Random number generator and random number generation method

By generating random numbers through all-digital circuits and using control words and pulse signal logical operations, the problem of random number generation being affected by environmental factors in the existing technology is solved, and low-cost, high-reliability true random number generation is achieved.

CN114115807BActive Publication Date: 2025-09-23BOE TECHNOLOGY GROUP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202010898911.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-08-31
Publication Date
2025-09-23
Estimated Expiration
2041-03-25

AI Technical Summary

Technical Problem

Existing random number generation methods are severely affected by process, voltage and temperature, and require additional circuit correction, resulting in high reliability and cost of hardware random number generation.

Method used

A fully digital circuit is used to generate random numbers. The control word provides the circuit, pulse generation circuit and random number generation circuit. The logical operation of the pulse signal is used to generate a random number sequence, including a signal generator and a frequency synthesizer. The frequency and proportion of the pulse signal are controlled, and the probability deviation is corrected in combination with the clock signal sampling and post-processing circuit.

Benefits of technology

It achieves low cost, low power consumption, high reliability and high programmability, generates true random numbers, improves the unpredictability and randomness of random number sequences, and reduces dependence on environmental factors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114115807B_ABST
    Figure CN114115807B_ABST
Patent Text Reader

Abstract

The present disclosure provides a random number generator and a random number generation method. The random number generator includes: a control word providing circuit, which generates multiple control words in response to a first rule; a pulse generating circuit, connected to the control word providing circuit, which outputs multiple pulse signals in response to the multiple control words, wherein the pulse signals include a first frequency signal and a second frequency signal, and the probability of the first frequency signal and the second frequency signal appearing in the pulse signal is controlled by the corresponding control word; and a random number generating circuit, connected to the pulse generating circuit, which performs a logical operation on the multiple pulse signals to generate a random number sequence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a random number generator and a random number generation method. Background Art

[0002] Information encryption can be accomplished through both software and hardware. The hardware is responsible for providing random numbers, and the software is responsible for generating more complex keys based on the random numbers provided by the hardware and using the keys to encrypt information.

[0003] Currently, random number generation primarily utilizes natural physical noise, such as device noise, nuclear decay noise, Brownian motion noise, and thermal noise, by amplifying, extracting, and post-processing these noises to generate random numbers. This approach is significantly affected by circuit manufacturing processes, voltage, and temperature, necessitating additional circuitry for correction. Summary of the Invention

[0004] The embodiments of the present disclosure provide a random number generator and a random number generation method.

[0005] At least one embodiment of the present disclosure provides a random number generator, comprising:

[0006] a control word providing circuit that generates a plurality of control words in response to a first rule;

[0007] a pulse generating circuit connected to the control word providing circuit, and outputting a plurality of pulse signals in response to the plurality of control words, wherein the pulse signals include a first frequency signal and a second frequency signal, and the probability of the first frequency signal and the second frequency signal appearing in the pulse signals is controlled by the corresponding control words;

[0008] The random number generating circuit is connected to the pulse generating circuit and performs logic operation on the multi-channel pulse signals to generate a random number sequence.

[0009] Optionally, the pulse generating circuit comprises a plurality of pulse sub-circuits, and the plurality of pulse sub-circuits are respectively connected to the control word providing circuit and the random number generating circuit;

[0010] Each of the pulse sub-circuits generates one pulse signal according to one of the control words.

[0011] Optionally, the pulse sub-circuit comprises: a signal generator and a frequency synthesizer, wherein the frequency synthesizer is respectively connected to the signal generator, the control word providing circuit and the random number generating circuit;

[0012] The signal generator generates a reference pulse signal with uniform phase intervals in response to the initial pulse signal;

[0013] The frequency synthesizer generates the pulse signal in response to the reference pulse signal and the control word;

[0014] Wherein, the control word includes a first coefficient and a second coefficient;

[0015] The pulse signal includes the first frequency signal generated based on the reference pulse signal and the first coefficient and the second frequency signal generated based on the reference pulse signal and the first coefficient. The proportion of the first frequency signal and the second frequency signal in the pulse signal is controlled by the second coefficient.

[0016] Optionally, the frequency synthesizer includes: a first processing unit, a second processing unit and an output unit;

[0017] a first processing unit connected to the control word providing circuit, and generating a first control signal and a second control signal based on the control word;

[0018] a second processing unit connected to the first processing unit, selecting a first pulse signal from a reference pulse signal with uniform phase intervals based on the first control signal, selecting a second pulse signal from the reference pulse signal based on the second control signal, and selecting one of the first pulse signal and the second pulse signal as an output signal;

[0019] The output unit is connected to the second processing unit and generates the pulse signal based on the output signal of the second processing unit.

[0020] Optionally, the random number generation circuit includes: a first processing subcircuit and a second processing subcircuit;

[0021] The first processing sub-circuit is connected to the pulse generating circuit and performs a first processing on the multiple pulse signals, wherein the first processing includes at least one of XOR, XNOR, and NAND;

[0022] The second processing sub-circuit is connected to the first processing sub-circuit and performs a second processing on the multi-channel pulse signal after the first processing;

[0023] The second processing includes sampling the signal output by the first processing sub-circuit based on the clock signal to obtain the random number sequence.

[0024] Optionally, the random number generation circuit further includes: a clock sub-circuit connected to the second processing sub-circuit, providing the clock signal to the second processing sub-circuit.

[0025] Optionally, the clock subcircuit is configured to use an output of one of the plurality of pulse subcircuits as the clock signal;

[0026] Alternatively, the clock sub-circuit is configured to use an output of an external clock as the clock signal.

[0027] Optionally, the random number generator further includes:

[0028] The post-processing circuit is connected to the random number generation circuit and performs probability deviation correction on the random number sequence output by the random number generation circuit.

[0029] Optionally, the post-processing circuit includes:

[0030] A storage module for storing random sequences;

[0031] a processing module, connected to the random number generation circuit and the storage module, respectively, and generating a first random number based on the random number output by the random number generation circuit and a bit in the random sequence of the storage module;

[0032] The operation module is connected to the processing module, performs a logic operation on the first random number output by the processing module and the second random number output by the operation module in the previous cycle, and outputs a third random number.

[0033] Optionally, the control word is a numerical value, and the integer parts of the multiple control words are prime numbers to each other.

[0034] At least one embodiment of the present disclosure provides a method for generating a random number, the method comprising:

[0035] generating a plurality of control words in response to a first rule;

[0036] In response to the multiple control words, output multiple pulse signals, the pulse signals including a first frequency signal and a second frequency signal, wherein the probability of the first frequency signal and the second frequency signal appearing in the pulse signals is controlled by the corresponding control words;

[0037] Performing logic operations on the multiple pulse signals to generate a random number sequence.

[0038] Optionally, the outputting multiple pulse signals in response to the multiple control words includes:

[0039] generating a reference pulse signal with uniform phase intervals in response to the initial pulse signal;

[0040] generating the pulse signal in response to the reference pulse signal and the control word;

[0041] Wherein, the control word includes a first coefficient and a second coefficient;

[0042] The pulse signal includes the first frequency signal generated based on the reference pulse signal and the first coefficient and the second frequency signal generated based on the reference pulse signal and the first coefficient. The proportion of the first frequency signal and the second frequency signal in the pulse signal is controlled by the second coefficient.

[0043] Optionally, performing a logical operation on the multiple pulse signals to generate a random number sequence includes:

[0044] Performing a first processing on the multiple pulse signals, wherein the first processing includes at least one of XOR, XNOR, and NAND;

[0045] Performing a second processing on the multi-channel pulse signal after the first processing; wherein the second processing includes sampling the signal output by the first processing based on a clock signal to obtain the random number sequence.

[0046] Optionally, the method further includes:

[0047] Probability deviation correction is performed on the random number sequence output by the random number generation circuit.

[0048] Optionally, performing probability deviation correction on the random number sequence output by the random number generation circuit includes:

[0049] Generate a first random number based on the generated random number sequence and one bit in the random sequence;

[0050] Perform a logical operation on the first random number and the second random number output in the previous cycle to output a third random number. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a schematic diagram of a random number generation scheme in the related art;

[0052] Figure 2 is a schematic structural diagram of a random number generator provided by an embodiment of the present disclosure;

[0053] Figure 3 A schematic structural diagram of a pulse sub-circuit provided by an embodiment of the present disclosure is shown;

[0054] Figure 4 To adopt Figure 3 Waveform diagram of K-channel reference pulse signals with uniform phase intervals generated by the signal generator in FIG.

[0055] Figure 5 This is a schematic diagram of the principle of using a frequency synthesizer to synthesize a pulse signal;

[0056] Figure 6 A schematic structural diagram of a frequency synthesizer provided by the present disclosure;

[0057] Figure 7 A schematic diagram showing the relationship between the frequency Fo of the pulse signal provided by the present disclosure and the control word F;

[0058] Figure 8 A schematic structural diagram of a random number generation circuit provided by an embodiment of the present disclosure is shown;

[0059] Figure 9 A detailed schematic diagram of a random number generation circuit provided by an embodiment of the present disclosure is shown;

[0060] Figure 10 is a schematic structural diagram of another random number generator provided by an embodiment of the present disclosure;

[0061] Figure 11 A schematic structural diagram of a post-processing circuit provided by an embodiment of the present disclosure is shown;

[0062] Figure 12 A schematic diagram of a random number sequence provided by an embodiment of the present disclosure is shown;

[0063] Figure 13 A schematic diagram of spectrum information of a random number sequence provided by an embodiment of the present disclosure is shown;

[0064] Figure 14 A flowchart of a random number generation method provided by an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0065] To make the principles and advantages of the present disclosure more clear, the embodiments of the present disclosure will be described in further detail below with reference to the accompanying drawings.

[0066] With the advent of 5G and the rapid development of the Internet of Things, everything from enterprise servers to personal heart rate monitors will be connected to the network. Therefore, information security and personal privacy issues have received widespread attention. How to protect information in the vast Internet of Things and Ethernet has become the key.

[0067] Information encryption is a key technology for ensuring information security. Hardware generates unpredictable random numbers for encryption, making subsequent key generation unpredictable. Currently, hardware random number generation methods primarily rely on metastable implementations.

[0068] Random number generation mainly utilizes physical noise in nature, such as device noise, nuclear decay noise, Brownian motion noise, thermal noise, etc., and obtains unpredictable 0 / 1 sequences by amplifying, extracting, and post-processing these noises. The extraction step is achieved through metastable states. Figure 1As shown, circuits used for extraction can be divided into two main categories. One type converts to metastable states in the voltage domain, where voltages above the voltage threshold (Ref0) are ultimately 1, and voltages below the voltage threshold (Ref0) are 0. The other type converts to metastable states in the time domain, where pulses ahead of the time threshold (Ref1) are 0, and pulses behind the time threshold (Ref1) are 1. This metastable method is severely affected by process voltage and temperature (PVT), requiring additional circuitry to correct for these effects.

[0069] Figure 2 This is a schematic diagram of the structure of a random number generator provided by an embodiment of the present disclosure. Figure 2 The random number generator includes: a control word providing circuit 10, a pulse generating circuit 20 and a random number generating circuit 30.

[0070] Wherein, the control word providing circuit 10 generates a plurality of control words in response to a first rule;

[0071] a pulse generating circuit 20 connected to the control word providing circuit 10, and outputting a plurality of pulse signals in response to the plurality of control words, wherein the pulse signals include a first frequency signal and a second frequency signal, and the probability of the first frequency signal and the second frequency signal appearing in the pulse signals is controlled by the corresponding control words;

[0072] The random number generating circuit 30 is connected to the pulse generating circuit 20 and performs a logic operation on the multi-channel pulse signals to generate a random number sequence.

[0073] In the embodiment of the present disclosure, the multi-channel pulse signal generated by the pulse subcircuit 200 in response to the control word is processed to generate a random number sequence. This solution does not utilize random noise in nature, but is generated entirely by digital circuits, and has the advantages of being fully digital, low-cost, low-power, highly reliable, and highly programmable. In addition, the random number generator first generates a pulse signal of a first frequency signal and a second frequency signal, and then performs a logical operation on these pulse signals, so that the output random number sequence is unpredictable, that is, the random number generator provided by the present disclosure can output true random numbers, and is a true random number generator (TRNG) that generates true random numbers.

[0074] In a possible implementation, the first rule may refer to randomly outputting multiple control words from a predetermined control word set, that is, the control word providing circuit 10 randomly outputs multiple control words from the predetermined control word set.

[0075] For example, the control word providing circuit can be implemented using a programmable chip. Through programming, the control word set is limited, thereby limiting the range of randomly output control words. For example, the integer portion of the control word can only be generated from coprime numbers such as 3, 5, 7, and 11, thereby ensuring that the randomly output numbers of the programmable chip are all coprime numbers. The programmable chip can include multiple output channels, thereby being able to output multiple control words simultaneously.

[0076] In other possible implementations, the first rule may also be other rules, such as selecting control words in sequence, etc., which is not limited in the present disclosure.

[0077] See also Figure 2 The pulse generating circuit 20 includes a plurality of pulse sub-circuits 200, each of which is connected to the control word providing circuit 10 and the random number generating circuit 30. Each of the pulse sub-circuits 200 generates a pulse signal according to a control word. Each pulse sub-circuit 200 corresponds to a control word.

[0078] Figure 3 FIG1 shows a schematic diagram of the structure of a pulse subcircuit provided by an embodiment of the present disclosure. Figure 3 The pulse sub-circuit 200 includes a signal generator 201 and a frequency synthesizer 202 .

[0079] The frequency synthesizer 202 is connected to the signal generator 201 , the control word providing circuit 10 , and the random number generating circuit 30 , respectively.

[0080] The signal generator 201 generates a reference pulse signal with uniform phase intervals in response to the initial pulse signal, and the frequency synthesizer 202 generates the pulse signal in response to the reference pulse signal with uniform phase intervals and the control word.

[0081] In which, the control word includes a first coefficient and a second coefficient; the pulse signal includes a first frequency signal generated based on a reference pulse signal with uniform phase intervals and the first coefficient and a second frequency signal generated based on a reference pulse signal with uniform phase intervals and the second coefficient, and the proportion of the first frequency signal and the second frequency signal in the pulse signal is controlled by the second coefficient.

[0082] In this implementation, the pulse subcircuit consists of two parts, wherein the signal generator is responsible for generating a reference pulse signal with uniform phase intervals, and the frequency synthesizer is responsible for generating a pulse signal based on the reference pulse signal with uniform phase intervals and a control word.

[0083] Exemplarily, the initial pulse signal can be generated by a voltage-controlled oscillator, for example, an inductor-capacitor voltage-controlled oscillator (LC Voltage Controlled Oscillator, LCVCO) is used as an oscillation source to generate the above-mentioned initial pulse signal. That is, the pulse subcircuit can also include a voltage-controlled oscillator, and the output end of the voltage-controlled oscillator is electrically connected to the input end of the signal generator. Different pulse subcircuits use different LCVCOs to generate initial pulse signals, and then pass through different signal generators, so that the initial phase and noise characteristics of the evenly spaced reference pulse signal in each pulse subcircuit are different, thereby increasing the unpredictability of the final output.

[0084] The reference pulse signal with uniform phase intervals means that the phase changes of the multiple pulse signals generated by the signal generator 201 are the same, and the initial phase intervals of the multiple pulse signals are equal.

[0085] Exemplarily, the signal generator 201 may be a frequency divider, which is configured to generate multiple reference pulse signals with evenly spaced phases according to an initial pulse signal.

[0086] Exemplarily, the signal generator 201 may also be a cross-coupled NAND gate.

[0087] For example, signal generator 201 can be implemented using a Johnson counter, also known as a twisted ring counter. Alternatively, signal generator 201 can be implemented using a rotary traveling-wave oscillator (RTWO), a transmission line-based clock generation technology that can easily generate the aforementioned K-channel reference pulse signals with uniform phase intervals. Alternatively, signal generator 201 can be implemented using a differential latch.

[0088] Figure 4 To adopt Figure 3 The waveform diagram of the K-way reference pulse signal with uniform phase intervals generated by the signal generator in FIG. Figure 4 , the waveforms of any two signals are the same (i.e., the period and amplitude are the same), and the waveforms of the K signals are evenly arranged, i.e., the intervals are the same. The phase difference between any two adjacent signals is the basic time unit Δ, and the frequency of the K signals is f i , K is an integer greater than 2.

[0089] In one implementation of the embodiment of the present disclosure, the frequency synthesizer 202 is configured to generate a pulse signal according to the following formula: TAF =(1-r)*T A +r*T B , T A =I*Δ,TB =(I+1)*Δ, T TAF =(1-r)*I*Δ+r*(I+1)*Δ=(I+r)*Δ, control word F=I+r.

[0090] Among them, T TAF is the period of the pulse signal, T A is the first frequency signal (or called the first periodic signal), T B is the second frequency signal (or the second periodic signal); I is the aforementioned first coefficient, which is used to select from the K-way reference pulse signals to synthesize the frequency signal. For example, if the control word I is 3, then within one cycle, two reference pulse signals with a phase difference of 3Δ are selected from the K-way reference pulse signals, and then synthesized and output T A =3Δ, in the next cycle, two reference pulse signals with a phase difference of 4Δ are selected, and then synthesized and output T B =4Δ, Δ is the phase difference between any two adjacent signals in the K-way phase-uniformly spaced reference pulse signals; r is the aforementioned second coefficient, which is used to control the probability of the first frequency signal and the second frequency signal appearing, where r controls T B The probability of occurrence, 1-r controls T A Probability of occurrence.

[0091] In the disclosed embodiments, each control word can be an integer or a decimal. Each control word can be split into an integer portion and a decimal portion. The integer portion can be used as the first coefficient, and the decimal portion can be used as the second coefficient to synthesize the pulse rate signal. For example, if the control word is 5.4, the integer portion is 5 and the decimal portion is 0.4. For another example, if the control word is 6, the integer portion is 6 and the decimal portion is 0.

[0092] In this case, when the decimal part of the control word is 0, the pulse signal is only generated by T A In addition, when the decimal part of the control word has different values, the T A and T B The proportions of occurrence are also different.

[0093] In a possible implementation, the integer parts of the multiple control words are prime numbers to each other.

[0094] If the integer parts of the control words are not mutually prime, then the T values ​​generated in different pulse subcircuits are A The period is a multiple relationship, which leads to the T AThe existence of identical waveforms in some parts of the control word can lead to intermittent identical waveforms between different pulse signals during subsequent logical operations, resulting in inconsistent logical operation results during these times and failing to meet randomness requirements. The present disclosure avoids this situation by making the integer parts of the control word coprime, thus ensuring the randomness of the random number sequence and further improving the entropy of the noise source.

[0095] In other implementations, the integer parts of the control words may not be mutually prime.

[0096] Figure 5 This is a schematic diagram of the principle of using a frequency synthesizer to synthesize a pulse signal. Figure 5 , the frequency synthesizer uses the concept of time-averaged frequency to synthesize the output pulse signal. The following takes the synthesis of the first frequency signal as an example: the frequency synthesizer receives the control word and K-way phase-uniformly spaced reference pulse signals. The control word F = I + r, where I is the integer part and r is the decimal part; the phase difference between any two adjacent signals in the K-way phase-uniformly spaced reference pulse signals is the basic time unit Δ. The frequency synthesizer first constructs two different clock periods T based on the basic time unit Δ and the integer part I in the control word F. A and T B , T A =I·Δ,T B =(I+1)·Δ. Then, the frequency synthesizer controls T based on the fractional part r in the control word F. A and T B The probability of occurrence of , thereby generating a pulse signal, the pulse signal includes the aforementioned clock period T A and T B Two parts.

[0097] Figure 6 This is a schematic diagram of the structure of a frequency synthesizer provided by the present disclosure. Figure 6 The frequency synthesizer may include a first processing unit 21 , a second processing unit 22 and an output unit 23 .

[0098] The first processing unit 21 is connected to the control word providing circuit 10 and generates a first control signal and a second control signal based on the control word;

[0099] a second processing unit 22 connected to the first processing unit 21, selecting a first pulse signal from a reference pulse signal with uniform phase intervals based on a first control signal, and selecting a second pulse signal from the reference pulse signal based on a second control signal, and selecting one of the first pulse signal and the second pulse signal as an output signal;

[0100] The output unit 23 is connected to the second processing unit 22 , and generates the pulse signal based on the output signal of the second processing unit 22 .

[0101] The following combination Figure 6 The detailed working process of the first processing unit 21, the second processing unit 22 and the output unit 23 is described as follows:

[0102] The first processing unit 21 includes a first logic control circuit 24 and a second logic control circuit 25 .

[0103] refer to Figure 6 The first logic control circuit 24 includes a first adder 241, a first register 242 and a second register 243. The first register 242 is connected to the first adder 241 and the second register 243 respectively.

[0104] The first adder 241 adds the control word F and the most significant bits (e.g., 5 bits) stored in the first register 242, and then stores the result of the addition in the first register 242 at the rising edge of the second clock signal CLK2. Alternatively, the first adder 241 may add the control word F and all information stored in the first register 242, and then store the result of the addition in the first register 242 at the rising edge of the second clock signal CLK2. At the next rising edge of the second clock signal CLK2, the most significant bits stored in the first register 242 are stored in the second register 243, which serves as the selection signal for the first K→1 multiplexer 221, i.e., the aforementioned first control signal, for selecting one signal from the K reference pulse signals with even phase intervals as the first pulse signal.

[0105] When adding the control word F and the most significant bit stored in the first register 242, if the control word carries, the most significant bit stored in the second register 243 is I+1. If the control word does not carry during the addition, the most significant bit stored in the second register 243 is I. When the second register 243 contains I+1, the corresponding output is T B =(I+1)·Δ, when the value in the second register 243 is I, the corresponding output is T A =I·Δ.

[0106] The second logic control circuit 25 includes a second adder 251, a third register 252, and a fourth register 222. The third register 252 is connected to the second adder 251 and the fourth register 222, respectively.

[0107] The second adder 251 adds half F / 2 of the control word to the most significant bit stored in the first register 242, and then saves the addition result to the third register 252 at the rising edge of the second clock signal CLK2. At the next rising edge of the first clock signal CLK1, the information stored in the third register 252 will be stored in the fourth register 222 and serve as the selection signal of the second K→1 multiplexer 222, that is, the aforementioned second control signal, for selecting one signal from the K multi-phase input signals as the second pulse signal. Figure 6 The second processing unit 22 includes a first K→1 multiplexer 221, a second K→1 multiplexer 222, and a 2→1 multiplexer 223. The first K→1 multiplexer 221 and the second K→1 multiplexer 222 each include a plurality of input terminals, a control input terminal, and an output terminal. The 2→1 multiplexer 223 includes a control input terminal, an output terminal, a first input terminal, and a second input terminal. The output terminal of the first K→1 multiplexer 221 is connected to the first input terminal of the 2→1 multiplexer 223, and the output terminal of the second K→1 multiplexer 222 is connected to the second input terminal of the 2→1 multiplexer 223.

[0108] The control input end of the first K→1 multiplexer 221 selects one signal from the K-channel phase-uniformly spaced reference pulse signals as the output signal, i.e., the first pulse signal, under the control of the first control signal generated by the first logic control circuit 24; the control input end of the second K→1 multiplexer 222 selects one signal from the K-channel phase-uniformly spaced reference pulse signals as the output signal, i.e., the second pulse signal, under the control of the second control signal generated by the second logic control circuit 25.

[0109] Taking the first K→1 multiplexer as an example, when selecting the output signal, it can be selected according to the value of the first control signal. For example, if the first control signal is 3, the third of the K phase-uniformly spaced reference pulse signals is selected as the output.

[0110] The 2→1 multiplexer 223 may select one of the first pulse signal output from the first K→1 multiplexer 221 and the second pulse signal output from the second K→1 multiplexer 222 as the output signal of the 2→1 multiplexer 223 at the rising edge of the first clock signal CLK1 .

[0111] Since the 2→1 multiplexer selects from the outputs of the two K→1 multiplexers, the outputs of the two K→1 multiplexers are combined to form a new cycle. Since the first pulse signal and the second pulse signal of the output of the two K→1 multiplexers differ by an integer Δ, the pulse signal output by the final frequency synthesizer contains T A and T BTwo different cycles.

[0112] refer to Figure 6 The output unit 23 includes a trigger circuit. The trigger circuit is used to generate a pulse train. The trigger circuit includes a D flip-flop 231, a first inverter 232, and a second inverter 233. The D flip-flop 231 includes a data input, a clock input, and an output. The first inverter 232 includes an input and an output. The second inverter 233 includes an input and an output. The clock input of the D flip-flop 231 is connected to the 2→1 multiplexer 223, the data input of the D flip-flop 231 is connected to the output of the first inverter 232, and the output of the D flip-flop 231 is connected to the input of the first inverter 232 and the input of the second inverter 233, respectively. The output of the D flip-flop 231 or the output of the second inverter 233 can serve as the output of the frequency synthesizer, that is, the end that generates the pulse signal.

[0113] The clock input terminal of the D flip-flop 231 receives the output from the output terminal of the 2→1 multiplexer 223, and outputs the first clock signal CLK1 through the output terminal; the input terminal of the first inverter 232 receives the first clock signal CLK1, and outputs the output signal to the data input terminal of the D flip-flop 231; the input terminal of the second inverter 233 receives the first clock signal CLK1, and outputs the second pulse signal CLK2 through the output terminal.

[0114] The first clock signal CLK1 is connected to the control input terminal of the 2→1 multiplexer 223 , and the output terminal of the first inverter 232 is connected to the data input terminal of the D flip-flop 231 .

[0115] The relationship between the frequency Fo of the output pulse signal and the control word F is as follows: Figure 7 As shown, the relationship between the two is Fo=1 / (F·Δ). It can be seen that when the phase difference Δ is constant, the frequency Fo is inversely proportional to the control word F, that is, the larger the control word, the smaller the frequency.

[0116] Figure 8 FIG1 shows a schematic diagram of a random number generation circuit provided by an embodiment of the present disclosure. Figure 8 The random number generation circuit 30 includes a first processing sub-circuit 301 and a second processing sub-circuit 302 .

[0117] The first processing sub-circuit 301 is connected to the pulse generating circuit 20 and performs a first processing on the multiple pulse signals, wherein the first processing includes at least one of XOR, XNOR, and NAND;

[0118] The second processing sub-circuit 302 is connected to the first processing sub-circuit 301 and performs a second processing on the multi-channel pulse signal after the first processing;

[0119] The second processing includes sampling the signal output by the first processing sub-circuit 301 based on the clock signal to obtain a random number sequence.

[0120] In this implementation, the first processing sub-circuit performs logical operations such as XOR and XNOR on multiple pulse signals, and then performs sampling to increase the entropy value of the bits in the output signal and ensure the randomness of the signal.

[0121] Figure 9 A detailed schematic diagram of a random number generation circuit provided by an embodiment of the present disclosure is shown. Figure 9 The first processing sub-circuit 301 may include an XOR sub-circuit that performs an XOR operation on the multiple pulse signals.

[0122] Among them, the XOR sub-circuit can calculate multiple pulse signals according to the following formula: a⊕b⊕c⊕…⊕n, where a~n represent multiple pulse signals.

[0123] In other implementations, the first processing sub-circuit 301 may also include multiple logic operation sub-circuits, for example, performing XOR processing on part of the pulse signals, performing XNOR processing on another part of the pulse signals, and finally performing NAND on the XOR processing results and the XNOR processing results as output.

[0124] like Figure 9 As shown, in a possible implementation, the second processing sub-circuit 302 may include a sampling sub-circuit, which is connected to the aforementioned XOR sub-circuit. The sampling sub-circuit samples the signal output by the XOR sub-circuit based on a clock signal to obtain the random number sequence.

[0125] like Figure 9 As shown, the pulse generating circuit 20 has n frequency synthesizers, which control their respective control words F1-F nTo generate pulses of different frequencies, the first processing sub-circuit then combines all waveforms through logical operations to produce a highly unpredictable waveform. The unpredictability of this waveform stems primarily from two factors. First, the K-channel reference pulse signals input to each frequency synthesizer have different noise characteristics and initial phases. Noise can affect the waveform. For example, the ideal signal period is 20ms, but due to noise, it may be 19ms or 21ms, resulting in different waveforms. Furthermore, the K-channel inputs of different frequency synthesizers are generated using different circuits, which can generate input waveforms with different noise and initial phases. The initial phase is related to the residual charge of the capacitor within the circuit. When different circuits are powered on, the residual charge of the capacitor varies, resulting in different initial phases. Second, the output and initial phase of each frequency synthesizer are different. It is precisely because of the above reasons that the waveform after mixing is highly unpredictable and abnormal.

[0126] See also Figure 8 and Figure 9 The random number generation circuit 30 further includes a clock sub-circuit 303 .

[0127] The clock sub-circuit 303 is connected to the second processing sub-circuit 302 and is used to provide the clock signal to the second processing sub-circuit 302 .

[0128] Exemplarily, the clock subcircuit 303 is configured to use the output of one of the plurality of pulse subcircuits as the clock signal;

[0129] Alternatively, the clock sub-circuit 303 is configured to use the output of an external clock as the clock signal.

[0130] In a possible implementation, the clock sub-circuit 303 may obtain a clock signal of an external clock and then output the clock signal to the second processing sub-circuit 302 .

[0131] In another possible implementation, the frequency synthesizer may obtain a pulse signal from one of the n frequency synthesizers (e.g., frequency synthesizer C#) in the pulse generating circuit 20 and then output the pulse signal as a clock signal to the second processing sub-circuit 302. In this implementation, the frequency synthesizer providing the clock signal may not be fixed. For example, based on the frequencies of the clock signals generated by the n frequency synthesizers, the frequency synthesizer with the smallest frequency among the pulse signals generated by the n frequency synthesizers may be used to provide the clock signal.

[0132] When using the aforementioned clock signal, the rising or falling edges of the clock signal are not periodically arranged. Therefore, using this clock signal can increase the randomness of the sampling. During the sampling process of the output of the first processing subcircuit according to the aforementioned clock signal, metastable states often occur, further increasing the unpredictability of the random numbers. The occurrence of a metastable state during the sampling process refers to a metastable state caused by the sampling point being at the rising or falling edge of the output signal of the first processing subcircuit. In this case, the sampling subcircuit outputs a random 0 or 1.

[0133] Exemplarily, the sampling subcircuit includes a D-flip Flop (DFF), an input terminal of which is connected to the first processing subcircuit 301 , and a control terminal of which is connected to the clock subcircuit 303 .

[0134] Figure 10 This is a schematic diagram of the structure of another random number generator provided by the embodiment of the present disclosure. Figure 10 , the random number generator also includes a post-processing circuit 40.

[0135] The post-processing circuit 40 is connected to the random number generation circuit 30 and performs probability deviation correction on the random number sequence output by the random number generation circuit.

[0136] The probability deviation refers to the deviation between the probability of bits 0 and 1 appearing in a random number sequence and the probability of 0 and 1 appearing in a truly random situation. By correcting the probability deviation of the random number sequence, the ratio of bits 0 and 1 in the random number sequence output by the random number generation circuit is made closer to 1:1, and the arrangement order of bits 0 and 1 is made more consistent with the random distribution, thereby increasing the chaos and complexity of the random sequence.

[0137] To prevent direct exposure of random numbers to higher-level applications while increasing their information complexity, the random number generator incorporates the aforementioned post-processing circuitry. This post-processing circuitry can utilize various algorithms, including at least one of the von Neumann correction algorithm, a hash algorithm, and a chaotic algorithm. Not directly exposing random numbers to higher-level applications means not directly outputting the sampling results to encryption applications. Direct exposure of random numbers could create a risk of being cracked.

[0138] Different algorithms have different pertinences. For example, if the original random number has an uneven distribution of 0 / 1, the XOR correction in the chaos algorithm can be used. After correction, the probability of 0 / 1 in the random number sequence tends to 0.5. The post-processing circuit disclosed in this disclosure uses one of the above algorithms to improve the randomness of the random number sequence.

[0139] Figure 11 The schematic diagram of the structure of a post-processing circuit provided by an embodiment of the present disclosure is shown. The characteristic of this solution is that the circuit is very small, with small area and power consumption. Figure 11 The post-processing circuit 40 includes a storage module 401, a processing module 402 and a calculation module 403.

[0140] Storage module 401, storing random sequences;

[0141] The processing module 402 is connected to the random number generation circuit 30 and the storage module 401, and generates a first random number based on the random number output by the random number generation circuit 30 and a bit in the random sequence of the storage module 401;

[0142] The operation module 403 is connected to the processing module 402, performs a logic operation on the first random number output by the processing module 402 and the second random number output by the operation module 403 in the previous cycle, and outputs a third random number.

[0143] By performing an operation on the random number output by the random number generation circuit 30 and a bit in the random sequence, and then performing a logical operation on the second random number output in the previous cycle, bits 0 and 1 in the random number sequence obtained after the above processing are made more random due to the randomness of the random sequence.

[0144] Exemplarily, the storage module 401 may include a shift register, which stores a random sequence and right-shifts the random sequence by one bit in each cycle. In each cycle, the random number generation circuit outputs one bit of the random number sequence.

[0145] Exemplarily, the processing module 402 may include a demultiplexer, which generates a first random number based on the random number output by the random number generation circuit and the last bit of the shift register, and inputs the generated first random number into the first bit of the shift register.

[0146] Exemplarily, the operation module 403 may include an XOR device, which performs an XOR operation on the first random number output by the demultiplexer and the second random number output by the XOR device in the previous cycle, and outputs a third random number.

[0147] like Figure 11As shown, the shift register stores a sequence Zn-1…Zn-k. Under the control of the clock signal Ck, it shifts one bit to the right in each cycle, and the bit newly added to the shift register is replaced by the output Zn of the demultiplexer instead of Zn-1. Zn is calculated by combining the last bit of the shift register, Zn-k, and the output Bn of the random number generation circuit as the output. At the same time, the output Zn of the demultiplexer serves as one input of the XOR, and the other input of the XOR is the output An-1 of the previous cycle of the XOR. Zn and An-1 are XORed to obtain An. In order to store An-1, the post-processing circuit 40 can also include a register 404. Under the action of the clock signal Ck, the register 404 can obtain and store the output of the XOR in each clock cycle, and input the stored bit together with the output of the demultiplexer into the XOR in the next clock cycle.

[0148] The clock signal for controlling the shift register and the clock signal for the control register can both be provided by the aforementioned clock subcircuit. Of course, in other implementations, the clock signal for controlling the shift register and the clock signal for the control register can also be provided by two independent clock circuits.

[0149] In this implementation, the demultiplexer determines the current output by the random number output by the output circuit and the last bit of the shift register. Since the initial value of the shift register is obtained randomly (a bit 0 or 1 is randomly generated at each bit when the shift register is powered on), the random number output by the output circuit and the initial value of the shift register are operated, which increases the chaos of the random number and further disrupts the order of bits 0 and 1; the exclusive OR device implements the aforementioned XOR correction, and outputs it by comparing the output of the demultiplexer with the output of its own previous cycle to avoid continuous 0 or 1. Because if it is continuous 11111, the exclusive OR will produce the result of 01010, making 0 and 1 more balanced.

[0150] Through the functions of the above two devices, we try to ensure that 0 or 1 does not appear all the time, so that the number of 0 and 1 is more even and the order is random.

[0151] Optionally, the demultiplexer is configured to calculate the first random number according to the following formula:

[0152] Zn=Bn*Zn-k+Bn -1 *Zn-k -1 ;

[0153] Wherein, Zn is the first random number, Zn-k is the last bit of the shift register, and Bn is the random number output by the random number generation circuit.

[0154] Among them, Bn -1 is the inverse operation of Bn, Zn-k -1is the inverse of Zn-k. The inverse of 0 is 1, and the inverse of 1 is 0. For example, if Bn is 1 and Zn-k is 1, then Zn = 1; if Bn is 1 and Zn-k is 0, then Zn = 0; if Bn is 0 and Zn-k is 1, then Zn = 0; if Bn is 0 and Zn-k is 0, then Zn = 1.

[0155] The random number generator implemented by this method passes all the random number tests of the National Institute of Standards and Technology (NIST) (an international standard for random number testing). The random number output by the random number generator is graphically displayed, as shown in Figure 1. Figure 12 As shown. Figure 12 The various combinations of bit sequences of a set length in the random number sequence shown are counted. It can be seen that the number of times each combination occurs is similar, that is, the proportion of each combination is comparable, with no obvious excess or deficiency. The random number sequence approaches white noise, indicating that it is an unpredictable true random number sequence. When counting the number of times each combination occurs, a fast Fourier transform can be used. For example, Figure 12 The random number sequence shown is subjected to fast Fourier transform to obtain Figure 13 The spectrum information diagram shown in FIG. 1 is a schematic diagram of spectrum information, where the horizontal axis is the index, each index corresponds to a combination of a bit sequence of a set length, and the vertical axis is the number of times the sequence corresponding to the index appears, such as Figure 13 As shown, there are about 5×10 6 sequences, the number of times the sequence corresponding to index 1 appears is 1.13×10 4 , and the number of occurrences of sequences corresponding to other index values ​​is mostly within 1×10 4 to 1.25×10 4 Between, so from Figure 13 It can be seen that the proportions of various bit sequences are similar. Figure 12 The provided random number sequence is a true random number sequence.

[0156] This proposal proposes a fully digital, low-cost, low-power, highly reliable, highly programmable, and reusable random number generator. This is based on multiple frequency synthesizers. The pulse signals output by these synthesizers are mixed through logical operations to form a high-entropy noise source. This is then sampled through a D-type flip-flop to generate a sequence of true random numbers. To enhance the complexity of the sequence, a post-processing circuit is added to the circuit. The true random numbers generated by this architecture have passed NIST random number testing and exhibit high entropy, high unpredictability, and high complexity. This random number generator can be integrated into a chip, providing efficient and reliable true random numbers at a low cost.

[0157] Figure 14A flow chart of a random number generation method provided by an embodiment of the present disclosure is shown. Figure 14 , the method comprising:

[0158] Step 501: Generate a plurality of control words in response to a first rule;

[0159] Step 502: Outputting a plurality of pulse signals in response to the plurality of control words, wherein the pulse signals include a first frequency signal and a second frequency signal, wherein the probability of the first frequency signal and the second frequency signal appearing in the pulse signals is controlled by the corresponding control words;

[0160] Optionally, the outputting multiple pulse signals in response to the multiple control words includes:

[0161] generating a reference pulse signal with uniform phase intervals in response to the initial pulse signal;

[0162] generating the pulse signal in response to the reference pulse signal and the control word;

[0163] Wherein, the control word includes a first coefficient and a second coefficient;

[0164] The pulse signal includes the first frequency signal generated based on the reference pulse signal and the first coefficient and the second frequency signal generated based on the reference pulse signal and the first coefficient. The proportion of the first frequency signal and the second frequency signal in the pulse signal is controlled by the second coefficient.

[0165] For example, the pulse signal is generated according to the following formula: TAF =(1-r)*T A +r*T B , T A =I*Δ,T B =(I+1)*Δ, T TAF =(1-r)*I*Δ+r*(I+1)*Δ=(I+r)*Δ, control word F=I+r.

[0166] Among them, T TAF is the period of the pulse signal, T A is the first frequency signal (or called the first periodic signal), T B is the second frequency signal (or the second periodic signal); I is the aforementioned first coefficient, which is used to select from the K-way reference pulse signals to synthesize the frequency signal. For example, if the control word I is 3, then within one cycle, two reference pulse signals with a phase difference of 3Δ are selected from the K-way reference pulse signals, and then synthesized and output T A =3Δ, in the next cycle, two reference pulse signals with a phase difference of 4Δ are selected, and then synthesized and output TB =4Δ, Δ is the phase difference between any two adjacent signals in the K-way phase-uniformly spaced reference pulse signals; r is the aforementioned second coefficient, which is used to control the probability of the first frequency signal and the second frequency signal appearing, where r controls T B The probability of occurrence, 1-r controls T A Probability of occurrence.

[0167] Step 503: Performing logic operations on the multiple pulse signals to generate a random number sequence.

[0168] Optionally, performing a logical operation on the multiple pulse signals to generate a random number sequence includes:

[0169] Performing a first processing on the multiple pulse signals, wherein the first processing includes at least one of an exclusive-OR, an exclusive-OR, and a not-AND;

[0170] Performing a second processing on the multi-channel pulse signal after the first processing; wherein the second processing includes sampling the signal output by the first processing based on a clock signal to obtain the random number sequence.

[0171] Optionally, the method further includes:

[0172] Probability deviation correction is performed on the random number sequence output by the random number generation circuit.

[0173] Exemplarily, performing probability deviation correction on the random number sequence output by the random number generation circuit includes:

[0174] Generate a first random number based on the generated random number sequence and one bit in the random sequence;

[0175] Perform a logical operation on the first random number and the second random number output in the previous cycle to output a third random number.

[0176] The following provides an example of correcting the probability deviation of the random number sequence output by the random number generation circuit, and the process is as follows:

[0177] Storing a random sequence in a shift register, and shifting the random sequence right by one bit in each cycle, wherein the random number generation circuit outputs one bit of the random number sequence in each cycle;

[0178] Generate a first random number based on the generated random number sequence and the last bit of the shift register, and input the generated first random number into the first bit of the shift register;

[0179] An exclusive-OR operation is performed on the first random number and the second random number output in the previous cycle to output a third random number.

[0180] The above are merely exemplary embodiments of the present disclosure and are not intended to limit the present disclosure. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present disclosure shall be included in the scope of protection defined by the claims appended to the present disclosure.

Claims

1. A random number generator, characterized in that The random number generator comprises: a control word providing circuit that generates a plurality of control words in response to a first rule; a pulse generating circuit connected to the control word providing circuit, and outputting a plurality of pulse signals in response to the plurality of control words, wherein the pulse signals include a first frequency signal and a second frequency signal, and the probability of the first frequency signal and the second frequency signal appearing in the pulse signals is controlled by the corresponding control words; The random number generating circuit is connected to the pulse generating circuit and performs logic operation on the multi-channel pulse signals to generate a random number sequence.

2. The random number generator according to claim 1, wherein The pulse generating circuit includes a plurality of pulse sub-circuits, and the plurality of pulse sub-circuits are respectively connected to the control word providing circuit and the random number generating circuit; Each of the pulse sub-circuits generates one pulse signal according to one of the control words.

3. The random number generator according to claim 2, wherein The pulse subcircuit comprises: a signal generator and a frequency synthesizer, wherein the frequency synthesizer is connected to the signal generator, the control word providing circuit and the random number generating circuit respectively; The signal generator generates a reference pulse signal with uniform phase intervals in response to the initial pulse signal; The frequency synthesizer generates the pulse signal in response to the reference pulse signal and the control word; Wherein, the control word includes a first coefficient and a second coefficient; The pulse signal includes the first frequency signal generated based on the reference pulse signal and the first coefficient and the second frequency signal generated based on the reference pulse signal and the first coefficient. The proportion of the first frequency signal and the second frequency signal in the pulse signal is controlled by the second coefficient.

4. The random number generator according to claim 3, wherein The frequency synthesizer includes: a first processing unit, a second processing unit and an output unit; a first processing unit connected to the control word providing circuit, and generating a first control signal and a second control signal based on the control word; a second processing unit connected to the first processing unit, selecting a first pulse signal from a reference pulse signal with uniform phase intervals based on the first control signal, selecting a second pulse signal from the reference pulse signal based on the second control signal, and selecting one of the first pulse signal and the second pulse signal as an output signal; The output unit is connected to the second processing unit and generates the pulse signal based on the output signal of the second processing unit.

5. The random number generator according to any one of claims 2 to 4, characterized in that The random number generation circuit includes: a first processing subcircuit and a second processing subcircuit; The first processing sub-circuit is connected to the pulse generating circuit and performs a first processing on the multiple pulse signals, wherein the first processing includes at least one of XOR, XNOR, and NAND; The second processing sub-circuit is connected to the first processing sub-circuit and performs a second processing on the multi-channel pulse signal after the first processing; The second processing includes sampling the signal output by the first processing sub-circuit based on the clock signal to obtain the random number sequence.

6. The random number generator according to claim 5, characterized in that The random number generation circuit further includes: a clock subcircuit connected to the second processing subcircuit, providing the clock signal to the second processing subcircuit.

7. The random number generator according to claim 6, wherein The clock subcircuit is configured to use the output of one of the plurality of pulse subcircuits as the clock signal; Alternatively, the clock sub-circuit is configured to use an output of an external clock as the clock signal.

8. The random number generator according to any one of claims 1 to 4 or 6 or 7, characterized in that The random number generator further includes: The post-processing circuit is connected to the random number generation circuit and performs probability deviation correction on the random number sequence output by the random number generation circuit.

9. The random number generator according to claim 8, characterized in that The post-processing circuit includes: A storage module for storing random sequences; a processing module, connected to the random number generation circuit and the storage module, respectively, and generating a first random number based on the random number output by the random number generation circuit and a bit in the random sequence of the storage module; The operation module is connected to the processing module, performs a logic operation on the first random number output by the processing module and the second random number output by the operation module in the previous cycle, and outputs a third random number.

10. The random number generator according to any one of claims 1 to 4, claim 6 or 7 or 9, characterized in that: The control word is a numerical value, and the integer parts of the multiple control words are prime numbers to each other.

11. A random number generation method, characterized in that: The method comprises: generating a plurality of control words in response to a first rule; In response to the multiple control words, output multiple pulse signals, the pulse signals including a first frequency signal and a second frequency signal, wherein the probability of the first frequency signal and the second frequency signal appearing in the pulse signals is controlled by the corresponding control words; Performing logic operations on the multiple pulse signals to generate a random number sequence.

12. The method according to claim 11, characterized in that Outputting multiple pulse signals in response to the multiple control words includes: generating a reference pulse signal with uniform phase intervals in response to the initial pulse signal; generating the pulse signal in response to the reference pulse signal and the control word; Wherein, the control word includes a first coefficient and a second coefficient; The pulse signal includes the first frequency signal generated based on the reference pulse signal and the first coefficient and the second frequency signal generated based on the reference pulse signal and the first coefficient. The proportion of the first frequency signal and the second frequency signal in the pulse signal is controlled by the second coefficient.

13. The method according to claim 11, characterized in that The performing of a logical operation on the multiple pulse signals to generate a random number sequence includes: Performing a first processing on the multiple pulse signals, wherein the first processing includes at least one of XOR, XNOR, and NAND; Performing a second processing on the multi-channel pulse signal after the first processing; wherein the second processing includes sampling the signal output by the first processing based on a clock signal to obtain the random number sequence.

14. The method according to any one of claims 11 to 13, characterized in that The method further comprises: Probability deviation correction is performed on the random number sequence output by the random number generation circuit.

15. The method according to claim 14, characterized in that The method of performing probability deviation correction on the random number sequence output by the random number generation circuit includes: Generate a first random number based on the generated random number sequence and one bit in the random sequence; Perform a logical operation on the first random number and the second random number output in the previous cycle to output a third random number.