Processor with Elliptic Curve Cryptography Algorithm and Its Processing Method

By designing a processor with SM2 cipher algorithm, using a single instruction set architectural instruction to implement the SM2 cipher algorithm, and storing intermediate data inside the processor, the problems of insufficient data security and high deployment cost in the existing technology are solved, and the effects of high security and low deployment cost are achieved.

CN113806770BActive Publication Date: 2025-07-01VIA ALLIANCE SEMICON CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111020355.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-01
Publication Date
2025-07-01
Estimated Expiration
2041-09-01

AI Technical Summary

Technical Problem

When implementing the SM2 cryptographic algorithm, it is difficult to effectively ensure the security of data, and specialized hardware deployment requires additional purchases, which increases the deployment cost.

Method used

Design a processor with elliptic curve cipher algorithm (SM2), implement the SM2 cipher algorithm through a single instruction set architectural instruction, and store the intermediate data in the internal hardware storage space of the processor.

Benefits of technology

Improves data security, avoids intermediate data being accessed externally, and reduces deployment costs because there is no need to purchase additional specialized hardware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113806770B_ABST
    Figure CN113806770B_ABST
Patent Text Reader

Abstract

A processor with an elliptic curve cryptography algorithm and its processing method, including a register for storing a private key pointer that points to a private key. In response to a single elliptic curve cryptography algorithm instruction of the instruction set architecture, the processor obtains a ciphertext input from a first memory space, performs an elliptic curve cryptography decryption operation on the ciphertext input using the private key obtained through the register, decrypts the ciphertext input into a plaintext output, and writes the plaintext output to a second memory space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a processor with a cryptographic algorithm and a processing method thereof. Background Art

[0002] The SM2 cryptographic algorithm is an elliptic curve public key cryptographic algorithm. However, in terms of signature and key exchange, it is different from international standards such as ECDSA (abbreviation for Elliptic Curve Digital Signature Algorithm) and ECDH (abbreviation for Elliptic-curve Diffie-Hellman), and instead adopts a more secure mechanism. The SM2 cryptographic algorithm involves not only encryption and decryption operations, but also digital signature, signature verification, key exchange protocol, etc.

[0003] The SM3 cryptographic algorithm is a hash (or hash, hash) cryptographic algorithm. In particular, some functions of the SM3 cryptographic algorithm are frequently used by the SM2 cryptographic algorithm.

[0004] In the known technology, the SM2 cryptographic algorithm is implemented using software and / or dedicated hardware (such as an external cryptographic card, etc.). Implementing it using software cannot effectively guarantee data security, and implementing it using dedicated hardware requires additional purchase of dedicated hardware during deployment, so the deployment cost will increase.

[0005] How to efficiently and more securely complete the SM2 cryptographic algorithm is a major issue in this technical field. Summary of the Invention

[0006] In order to effectively guarantee data security and reduce deployment costs, the present invention provides a processor with an elliptic curve cryptographic algorithm (SM2) and a processing method thereof.

[0007] A processor implemented according to an embodiment of the present invention includes a first register that stores a private key pointer pointing to a private key. In response to a single elliptic curve cryptographic algorithm instruction of the instruction set architecture, the processor obtains a ciphertext input from a first memory space, performs an elliptic curve cryptographic algorithm decryption operation on the ciphertext input using the private key obtained through the first register, decrypts the ciphertext input into a plaintext output, and writes the plaintext output into a second memory space.

[0008] A processing method of a processor implemented according to an embodiment of the present invention includes: in response to a single elliptic curve cryptographic algorithm instruction of the instruction set architecture, obtaining a ciphertext input from a first memory space, performing an elliptic curve cryptographic algorithm decryption operation on the ciphertext input using a private key, decrypting the ciphertext input into a plaintext output, and writing the plaintext output into a second memory space.

[0009] With the processor having an elliptic curve cryptography algorithm (SM2) and its processing method provided by the present invention, the elliptic curve cryptography algorithm can be implemented with only one instruction set architecture instruction. Intermediate data generated during the implementation of the elliptic curve cryptography algorithm can be stored in the internal hardware storage space of the processor, making these intermediate data inaccessible outside the processor, greatly improving security. In addition, since there is no need to purchase special hardware separately during deployment, the deployment cost is reduced.

[0010] Specific embodiments are given below and in conjunction with the accompanying drawings, the content of the present invention will be described in detail. Description of the Drawings

[0011] Figure 1 It is a block diagram, illustrating a processor 100 according to an embodiment of the present invention;

[0012] Figures 2A to 2D Illustrating the format of the SM3 cryptography algorithm instruction of the ISA and the related microcode ucode design according to different embodiments of the present invention;

[0013] Figure 3 Also illustrating an embodiment of ISA instruction writing;

[0014] Figure 4 It is a flowchart, illustrating the step program triggered by the SM3 cryptography algorithm instruction of the ISA according to an embodiment of the present invention, and multiple microinstructions converted from the SM3 cryptography algorithm instruction;

[0015] Figure 5 Illustrating an SM3 engine 500 according to an embodiment of the present invention;

[0016] Figure 6 It is a block diagram, illustrating a processor 600 according to an embodiment of the present invention;

[0017] Figure 7 Illustrating the format 702 of the SM2 cryptography algorithm instruction of the ISA according to an embodiment of the present invention;

[0018] Figure 8 Illustrating the microcode ucode design corresponding to the encryption operation in a table 804, showing how the corresponding generated microinstructions interpret the content of the architecture register 124;

[0019] Figure 9A 、 9B It is a flowchart, illustrating the encryption operation triggered by a single SM2 cryptography algorithm instruction of the ISA according to an embodiment of the present invention, and multiple microinstructions converted from the SM2 cryptography algorithm instruction;

[0020] Figure 10The microcode ucode design of the corresponding decryption operation is illustrated in Table 1004, showing how the corresponding generated microinstructions interpret the content of architecture register 124;

[0021] Figure 11A 、 11B is a flowchart that illustrates, according to an embodiment of the present invention, the decryption operation triggered by a single ISA SM2 cryptographic algorithm instruction and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0022] Figure 12 The microcode ucode design of the corresponding signature operation is illustrated in Table 1204, showing how the corresponding generated microinstructions interpret the content of architecture register 124;

[0023] Figure 13 is a flowchart that illustrates, according to an embodiment of the present invention, the signature operation triggered by an SM2 cryptographic algorithm instruction and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0024] Figure 14 The microcode ucode design of the corresponding signature verification operation is illustrated in Table 1404, showing how the corresponding generated microinstructions interpret the content of architecture register 124;

[0025] Figure 15 is a flowchart that illustrates, according to an embodiment of the present invention, the signature verification operation triggered by an SM2 cryptographic algorithm instruction and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0026] Figure 16 The microcode ucode design of the corresponding first program of key exchange is illustrated in Table 1604, showing how the microinstructions generated by the first SM2 cryptographic algorithm instruction interpret the content of architecture register 124;

[0027] Figure 17 is a flowchart that illustrates, according to an embodiment of the present invention, the first program operation of key exchange triggered by an SM2 cryptographic algorithm instruction and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0028] Figure 18 The microcode ucode design of the corresponding second program operation of key exchange is illustrated in Table 1804, showing how the microinstructions generated by the second SM2 cryptographic algorithm instruction interpret the content of architecture register 124;

[0029] Figure 19A 、 19B is a flowchart that illustrates, according to an embodiment of the present invention, the second program operation of key exchange triggered by an SM2 cryptographic algorithm instruction and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0030] Figure 20 The microcode ucode design corresponding to the third program operation of the key exchange is illustrated in Table 2004, showing how the microinstructions generated corresponding to the third SM2 cryptographic algorithm instruction interpret the content of architecture register 124;

[0031] Figure 21A 、 21B is a flowchart that illustrates, according to an embodiment of the present invention, the third program operation of the key exchange triggered by an SM2 cryptographic algorithm instruction, and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0032] Figure 22 According to an embodiment of the present invention, it illustrates how the initiator and the responder use the first to third program operations of the key exchange proposed by the present invention to achieve key exchange. The initiator and the responder can communicate with each other and each has a processor (600);

[0033] Figure 23 The microcode ucode design corresponding to the first preprocessing operation is illustrated in Table 2304, showing how the microinstructions generated corresponding to a single SM2 cryptographic algorithm instruction interpret the content of architecture register 124;

[0034] Figure 24 is a flowchart that illustrates, according to an embodiment of the present invention, the first preprocessing operation triggered by an SM2 cryptographic algorithm instruction, and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0035] Figure 25 The microcode ucode design corresponding to the second preprocessing operation is illustrated in Table 2504, showing how the microinstructions generated corresponding to a single SM2 cryptographic algorithm instruction interpret the content of architecture register 124;

[0036] Figure 26 is a flowchart that illustrates, according to an embodiment of the present invention, the second preprocessing operation triggered by an SM2 cryptographic algorithm instruction, and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction;

[0037] Figure 27 According to an embodiment of the present invention, it illustrates the detailed hardware architecture of the SM2 engine 626;

[0038] Figure 28 According to an embodiment of the present invention, it illustrates the point multiplication hardware 2704 driven by microinstructions of point multiplication hardware operations;

[0039] Figure 29 According to an embodiment of the present invention, it illustrates the preprocessing hardware 2706 driven by microinstructions of preprocessing hardware operations;

[0040] Figure 30Illustrated according to an embodiment of the present invention is the modular multiplication hardware 2708 driven by a modular multiplication hardware operation micro-instruction; and

[0041] Figure 31 Illustrated according to an embodiment of the present invention is the modular inverse hardware 2710 driven by a modular inverse hardware operation micro-instruction. Detailed Embodiments

[0042] The following description lists various embodiments of the present invention. The following description introduces the basic concepts of the present invention and is not intended to limit the content of the present invention. The actual scope of the invention should be defined according to the claims.

[0043] An embodiment of the present invention discloses a processor with a hash cryptographic algorithm (SM3 cryptographic algorithm), including a single hash cryptographic algorithm instruction (SM3 cryptographic algorithm instruction) designed for the instruction set architecture (Instruction Set Architecture, abbreviated as ISA) of the SM3 cryptographic algorithm. In one embodiment, corresponding to the SM3 cryptographic algorithm instruction, the present invention designs the microcode (ucode) of the processor and also adds a hash cryptographic algorithm accelerator (SM3 engine) to the cryptographic execution unit of the processor. When processing the SM3 cryptographic algorithm instruction, the processor generates multiple micro-instruction definitions, uses, and manages the content of architecture registers according to the microcode to operate the cryptographic execution unit (including the SM3 engine) to perform the SM3 cryptographic algorithm on an input data (input stream) m, converting an initial hash constant V(0) into a converted hash value V(n), where the process includes message padding and grouping (including n groups of messages B(0), …, B(n - 1)), message expansion (expanding B(i) into W0 i …W 67 i 、and W0 i ’…W 63 i ’), and iterative compression (converting the hash value from V(i) to V(i + 1) based on the result of the expansion of B(i)). The instruction set supported by the processor may include the x86 instruction set. The intermediate values (e.g., W0 i …W 67 i and W0 i ’…W 63 i ’, V(1) … V(n - 1) …, etc.) of the conversion from the initial hash constant V(0) to the converted hash value V(n) can be properly hidden in the cryptographic execution unit and not exposed on the architecture registers.

[0044] Figure 1is a block diagram that illustrates a processor 100 according to an embodiment of the present invention. According to the branch predictor 102, instructions are loaded into the instruction cache 104 according to the translation result of the instruction translation lookaside buffer (ITLB), cached in the instruction buffer (abbreviated as XIB) 106, and then pushed into the format instruction queue (abbreviated as FIQ) 108. The decoder 110 decodes them into multiple microinstructions recognizable by the pipeline according to the microcode (stored in a microcode storage), and pushes them into the instruction queue (abbreviated as XIQ) 112. Then, they are stored in the corresponding reservation station (RS) by the rename unit 114, driving the arithmetic logical unit (ALU), the address generating unit (AGU) of the memory order buffer 116, and the corresponding hardware for various instructions, such as Fadd, Fmul, Fmisc, MMX, or the cryptographic execution unit 118. The data required for the operation can be loaded into the data cache 120 according to the translation result of the data translation lookaside buffer (DTLB) and then cached in the memory order buffer 116. The processor 100 further includes a reorder buffer (abbreviated as ROB) 122 and architecture registers 124 to implement the operation.

[0045] The password execution unit 118 includes an SM3 engine 126. The microcode ucode includes architecture registers 124 for accessing SM3 cryptographic algorithm instructions of the corresponding ISA, specifically including registers for accessing the preprocessing method of the stored input data m (e.g., whether message padding is required), input data size registers, and even input data m pointer registers and hash value pointer registers. The decoder 110 decodes the SM3 cryptographic algorithm instructions of the ISA of the present invention into multiple microinstructions recognizable by the processor 100 pipeline according to the microcode ucode, for interpreting the content of the architecture registers 124, obtaining the initial hash constant V(0) and the input data m, and then driving the SM3 engine 126 to perform hash value conversion to generate the converted hash value V(n). The multiple decoded microinstructions include an accelerator operation microinstruction (SM3 engine microinstruction), that is, responsible for driving the SM3 engine 126. The multiple decoded microinstructions also include accessing and managing the content of the group architecture registers 124, and operating the password execution unit 118 to perform the hash cryptographic algorithm on the input data m.

[0046] Figures 2A to 2D Illustrate the format of the SM3 cryptographic algorithm instructions of the ISA according to different embodiments of the present invention, as well as the related microcode ucode design. In addition to the illustrated embodiments, the format content (e.g., numerical opcode) and register applications mentioned in the present invention may also have various variations.

[0047] Figure 2A Illustrate the format 202 of the SM3 cryptographic algorithm instructions of the ISA, and introduce the related microcode ucode design in Table 204. The prefix, opcode, and field ModR / M of format 202 are: 0xF3 0x0F 0xA6 0xE8 (which can also be other values). The fields SIB, Displacement, and Immediate are not filled (non). After the decoder 110 identifies the encoding "0xF3 0x0F 0xA6 0xE8", it generates multiple microinstructions according to the microcode ucode, including defining, using, and managing the architecture registers 124 to operate the password execution unit 118 to perform the SM3 cryptographic algorithm on the input data m.

[0048] First, referring to Table 204, discuss how the microcode ucode defines input registers corresponding to the SM3 cryptographic algorithm instructions of the ISA, using the registers EAX, ECX, ESI, and EDI in the architecture registers 124.

[0049] Register EAX holds a message padding flag, indicating whether the input data m needs message padding to meet the input bit length of the SM3 cryptographic algorithm. EAX = 0 indicates that the input data m has a message padding requirement. EAX = -1 indicates that the input data m does not need message padding. When this message padding flag indicates a padding requirement, the multiple microinstructions pad the input data m to a multiple of the input message block size. In one implementation, the input message block size is 512 bits. When EAX = 0, the multiple microinstructions pad the input data m, and the padded data is m', where m' = m,1,k{0},64{len}. len is the bit length of the input data m. The padded data m' includes the input data m, a 1-bit high-order '1', k low-order '0' bits, and 64 bits representing len. The value of k is such that the remainder of (len + 1 + k) divided by 512 is 448. According to the multiple microinstructions, the input data m of length that is a multiple of 512 bits, or the padded data m', is grouped in units of 512 bits into n input messages of 512 bits each, including B(0),..., B(n - 1), where n is an integer.

[0050] Register ECX stores the length of an input data (m). If EAX = 0, the length of the input data held in register ECX is counted in bytes. If EAX = -1, the length of the input data held in register ECX is counted in 64-byte blocks.

[0051] Register ESI stores a pointer to an input data, pointing to a memory space that stores the input data m. The memory space described in the present invention can be a system memory (such as a RAM) space coupled to the processor, and can follow the ES segment segmentation technique. Register EDI stores a pointer to a hash value, pointing to a memory space (which can follow the ES segment segmentation technique) that stores the initial hash constant V(0).

[0052] In addition, Table 204 also shows how the microcode ucode corresponds to the definition of the output registers of the SM3 cryptographic algorithm instruction in the ISA; after the SM3 cryptographic algorithm is completed and the transformed hash value V(n) is obtained, the following settings are made for each of the registers EAX, ECX, ESI, and EDI.

[0053] The input data pointer maintained on register ESI is incremented by a displacement. When register EAX is "0", this displacement is the length of the input data managed by register ECX. When register EAX is "-1", this displacement is the size of the input data carried by register ECX multiplied by 64. The hash value pointer on register EDI remains unchanged, enabling the transformed hash value V(n) converted by the SM3 cryptographic algorithm to overwrite the initial hash constant V(0).

[0054] In addition, registers EAX and ECX can be adjusted as follows after the SM3 cryptographic algorithm is completed. If register EAX is set to "0" during input, then register ECX remains unchanged and register EAX is updated with the same value as register ECX. If register EAX is set to "-1" during input, then register ECX is reset to zero and register EAX remains unchanged.

[0055] Figure 2B Illustrate format 212 of the SM3 cryptographic algorithm instruction of ISA, and introduce the relevant microcode ucode design in Table 214. Format 212 is the same as format 202. After decoder 110 identifies the encoding "0xF3 0x0F 0xA6 0xE8", it generates multiple microinstructions according to the microcode ucode, including defining, using, and managing architecture register 124 to operate the cryptographic execution unit 118 to perform the SM3 cryptographic algorithm on the input data m.

[0056] Different from the microcode ucode design shown in Table 204 that provides register ESI and register EDI for the input data pointer and the hash value pointer respectively, Figure 2B The microcode ucode design shown in Table 214 stores an information pointer in register ESI, which points to a memory space that stores an input data pointer and a hash value pointer. The memory space pointed to by the input data pointer stores the input data m, and the memory space pointed to by the hash value pointer stores the initial hash constant V(0). Correspondingly, regarding the setting of the output register of the SM3 cryptographic algorithm, the microcode ucode design shown in Table 214 does not change register ESI.

[0057] Figure 2C Illustrate format 222 of the SM3 cryptographic algorithm instruction of ISA, and introduce the relevant microcode ucode design in Table 224. Format 222 is the same as format 202 and 212. After decoder 110 identifies the encoding "0xF3 0x0F 0xA6 0xE8", it generates multiple microinstructions according to the microcode ucode, including defining, using, and managing architecture register 124 to operate the cryptographic execution unit 118 to perform the SM3 cryptographic algorithm on the input data m.

[0058] And Figure 2AIn contrast, different from the microcode ucode design shown in Table 204 that provides register EDI for the hash value pointer, Figure 2C The microcode ucode design shown in Table 224 is to fill register EDI with 0 when starting the SM3 cryptographic algorithm, and set an execution unit internal register in the cryptographic execution unit 118 to store the converted hash value V(n). Regarding the setting of the output register of the SM3 cryptographic algorithm, the microcode ucode design shown in Table 224 enables register EDI to store an execution unit register number of the execution unit internal register. As long as register EDI is accessed again by a microinstruction, the execution unit internal register can be found according to the execution unit register number, and the converted hash value V(n) can be obtained and used as the initial hash constant for the next input data.

[0059] Figure 2D Illustrate the format 232 of the SM3 cryptographic algorithm instruction of the ISA, and introduce the relevant microcode ucode design in Table 234. Different from formats 202, 212, and 222, format 232 has fields InPointer and OutPointer, which store an input data pointer and a hash value pointer respectively, pointing to the input data m and the initial hash constant V(0) stored in the system memory. This can save the use of the set of architecture registers 124. In one implementation, the fields InPointer and OutPointer of the SM3 cryptographic algorithm instruction format 232 are each 32 bits. After the decoder 110 identifies the encoding "0xF3 0x0F 0xA6 0xE8", it generates multiple microinstructions according to the microcode ucode, including defining, using, and managing the architecture registers 124, and registers ESI and EDI will not be applied.

[0060] Figure 3 Also illustrate an implementation of ISA instruction writing. The program code 300 may include the SM3 cryptographic algorithm instruction 302 in the above formats 202, 212, 222, or 232. At least one register setting instruction 304 may be included before the SM3 cryptographic algorithm instruction 302 to fill the architecture registers 124 in preparation for the execution of the SM3 cryptographic algorithm instruction 302.

[0061] Figure 4 Is a flowchart, which illustrates the step procedure triggered by the SM3 cryptographic algorithm instruction of the ISA according to an implementation of the present invention, corresponding to multiple microinstructions converted from the SM3 cryptographic algorithm instruction.

[0062] Step S402 checks the length of the input data (m). For example, it reads register ECX. If register ECX is 0, the process proceeds to step S404 and the execution of the SM3 cryptographic algorithm instruction ends. If register ECX is not 0, the process proceeds to step S406.

[0063] Step S406 checks the register EAX to determine whether there is a message padding requirement (padding to a multiple of 512 bits). If the register EAX is 0, step S408 performs message padding. The input data m is padded to m' (= m, 1, k{0}, 64{len}). If the register EAX is not 0, the process skips the message padding step S408. The input data m with a length that is a multiple of 512 bits, or the padded data m', is grouped into n groups of input messages in units of 512 bits, including B(0), …, B(n - 1), where n is an integer. Then, the processor 100 gradually converts to a transformed hash value V(n) of a specific length through steps S410, S412, and S414. First, the process proceeds to step S410 and starts operating the SM3 engine 126 according to an SM3 engine micro-instruction.

[0064] In step S410, the initial hash constant V(0) and B(0) of the first group of 512-bit input messages are input into the SM3 engine 126 from the system memory space, causing the SM3 engine 126 to operate according to the initial hash constant V(0) and the group of input messages B(0). In step S412, the SM3 engine 126 converts to an intermediate hash value V(1). Step S414 checks whether the operation on all groups of input messages is completed to continue or stop the loop. In one implementation, the number of loop iterations can be managed by a register temp_gpr inside the cryptographic execution unit 118, and its initial value is related to the input values of the register EAX and the register ECX. The number of loop iterations managed by the register temp_gpr will decrease as the operation on each group of input messages is completed, and it can be used to determine whether all of the input messages B(0), …, B(n - 1) of the input data m have been operated on to complete the SM3 cryptographic algorithm for the input data m. If there are still input messages unprocessed, the process returns to step S410, causing the SM3 cryptographic algorithm engine 126 to operate according to the intermediate hash value (e.g., V(1)) and the next group of input messages (e.g., B(1)), and converting to the next intermediate hash value (e.g., V(2)) in step S412. And so on, the processor 100 gradually processes each group of input messages until all groups of input messages are processed to obtain a transformed hash value V(n) of a specific length. In one embodiment, the specific length is 256 bits.

[0065] If the operation on all groups of input messages B(0), …, B(n - 1) is completed, that is, the SM3 cryptographic algorithm for the input data m is completed, the process enters step S416 to store the transformed hash value V(n). If Figure 2A 、 2B or 2D design is adopted, the SM3 engine 126 fills the transformed hash value V(n) into the system memory; for example, it overwrites the initial hash constant V(0) in the memory according to the hash value index. IfFigure 2C In the design, the SM3 engine 126 fills the converted hash value V(n) into an internal register of an execution unit in the cryptographic execution unit 118, and it can be read out by microinstructions. In step S418, the execution of the SM3 cryptographic algorithm instruction ends.

[0066] The above SM3 engine microinstructions correspond to steps S410 and S412, and repeatedly drive the SM3 engine 126 to complete the hash value conversion of each group of input messages B(i) (V(i) → V(i + 1)), so that the initial hash constant V(0) is converted into the converted hash value V(n).

[0067] The operations implemented by the SM3 engine 126 are as follows:

[0068] V(i + 1) = CF(V(i), B(i))

[0069] CF is a compression function: Each group of 512-bit input messages B(i) is expanded through message expansion and then undergoes 64 rounds (j = 0 to 63) of iterative compression to convert and output a 256-bit hash value V(i + 1). After all groups of input messages B(0) to B(n - 1) are operated on, the initial hash constant V(0) is converted into the converted hash value V(n).

[0070] Figure 5 According to an embodiment of the present invention, an SM3 engine 500 is illustrated, which is used to implement the processing of a group of input messages (such as B(i)), where the hardware is used for: message expansion 502, iterative compression 504, and includes an internal storage space M1 of the accelerator. The internal storage space M1 of the accelerator stores the constants used in the iterative compression 504.

[0071] After the SM3 engine 500 receives a group of 512-bit input messages B(i), the message expansion 502 expands the group of input messages B(i) into 132 words, including and Then, 64 rounds of iterative operations are performed through the iterative compression 504 to convert it into a hash value V(i + 1) for use by the next group of 512-bit input messages B(i + 1).

[0072] The iterative compression 504 implements the following operations:

[0073] ABCDEFGH ← V(i)

[0074] FOR j = 0 TO 63

[0075] SS1 ← ((A <<< 12) + E + (Tj <<< j)) <<< 7

[0076] SS2 ← SS1 ^ (A <<< 12)

[0077] TT1 ← FFj(A, B, C) + D + SS2 + Wj′

[0078] TT2 ← GGj(E, F, G) + H + SS1 + Wj

[0079] D ← C

[0080] C ← B <<< 9

[0081] B ← A

[0082] A ← TT1

[0083] H ← G

[0084] G ← F <<< 19

[0085] F ← E

[0086] E ← P0(TT2)

[0087] ENDFOR

[0088] V(i + 1) ← ABCDEFGH ^ V(i)

[0089] Among them, FFj and GGj are Boolean functions, and P0(.) is a permutation function. The iterative compression 504 hardware includes the accelerator internal storage spaces M2 and M3, and the function hardware 506. The accelerator internal storage space M2 caches the hash value V(i) at the beginning of these 64 rounds of compression operations, which is used as parameters A to H. After being operated on by the functions FFj, GGj, and P0(.) provided by the function hardware 506, the parameters A to H are updated and cached in the accelerator internal storage space M3, and then the hash value V(i + 1) is converted for use by the next group of 512-bit input message B(i + 1). After all the input messages B(0)…B(n - 1) are operated on, the content of the accelerator internal storage space M3 is used to store the converted hash value V(n).

[0090] The illustrated initial hash constant (V(0)) 508 is obtained from the system memory according to the aforementioned hash value pointer and is used to fill the accelerator internal storage space M2 for the iterative compression of the first group of input messages B(0) with 132 words (including and ).

[0091] In one implementation, the converted hash value V(n) obtained after all the input messages B(0)…B(n - 1) are operated on can be stored in the internal space of the cryptographic execution unit 118 and wait to be fetched by subsequent microinstructions. In another implementation, the converted hash value V(n) overwrites the system memory space indicated by the hash value pointer.

[0092] The present invention properly protects the intermediate hash values V(1)…V(n - 1) in the SM3 engine 500. The present invention designs a hardware for cryptographic algorithms with higher security.

[0093] In one embodiment, the cryptographic execution unit 118 does not specifically design the SM3 engine 126. Only by programming the content of the microcode ucode, a single ISA SM3 cryptographic algorithm instruction is converted into multiple micro-instruction operation logic arithmetic units ALU, thus completing the SM3 cryptographic algorithm for the input data m. In particular, in such an embodiment, the intermediate data of the SM3 cryptographic algorithm is also protected in the internal storage space of the processor, with high security.

[0094] In one embodiment, the SM3 engine has fewer functional modules than the SM3 engine 500, and the missing functional modules (such as the message expansion 502) are implemented by using the microcode ucode to configure the micro-instruction operation logic arithmetic unit ALU. This embodiment also has the ability to protect the intermediate data in the internal storage space of the processor.

[0095] In summary, according to one embodiment of the present invention, a processor implemented responds to a single hash cryptographic algorithm instruction of an instruction set architecture (ISA). The processor obtains a finite-length input data from a first memory space, performs a hash cryptographic algorithm (SM3 cryptographic algorithm) on the input data, and converts it into a converted hash value of a specific length. The present invention completes the SM3 cryptographic algorithm with a single ISA instruction. Using the SM3 engine 126 to implement the SM3 cryptographic operation can improve the operation speed and security. In addition to being assisted by special hardware (SM3 engine 126), there are also embodiments implemented entirely by microcode.

[0096] The present invention also applies the SM3 engine 126 to the elliptic curve public key cryptographic algorithm (SM2 cryptographic algorithm). The following introduces a processor with the SM2 cryptographic algorithm.

[0097] Figure 6 Is a block diagram, illustrating a processor 600 according to one embodiment of the present invention. Compared with Figure 1 The cryptographic execution unit 618 includes, in addition to the SM3 engine 126, an SM2 engine 626 (i.e., an elliptic curve cryptographic algorithm accelerator), and the detailed hardware architecture of the SM2 engine 626 will be described later in combination with Figure 27 The microcode ucode also has the content of the SM2 cryptographic algorithm instruction (i.e., the elliptic curve cryptographic algorithm instruction) corresponding to the ISA. The decoder 110 is based on Figure 6The microcode ucode decodes the SM2 cryptographic algorithm instructions of the ISA of the present invention into multiple microinstructions recognizable by the pipeline of the processor 100, defines, uses, and manages the architectural registers 124 to operate the cryptographic execution unit 618 including the SM2 engine 626 and the SM3 engine 126, and implements operations such as encryption, decryption, signature, signature verification, key exchange... of the SM2 cryptographic algorithm. In particular, the present invention properly hides the key intermediate variables of the SM2 cryptographic algorithm inside the processor, and the security factor is quite high. As for the intermediate variables with lower security requirements, they can be temporarily stored in the system memory (for example, the RAM outside the processor) to save the storage space inside the processor.

[0098] Figure 7 According to an embodiment of the present invention, the format 702 of the SM2 cryptographic algorithm instructions of the ISA is illustrated. The prefix, opcode, and field ModR / M of the format 702 are: 0xF2 0x0F 0xA6 0xC0. The fields SIB, Displacement, and Immediate are not filled (non). After the decoder 110 recognizes the encoding "0xF2 0x0F 0xA6 0xC0", it generates multiple microinstructions according to the microcode ucode, including querying a control word stored in one of the architectural registers 124, the register EDX, to determine which operation of the SM2 cryptographic algorithm is being performed. The control word can be represented by 6 bits, and the corresponding operations are as follows:

[0099] · 6’b 000001: Encryption.

[0100] · 6’b 000010: Decryption.

[0101] · 6’b 000100: Signature.

[0102] · 6’b 001000: Verify signature.

[0103] · 6’b 010000: Key exchange1.

[0104] · 6’b 010001: Key exchange2, don’t calculate hash.

[0105] · 6’b 010101: Keyexchange2, calculate hash.

[0106] · 6’b 010010: Key exchange 3, don’t calculate hash.

[0107] · 6’b 010110: Key exchange 3, calculate hash.

[0108] · 6’b 100000: Preprocess1 to calculate value Z of user’s identification.

[0109] · 6’b 100001: Preprocess2 to calculate hash value for Z and message M.

[0110] First, discuss the encryption operation of the SM2 cryptographic algorithm.

[0111] Figure 8 Use Table 804 to illustrate the ucode design of the corresponding encryption operation, showing how the corresponding generated microinstructions interpret the content of architecture register 124. The aforementioned control word 6’b 000001 (cw) will be stored in input register EDX in advance to indicate an encryption operation. In addition to this input register EDX, Table 804 also lists input registers EAX, EBX, ECX, ESI, and EDI item by item, all of which serve as input registers for the initial encryption operation. The completion of the encryption operation indicated by an ISA SM2 cryptographic algorithm instruction includes filling output registers EAX, ECX, and EDI. There may be other implementation methods for the application of input or output registers.

[0112] When serving as an input register, register EAX stores a pointer to a plaintext input M, pointing to a memory space that stores a plaintext input M (which can be provided by a system memory, such as RAM, coupled to the processor and can follow the ES segment segmentation technology). Register EBX stores an encryption public key P B pointer, pointing to a memory space that stores an encryption public key P BA memory space (which can follow the ES segment segmentation technology). The register ECX stores the number of bytes of the plaintext input M. The register EDX stores the control word cw indicating the encryption code (6'b 000001). The register ESI stores a pointer to an intermediate variable, which points to a memory space (also known as the scratch space, which can temporarily store intermediate variables with high security. It can be 8K in size, can follow the ES segment segmentation technology, can be initialized to all 0, and can be obtained by software requesting the operating system to allocate system memory). In one implementation, the intermediate variable is a parameter used in the calculation. For example, the intermediate variables involved in the point multiplication function include the point coordinates after coordinate transformation, or the intermediate values involved in coordinate transformation... etc. The register EDI stores a pointer to the ciphertext output C, which points to a memory space (which can follow the ES segment segmentation technology), specifying the storage location of the ciphertext output C.

[0113] After the encryption operation indicated by the SM2 cryptographic algorithm instruction of this ISA is completed, the adjustment of the output register includes: increasing the pointer stored in the register EAX by a displacement amount, which is the number of bytes of the plaintext input M; making the register ECX store the number of bytes of the ciphertext output C; and, increasing the pointer stored in the register EDI by a displacement amount, which is the number of bytes of the ciphertext output C.

[0114] Figure 9A , 9B is a flowchart, which illustrates the encryption operation triggered by a single SM2 cryptographic algorithm instruction of the ISA according to an implementation of the present invention, corresponding to multiple microinstructions converted from the SM2 cryptographic algorithm instruction.

[0115] Starting from Figure 9A , step S902 inputs a hardware operation control word (obtained from the input register EDX) into the SM2 engine 626, and uses the point multiplication hardware of the SM2 engine 626 to calculate an elliptic curve point C1, where C1 = [k]G, k is a random number, k ∈ [1, n - 1]. G is one of the elliptic curve parameters, provided by the microcode ucode, and is the base point of the elliptic curve. The SM2 engine 626 returns the elliptic curve point C1. Step S902 may include the execution of a point multiplication hardware operation microinstruction. The cryptographic execution unit 618 may include a random number generator, which is operated by a random number generation microinstruction to generate the random number k.

[0116] Step S904 inputs the hardware operation control word and the encryption public key P B (obtained according to the pointer saved in the input register EBX) into the SM2 engine 626, and uses the point multiplication hardware to calculate an elliptic curve point S, where S = [h]P B。h is one of the elliptic curve parameters and is the cofactor of the elliptic curve. The SM2 engine 626 returns the elliptic curve point S. Step S904 may include the execution of a scalar multiplication hardware operation micro-instruction.

[0117] Step S906 checks whether the elliptic curve point S is a zero point (the zero point is a special point on the elliptic curve, also known as the infinite point). If so, the process proceeds to step S908, and the processor generates an encryption failure prompt. If not, the process proceeds to step S910, and the hardware operation control word and the encryption public key P B are input into the SM2 engine 626, and using this scalar multiplication hardware, an elliptic curve point (x2, y2) = [k]P is calculated B 。The SM2 engine 626 returns the elliptic curve point (x2, y2). Step S910 may include the execution of a scalar multiplication hardware operation micro-instruction.

[0118] Step S912 performs key derivation (Key derivation function) based on the bit length klen of the plaintext input M (obtained according to the plaintext input M pointer saved in the input register EAX), and calculates: t = KDF(x2||y2, klen), where KDF is the key derivation function (i.e., the key derivation function), and x2||y2 represents the concatenation of x2 and y2.

[0119] Step S914 checks whether the derived key t is zero (i.e., determines whether t is an all-0 bit string). If so, the process returns to step S902 to update the random number k and calculate the elliptic curve points C1 and S again. If not, the process proceeds Figure 9B to step S916, loads the plaintext input M from the system memory into the processor 600, and performs an exclusive OR operation to generate the partial ciphertext C2: C2 = M ⊕ t.

[0120] Step S918 inputs the hardware operation control word and the value (x2||M||y2) that has completed message padding into the SM2 engine 626, uses a preprocessing unit of the SM2 engine 626 to perform preprocessing such as grouping on the value (x2||M||y2), and then inputs it into the SM3 engine 126 (the process of using the SM3 engine is shown in the previous Figure 4 steps S410, S412, and S414), to implement the hash operation: C3 = Hash(x2||M||y2), where Hash is the cryptographic hash function, and x2||M||y2 represents the concatenation of x2, M, and y2. The SM2 engine 626 returns the partial ciphertext C3. Step S918 may include the execution of a preprocessing hardware operation micro-instruction and even an SM3 engine micro-instruction.

[0121] Step S920 loads the ciphertext output C to the system memory according to the ciphertext output C pointer stored in the input register EDI, where C = C1||C2||C3, and C1||C2||C3 represents the concatenation of C1, C2, and C3. Step S922 ends the encryption operation triggered by this SM2 cryptographic algorithm instruction. In another embodiment, C = C1||C3||C2.

[0122] In summary, in response to a single elliptic curve cryptographic algorithm instruction (SM2 cryptographic algorithm instruction) of an instruction set architecture (ISA), a processor obtains a plaintext input M from a first memory space and uses a public key P obtained through a register (e.g., EBX) B to perform an encryption operation of an elliptic curve cryptographic algorithm (SM2 cryptographic algorithm) on the plaintext input M, encrypt the plaintext input M into a ciphertext output C, and write the ciphertext output C to a second memory space. The present invention completes the encryption operation of the SM2 cryptographic algorithm with a single ISA instruction. Compared with implementing the encryption operation of the elliptic curve cryptographic algorithm using only the SM2 engine 626, using both the SM2 engine 626 and the SM3 engine 126 can improve the operation speed and security. In addition to being assisted by special hardware (SM3 engine 126, SM2 engine 626), there are also embodiments implemented entirely by microcode.

[0123] Next, the decryption operation of the SM2 cryptographic algorithm is discussed.

[0124] Figure 10 Table 1004 illustrates the microcode ucode design of the corresponding decryption operation, showing how the corresponding microinstructions interpret the content of the architecture register 124. The aforementioned control word 6’b 000010 (cw) will be stored in the input register EDX in advance to indicate that a decryption operation is to be performed. In addition to the input register EDX, Table 1004 also lists the input registers EAX, EBX, ECX, ESI, and EDI item by item, all of which serve as input registers for starting the decryption operation. The completion of the decryption operation indicated by an SM2 cryptographic algorithm instruction of an ISA includes filling the output registers EAX, ECX, and EDI. There may be other implementation manners for the application of input or output registers.

[0125] When used as an input register, the register EAX stores a ciphertext input C pointer, pointing to a memory space (which can follow the ES segment segmentation technique) storing a ciphertext input C. Among them, as described above, the ciphertext C = C1||C2||C3 (in another embodiment, C = C1||C3||C2). The register EBX stores a decryption private key d B pointer, pointing to a memory space storing a decryption private key d Ba memory space (which can follow the ES segment segmentation technology). The register ECX stores the number of bytes of the ciphertext input C. The register EDX stores the control word cw indicating the decryption code (6’b 000010). The register ESI stores a pointer to an intermediate variable, pointing to a memory space (also known as the scratch space, which can temporarily store intermediate variables with high security, can be 8K in size, can follow the ES segment segmentation technology, can be initialized to all 0s, and can be requested by software from the operating system to allocate memory). The register EDI stores a pointer to the plaintext output M’, pointing to a memory space (which can follow the ES segment segmentation technology), specifying the storage location of a plaintext output M’.

[0126] With the end of the decryption operation indicated by the SM2 cryptographic algorithm instruction of this ISA, the adjustment of the output registers includes: increasing the pointer stored in the register EAX by a displacement amount, which is the number of bytes of the ciphertext input C; making the register ECX store the number of bytes of the plaintext output M’; and, increasing the pointer stored in the register EDI by a displacement amount, which is the number of bytes of the plaintext output M’.

[0127] Figure 11A 、 11B is a flowchart, illustrating the decryption operation triggered by a single SM2 cryptographic algorithm instruction of the ISA according to an embodiment of the present invention, corresponding to multiple microinstructions converted from the SM2 cryptographic algorithm instruction.

[0128] Starting from Figure 11A , in step S1102, part of the ciphertext C1 (C1 is an elliptic curve point, also referred to as point C1 later) is loaded from the system memory to the processor 600 according to the ciphertext input C pointer saved in the input register EAX (that is, C1 is taken out from the ciphertext and then loaded into the processor 600). In step S1104, it is verified whether point C1 conforms to an elliptic curve equation. If not, the process proceeds to step S1106, and the processor outputs a decoding failure prompt, reports an error, and exits the decryption operation. On the contrary, if C1 conforms to the elliptic curve equation, the process proceeds to step S1108.

[0129] In step S1108, a hardware operation control word (taken from the input register EDX) and point C1 are input into the SM2 engine 626, and using the point multiplication hardware, an elliptic curve point S is calculated, where S = [h]C1. The SM2 engine 626 returns the elliptic curve point S. Step S1108 may include the execution of a point multiplication hardware operation microinstruction.

[0130] Step S1110 verifies whether the elliptic curve point S is a zero point. If so, it is determined that the decoding fails, and the process proceeds to step S1106, where the processor outputs a decoding failure prompt. If the elliptic curve point S is not a zero point, the process proceeds to step S1112, where the hardware operation control word and the decryption private key d B are input to the SM2 engine 626, and using the point multiplication hardware, an elliptic curve point (x2, y2) = [d B C1 is calculated. The SM2 engine 626 returns the elliptic curve point (x2, y2). Step S1112 may include the execution of a point multiplication hardware operation micro-instruction.

[0131] In step S1114, based on the bit length klen of a part of the ciphertext C2 (i.e., C2 in the ciphertext, which is obtained from the system memory according to the ciphertext input C pointer saved in the input register EAX), key derivation is performed: t = KDF(x2||y2, klen).

[0132] In step S1116, it is checked whether the derived key t is zero (i.e., it is determined whether t is an all-0 bit string). If so, in step S1106, it is determined that the decoding fails, and the processor outputs a decoding failure prompt. If not, the process proceeds to Figure 11B step S1118, where this part of the ciphertext C2 is loaded from the system memory to the processor 600, and an exclusive OR operation is performed: M’ = C2 ⊕ t.

[0133] In step S1120, the hardware operation control word and the value (x2||M’||y2) that completes the message padding are input to the SM2 engine 626. Using the preprocessing hardware, preprocessing such as grouping is performed on the value (x2||M’||y2), and then it is input to the SM3 engine 126 (the process of using the SM3 engine is shown in the previous Figure 4 steps S410, S412, and S414), to implement a hash operation: u = Hash(x2||M’||y2), where Hash is a cryptographic hash function, and x2||M’||y2 represents the concatenation of x2, M’, and y2. The SM2 engine 626 returns the hash value u. Step S1120 may include the execution of a preprocessing hardware operation micro-instruction and even an SM3 engine micro-instruction.

[0134] In step S1122, it is verified whether the hash value u is equal to a part of the ciphertext C3 (obtained from the system memory according to the ciphertext input C pointer saved in the input register EAX). If not, it is determined that the decoding fails, and the process proceeds to step S1106, where the processor outputs a decoding failure prompt. If the hash value u is equal to a part of the ciphertext C3, in step S1124, the plaintext output M’ is loaded into the system memory according to the plaintext output M’ pointer saved in the input register EDI. Step S1126 ends the decryption operation triggered by this single SM2 cryptographic algorithm instruction.

[0135] In summary, in response to a single elliptic curve cryptography algorithm instruction (SM2 cryptography algorithm instruction) of an instruction set architecture (ISA), a processor obtains a ciphertext input C from a first memory space and uses the private key d obtained through the first register B to perform a decryption operation of an elliptic curve cryptography algorithm on the ciphertext input C, decrypt the ciphertext input C into a plaintext output M', and write the plaintext output M' into a second memory space. The present invention completes the decryption operation of the SM2 cryptography algorithm with a single ISA instruction. Compared with implementing the decryption operation of the elliptic curve cryptography algorithm by using only the SM2 engine 626, using both the SM2 engine 626 and the SM3 engine 126 simultaneously can improve the operation speed and security. In addition to being assisted by special hardware (SM3 engine 126, SM2 engine 626), there are also embodiments implemented entirely by microcode.

[0136] Next, the signature operation of the SM2 cryptography algorithm is discussed, where a hash value calculated by a first preprocessing operation and a second preprocessing operation is used. The first preprocessing operation and the second preprocessing operation will be discussed in detail in later paragraphs.

[0137] Figure 12 Table 1204 illustrates the microcode ucode design corresponding to the signature operation, showing how the corresponding microinstructions interpret the content of the architecture register 124. The aforementioned control word 6'b 000100 (cw) will be stored in the input register EDX in advance to indicate the signature operation. In addition to the input register EDX, Table 1204 also lists the input registers EAX, EBX, ESI, and EDI item by item, all of which serve as input registers for starting the signature operation. The completion of the signature operation indicated by a single ISA SM2 cryptography algorithm instruction includes filling the output registers ECX and EDI. There may be other implementation manners for the application of the input or output registers.

[0138] When serving as an input register, the register EAX stores a pointer to a hash value e, which points to a memory space storing the hash value e (which can follow the ES segment segmentation technique); the hash value e is generated by a first preprocessing operation and a second preprocessing operation for a data M to be signed and is pre-stored in the memory space. The register EBX stores a private key d A pointer, which points to a memory space storing a private key d of the signer AA memory space (which can follow the ES segment segmentation technology). The register EDX stores the control word cw indicating the signature code (6’b 000100). The register ESI stores a pointer to an intermediate variable, pointing to a memory space (also known as the scratch space, which can temporarily store intermediate variables with high security, can be 8K in size, can follow the ES segment segmentation technology, can be initialized to all 0, and can be planned by software from the operating system). The register EDI stores a pointer to a signature (r, s), pointing to a memory space (which can follow the ES segment segmentation technology), specifying the storage location of the signature (r, s).

[0139] With the end of the signature operation indicated by the SM2 cryptographic algorithm instruction of this ISA, the adjustment of the output register includes: making the register ECX store the number of bytes of the signature (r, s); and, increasing the signature pointer stored in the register EDI by an offset, which is the number of bytes of the signature (r, s).

[0140] Figure 13 is a flowchart, which illustrates a signature operation triggered by an SM2 cryptographic algorithm instruction according to an embodiment of the present invention, corresponding to multiple microinstructions converted from the SM2 cryptographic algorithm instruction.

[0141] Step S1302 inputs a hardware operation control word (obtained from the input register EDX) into the SM2 engine 626, and uses the point multiplication hardware to calculate an elliptic curve point (x1, y1) = [k]G. The SM2 engine 626 returns the elliptic curve point (x1, y1). k is a random number. G is the elliptic curve base point. Step S1302 may include the execution of a microinstruction for the point multiplication hardware operation.

[0142] Step S1304 loads the hash value e from the system memory to the processor 600 according to the hash value e pointer saved in the input register EAX, and calculates a value r = (e + x1) mod n. n is one of the elliptic curve parameters and is the order of the base point G.

[0143] Step S1306 verifies whether the value r is zero, or whether r + k is n. If r is zero, or / and r + k is n holds, the process returns to step S1302 to operate the point multiplication hardware again with a new random number k. If r is not zero and r + k is not n, the process enters step S1308.

[0144] Step S1308 is based on the private key d A pointer saved in the input register EBX to load the private key d A of the signer from the system memory to the processor 600, and calculates the value (1 + d A ) -1, with an order-n input SM2 engine 626, using the modular inverse hardware of the SM2 engine 626, calculates a value s' = (1 + d A ) -1 mod n. Based on the value s', the modular multiplication hardware of the SM2 engine 626 calculates a value s = (s' * (k - r * d A )) mod n. The modular inverse hardware can receive a first modular inverse input and a second modular inverse input, and generate a modular inverse output. The modular multiplication hardware can receive a first modular multiplication input, a second modular multiplication input, and a third modular multiplication input, and generate a modular multiplication output. When r is not zero and r + k is not n, the processor executes the modular inverse hardware operation micro-instruction and the modular multiplication hardware operation micro-instruction provided by the multiple micro-instructions. In response to the modular inverse hardware operation micro-instruction, the modular inverse hardware performs a modular inverse operation, s' = (1 + d A ) -1 mod n, (1 + d A ) is the first modular inverse input, n is the second modular inverse input, and s' is the modular inverse output. In response to the modular multiplication hardware operation micro-instruction, the modular multiplication hardware performs a modular multiplication operation s = (s' * (k - r * d A )) mod n, s' is the first modular multiplication input, (k - r * d A ) is the second modular multiplication input, n is the third modular multiplication input, and s is the modular multiplication output.

[0145] Step S1310 verifies whether the value s is zero. If so, the process returns to step S1302 to operate the point multiplication hardware again with a new random number k. If s is not zero, in step S1312, the processor loads the signature (r, s) into the system memory according to the signature (r, s) pointer saved in the input register EDI, and loads the length of the signature (r, s) into the register ECX. Step S1314 ends the signature operation triggered by the SM2 cryptographic algorithm instruction.

[0146] In summary, in response to an elliptic curve cryptographic algorithm instruction (SM2 cryptographic algorithm instruction) of an instruction set architecture (ISA), a processor obtains a hash value (e) of a data to be signed (M) from a first memory space through a first register (EAX), obtains a private key (d A ) of the signer through a second register, and uses the private key (d A)Perform a signature operation of an elliptic curve cryptography algorithm on the hash (e) value to generate a signature (r, s), and write the signature (r, s) into a second memory space. With this ISA instruction, the present invention completes the above signature operation of the SM2 cryptography algorithm. Implementing the signature operation of the elliptic curve cryptography algorithm using the SM2 engine 626 can improve the operation speed and security. In addition to being assisted by special hardware (SM2 engine 626), there are also embodiments implemented entirely by microcode.

[0147] Next, discuss the signature verification operation of the SM2 cryptography algorithm, which also uses a first preprocessing operation and a second preprocessing operation that will be discussed in detail later. The first preprocessing operation and the second preprocessing operation are used to calculate a hash value e' for a data M' to be verified.

[0148] Figure 14 Illustrate the ucode design of the corresponding signature verification operation in Table 1404, showing how the corresponding generated microinstructions interpret the content of the architecture register 124. The aforementioned control word 6'b001000 (cw) will be stored in the input register EDX in advance to indicate the signature verification operation. In addition to the input register EDX, Table 1404 also lists the input registers EAX, EBX, ESI, and EDI item by item, all of which are used as input registers for the initial signature verification operation. Completion of the signature verification operation indicated by an ISA SM2 cryptography algorithm instruction includes filling the output register ECX. The application of input or output registers may also have other implementation manners.

[0149] When used as an input register, the register EAX stores a pointer to a hash value e', which points to a memory space (which can follow the ES segment segmentation technique) storing a hash value e'. The hash value e' is generated by the first preprocessing operation and the second preprocessing operation based on a data M' to be verified. The register EBX stores a public key P A pointer, which points to a memory space (which can follow the ES segment segmentation technique) storing a public key P A of the signer. The register EDX stores the control word cw indicating the verification signature code (6'b001000). The register ESI stores a pointer to an intermediate variable, which points to a memory space (also known as a scratch space, which can temporarily store intermediate variables with high security, can be 8K in size, can follow the ES segment segmentation technique, can be initialized to all 0, and can be applied for by software to the operating system). The register EDI stores a pointer to a signature (r', s'), which points to a memory space (which can follow the ES segment segmentation technique) storing a signature (r', s').

[0150] With the end of the signature verification operation indicated by the SM2 cryptographic algorithm instruction of this ISA, the adjustment of the output register includes: filling the register ECX, where '1' represents successful signature verification and '0' represents failed signature verification.

[0151] Figure 15 It is a flowchart that illustrates the signature verification operation triggered by an SM2 cryptographic algorithm instruction according to an embodiment of the present invention, corresponding to multiple microinstructions converted from the SM2 cryptographic algorithm instruction.

[0152] In step S1502, the signature (r’, s’) is loaded from the system memory to the processor 600 according to the signature (r’, s’) pointer saved in the input register EDI. Step S1504 checks two conditions: r’ ∈ [1, n - 1]; and s’ ∈ [1, n - 1]. The value n is the order of the elliptic curve base point G. If any of the conditions is not satisfied, step S1506 determines that the signature verification operation fails (for example, the register ECX is filled with 0). If both conditions are satisfied, step S1508 calculates the value t = (r’ + s’) mod n. Step S1510 checks whether the value t is zero. If so, step S1506 determines that the signature verification operation fails. If not, the process proceeds to step S1512.

[0153] In step S1512, a hardware operation control word (obtained from the register EDX), the value t, and the signature s’ are input into the SM2 engine 626, and using the point multiplication hardware, an elliptic curve point (x1’, y1’) = [s’]G + [t]P is calculated. A The SM2 engine 626 returns the elliptic curve point (x1’, y1’). Step S1512 may involve two microinstructions for point multiplication hardware operations. The first operation uses the SM2 engine 626 to calculate [s’]G. The second operation uses the SM2 engine 626 to calculate [t]P. A .

[0154] In step S1514, the hash value e’ of the data M’ to be verified (previously calculated and stored in the system memory through the first and second preprocessing operations) is loaded from the system memory to the processor 600 according to the hash value e’ pointer saved in the input register EAX, and a signature R = (e’ + x1’) mod n is calculated.

[0155] Step S1516 verifies whether the signature R is equal to the signature r'. If not, step S1506 determines that the signature verification operation fails and fills the output register ECX with 0. If so, step S1518 determines that the signature verification operation succeeds and fills the output register ECX with 1. In another embodiment, filling the output register ECX with 1 indicates that the signature verification operation fails, while filling the output register ECX with 0 indicates that the signature verification operation succeeds. In short, the present invention does not limit the specific values used to represent the success or failure of the signature verification operation. Step S1520 ends the signature verification operation triggered by the SM2 cryptographic algorithm instruction.

[0156] In short, in response to an elliptic curve cryptographic algorithm instruction (SM2 cryptographic algorithm instruction) of an instruction set architecture (ISA), a processor obtains a hash value e' of a data M' to be verified through a first register (EAX), and obtains a public key P of a signer through a second register (EBX) A , obtains a signature (r', s') through a third register, and performs a signature verification operation of an elliptic curve cryptographic algorithm on the hash value with the public key and the signature, and stores the verification result. The present invention completes the above signature verification operation of the SM2 cryptographic algorithm with this ISA instruction. Implementing the signature verification operation of the elliptic curve cryptographic algorithm using the SM2 engine 626 can improve the operation speed and security. In addition to being assisted by special hardware (SM2 engine 626), there are also embodiments implemented entirely in microcode.

[0157] Next, the key exchange function of the SM2 cryptographic algorithm is discussed, which uses a first key exchange program, a second key exchange program, and a third key exchange program. The second and third key exchange programs each have versions with and without a hash value involved. An embodiment of the present invention designs three elliptic curve cryptographic algorithm instructions (three SM2 cryptographic algorithm instructions) of an instruction set architecture. The initiator processor generates a key pair (r A , R A ) through the first elliptic curve cryptographic algorithm instruction. Based on the first temporary public key R A , and the second temporary public key R B generated by itself, the responder processor executes the second elliptic curve cryptographic algorithm instruction to generate the responder's shared public key K B . Based on the temporary private key r A , and the temporary public keys R A and R B , the initiator executes the third elliptic curve cryptographic algorithm instruction to generate the initiator's shared public key K A .

[0158] Figure 16The microcode ucode design of the corresponding first key exchange procedure is illustrated in Table 1604, showing how the microinstructions generated for the first SM2 cryptographic algorithm instruction interpret the content of architecture register 124. The aforementioned control word 6'b010000 (cw) will be stored in input register EDX in advance to indicate an operation of the first key exchange procedure. In addition to input register EDX, Table 1604 also lists input registers ESI and EDI separately, both serving as input registers for starting the operation of the first key exchange procedure. The completion of the first key exchange procedure operation indicated by an ISA SM2 cryptographic algorithm instruction includes filling output register EDI. The application of input or output registers may also have other implementation manners.

[0159] When serving as an input register, register EDX stores the control word cw indicating the first key exchange procedure code (6'b010000). Register ESI stores a pointer to an intermediate variable, pointing to a system memory space (also known as a scratch space, which can temporarily store intermediate variables with high security, with a size of 8K, can follow the ES segment segmentation technology, can be initialized to all 0, and can be applied for by software to the operating system). Register EDI stores a pointer to an output key pair (r A ,R A ), indicating the storage of the key pair (r A ,R A ) to a memory (which can follow the ES segment segmentation technology).

[0160] As the operation of the first key exchange procedure indicated by the ISA SM2 cryptographic algorithm instruction ends, output register ECX remains unchanged.

[0161] Figure 17 The flowchart illustrates the operation of the first key exchange procedure triggered by an SM2 cryptographic algorithm instruction according to an embodiment of the present invention, corresponding to multiple microinstructions converted from this SM2 cryptographic algorithm instruction. This SM2 cryptographic algorithm instruction is executed by the initiator of the key exchange.

[0162] In step S1702, a hardware operation control word (obtained from input register EDX) is input into SM2 engine 626, and using the point multiplication hardware, an elliptic curve point R A =[r A G=(x1,y1) is calculated. r A is a random number and serves as the temporary private key of the initiator. R A is the first temporary public key. Step S1702 may include the execution of a point multiplication hardware operation microinstruction, and may also include a random number generation microinstruction, operating a random number generator in the cryptographic execution unit 618 to generate a random number as the temporary private key r A .

[0163] Step S1704 checks two conditions: x1 ∈ [1, p - 1], and y1 ∈ [1, p - 1], where p is a prime number of 256 bits. If any of the conditions does not hold, the process returns to step S1702 to update the key pair with a new random number (r A , R A ). If both conditions hold, step S1706 checks whether the first temporary public key R A conforms to an elliptic curve (i.e., whether it satisfies the elliptic curve equation, the same below). If not, the process returns to step S1702 to update the key pair with a new random number (r A , R A ). If so, step S1708 loads the key pair (r A , R A ) into the memory according to the pointer of the output key pair (r A , R A ) saved in the input register EDI. Step S1710 ends the operation of the first program of the key exchange of the SM2 cryptographic algorithm. The key pair (r A , R A ) is retained by the initiator for use when generating the initiator's shared key K A . The first temporary public key R A also needs to be transmitted (e.g., through the network) to the responder so that the responder can perform the second program operation of the key exchange.

[0164] Figure 18 Table 1804 illustrates the ucode design of the corresponding second program operation of the key exchange, showing how the microinstructions corresponding to the second SM2 cryptographic algorithm instruction interpret the content of architecture register 124. The aforementioned control word (cw) 6'b010001 (not involving the hash value), or 6'b010101 (involving the hash value) will be stored in the input register EDX in advance to indicate the version of the second program operation of the key exchange that does not involve the hash value or involves the hash value. In addition to the input register EDX, Table 1804 lists the input registers EAX, ECX, ESI, and EDI separately, all of which are used as input registers for starting the second program operation of the key exchange. The completion of the key exchange second program indicated by an ISA's SM2 cryptographic algorithm instruction includes managing the output register EDI. There may be other implementation manners for the application of the input or output registers.

[0165] When used as an input register, the register EAX records a key exchange information pointer, pointing to a stored key exchange information stored in the memory (which can follow the ES segment segmentation technology). The key exchange information includes: the first temporary public key R A of the initiator; the responder's private key d B, responder public key P B , initiator public key P A , the bit length ID of the initiator identity identifier (i.e., the distinguishable identifier, the same below) A _len, initiator identity identifier ID A , the bit length ID of the responder identity identifier B _len, and responder identity identifier ID B . The register ECX stores a shared key bit length (klen). The shared key bit length klen depends on what the two communication parties need the key for; for example, when used for SM4 encryption, the shared key bit length klen can be 128 bits / 192 bits / 256 bits. The register EDX stores one of the two control words cw indicating the second program operation of the key exchange (one of the two types of the second program code of the key exchange: 6'b010001 not involving the hash value, or 6'b010101 involving the hash value). The register ESI stores a pointer to an intermediate variable, pointing to a system memory space (also known as the scratch space, which can temporarily store intermediate variables with high security, can be 8K in size, can follow the ES segment segmentation technology, can be initialized to all 0, and can be applied for by software to the operating system). The register EDI stores a pointer to a shared key, indicating a responder shared key K generated by the responder B , the second ephemeral public key R B , even the hash values S2 and S B (optional; not used when not involving the hash value, used when involving the hash value) to the storage of this memory (can follow the ES segment segmentation technology).

[0166] As the second program operation of the key exchange indicated by the SM2 cryptographic algorithm instruction of this ISA ends, the output register EDI remains unchanged.

[0167] Figure 19A , 19B is a flowchart, which illustrates the second program operation of the key exchange triggered by an SM2 cryptographic algorithm instruction according to an embodiment of the present invention, corresponding to multiple microinstructions converted from this SM2 cryptographic algorithm instruction. This SM2 cryptographic algorithm instruction is executed by the responder of the key exchange.

[0168] Starting from Figure 19A , step S1902 inputs a hardware operation control word (obtained from the input register EDX) into the SM2 engine 626, and uses this point multiplication hardware to calculate an elliptic curve point R B =[r B G=(x2,y2). r B is a random number, serving as the ephemeral private key of the responder. R Bis the second temporary public key. Step S1902 may include the execution of a point multiplication hardware operation micro-instruction, and may also include a random number generation micro-instruction to operate a random number generator within the cryptographic execution unit 618 to generate a random number as the temporary private key r B .

[0169] Step S1904 calculates the value where w is a constant.

[0170] Step S1906 determines whether the first temporary public key R of the initiator A also conforms to an elliptic curve at the responder, where the first temporary public key R A is obtained from the system memory according to the key exchange information pointer stored in the input register EAX. If not, step S1908 is executed and the processor outputs a key exchange negotiation failure prompt. If so, in step S1910, the x coordinate x1 of the first temporary public key R A is loaded from the memory, and a value

[0171] Step S1912 inputs the value t B , the initiator's public key P A and the first temporary public key R A into the SM2 engine 626, and uses the point multiplication hardware to calculate an elliptic curve point Step S1912 may include the execution of two point multiplication hardware operation micro-instructions, one to calculate and the other to calculate

[0172] Step S1914 determines whether the elliptic curve point V is an infinite point (also known as an infinitely distant point or a zero point). If so, step S1908 is executed and the responder outputs a key exchange negotiation failure prompt. If not, the process proceeds to Figure 19B step S1916.

[0173] In step S1916, according to the key exchange information pointer stored in the input register EAX, the initiator identity identifier bit length ID A _len, the initiator identity identifier ID A , the responder identity identifier bit length ID B _len, and the responder identity identifier ID B are loaded into the processor 600, the identity hash value Z A and Z B are calculated, and then key derivation is performed to calculate the responder's shared key K B = KDF(x V ||y V||Z A ||Z B , klen). In one implementation, the identity hash value Z A and Z B are calculated using the first preprocessing operation.

[0174] Step S1918 checks the control word cw stored in register EDX to determine whether to output the hash value calculation result. If not (6’b 010001), step S1920 loads the responder's shared key K B and the second temporary public key R B into the system memory, and then step S1922 ends the second program operation of the key exchange triggered by an SM2 cryptographic algorithm instruction. Otherwise (cw = 6’b010101), the process proceeds to steps S1924 and S1926.

[0175] Step S1924 calculates the hash value S2,

[0176] S2 = Hash(0x03||y V ||Hash(x V ||Z A ||Z B ||x1||y1||x2||y2)).

[0177] Step S1926 calculates the hash value S B ,

[0178] S B = Hash(0x02||y V ||Hash(x V ||Z A ||Z B ||x1||y1||x2||y2)).

[0179] Step S1928 loads the responder's shared key K B , the second temporary public key R B , the hash values S2 and S B into the system memory according to the shared key pointer stored in input register EDI, and then step S1922 ends the second program operation of the key exchange triggered by an SM2 cryptographic algorithm instruction. The second temporary public key R B also needs to be transmitted (e.g., via a network) to the initiator so that the initiator can perform the third program operation of the key exchange.

[0180] Figure 20The microcode ucode design for the corresponding key exchange third program operation is illustrated in Table 2004, showing how the microinstructions generated corresponding to the third SM2 cryptographic algorithm instruction interpret the content of architecture register 124. The aforementioned control word (cw) 6’b010010 (not involving hash value), or 6’b 010110 (involving hash value) will be stored in input register EDX in advance to indicate the version of the key exchange third program operation that does not involve hash value or involves hash value. In addition to input register EDX, Table 2004 also lists input registers EAX, ECX, ESI, and EDI item by item, all of which are used as input registers for the initial key exchange third program operation. The completion of the key exchange third program operation indicated by an ISA SM2 cryptographic algorithm instruction includes managing output register EDI. The application of input or output registers may also have other implementation manners.

[0181] When used as an input register, register EAX stores a key exchange information pointer that points to the key exchange information stored in memory. The key exchange information includes: the initiator's ephemeral private key r A , the initiator's first ephemeral public key R A , the second ephemeral public key R provided by the responder B , the responder's public key P B , the initiator's private key d A , the initiator's public key P A , the initiator's identity identifier length ID A _len, the initiator's identity identifier ID A , the responder's identity identifier length ID B _len, and the responder's identity identifier ID B . Register ECX stores a shared key bit length (klen). Register EDX stores one of the two control words cw indicating the key exchange second program (one of the two types of key exchange second program codes; 6’b 010010 not involving hash value, or 6’b 010110 involving hash value). Register ESI stores a pointer to an intermediate variable that points to a system memory space (also known as a scratch space, which can temporarily store intermediate variables with high security, can be 8K in size, can follow the ES segment segmentation technology, can be initialized to all 0, and can be applied for by software to the operating system). Register EDI stores a pointer to a shared key, indicating a shared key K A generated by the initiator, and even the hash values S1 and S A (optional; not used when not involving hash value, used when involving hash value) to the storage of this memory (can follow the ES segment segmentation technology).

[0182] With the completion of the third program operation of the key exchange indicated by the SM2 cryptographic algorithm instruction of this instruction, the output register EDI remains unchanged.

[0183] Figure 21A 、 21B is a flowchart that illustrates the third program operation of the key exchange triggered by an SM2 cryptographic algorithm instruction according to an embodiment of the present invention, corresponding to multiple microinstructions converted from this SM2 cryptographic algorithm instruction. This SM2 cryptographic algorithm instruction is executed by the initiator of the key exchange.

[0184] Starting from Figure 21A , in step S2102, the x - coordinate x1 of the first temporary public key R A is loaded from the system memory to the processor 600 according to the key exchange information pointer stored in the input register EAX, and calculate In step S2104, the private key d A of the initiator is loaded from the system memory to the processor 600, and calculate In step S2106, it is determined whether the second temporary public key R B provided by the responder conforms to an elliptic curve of the initiator. If not, in step S2108, the processor outputs a key exchange negotiation failure prompt. On the contrary, in step S2110, calculate the value B using the x2 - coordinate of the second temporary public key R

[0185] In step S2112, the value t A 、 the responder's public key P B and the second temporary public key R B are input into the SM2 engine 626, and using the point - multiplication hardware, an elliptic curve point is calculated. The SM2 engine 626 returns the elliptic curve point U. Step S2112 may include the execution of two microinstructions for point - multiplication hardware operations, one calculating and the other calculating

[0186] In step S2114, it is determined whether the elliptic curve point U is an infinite point. If so, in step S2108, the processor outputs a key exchange negotiation failure prompt. If not, the process proceeds to Figure 21B step S2116.

[0187] In step S2116, according to the key exchange information pointer stored in the input register EAX, the initiator's identity identifier bit length ID A _len, the initiator's identity identifier ID A , the responder's identity identifier bit length ID B_len, and the responder identity identifier ID B Load into the processor 600, calculate the identity hash value Z A And Z B , and then perform key derivation to calculate the initiator's shared key K A = KDF(x U ||y U ||Z A ||Z B , klen). In one implementation, the identity hash value Z A And Z B Is calculated using the first preprocessing operation

[0188] Step S2118 checks the control word cw stored in the register EDX to determine whether to output the hash value calculation result. If not (6'b 010010), step S2120 loads the initiator's shared key K A Into the system memory, and then step S2122 ends the third program operation of the key exchange triggered by an SM2 cryptographic algorithm instruction. If so (cw = 6'b 010110), the process proceeds to steps S2124 and S2126

[0189] Step S2124 calculates the hash value S A ,

[0190] S A = Hash(0x03||y U ||Hash(x U ||Z A ||Z B ||x1||y1||x2||y2)).

[0191] Step S2126 calculates the hash value S1

[0192] S1 = Hash(0x02||y U ||Hash(x U ||Z A ||Z B ||x1||y1||x2||y2)).

[0193] Step S2128 loads the initiator's shared key K A , the hash value S A And S1 into the system memory according to the shared key pointer saved in the input register EDI, and then step S2122 ends the third program operation of the key exchange triggered by an SM2 cryptographic algorithm instruction

[0194] Taking the example of considering the hash value, the initiator's S A And S1 will be compared with the responder's S2 and SB Compare to determine whether the key exchange negotiation is successful.

[0195] Figure 22 According to an embodiment of the present invention, the following illustrates how the initiator and the responder use the first to third program operations of the key exchange proposed by the present invention to achieve key exchange. The initiator and the responder can communicate with each other. In one embodiment, the initiator and the responder each have a processor (600). In another embodiment, the processors of the initiator and the responder are the same (such as the processor 600). In another embodiment, the initiator and / or the responder is an encryption card. In short, the present invention does not limit the specific forms of the initiator and the responder.

[0196] Step S2202 enables the initiator to prepare the original data, including: elliptic curve system parameters, identity hash value Z A , Z B , the initiator's private key d A , the initiator's public key P A , and the responder's public key P B . Step S2204 enables the responder to prepare the original data, including: elliptic curve system parameters, identity hash value Z A , Z B , the responder's private key d B , the responder's public key P B , and the initiator's public key P A .

[0197] Step S2206 executes the first SM2 cryptographic algorithm instruction at the initiator, where the register EDX has been noted with the control word cw to perform the first program operation of the key exchange. The calculated first temporary public key R A is sent to the responder via communication.

[0198] Step S2208, the responder executes the second SM2 cryptographic algorithm instruction based on the first temporary public key R A sent by the initiator, where the register EDX has been noted with the control word cw to perform the second program operation of the key exchange. The second temporary public key R B calculated by the responder is sent to the initiator via communication. In addition, the responder also calculates a responder's shared key K B , and hash values S2 and S B with this second SM2 cryptographic algorithm instruction. The hash values S2 and S B are used to confirm whether the negotiation is successful later.

[0199] Step S2210, the initiator executes the third SM2 cryptographic algorithm instruction based on the second temporary public key R B, execute the third SM2 cryptographic algorithm instruction, where the register EDX has been annotated with the control word cw to indicate that it is performing the third program operation of key exchange. The initiator uses this third SM2 cryptographic algorithm instruction to calculate the initiator's shared key K A and the hash value S A and S1. The hash value S A and the hash value S1 are used to confirm whether the negotiation is successful later.

[0200] Step S2212 checks whether the hash value S1 is equal to the hash value S B (judgment by the initiator), and whether the hash value S2 is equal to the hash value S A (judgment by the responder). If both conditions are met, step S2214 causes the processor to determine that the key exchange from the initiator to the responder is successful. If either condition is not met, step S2216 causes the processor to output a prompt indicating that the key exchange negotiation has failed.

[0201] In summary, according to an embodiment of the present invention, the initiator uses a first register (EDI) and a second register (EAX). For a first elliptic curve cryptographic algorithm instruction of an instruction set architecture (ISA), the first register (EDI) stores a key pair (r A , R A ) pointer, indicating the storage of the key pair (r A , R A ) to memory. In response to the first elliptic curve cryptographic algorithm instruction, the processor performs a first program operation of key exchange for an elliptic curve cryptographic algorithm, generates a random number as a temporary private key r A , and uses the temporary private key r A to process an elliptic curve base point G to generate a first temporary public key R A , and writes the temporary private key r A and the first temporary public key R A to the memory through the first register. The second register (EAX) stores a key exchange information pointer, pointing to the key exchange information stored in the memory, and the key exchange information includes the temporary private key r A , the first temporary public key R A , and a second temporary public key R B . The second temporary public key R B is provided by the responder of the key exchange. The processor of the responder executes a second elliptic curve key algorithm instruction to perform a second program operation of key exchange for the elliptic curve cryptographic algorithm, generates the second temporary public key R B , and generates a responder's shared key K A based on the first temporary public key R B and the second temporary public key R BFor a third elliptic curve cryptography algorithm instruction, the first register (EDI) is updated to store a shared key pointer indicating an initiator shared key K A for storage to the memory. In response to the third elliptic curve cryptography algorithm instruction, the processor performs a third program operation of the elliptic curve cryptography algorithm's key exchange, obtaining the second temporary public key R through the second register (EAX) B , based on the temporary private key r A , the first temporary public key R A , and the second temporary public key R B to generate the initiator shared key K A , and writes the initiator shared key K A to the memory through the first register (EDI).

[0202] In summary, according to an embodiment of the present invention, a responder uses a first register (EDI) and a second register (EAX). The second register (EAX) stores a key exchange information pointer pointing to key exchange information stored in a memory, and the key exchange information includes a first temporary public key R A . The first temporary public key R A is provided by the initiator of the key exchange. The processor of the initiator executes a first elliptic curve key algorithm instruction of an instruction set architecture to perform a first program operation of the elliptic curve cryptography algorithm's key exchange to generate the first temporary public key R A . The first register stores a shared key pointer indicating a responder shared key K B , and storage of a second temporary public key R B to the memory. In response to a second elliptic curve cryptography algorithm instruction, the processor performs a second program operation of the elliptic curve cryptography algorithm's key exchange to generate a random number as a temporary private key r B , processes an elliptic curve base point G with the temporary private key r B to generate the second temporary public key R B , obtains the first temporary public key R through the second register (EAX) A , generates a responder shared key K A based on the first temporary public key R B and the second temporary public key R B , and deposits the second temporary public key R B , and the responder shared key K B into the memory through the first register (EDI). The second temporary public key R BFor the processor of the initiator to execute a third elliptic curve key algorithm instruction to perform a third program operation of key exchange of the elliptic curve cryptography algorithm to generate an initiator shared key K A .

[0203] The present invention completes the key exchange of the SM2 cryptography algorithm with only three simple ISA instructions. Compared with implementing the key exchange operation of the elliptic curve cryptography algorithm by using the SM2 engine 626 alone, the simultaneous use of the SM2 engine 626 and the SM3 engine 126 can improve the operation speed and security. In addition to being assisted by special hardware (the SM3 engine 126, the SM2 engine 626), there are also embodiments implemented entirely by microcode.

[0204] The following paragraphs will detail the first preprocessing operation and the second preprocessing operation applied to the hash value calculation.

[0205] Figure 23 Table 2304 illustrates the microcode ucode design corresponding to the first preprocessing operation, showing how the microinstructions corresponding to a single SM2 cryptography algorithm instruction interpret the content of the architecture register 124. The aforementioned control word (cw) 6’b 100000 will be stored in the input register EDX in advance to indicate that the single SM2 cryptography algorithm instruction performs the first preprocessing operation. In addition to the input register EDX, Table 2304 also lists the registers EAX, EBX, ECX, ESI, and EDI separately, all of which serve as input registers for the first preprocessing operation. The completion of the first preprocessing operation indicated by an ISA SM2 cryptography algorithm instruction also includes managing the output register EDI. There may be other implementation manners for the application of input or output registers.

[0206] When serving as an input register, the register EAX records a user identifier ID A pointer, pointing to a memory space (which can follow the ES segment segmentation technique) storing a user identifier ID A . The register EBX records a public key (x A , y A ) pointer, pointing to a memory space (which can follow the ES segment segmentation technique) storing a public key (x A , y A ). The register ECX records the bit length ENTL of the user identifier ID A A ​. The register EDX stores the control word cw (6’b100000) indicating the first preprocessing operation code. The register ESI stores a pointer to an intermediate variable, which points to a memory space (also known as a scratch space, which can temporarily store intermediate variables with high security, can be 8K in size, can follow the ES segment segmentation technology, can be initialized to all 0, and can be applied for by software to the operating system). The register EDI stores a preprocessing hash value Z A A pointer indicating a memory space (which can follow the ES segment segmentation technology) for storing a preprocessing hash value Z A .

[0207] After the first preprocessing operation indicated by the SM2 cryptographic algorithm instruction of this ISA ends, the output register EDI is incremented by a displacement amount, which is the number of 32-byte blocks of the preprocessing hash value Z A .

[0208] Figure 24 is a flowchart that illustrates the first preprocessing operation triggered by an SM2 cryptographic algorithm instruction according to an embodiment of the present invention, corresponding to multiple microinstructions converted from the SM2 cryptographic algorithm instruction

[0209] In step S2402, according to the user identifier ID saved in the input register EAX A The pointer loads the user identifier ID from the memory into the processor 600, and loads the length ENTL of the user identifier ID A into the processor 600 from the input register ECX. In step S2404, the data S is pieced together, A where S = ENTL A || ID

[0210] || a || b || x A || y A || x G || y G || x A || y A

[0211] a and b are elliptic curve parameters, (x G , y G ) is a base point G of an elliptic curve, (x A , y A ) is the public key, and S is a bit string

[0212] In step S2406, message padding is performed on the bit string S. In step S2408, the hardware operation control word, the loop size (the number of bytes of the bit string S), and the value of the bit string S after padding are input into the SM2 engine 626, and the preprocessing hardware therein is used to implement the preprocessing hash value operation through the SM3 engine 126

[0213] Z A = Hash(ENTL A || ID A || a || b || x G || y G || x A || y A )

[0214] Among them, the calculation formula for the loop size is: 2 + ECX / 8 + 32 + 32 + 32 + 32 + 32 + 32, where ECX is the bit length ENTL of the user identifier ID A of A .

[0215] Step S2408 may include a preprocessing hardware operation micro-instruction and even an SM3 engine operation micro-instruction. In step S2410, the SM2 engine 626 returns the preprocessing hash value Z A . In step S2412, according to the preprocessing hash value Z saved in the input register EDI A pointer, the preprocessing hash value Z A is loaded into the memory. Step S2414 ends the first preprocessing operation triggered by an SM2 cryptographic algorithm instruction

[0216] In summary, in response to an elliptic curve cryptographic algorithm instruction (SM2 cryptographic algorithm instruction) of an instruction set architecture (ISA), a processor obtains a user identifier ID through a first register (EAX) A , obtains the public key (x A , y A ) through a second register (EBX), and performs a first preprocessing operation of an elliptic curve cryptographic algorithm on the public key (x A , y A ), the user identifier ID A , and a user identifier length ENTL A to generate a preprocessing hash value Z A , and writes the preprocessing hash value Z A into the memory for subsequent use in a second preprocessing operation. The present invention completes the first preprocessing operation of the SM2 cryptographic algorithm with a single ISA instruction. In addition to being assisted by special hardware (SM3 engine 126, SM2 engine 626), there are also embodiments implemented entirely by microcode

[0217] Figure 25The microcode ucode design for the corresponding second preprocessing operation is illustrated in Table 2504, showing how the microinstructions generated for a single SM2 cryptographic algorithm instruction interpret the content of architecture register 124. The aforementioned control word (cw) 6’b100001 is pre-stored in input register EDX to indicate the second preprocessing operation. In addition to input register EDX, Table 2504 also lists input registers EAX, EBX, ECX, and EDI one by one, all of which serve as input registers for the second preprocessing operation. The completion of the second preprocessing operation indicated by an ISA SM2 cryptographic algorithm instruction also includes managing output register EDI. The application of input or output registers may also have other implementation manners.

[0218] When serving as an input register, register EAX stores a preprocessing hash value Z A Pointer, pointing to the preprocessing hash value Z generated and stored in an earlier first preprocessing operation A . Register EBX stores a pointer to an input data M, pointing to a memory space (which may follow the ES segment segmentation technique) storing an input data M (e.g., the data to be signed in a signature operation or the signed data in a signature verification operation). Register ECX stores the number of bytes of the input data M. Register EDX stores the control word cw (6’b 100001) indicating the second preprocessing operation code. Register EDI stores a pointer to a hash value e, indicating a memory space (which may follow the ES segment segmentation technique) for storing a hash value e.

[0219] With the end of the second preprocessing operation indicated by the ISA SM2 cryptographic algorithm instruction, the output register EDI is incremented by a displacement amount, which is the number of 32-byte blocks of the hash value e.

[0220] Figure 26 is a flowchart, illustrating the second preprocessing operation triggered by an SM2 cryptographic algorithm instruction according to an embodiment of the present invention, and the multiple microinstructions converted from the SM2 cryptographic algorithm instruction.

[0221] Step S2602 loads a preprocessing hash value Z A pointer from the system memory and an input data M into the processor 600 according to the preprocessing hash value Z saved in input register EAX. A Step S2604 assembles the preprocessing data Step S2606 performs message padding on the preprocessing data.

[0222] Step S2608 loads a hardware operation control word, the loop size (the number of bytes of the preprocessing data The filled result is input into the SM2 engine 626, and the preprocessing hardware therein is used to implement the hash value through the SM3 engine 126 operations. Among them, the calculation formula for the loop size is: 32 + ECX, where ECX is the number of bytes of the input data M. Step S2608 may include a preprocessing hardware operation micro-instruction and even an SM3 engine operation micro-instruction. In step S2610, the SM2 engine 626 returns the hash value e. In step S2612, the hash value e is loaded into the system memory according to the hash value e pointer saved in the input register EDI. Step S2614 ends the second preprocessing operation triggered by the SM2 cryptographic algorithm instruction

[0223] In summary, in response to an elliptic curve cryptographic algorithm instruction (SM2 cryptographic algorithm instruction) of an instruction set architecture (ISA), a processor obtains a preprocessed hash value Z from memory through a first register (EAX) A , obtains an input data M from memory through a second register (EBX), and performs a second preprocessing operation of the elliptic curve cryptographic algorithm on the preprocessed hash value Z A and the input data M to generate a preprocessed data and based on the preprocessed data converts the hash value e and stores the hash value e in memory. The present invention completes the second preprocessing operation of the SM2 cryptographic algorithm with a single ISA instruction. In addition to being assisted by special hardware (SM3 engine 126, SM2 engine 626), there are also embodiments implemented entirely by microcode

[0224] The above preprocessing design enables the hash value operation to be implemented by two SM2 cryptographic algorithm instructions, converting the input data M into the hash value e. The first SM2 cryptographic algorithm instruction performs the first preprocessing operation to generate a preprocessed hash value Z related to the user identity A = Hash(ENTL A ||ID A ||a||b||x G ||y G ||x A ||y A ). The second SM2 cryptographic algorithm instruction performs the second preprocessing operation to generate the hash value e based on the input data M and the preprocessed hash value Z A , including operations: and Before the signature operation, the first and second preprocessing operations can be used to prepare the hash value for the data to be signed. Before the signature verification, the first and second preprocessing operations can also be used to prepare the hash value for the data to be verified

[0225] In addition, taking the example of key exchange, the aforementioned first preprocessing operation can also be used to implement the calculation of the identity hash value Z. B For the calculation of the identity hash value Z A different from the above, when using the first preprocessing operation to calculate the identity hash value Z B the register EAX records a pointer to a user identifier ID B to point to a memory space (which can follow the ES segment technology) storing a user identifier ID B . The register EBX records a pointer to a public key (x B , y B ) to point to a memory space (which can follow the ES segment technology) storing a public key (x B , y B ). The register ECX records the bit length ENTL B of the user identifier ID B . The register EDI stores a pointer to a preprocessing hash value Z B indicating a memory space (which can follow the ES segment technology) for storing the preprocessing hash value Z B . And, in the steps of the flowchart shown in Figure 24 , the data related to the calculation of the preprocessing hash value Z B is also used, which will not be elaborated here.

[0226] The following paragraphs detail the hardware implementation of the present invention.

[0227] Figure 27 According to an embodiment of the present invention, the detailed hardware architecture of the SM2 engine 626 is illustrated, including a control logic hardware 2702, a point multiplication hardware 2704, a preprocessing hardware 2706, a modular multiplication hardware 2708, and a modular inverse hardware 2710. The cryptographic execution unit 618 additionally has a random number generator 2712. The SM2 engine 626 is also coupled to the random number generator 2712 and the SM3 engine 126.

[0228] According to a hardware operation control word 2714, the control logic hardware 2702 outputs a control signal pnt_mul to drive the point multiplication hardware 2704, or outputs a control signal pre_process to drive the preprocessing hardware 2706, or outputs a control signal modular_mul to drive the modular multiplication hardware 2708, or outputs a control signal modular_inverse to drive the modular inverse hardware 2710. The input data 2716 can be obtained according to the content of the input registers of each operation. The return data of each operation of the SM2 engine 626 is the output data 2718.

[0229] Figure 28According to an embodiment of the present invention, a dot product hardware operation micro-instruction drives the dot product hardware 2704, which implements a first coordinate system conversion hardware 2802, a multiple point calculation hardware 2804, and a second coordinate system conversion hardware 2806. The dot product hardware 2704 is also coupled to a modular multiplication hardware 2708 and a modular inverse hardware 2710. After an elliptic curve input point 2808 and an input large number 2810 are input into the dot product hardware 2704, in combination with the use of the modular multiplication hardware 2708 and the modular inverse hardware 2710, an elliptic curve output point 2812 is converted.

[0230] In one embodiment, the first coordinate system conversion hardware 2802 converts the elliptic curve input point 2808, which is an affine coordinate point, into a first intermediate point, which is a weighted projective coordinate point. The multiple point calculation hardware 2804 performs a multiple point calculation on the first intermediate point with the input large number 2810 to generate a second intermediate point. The second coordinate system conversion hardware 2806 converts the second intermediate point, which is a weighted projective coordinate point, into the elliptic curve output point 2812. The elliptic curve output point 2812 is an affine coordinate point.

[0231] Figure 29 According to an embodiment of the present invention, a preprocessing hardware operation micro-instruction drives the preprocessing hardware 2706, which performs message grouping, converts an input data 2902 that has undergone message padding processing into n groups of input messages B(0)…B(n - 1), and sequentially passes them to the SM3 engine 126 for message expansion and iterative compression, sequentially generating instantaneous hash values, and finally converting into a converted hash value 2904. Specifically, the preprocessing hardware 2706 passes the first group of input messages B(0) and the initial hash constant V(0) to the SM3 engine 126 to generate an instantaneous hash value V(1), and then passes the second group of input messages B(1) and the instantaneous hash value V(1) to the SM3 engine 126 to generate an instantaneous hash value V(2), and so on, until the converted hash value V(n) is generated.

[0232] Figure 30 According to an embodiment of the present invention, a modular multiplication hardware operation micro-instruction drives the modular multiplication hardware 2708, which implements an operation according to a hardware input:

[0233] Output product = (input multiplier #1) * (input multiplier #2) mod (input modulus)

[0234] The input multiplier #1, the input multiplier #2, and the input modulus can be respectively referred to as the first, second, and third modular multiplication inputs. The output product is the modular multiplication output.

[0235] Figure 31According to an embodiment of the present invention, the modular inverse hardware 2710 driven by the microinstructions of the inverse hardware operation of Diagram 1 performs operations according to the hardware input:

[0236] Modular inverse output = (input large number) -1 mod (input modulus)

[0237] The input large number can be called the first modular inverse input. The input modulus can be called the second modular inverse input.

[0238] The hardware and microcode ucode design of the present invention is more likely to have various deformations.

[0239] In one embodiment, the cryptographic execution unit 118 does not specifically design the SM2 engine 626, but by planning the content of the microcode ucode, multiple microinstruction operation logic units ALU are converted from a single ISA SM2 cryptographic algorithm instruction, that is, the SM2 cryptographic algorithm is completed.

[0240] In one embodiment, the SM2 engine has fewer functional modules than the SM2 engine 626, and the missing functional modules (for example, the modular multiplication hardware 2708) are implemented by using the microcode ucode to configure the microinstruction operation logic unit ALU.

[0241] As can be seen from the above, in the known technology, the SM2 cryptographic algorithm is implemented by using software and / or dedicated hardware (such as an external cryptographic card, etc.). Implementing it with software cannot effectively guarantee the security of data, and implementing it with dedicated hardware requires additional purchase of dedicated hardware during deployment, so the deployment cost will increase. However, through the processor with the elliptic curve cryptographic algorithm (SM2) and its processing method provided by the present invention, the elliptic curve cryptographic algorithm can be implemented with only one instruction set architecture instruction, and the intermediate data generated during the implementation of the elliptic curve cryptographic algorithm can be stored in the internal hardware storage space of the processor, making these intermediate data inaccessible outside the processor, greatly improving the security. In addition, since there is no need to purchase dedicated hardware separately during deployment, the deployment cost is reduced.

[0242] Although the present invention has been disclosed above with preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications and refinements without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention is defined by the claims.

[0243] [Symbolic Explanation]

[0244] 100: Processor;

[0245] 102: Branch predictor;

[0246] 104: Instruction cache;

[0247] 106: Instruction cache (XIB);

[0248] 108: Format instruction queue (FIQ);

[0249] 110: Decoder;

[0250] 112: Instruction queue (XIQ);

[0251] 114: Rename unit;

[0252] 116: Memory order buffer;

[0253] 118: Cryptographic execution unit;

[0254] 120: Data cache;

[0255] 122: Reorder buffer;

[0256] 124: Architecture register;

[0257] 126: SM3 engine (Hash cryptographic algorithm accelerator);

[0258] 202, 212, 222, 232: Formats of SM3 cryptographic algorithm instructions;

[0259] 204, 214, 224, 234: Tables, microcode ucode design for corresponding formats 202, 212, 222, 232;

[0260] 300: Program code;

[0261] 302: SM3 cryptographic algorithm instructions;

[0262] 304: At least one register setting instruction;

[0263] 500: SM3 engine;

[0264] 502: Hardware for message expansion;

[0265] 504: Hardware for iterative compression;

[0266] 506: Functional hardware to implement Boolean functions FFj and GGj, and permutation function P0(.);

[0267] 508: Initial hash value V(0);

[0268] 600: Processor;

[0269] 618: Cryptographic execution unit;

[0270] 626: SM2 engine;

[0271] 702: Format of SM2 cryptographic algorithm instructions;

[0272] 804: Table, encryption operation of the corresponding SM2 cryptographic algorithm;

[0273] 1004: Table, decryption operation of the corresponding SM2 cryptographic algorithm;

[0274] 1204: Table, signature operation of the corresponding SM2 cryptographic algorithm;

[0275] 1404: Table, signature verification operation of the corresponding SM2 cryptographic algorithm;

[0276] 1604: Table, first program operation of key exchange of the corresponding SM2 cryptographic algorithm;

[0277] 1804: Table, second program operation of key exchange of the corresponding SM2 cryptographic algorithm;

[0278] 2004: Table, third program operation of key exchange of the corresponding SM2 cryptographic algorithm;

[0279] 2304: Table, first preprocessing operation of the corresponding SM2 cryptographic algorithm;

[0280] 2504: Table, second preprocessing operation of the corresponding SM2 cryptographic algorithm;

[0281] 2702: Control logic hardware;

[0282] 2704: Scalar multiplication hardware;

[0283] 2706: Preprocessing hardware;

[0284] 2708: Modular multiplication hardware;

[0285] 2710: Modular inverse hardware;

[0286] 2712: Random number generator;

[0287] 2714: Hardware operation control word;

[0288] 2716: Input data;

[0289] 2718: Output data;

[0290] 2802: First coordinate system conversion hardware;

[0291] 2804: Multiple point calculation hardware;

[0292] 2806: Second coordinate system conversion hardware;

[0293] 2808: Elliptic curve input point;

[0294] 2810: Input large number;

[0295] 2812: Output point of elliptic curve;

[0296] 2902: Input data

[0297] 2904: Converted hash value;

[0298] A…H: Parameters;

[0299] AGU: Address generation unit;

[0300] ALU: Arithmetic logic unit;

[0301] DTLB: Data translation lookaside buffer;

[0302] EAX, ECX, ESI, EDI ~ Registers;

[0303] Fadd, Fmul, Fmisc, MMX: Corresponding hardware for various instructions;

[0304] ITLB: Instruction translation lookaside buffer;

[0305] M1…M3 ~ Internal storage space of accelerator;

[0306] Opcode, ModR / M, SIB, Displacement, and Immediate:

[0307] Format fields of SM3 cryptographic algorithm instructions;

[0308] pnt_mul, pre_process, modular_mu, modular_inverse: Hardware control signals;

[0309] RS: Reservation station;

[0310] S402…S418, S902…S920, S1102…S1126, S1302…S1314, S1502…S1520, S1702…S1710, S1902…S1928, S2102…S2128, S2202…S2216, S2402…S2414, S2602…S2614: Steps;

[0311] ucode: Microcode;

[0312] V(i + 1): Hash value;

[0313] And 132 words extended from each input message B(i).

Claims

1. A processor with an elliptic curve cryptography algorithm, comprising: A first register that stores a private key pointer pointing to a private key; And A third register, Wherein, in response to a single elliptic curve cryptography algorithm instruction of an instruction set architecture, the processor obtains a ciphertext input from a first memory space, performs a decryption operation of the elliptic curve cryptography algorithm on the ciphertext input by using the private key obtained through the first register, decrypts the ciphertext input into a plaintext output, and writes the plaintext output into a second memory space; The third register stores an intermediate variable pointer pointing to a third memory space; An intermediate variable generated by the processor performing the decryption operation on the ciphertext input is temporarily stored in the third memory space according to the intermediate variable pointer stored in the third register; And Before performing the decryption operation on the ciphertext input, the processor stores the starting address of the third memory space in the third register and sets all bytes in the third memory space to zero.

2. The processor with an elliptic curve cryptography algorithm according to claim 1, wherein: Parameters of the single elliptic curve cryptography algorithm instruction include a ciphertext input pointer pointing to the first memory space, a plaintext output pointer pointing to the second memory space, and the private key pointer.

3. The processor with an elliptic curve cryptography algorithm according to claim 1, further comprising: A second register that stores the length of the ciphertext input.

4. The processor with an elliptic curve cryptography algorithm according to claim 1, wherein: The third memory space is applied for by software to the operating system.

5. The processor with an elliptic curve cryptography algorithm according to claim 1, further comprising: A second register that stores the length of the ciphertext input; Wherein, after the processor performs the decryption operation on the ciphertext input, it updates the length of the plaintext output stored in the second register.

6. The processor with an elliptic curve cryptography algorithm according to claim 1, further comprising: A fourth register that stores a plaintext output pointer pointing to the second memory space; Wherein, after the processor performs the decryption operation on the ciphertext input, it increases the content of the fourth register by a displacement amount; The displacement amount is the length of the plaintext output.

7. The processor with an elliptic curve cryptography algorithm according to claim 1, further comprising: A fifth register that stores a ciphertext input pointer pointing to the first memory space; Wherein, after the processor performs the decryption operation on the ciphertext input, it increases the content of the fifth register by a displacement amount; The displacement amount is the length of the ciphertext input.

8. The processor with an elliptic curve cryptography algorithm according to claim 1, further comprising: A sixth register that stores a control word indicating that the single elliptic curve cryptography algorithm instruction performs the decryption operation.

9. The processor with an elliptic curve cryptography algorithm according to claim 1, further comprising: A cryptographic execution unit; A set of architecture registers including the first register; A microcode storage device that stores microcode; And A decoder that, in response to the single elliptic curve cryptography algorithm instruction, decodes multiple microinstructions according to the microcode; Among them, the multiple microinstructions generated in response to the single elliptic curve cryptography algorithm instruction include accessing and managing the content of the set of architecture registers, and when the control word decoded from one of the set of architecture registers indicates a decryption code, the cryptographic execution unit is operated to perform the decryption operation of the elliptic curve cryptography algorithm on the ciphertext input with the private key.

10. The processor with an elliptic curve cryptography algorithm as claimed in claim 9, wherein: The cryptographic execution unit includes an elliptic curve cryptography algorithm accelerator, wherein the point multiplication hardware receives an elliptic curve input point and an input large number, and generates an elliptic curve output point therefrom.

11. The processor with an elliptic curve cryptography algorithm as claimed in claim 10, wherein: The multiple microinstructions include checking whether C1 taken from the ciphertext input conforms to the elliptic curve, the ciphertext input being C, where C = C1||C2||C3 or C = C1||C3||C2, and C1, C2, and C3 are partial ciphertexts; When C1 does not conform to the elliptic curve, the processor outputs a decryption failure prompt; The multiple microinstructions include first point multiplication hardware operation microinstructions, which are executed when C1 conforms to the elliptic curve; In response to the first point multiplication hardware operation microinstructions, the point multiplication hardware performs an operation, S = [h]C1, where h as the input large number is the elliptic curve cofactor, C1 as the elliptic curve input point, and S is the elliptic curve output point converted by the point multiplication hardware; and The multiple microinstructions include comparing whether S is a zero point, and when S is a zero point, the processor outputs a decryption failure prompt.

12. The processor with an elliptic curve cryptography algorithm as claimed in claim 11, wherein: The multiple microinstructions further include second point multiplication hardware operation microinstructions; When S is not zero, the dot product hardware performs operations in response to the second dot product hardware operation micro-instruction, (x2, y2) = [d B C1, where d as the input large number B is the private key, and (x2, y2) is the elliptic curve output point converted by the dot product hardware; The multiple microinstructions include performing an operation, t = KDF(x2||y2||klen), where KDF(.) performs key derivation, klen is the bit length of C2, and t is the derived key; The multiple microinstructions include comparing whether t is zero, and when t is zero, the processor outputs a decryption failure prompt when S is a zero point.

13. The processor with an elliptic curve cryptography algorithm as claimed in claim 12, wherein: The multiple microinstructions perform an exclusive OR operation when t is not zero, M' = C2⊕t, and M' is the exclusive OR result; When the hash value developed based on M' is equal to C3, the multiple microinstructions output M' as the plaintext, the hash value being u, equal to Hash(x2||M'||y2); and When u is not equal to C3, the processor outputs a decryption failure prompt.

14. The processor with an elliptic curve cryptography algorithm as claimed in claim 10, wherein the point multiplication hardware includes: A first coordinate system conversion hardware that converts the elliptic curve input point, which is an affine coordinate point, into a first intermediate point, the first intermediate point being a weighted projective coordinate point; A multiple point calculation hardware that performs a multiple point calculation on the first intermediate point with the input large number to generate a second intermediate point; And A second coordinate system conversion hardware that converts the second intermediate point, which is a weighted projective coordinate point, into the elliptic curve output point, the elliptic curve output point being an affine coordinate point.

15. The processor with an elliptic curve cryptography algorithm as claimed in claim 10, wherein: The elliptic curve cryptography algorithm accelerator includes preprocessing hardware, and the cryptographic execution unit further includes a hash cryptography algorithm accelerator; The multiple microinstructions further include preprocessing hardware operation microinstructions. After the message padding of (x2||M’||y2) is completed, the preprocessing hardware is made to respond to the preprocessing hardware operation microinstructions to implement the grouping of (x2||M’||y2) to provide a grouped message to the hash cryptography algorithm accelerator for hash value conversion; and The preprocessing hardware further has an internal storage space in the execution unit to temporarily store the initial hash value for use by the hash cryptography algorithm accelerator, and then updated by the hash cryptography algorithm accelerator until Hash(x2||M’||y2) is filled in as u.

16. A processing method of a processor, comprising: In response to a single elliptic curve cryptography algorithm instruction of an instruction set architecture, obtaining a ciphertext input from a first memory space, decrypting the ciphertext input using a private key by an elliptic curve cryptography algorithm, decrypting the ciphertext input into a plaintext output, and writing the plaintext output into a second memory space; Temporarily storing intermediate variables generated by performing the decryption operation on the ciphertext input in a third memory space; And Before performing the decryption operation on the ciphertext input, setting all bytes in the third memory space to zero.

17. The processing method as claimed in claim 16, wherein: The parameters of the single elliptic curve cryptography algorithm instruction include a ciphertext input pointer pointing to the first memory space, a plaintext output pointer pointing to the second memory space, and a private key pointer pointing to the private key.

18. The processing method as claimed in claim 16, wherein: The third memory space is applied for from the operating system by software.

19. The processing method as claimed in claim 16, further comprising: In response to the single elliptic curve cryptography algorithm instruction, decoding multiple microinstructions according to microcode; And In response to the multiple microinstructions generated by the single elliptic curve cryptography algorithm instruction, when the control word indicates a decryption code, performing the decryption operation of the elliptic curve cryptography algorithm on the ciphertext input using the private key.

Citation Information

Patent Citations

  • Sanctioned client device and methods for use therewith

    US20120221847A1

  • Reversible cipher

    US20120328091A1

  • Secure crypto system attributes

    US20190245686A1