the above method for number theory transformation, the number of p is And the number of x and y are
[0012] In the above method for number theory transformation, the value of p is 0 to 255, the value of x is 16*m, m=0 to 15, and the value of y is 0 to 15.
[0013] According to another aspect of the present application, an apparatus for number theoretic transformation is provided, comprising: a rotation factor storage unit for storing, for each rotation factor set used for a transformation operation and an inverse transformation operation of the number theoretic transformation, at least two sub-rotation factor sets having a predetermined number, wherein the sum of the predetermined number of sub-rotation factors in the sub-rotation factor sets is less than the number of rotation factors in the rotation factor set; and a rotation factor calculation unit for generating each rotation factor in the rotation factor set by performing a predetermined combination calculation of the sub-rotation factors in the at least two sub-rotation factor sets, wherein a first calculation time of the transformation operation or the inverse transformation operation of the operation unit is greater than or equal to a second calculation time of the predetermined combination calculation of the rotation factor calculation unit.
[0014] In the above-mentioned apparatus for number theory transformation, it further comprises: an operation unit, which is used to perform the transformation operation from input data to output data and the inverse transformation operation from output data to input data;
[0015] The above-mentioned device for number theoretic transformation further includes: a rotation factor storage unit for temporarily storing the rotation factor generated by the rotation factor calculation unit through the predetermined combined calculation, for use in the parallel transformation operation or the inverse transformation operation of the operation unit.
[0016] In the apparatus for number-theoretic transformation, the at least two sub-rotation factor sets include a first sub-rotation factor set and a second sub-rotation factor set, the first sub-rotation factor set being stored in a first random access memory element of the rotation factor storage unit, the second sub-rotation factor set being stored in a second random access memory element, and the rotation factor calculation unit being a modular multiplier of the first sub-rotation factor and the second sub-rotation factor.
[0017] According to another aspect of the present application, a chip for number-theoretic transformation is provided, comprising the apparatus for number-theoretic transformation as described above.
[0018] Compared with the prior art, the method, device and chip for number theoretic transformation provided by the present application can generate the rotation factors for the transformation operation and inverse transformation operation of the number theoretic transformation by setting the rotation factors into multiple subsets for storage, and generating the rotation factors for the transformation operation and inverse transformation operation of the number theoretic transformation by predetermined combination calculation of the sub-rotation factors in the subsets, thereby reducing the storage amount without affecting the computational efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0020] Figure 1 The figure shows a schematic diagram of an existing device for number theory transformation.
[0021] Figure 2A and Figure 2B Examples of a CT_BF module that performs a transform operation and a GS_BF module that performs an inverse transform operation in an operation unit in an apparatus for number theoretic transform are respectively illustrated.
[0022] Figure 3 A schematic diagram illustrating an example of a MAE implementation of an arithmetic unit in a device for number theoretic transformation is shown.
[0023] Figure 4 A schematic diagram illustrating an example of an existing apparatus for number-theoretic transformation including 128 parallel AEs is shown.
[0024] Figure 5 The figure shows a schematic flow chart of a method for number theory transformation according to an embodiment of the present application.
[0025] Figure 6 The figure shows a schematic block diagram of a device for number-theoretic transformation according to an embodiment of the present application.
[0026] Figure 7 The diagram shows a device for number theory transformation according to an embodiment of the present application. Figure 4 Schematic diagram of the corresponding specific example.
[0027] Figure 8 The figure shows a schematic block diagram of a chip for number theory transformation according to an embodiment of the present application. DETAILED DESCRIPTION
[0028] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.
[0029] As described above, the apparatus for number theoretic transformation includes an operation unit for performing a transformation operation (NTT) and an inverse transformation operation (invNTT). In one example, the operation unit can be constructed as a CT_BF module, and the inverse transformation unit can be constructed as a GS_BF. Figure 2A and Figure 2B Examples of a CT_BF module that performs a transform operation and a GS_BF module that performs an inverse transform operation in an operation unit in an apparatus for number theoretic transform are respectively illustrated.
[0030] As shown in Figure 2, the CT_BF module is used to perform a transform operation (NTT). For example, when the input data is (a, b) and the rotation factor is ω, the output data is (a+bω, a-bω). The GS_BF module is used to perform an inverse transform operation (invNTT). When the input data is (c, d) and the rotation factor is ω, the output data is ((c+d) / 2, (dc)*ω / 2).
[0031] In practical applications, the operation unit for performing the transformation operation (NTT) and the inverse transformation operation (invNTT) is implemented as a MAE (Multiple Arithmetic Element: MAE) composed of multiple parallel basic operators (Arithmetic Element: AE). For example, Figure 3 FIG2 shows a schematic diagram of an example of a MAE implementation of an arithmetic unit in a device for number theoretic transformation. Figure 3 As shown, the MAE includes 128 parallel AEs from AE0 to AE127, wherein each AE includes an operation module for performing a transform operation (NTT) and an inverse transform operation (invNTT).
[0032] Furthermore, those skilled in the art will appreciate that the number of basic operators (AE) in the arithmetic unit of the apparatus for number theoretic transformation is not limited to 128, but may also be 16, 32, 64, etc. Thus, when each arithmetic unit requires two rotation factors to perform a transformation operation (NTT) and an inverse transformation operation (invNTT), in the apparatus for number theoretic transformation, the number of rotation factors is twice the number of basic operators in parallel in the arithmetic unit. That is, when the number of basic operators (AE) in the arithmetic unit of the apparatus for number theoretic transformation is 128, the number of rotation factors is 256, i.e., the rotation factor ω is ω.p , p=0~255.
[0033] Figure 4 FIG. 1 shows a schematic diagram of an example of an existing apparatus for number theory transformation including 128 parallel AEs. Figure 4 As shown, in the case of an MAE (Main Arithmetic Element) consisting of 128 elementary operators (AEs), register files 1 / 2 are used to store input data, with the MAE's A input / output port connected to the first 128 elements of register file 1 / 2, and the B input / output port connected to the last 128 elements of register file 1 / 2. Register file 2 / 1 is used to store input data, with the MAE's C input / output port connected to the even-numbered elements of register file 2 / 1, and the MAE's D input / output port connected to the odd-numbered elements of register file 2 / 1. When performing a transform operation (NTT), data enters from A and B and exits from C and D. When performing an inverse transform operation (invNTT), data enters from C and D and exits from A and B. Twiddle factors are obtained from a twiddle factor random access memory (RAM) as operation parameters required for the transform operation (NTT) and the inverse transform operation (invNTT).
[0034] Specifically, if Figure 4 The process of performing the transformation operation (NTT) by the apparatus for number theory transformation shown is as follows:
[0035] The coefficients of f(x) (f0,f1,…,f 255 ) fills 1 / 2 of the register file, and then performs 8 rounds of iterations. Each round of iteration always follows these steps:
[0036] From register stack 1 / 2, which is the current input register stack, position (i, i+128) is taken and input into the CT_BF module in AE through the A and B input / output ports. The corresponding rotation factor is selected and the calculation result is filled into position (2i, 2i+1) in register stack 2 / 1, which is the target output register stack, through the C and D input / output ports. When all 256 positions in register stack 2 / 1 are filled, register stack 2 / 1 becomes the current input register stack in the next round, and register stack 1 / 2 becomes the target output register stack. Then the next round of iteration begins until 8 rounds of iteration are completed.
[0037] The process of performing the inverse transform operation (invNTT) by the apparatus for number theory transform is as follows:
[0038] Perform 8 rounds of iterations, and each round of iteration always follows the following rules:
[0039] Take the element at position (2i, 2i+1) of register stack 2 / 1, which is the current input register stack, and input it into the GS_BF module in AE through the C and D input / output ports. Select the corresponding rotation factor, and fill the calculation result into position (i, i+128) of register stack 1 / 2, which is the target register stack, through the A and B input / output ports. When all 256 positions in the target register stack are filled, register stack 1 / 2 becomes the current input register stack in the next round, and register stack 2 / 1 becomes the target output register stack. Then the next round of iteration begins, and this continues until 8 rounds of iteration are completed.
[0040] In addition, during the above transformation operation (NTT) / inverse transformation operation (invNTT), the rotation factor is set as follows:
[0041] First, define the BitInv concept:
[0042] If Bit(m,T)=(b0b1…b T-1 ), where m is the decimal number and T is the number of bits, then BitInv(m,T)=(b T-1 b T-2 ...b0), for example, in the case of Bit(19,5)=(10011), BitInv(19,5)=(11001)=Bit(25,5).
[0043] In the xth iteration of the transformation operation (NTT), the rotation factor z=ω used when the position (y,y+128) participates in the CT_BF calculation p , where p = (2k + 1) × 2 8-x , k = BitInv(y%2 x-1 ,x-1), where % represents the modulo operation.
[0044] In the xth iteration of the inverse transform operation (invNTT), when the position (2y, 2y+1) participates in the GS_BF calculation, its corresponding rotation factor z=ω p , where p = 256-(2k+1)*2 X-1 , where k = BitInv(y%2 8-x ,8-x).
[0045] That is, when the transformation calculation in the method and apparatus for number theory transformation includes 8 rounds of iterative calculation, the number of rotation factors required for each round of iterative calculation is 2 i-1, where i represents the i-th iteration, i = 1-8. Furthermore, the transformation operation takes as input (a, b) and a rotation factor ω and outputs (a+bω, a-bω), and the inverse transformation for the number-theoretic transformation is calculated as input (c, d) and a rotation factor ω and outputs [(c+d) / 2, (dc)*ω / 2].
[0046] Then in the i-th iteration of the transformation operation, when the (y,y+128)th position in the register stack 1 / 2 participates in the calculation, the rotation factor is ω p , where p = (2k+1)*2 8-i , k = BitInv(y%2 i-1 ,i-1), and % represents the modulo operation, and BitInv represents the decimal value obtained by reversing the binary string.
[0047] In the i-th iteration of the inverse transform operation, when the (2y, 2y+1)th position in the register pair 2 / 1 participates in the calculation, the rotation factor is ω p , where p = 256-(2k+1)*2 i-1 , k = BitInv(y%2 8-i ,8-i), and % represents the modulo operation, and BitInv represents the decimal value obtained by reversing the binary string.
[0048] Therefore, based on the above-mentioned rotation factor ω p The calculation process of the operation unit is as a MAE including 128 AEs, and a total of 255 rotation factors are required in 8 rounds of iterative calculations:
[0049]
[0050] Therefore, the rotation factor power p here takes a value in the range of 0 to 255, that is, it can be represented by 8 bits. In this case, the applicant of this application considers that the rotation factor ω can be p Set to ω x ×ω y , where × is a modular multiplication operation. Here, the value range of x is {16*0,16*1,16*2,..,16*15}, the value range of y is {0,1,2,..,15}, and ω x The value of and ω y The values of are stored separately, for example, ω x Stored in x random access memory (X_RAM), ω y Stored in y random access memory (Y_RAM), or, ω x and ω y It can also be stored in physically identical but logically different memories, i.e.x and ω y They can also be stored in the same physical memory, but logical storage isolation is achieved.
[0051] Here, in the method for number theory transformation according to an embodiment of the present application, the rotation factor is not directly obtained from the memory, but the rotation factor is set to two or more sub-rotation factor sets and calculated by a predetermined combination, such as ω as described above. p =ω x ×ω y Moreover, those skilled in the art will appreciate that, in the embodiments of the present application, the present invention is not limited to a set including two sub-rotation factors, but may include a set including more than two sub-rotation factors, as long as the sum of the predetermined number of sub-rotation factors in the sub-rotation factor set is less than the number of rotation factors in the rotation factor set. For example, in the above example, the rotation factor ω p The number of is 256, and the sub-twiddle factor ω x and ω y The sum of the number of twiddle factors is 16+16=32. In this way, the storage space of the twiddle factors can be reduced.
[0052] Furthermore, in the method for number theory transformation according to the embodiment of the present application, it is also necessary to consider the predetermined combined calculation of the sub-rotation factors. Here, those skilled in the art can understand that although the above sub-rotation factor ω x and ω y The modular multiplication operation is used as an example to illustrate the predetermined combined calculation, but depending on the setting method of the sub-rotation factor, the predetermined combined calculation can also be other calculation methods. However, considering that the computational efficiency of the operation unit will not be reduced due to the predetermined combined calculation of the sub-rotation factor, if the transformation operation (NTT) or inverse transformation operation (invNTT) of the number-theoretic transformation performed by the operation unit has a first calculation time, and the predetermined combined calculation has a second calculation time, then the first calculation time is greater than or equal to the second calculation time. In this way, the calculation of the next round of rotation factors can be completed during the current iteration process of the transformation operation (NTT) or inverse transformation operation (invNTT) performed by the operation unit, thereby avoiding the reduction of the computational efficiency of the operation unit due to the calculation of the rotation factor. That is, while reducing the storage space of the rotation factor, there is no increase in the calculation time of the number-theoretic transformation due to the newly added predetermined combined calculation, thereby avoiding the decline in computing performance and achieving optimization of storage space and computing performance.
[0053] Based on this, the method for number theoretic transformation according to an embodiment of the present application includes: setting and storing at least two sub-rotation factor sets with a predetermined number for a rotation factor set used for a transformation operation and an inverse transformation operation of the number theoretic transformation, wherein the sum of the predetermined number of sub-rotation factors in the sub-rotation factor set is less than the number of rotation factors in the rotation factor set; and generating each rotation factor in the rotation factor set by a predetermined combination calculation of the sub-rotation factors in the at least two sub-rotation factor sets, wherein the first calculation time of the transformation operation or the inverse transformation operation of the number theoretic transformation is greater than or equal to the second calculation time of the predetermined combination calculation.
[0054] Figure 5 FIG2 shows a schematic flow chart of a method for number theory transformation according to an embodiment of the present application. Figure 5 As shown, the method for number theoretic transformation according to an embodiment of the present application includes: S110, for a rotation factor set used for a transformation operation and an inverse transformation operation of the number theoretic transformation, setting and storing at least two sub-rotation factor sets with a predetermined number, wherein the sum of the predetermined number of sub-rotation factors in the sub-rotation factor sets is less than the number of rotation factors in the rotation factor set; and, S120, generating each rotation factor in the rotation factor set by a predetermined combination calculation of the sub-rotation factors in the at least two sub-rotation factor sets, wherein the first calculation time of the transformation operation or the inverse transformation operation of the number theoretic transformation is greater than or equal to the second calculation time of the predetermined combination calculation.
[0055] Furthermore, in the above method for number theoretic transformation, the at least two sub-rotation factor sets include a first sub-rotation factor set and a second sub-rotation factor set, and the rotation factor is represented by ω p , the first sub-twist factor in the first sub-twist factor set is ω x , the second sub-twist factor in the second sub-twist factor set is ω y , and the predetermined combination is calculated as ω p =ω x ×ω y , where × is a modular multiplication operation.
[0056] For the above example, the following inference can be made: if the rotation factor is expressed as ω p , and p = m × n, m ≥ n, and m ≥ 2, n ≥ 2, then the first sub-twiddle factor is ω x and the second sub-twiddle factor is ω y In, x=m×0, m×1,…,m×(n-1), y=0,1,…,n-1.
[0057] In practical applications, the number of p is usually Then the numbers of x and y are Where n ≥ 2. For example, when n = 3, the number of p is 256, that is, the value range is 0 to 255, then the number of x and y is 16 respectively, that is, x = {16*0, 16*1, 16*2,..., 16*15}, y = {0, 1, 2,..., 15}. In other words, when the value of p is 0 to 255, the value of x is 16*m, m = 0 to 15, and the value of y is 0 to 15.
[0058] In addition, based on the above description of number theoretic transformation, the method for number theoretic transformation according to an embodiment of the present application may further include: receiving and storing input data, performing a transformation operation based on the input data and the generated rotation factor to obtain output data, and outputting and storing the output data.
[0059] In addition, the method for number theoretic transformation according to an embodiment of the present application may further include storing the generated rotation factors, whereby performing a transformation operation based on the input data and the generated rotation factors to obtain output data includes: performing a transformation operation based on the input data and the read stored rotation factors to obtain output data.
[0060] Similarly, the method for number theory transformation according to an embodiment of the present application may further include: receiving and storing output data, performing an inverse transformation operation based on the output data and the generated rotation factor to obtain input data, and outputting and storing the input data.
[0061] And, performing an inverse transform operation based on the output data and the generated twiddle factor to obtain the input data may include performing an inverse transform operation based on the output data and the read registered twiddle factor to obtain the input data.
[0062] Furthermore, Figure 6 FIG2 shows a schematic block diagram of a device for number theory transformation according to an embodiment of the present application. Figure 6 As shown, the apparatus 200 for number theoretic transformation according to an embodiment of the present application includes: a rotation factor storage unit 210, for storing at least two sub-rotation factor sets having a predetermined number for the rotation factor sets used for the transformation operation and the inverse transformation operation, respectively, wherein the sum of the predetermined number of sub-rotation factors in the sub-rotation factor sets is less than the number of rotation factors in the rotation factor set; and a rotation factor calculation unit 220, for generating each rotation factor of the rotation factor set by calculating a predetermined combination of the sub-rotation factors in the at least two sub-rotation factor sets, wherein the first calculation time of the transformation operation or the inverse transformation operation of the operation unit is greater than or equal to the second calculation time of the predetermined combination calculation of the rotation factor calculation unit.
[0063] Furthermore, the apparatus for number-theoretic transformation further comprises: an operation unit for performing a transformation operation for the number-theoretic transformation from input data to output data and an inverse transformation operation for the number-theoretic transformation from output data to input data;
[0064] Furthermore, the above-mentioned device for number theoretic transformation further includes: a rotation factor storage unit for temporarily storing the rotation factor generated by the rotation factor calculation unit through the predetermined combined calculation, for use in the parallel transformation operation or the inverse transformation operation of the operation unit.
[0065] That is, in the apparatus for number theoretic transformation according to an embodiment of the present application, when the rotation factor calculation unit 220 completes the predetermined combination calculation of the sub-rotation factors, the generated rotation factors can be temporarily stored in a rotation factor register unit, such as a rotation factor register file, for use by the operation unit to perform a transformation operation (NTT) or an inverse transformation operation (invNTT).
[0066] In addition, in the above-mentioned apparatus for number theoretic transformation, the at least two sub-rotation factor sets include a first sub-rotation factor set and a second sub-rotation factor set, the first sub-rotation factor set is stored in a first random access memory element of the rotation factor storage unit, the second sub-rotation factor set is stored in a second random access memory element, and the rotation factor calculation unit is a modular multiplier of the first sub-rotation factor and the second sub-rotation factor.
[0067] Figure 7 The diagram shows a device for number theory transformation according to an embodiment of the present application. Figure 4 The schematic diagram of the corresponding specific example. Figure 7 As shown, the device for number theory transformation is Figure 4 Correspondingly, it includes register file 1 / 2, register file 2 / 1 and MAE including 128 AEs. In addition, the apparatus for number theory transformation is for the rotation factor ω p , split it into ω x and ω y , and ω x Stored in x random access memory (X_RAM), ω y Stored in the y random access memory (Y_RAM). By performing ω x ×ω y , where × is a modular multiplication operation, to obtain the rotation factor ω p, and temporarily stored in the twiddle factor register file. Here, the number of twiddle factors stored in the twiddle factor register file is consistent with the number of AEs in the MAE and corresponds one to one. In this way, if the number of AEs is 128, the improved storage space is 128+16+16, which is smaller than the storage space of 256 required before the improvement. This can achieve the effect of reducing the chip size. In addition, in the device for number theoretic transformation according to the embodiment of the present application, the sub-storage unit for storing the sub-twiddle factors, such as Figure 7 The X_RAM and Y_RAM shown are logically separated, and in actual application they can be stored in one RAM or in two independent RAMs.
[0068] The following describes the specific access relationship between MAE and X_RAM and Y_RAM. As described in the above example, X_RAM stores:
[0069] {ω 0 ,ω 16 ,ω 32 ,ω 48 ,ω 64 ,ω 80 ,ω 96 ,ω 112 ,ω 128 ,
[0070] ω 144 ,ω 160 ,ω 176 ,ω 192 ,ω 208 ,ω 224 ,ω 240}
[0071] Y_RAM stores:
[0072] {ω 0 ,ω 1 ,ω 2 ,ω 3 ,ω 4 ,ω 5 ,ω 6 ,ω 7 ,ω 8 ,ω 9 ,ω 10 ,ω 11 ,ω 12 ,ω 13 ,ω 14 ,ω 15}
[0073] When there are 128 AEs in MAE, taking AE1 as an example, 8 rotation factors are needed in 8 rounds of transformation operations (NTT), which are ω 128 ,ω 192,ω 160 ,ω 144 ,ω 136 ,ω 132 ,ω 130 ,ω 129 , then the storage and calculation relationship between AE1 and X_RAM, Y_RAM is:
[0074]
[0075] In addition, the remaining AEs in the MAE are also determined by the rotation factors needed in the calculation process and which sub-rotation factors in the X_RAM and Y_RAM are stored and calculated.
[0076] To summarize, the method and apparatus for number theoretic transformation according to the embodiments of the present application only need to store sub-rotation factors less than 256 when performing transformation operations (NTT) and inverse transformation operations (invNTT), for example, 16+16=32, compared to the existing method and apparatus for number theoretic transformation when performing transformation operations (NTT) and inverse transformation operations (invNTT). The cost is that before performing transformation operations (NTT), such as CT_BF calculations or inverse transformation operations (invNTT), such as GS_BF calculations, an additional modular multiplication operation is required, and optionally an access connection between the operation unit and the register stack is added.
[0077] Furthermore, in actual operations, pipeline operations can be performed. That is, before performing the first round of transform operations (NTT) / inverse transform operations (invNTT), the twiddle factor register stack can be filled. During the first round of transform operations (NTT) / inverse transform operations (invNTT), the data in the twiddle factor register stack has been removed by the MAE for calculation. At this time, the twiddle factor register stack is updated in parallel using X_RAM and Y_RAM to prepare for the next round of transform operations (NTT) / inverse transform operations (invNTT). It can be seen that compared with existing methods and devices for number theoretic transformation, the method and device for number theoretic transformation according to the embodiments of the present application reduces the storage cost of the twiddle factors while not causing performance degradation due to the addition of new operations.
[0078] On the other hand, embodiments of the present application provide a chip for number-theoretic transformation, comprising the apparatus for number-theoretic transformation described above. The foregoing description demonstrates that the chip for number-theoretic transformation according to embodiments of the present application can reduce chip area by reducing memory space without affecting the chip's computational performance for number-theoretic transformation, thereby achieving chip optimization.
[0079] Figure 8 FIG2 shows a schematic block diagram of a chip for number theory transformation according to an embodiment of the present application. Figure 8As shown, the chip 300 for number-theoretic transformation according to an embodiment of the present application includes an apparatus 310 for number-theoretic transformation. Those skilled in the art will appreciate that the details of the apparatus 310 for number-theoretic transformation are the same as those of the apparatus 200 for number-theoretic transformation described above, and are not further described here to avoid redundancy.
[0080] In addition, those skilled in the art will appreciate that although Figure 8 Although not shown in the figure, the chip 300 for number theoretic transformation according to the embodiment of the present application further includes the arithmetic unit, the rotation factor register unit, and the register files for input data and output data as described above, and the details of these units are the same as those described previously, and will not be repeated here to avoid redundancy.
[0081] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this application are merely illustrative and not restrictive, and it should not be assumed that these advantages, strengths, and effects are required of each embodiment of this application. In addition, the specific details disclosed above are merely illustrative and facilitating understanding, and are not restrictive. The above details do not limit this application to necessarily being implemented using the above specific details.
[0082] The block diagrams of the devices, devices, equipment, and systems involved in this application are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "include," "comprise," "have," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.
[0083] It should also be noted that in the apparatus, device, and method of the present application, each component or each step can be decomposed and / or recombined, and such decomposition and / or recombination should be regarded as equivalent solutions of the present application.
[0084] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0085] The above description has been provided for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present application to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A method for number theoretic transformation, characterized in that include: For a rotation factor set used for a transform operation and an inverse transform operation of the number theoretic transform, setting and storing at least two sub-rotation factor sets having a predetermined number, wherein a sum of the predetermined numbers of sub-rotation factors in the sub-rotation factor sets is less than the number of rotation factors in the rotation factor set; Each rotation factor in the rotation factor set is generated by a predetermined combination calculation of the sub-rotation factors in the at least two sub-rotation factor sets, wherein a first calculation time of a transformation operation or an inverse transformation operation of the number-theoretic transformation is greater than or equal to a second calculation time of the predetermined combination calculation.
2. The method for number-theoretic transformation according to claim 1, wherein: The at least two sub-rotation factor sets include a first sub-rotation factor set and a second sub-rotation factor set, and the rotation factor is represented by ω p , the first sub-twist factor in the first sub-twist factor set is ω x , the second sub-twist factor in the second sub-twist factor set is ω y , and the predetermined combination is calculated as ω p =ω x ×ω y , where × is a modular multiplication operation.
3. The method for number-theoretic transformation according to claim 2, wherein: p=m×n, and m≥n, m≥2, n≥2, then x=m×0, m×1,…, m×(n-1), y=0, 1,…, n-1.
4. The method for number-theoretic transformation according to claim 2, wherein: The number of p is And the number of x and y are 5. The method for number-theoretic transformation according to claim 4, wherein: The value of p is 0 to 255, the value of x is 16*m, m=0 to 15, and the value of y is 0 to 15.
6. A device for number-theoretic transformation, characterized in that: include: a rotation factor storage unit for storing, for each rotation factor set used for a transform operation and an inverse transform operation of the number theoretic transform, at least two sub-rotation factor sets having a predetermined number, wherein a sum of the predetermined numbers of sub-rotation factors in the sub-rotation factor sets is less than the number of rotation factors in the rotation factor set; A rotation factor calculation unit is configured to generate each rotation factor in the rotation factor set by performing a predetermined combined calculation of the sub-rotation factors in the at least two sub-rotation factor sets, wherein a first calculation time of the transform operation or the inverse transform operation of the operation unit is greater than or equal to a second calculation time of the predetermined combined calculation of the rotation factor calculation unit.
7. The apparatus for number-theoretic transformation according to claim 6, further comprising: The operation unit is used to perform the transformation operation from input data to output data and the inverse transformation operation from output data to input data.
8. The apparatus for number-theoretic transformation according to claim 7, wherein: The rotation factor storage unit is used to temporarily store the rotation factor generated by the rotation factor calculation unit through the predetermined combination calculation, so as to be used for the parallel transformation operation or the inverse transformation operation of the operation unit.
9. The apparatus for number-theoretic transformation according to claim 6, wherein: The at least two sub-rotation factor sets include a first sub-rotation factor set and a second sub-rotation factor set, the first sub-rotation factor set being stored in a first random access memory element of the rotation factor storage unit, the second sub-rotation factor set being stored in a second random access memory element, and the rotation factor calculation unit being a modular multiplier of the first sub-rotation factor and the second sub-rotation factor.
10. A chip for number theory transformation, characterized in that: The method comprises an apparatus for number-theoretic transformation as claimed in any one of claims 6 to 9.