reduction and conversion of scalars to dow notation
By reducing and transforming scalars using τ-adic representation, and generating τ-adic representations of scalars using iteration and random multiples τm-1, the problem of complex and time-consuming scalar transformation is solved, improving the efficiency and security of cryptographic operations and reducing the risk of scalar detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- STMICROELECTRONICS (ROUSSET) SAS
- Filing Date
- 2022-11-14
- Publication Date
- 2026-05-22
AI Technical Summary
In existing technologies, the transformation process of scalars on Koblitz curves is complex and time-consuming, especially when a shorter representation is required, which necessitates multiple reductions. Furthermore, scalar values are easily detected in electronic devices, affecting the security and efficiency of cryptographic operations.
The τ-adic representation is used to reduce and transform scalars. An algorithm is implemented through cryptographic circuits to generate an output vector of length l+n. Iterative operations and random multiples τm-1 are used to make the scalar multiplication result difficult to detect. The algorithm includes multiple iterative steps and a stopping index to determine the number of iterations, and generates scalars in τ-adic representation.
It improves the speed and security of scalar transformation, making scalars difficult to detect in cryptographic operations, reducing the success rate of power analysis attacks, and improving the efficiency and security of cryptographic operations.
Smart Images

Figure CN116127534B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates in general to the field of cryptography, and more specifically to methods and apparatus for performing cryptographic operations based on elliptic curve cryptography. Background Technology
[0002] Elliptic curve cryptography (ECC) is well-suited to public-key cryptography methods because it allows for the use of smaller cryptographic keys. For example, elliptic curve cryptography can be used to implement encryption, key exchange, key protocols, digital signatures, or authentication operations.
[0003] In addition, using K o Koblitz curves enable improvements in the speed of some cryptographic operations, particularly dot multiplication of scalars. However, for greater efficiency, scalars should typically be converted to a specific representation before performing cryptographic operations on Koblitz curves.
[0004] The goal is to make the conversion process faster and / or to make the scalar value harder to detect when electronic devices perform cryptographic operations involving it. Summary of the Invention
[0005] In one embodiment, the method includes performing cryptographic operations and protecting the execution of the cryptographic operations. Performing the cryptographic operations and protecting the operations includes: implementing an algorithm applied to a scalar via cryptographic circuitry to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Determined according to the following equation:
[0006] Where m, L, and n are positive integers and each iteration i includes:
[0007] a) Calculate the first intermediate data value (u) by applying a first operation, modulo τ, to the first input data (ρ) and the input vector, where τ is a complex number;
[0008] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0009] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0010] The number of iterations is determined by the cryptographic circuit based on a stopping index.
[0011] In one embodiment, the content of a non-transitory computer-readable medium causes a cryptographic circuit to execute a method, the method comprising: performing a cryptographic operation; and protecting the execution of the cryptographic operation. Performing the cryptographic operation and protecting it includes: implementing an algorithm applied to a scalar to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Determined according to the following equation:
[0012] Where m, L, and n are positive integers and each iteration i includes:
[0013] a) Calculate the first intermediate data value (u) by applying the first operation moduloτ to the first input data (ρ) and the input vector, where τ is a complex number;
[0014] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0015] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0016] The number of iterations is determined by the cryptographic circuit based on a stopping index.
[0017] In one embodiment, the device includes a memory and cryptographic circuitry coupled to the memory. The cryptographic circuitry performs encryption operations and protects the execution of these operations during operation. Performing the encryption operations and protecting the operations includes: implementing an algorithm applied to a scalar to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Determined according to the following equation:
[0018] Where m, L, and n are positive integers and each iteration i includes:
[0019] a) Calculate the first intermediate data value (u) by applying the first operation moduloτ to the first input data (ρ) and the input vector, where τ is a complex number;
[0020] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0021] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0022] The number of iterations is determined by the cryptographic circuit based on a stopping index.
[0023] In one embodiment, the system includes a host processor and cryptographic circuitry coupled to the host processor. The cryptographic circuitry performs cryptographic operations and protects the execution of these operations during operation. Performing the cryptographic operations and protecting the operations includes: implementing an algorithm applied to a scalar to generate an output vector of length L+n, the output vector having digits d0, ..., dn. l+-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Determined according to the following equation:
[0024] Where m, L, and n are positive integers and each iteration i includes:
[0025] a) Calculate the first intermediate data value (u) by applying the first operation moduloτ to the first input data (ρ) and the input vector, where τ is a complex number;
[0026] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0027] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0028] The number of iterations is determined by the cryptographic circuit based on a stopping index. Attached Figure Description
[0029] The above-described features and advantages, as well as other features and advantages, will be described in detail below with reference to the accompanying drawings and specific embodiments given in an illustrative and non-limiting manner, wherein:
[0030] Figure 1 An example of an electronic device according to an embodiment of the present disclosure is illustrated schematically;
[0031] Figure 2 This is a flowchart illustrating the operation of performing a scalar conversion method according to one embodiment;
[0032] Figure 3 The illustration shows that in Figure 2 The initial state of the l-bit value used in the method;
[0033] Figure 4 This is a flowchart illustrating the operation of performing a scalar conversion method according to one embodiment;
[0034] Figure 5 The illustration shows that in Figure 4 The initial state of the l-bit value used in the method; and
[0035] Figure 6 This is a flowchart illustrating an example of a cryptographic method according to an embodiment of the present disclosure. Detailed Implementation
[0036] In the various figures, the same features are designated by the same reference numerals. Specifically, unless the context otherwise indicates, common structural and / or functional features in various embodiments may have the same reference numerals and may be provided with the same structure, dimensions, and material properties.
[0037] For clarity, only operations and elements useful for understanding the embodiments described herein are illustrated and described in detail. Specifically, cryptographic operations of dot-scalar multiplication on elliptic curves, properties of Koblitz curves, and various choices of scalar representation are not described in detail.
[0038] Unless otherwise stated, when referring to two elements connected together, it means that they are directly connected without any intermediate elements other than conductors. When referring to two elements coupled together, it means that the two elements can be connected or that they can be coupled via one or more other elements.
[0039] In the following disclosure, unless otherwise stated, when referring to absolute position qualifiers such as the terms “front,” “back,” “up,” “down,” “left,” “right,” etc., or relative position qualifiers such as the terms “above,” “below,” “high,” “low,” etc., or orientation qualifiers such as “horizontal,” “vertical,” etc., refer to the orientation shown in the figure.
[0040] Unless otherwise stated, the terms “about,” “approximately,” “roughly,” and “the magnitude of…” indicate within 10%, and within 5%, etc.
[0041] Figure 1 A device 100 according to one embodiment is schematically illustrated. Device 100 is, for example, a computer, a mobile phone, or an integrated circuit card.
[0042] Device 100 includes, for example, a main processor 102 (which is, for example, the host processor of device 100) and a cryptographic coprocessor 104. Device 100 also includes a memory 106 that stores instructions 108 for controlling the main processor 102 and / or the cryptographic coprocessor 104. A communication interface 110 is coupled to the main processor 102, for example, and allows wireless communication, for example, via a LAN (“Local Area Network”, not shown). As shown, the host processor 102 and the cryptographic coprocessor 104 have corresponding internal memories 103, 105, such as registers or cache memories, which can be used individually or in combination with memory 106 when performing one or more of the methods described herein. For example, an application implemented on the main processor or the host processor 102 can be stored wholly or partially in memory 103. The application can initiate the execution of cryptographic operations on the cryptographic processor 104, and the cryptographic operations can be executed using memory 105 or a combination of memory 106 and memory 105.
[0043] Device 100, particularly cryptographic coprocessor 104, is adapted, for example, to perform elliptic curve cryptography operations. Specifically, cryptographic coprocessor 104 is configured, for example, to perform the multiplication of a point P belonging to the Koblitz curve E by a scalar k, in the following form:
[0044] Formula (Math) 1
[0045] E:={(x,y)∈K×K:y 2 +xy=x 3 +ax 2 +1}, Where a∈{0,1}, and where K is of the form K=GF(2 m A binary finite field of , where m is a prime number.
[0046] Scalar multiplication is used, for example, during data encryption, where the scalar k is the encryption key, and is performed, for example, by implementing a "double-and-add type" algorithm or its variants (such as "double-addition-subtraction type") and a generalization of window multiplication. In the "double-addition-subtraction" algorithm, the scalar k can take the values 1, -1, or 0. A "double" operation is performed on each number on the accumulator, and for each non-zero number, point P is added to the accumulator when the number is 1, or subtracted from the accumulator when the number is -1. In window multiplication, the numbers belong to a larger set of values, and scalar multiplication is performed similarly to double-addition-subtraction, except that each addition or subtraction involves not P, but a pre-computed small multiple of P, which depends on the value of the number. This type of algorithm is iterative. Each iteration involves, for example, modifying the value of an elliptic curve point called the accumulator based on the number of scalar k. In one example, the scalar k is represented by bits, and each iteration involves performing a point operation based on the value of the bit being read, either from the most significant bit to the least significant bit, or vice versa, processing the corresponding bits of scalar k. In the left-to-right doubling-add multiplication method—in other words, the doubling-add multiplication is performed from the most significant bit to the least significant bit, regardless of the value of the bit being read—the so-called doubling operation is performed on the accumulator, followed by the so-called addition operation, where P is added to the accumulator only if the read bit is not empty.
[0047] In the case of Koblitz curves, doubling operations are often replaced by Frobenius operations, which involve squaring the point coordinates. Frobenius operations are advantageous over regular doubling operations because they are faster and less expensive to implement.
[0048] However, to use Frobenius operations, the scalar k should be converted to τ-adic representation, where τ is a complex number equal to Where μ equals (-1) 1-a And 'a' is the coefficient of the Koblitz curve E above. In the τ-adic notation, the scalar k is represented by the number 'd'. i The sequence is such that:
[0049] Formula 2
[0050] Where the coefficient d iFor example, it belongs to {0, 1} or {-1, 0, 1}. The integer M is the length of the scalar k in τ-adic form. The scalar k can be an integer or a so-called τ-adic integer of the form a + bτ, where a and b are integers. One difficulty is that the τ-adic representation of an integer is approximately twice as long as its binary form. Due to the inefficiency of the long representation, the scalar k is usually reduced before being converted to τ-adic form. The reduction of the scalar k involves replacing k with a smaller complex number ρ, which is equivalent to the scalar k modulo τ. m -1, where, as mentioned earlier, m is defined by the finite field K under the Koblitz curve, K = GF(2 m Then, for any point P on the Koblitz curve under consideration, kP = ρP, where P multiplied by the complex number τ is defined by applying the Frobenius automorphism to point P.
[0051] Existing methods for performing reductions and τ-adic transformations on scalars k have the disadvantage that they tend to be relatively complex and time-consuming. Furthermore, in some cases, when the size of the scalar k is relatively high, several reduction operations need to be performed before the transformation operations if a shorter representation is required.
[0052] In this disclosure, the following symbols are defined:
[0053] k is the scalar to be converted, which can be an integer or a τ-adic integer; and n is a non-negative integer.
[0054] According to the embodiments described herein, the scalar k is converted into a set of numbers (d0, ..., d...). m+n-1 The τ-adic representation consists of c consecutive number groups, where each number belongs to set D and may hold a predicate or relation C(d) based on the transformed set. i , ..., d i+c-1 ).
[0055] According to some embodiments, the scalar k is converted to τ-adic non-adjacent form (τNAF), where the numbers belong to D = {-1, 0, 1} and where c = 2, and the product of two consecutive numbers is equal to zero. In other words, In this case, the τ-adic transformation can be performed, for example, where n = 4.
[0056] Figure 2 This is a flowchart illustrating the operation of a scalar reduction and transformation method according to one embodiment. Figure 2 The method is implemented, for example, by the cryptographic coprocessor 104 of the electronic device 100. Figure 2The method is used as a step in elliptic curve cryptography (such as encryption, key exchange, key protocol, digital signature, or authentication operations).
[0057] In operation 200 (INITIALIZATIONρ=k;i=0;(d0,...,d m+n-1 The current value i is initialized to, for example, zero. A vector (d0, ..., dn) of length m+n. m+n-1 ) is also initialized.
[0058] Figure 3 The diagram illustrates the accumulator (d0, ..., d...). m+n An example of initialization. In this example, all coefficients (d0, ..., d...) are initialized. m+n All of them were initialized to zero.
[0059] exist Figure 3 In the middle, only the first m coefficients (d0, ..., dm) of the accumulator are considered. m-1 The last n coefficients (d) of the accumulator are represented. m , ..., d m+n-1 For example, it is initialized to zero, and only in Figure 2 The algorithm is updated when it ends. In fact, the last n coefficients (d) are updated. m , ..., d m+n-1 It is not provided as input data value in the algorithm iteration.
[0060] Return to Figure 2 Operation 200, for example, further includes initializing the current value ρ to zero.
[0061] For example, after operation 200, the process continues to execute the operation sequence (OP SEQ) consisting of operations 201 to 203.
[0062] In operation 201(u←OP1(ρ;d′) i ,...;d′ i+c-1 In the complex number τ), the intermediate value u is calculated as a function of the input data value and the complex number τ, according to the following:
[0063] Formula 3
[0064] The mod function returns a valid number u belonging to set D such that ρ+d′ i -u is divisible by τ. The subscript of mod indicates that the exact choice of u may depend on the number d′. i+1 to d′ i+c-1 Each number d′ i Corresponding to the accumulator (d0, ..., d m+n-1The cyclic exponentiation of the m lower numbers of d'. In other words, if the exponent i is less than m, then d'' i =d i Otherwise d′ i =d i-m For example, to obtain the τNAF representation, for all τ-adic integers represented as a+bτ, The following definition is used, where a and b are integers:
[0065] Formula 4
[0066] In other words, the intermediate value u is, for example, equal to (ρ+d) i The remainder of Euclidean division of τ by a complex number τ. This remainder is not necessarily the smallest, and the exact choice of remainder depends, for example, on the vector (d′). i+1 ,...,d′ i+c-1 The rest of the ).
[0067] Following operation 201, operation 202(ρ←OP2(ρ;d) i In (;u;τ)), the current value is updated, for example, by (ρ+d) i -u) divides the complex number τ to produce the new current value ρ.
[0068] Operation 203(d) follows operation 202 i In ←u), the intermediate value u is, for example, stored in the number d. i middle.
[0069] In operation 204 (Stop indicator?), the cryptographic coprocessor 104 checks, for example, whether the stop indicator has been reached. If the stop indicator has not been reached (branch N), the current value i (box 205, i = i + 1 mod m) is updated to i + 1 modulo m. The method then returns to operation 201. In other words, if in operation 205 the current value i is less than or equal to m - 2, it will be updated to i + 1. However, if the current value i is equal to m - 1, the rank i of the position will be reset to zero. Therefore, the algorithm iteratively updates the numbers d0 to d1 one after another. m-1 Until the stopping indicator is reached.
[0070] Stopping indices can be based on, for example, the value of ρ and the index i. In one example, when the expected representation of the transformed scalar k is τNAF representation and the number of most significant digits is n = 4, the stopping indices are, for example:
[0071] Formula 5
[0072] ρ=0 or(|ρ|≤2 and i=m-1), Where |ρ| is the modulo operation of the value ρ of a general complex number.
[0073] Once the stopping criterion (branch Y) is reached, the process terminates, for example, in operation 206 (END). In this phase, the values of the n most significant numbers remain their initial values, such as 0. During operation 206, for example, by sequentially performing operations 201 to 203 on each of the n numbers, the last n coefficients (d) of the accumulator are... m , ..., d m+n-1 The accumulator (d0, ..., dn) is set as a representation of the current value ρ. m+n-1 Then, for example, the output data of the method is provided, where the coefficients d0 to d m+3 Numerical representations of the reduction and τ-adic transformation of scalar k:
[0074] Formula 6
[0075]
[0076] In another example, we set n = 0 and output coefficients d0 to d m+1 And the final value of ρ, the method outputs the reduced scalar in a mixed form, such that
[0077] Formula 7
[0078]
[0079] The magnitude of ρ is relatively small and is limited by the stopping index. For example, when the expected representation of the transformed scalar k is τNAF and the number of most significant digits is n=4, the modulus of ρ is less than or equal to 2.
[0080] Figure 4 This is another flowchart illustrating the operation of a scalar conversion implementation method according to one embodiment. The method is implemented, for example, by a cryptographic coprocessor 104 of electronic device 100.
[0081] Figure 4 The method has the same Figure 2 The methods are similar to those used in the figure, and the same operations have been labeled with the same reference numerals.
[0082] Figure 4 The method relative to Figure 2 The difference in the method is that the accumulator is a vector (d0, ..., dn) of length l+n. l+n-1 ), where l = m + l' is an integer greater than the integer m, and l' is an integer greater than 0. To avoid confusion with the number 1, the integer 1 will be represented as an integer L in addition to being represented as an integer L.
[0083] In addition, Figure 4In this embodiment, the accumulator's output number represents the scalar k after τ-adic reduction and transformation, where the reduction is intentionally not optimal. In other words, since the transformation is correct, the method outputs the τ-adic representation of the τ-adic integer ρ such that ρ ≡ k (mod τ). m -1), but the reduction is not optimal, meaning that ρ is not necessarily the smallest τ-adic integer with respect to the equivalent.
[0084] In operation 400(INITIALIZATION; i = 0; (d0, ..., d...), l+n-1 In the vector (d0, ..., d...), the current value i is initialized to, for example, zero. l+n-1 It is also initialized to, for example, τ. m - 1 The τ-adic representation of multiples of .
[0085] Accumulator (d0, ..., d l+n-1 An initialization example is in Figure 5 The illustration shows that this example is valid when the set of numbers D is symmetric about 0, meaning that for any number d∈D, its opposite -d also belongs to the set D.
[0086] exist Figure 5 In the middle, only the first coefficient of the accumulator (d0, ..., d) l-1 The last n coefficients (d) of the accumulator are represented. l , ..., d l+n-1 For example, it is initialized to zero, and only when... Figure 4 The algorithm is updated when it ends. In fact, the last n coefficients (d) are updated. l , ..., d l+n-1 It is not provided as input data value in the algorithm iteration.
[0087] The previous coefficient of the accumulator (d0, d1, ...). .., d l′-1 d 1′ , ..., d m-1 d m , ..., d l-1 ) is initialized to τ in τ-adic form m Encode numbers that are random or pseudo-random multiples of -1. In fact, the result of multiplying any point P on the considered Koblitz curve by a scalar k is the same as multiplying point P by a scalar k and τ. m Adding multiples of -1 yields the same result. In other words, for any point P belonging to the Koblitz curve and for any integer or τ-adic integer r...
[0088] Formula 8
[0089] kP=(k+r(τ m -1)).P. Towards Adding τ to scalar k m A random multiple of -1 allows device 100 to perform scalar multiplication using pseudo-random multipliers while maintaining the expected result of scalar k multiplication. This makes it more difficult to successfully attack the scalar k value using power analysis.
[0090] For this purpose, given l' random coefficients (r0, ..., r... l′-1 For example, using the value in D, the value Let l' represent random τ-adic integers. These l' coefficients (r0, ..., r) l′-1 Then it is chosen to follow the predicate C(d) i , ..., d i+c-1 For example, if the expected output is τNAF, then (r0, ..., r l′-1 The product of the two continuous coefficients in () is empty. Then, r is multiplied by τ. m -1, for example, has the following τ-adic form:
[0091] Formula 9
[0092]
[0093] The first coefficient (d0, ..., d) of the accumulator l-1 Initialization to τ-adic form τ m Encoding random multiples of -1 corresponds to randomly selecting, for example, l' numbers (r0, ..., r') belonging to D. l′-1 The value of ) and setting: +
[0094] Formula 10
[0095] For j∈{0, ..., l′-1}, d j =-r j And d j+m =r j ,as well as
[0096] For j∈{l′,..,m-1},d j =0
[0097] After operating 400 Figure 4 The method shown continues to operate on sequences (OP SEQ) 401, 202, and 203, wherein operations 202 and 203 are related to the above. Figure 2 To describe.
[0098] Operation 401(u←OP1(ρ;d′) i ,...,d′ i+c-1 ;τ) is similar to operation 201, except that from d′i arrive' i+c-1 The numbers are from the accumulator (d0, ..., d... l+n-1 A low-value fetch of d′. If index i is strictly less than l, then d′ i =d i Otherwise d′ i =d i-m .
[0099] After operation 203, the method continues also regarding... Figure 2 The verification operation 204 is described. In one example, if the stopping criterion (branch N) is not reached, another verification is performed, for example, by the cryptographic coprocessor 104 (box 405, i ≤ l-2?). If the current value i is less than or equal to the value l-2 (branch Y), the current value i is set to the value i+1 in operation 407 (i = i+1). If the current value i is greater than l-1 (branch N), the current value i is set to i+1-m in operation 407' (i = i+1-m), and the subsequent loop begins. After operation 407, the method returns to operation 201, for example.
[0100] After operation 407', operation 408((d) is performed. l′-c+1 , ..., d l′-1 ,ρ)←CORRECT(d l′-c+1 , ..., d l′ Operation 408 conditionally modifies the c-1 numbers (d0, ..., d1) preceding index l' based on the value of ρ. l-1 It includes inputting (d) to the function CORRECT (described later). l′-c+i , ..., d l′ , ρ), and write the vector output by the function into (d l′-c+1 , ..., d l′-1 (ρ). For example, this optional correction is used when the predicate is validated by a group of c consecutive numbers. After operation 408, the method returns to operation 201, for example.
[0101] The CORRECT function follows these three properties:
[0102] (1) value It remains unchanged by applying a function;
[0103] (2) The number d output by the function i All belong to set D;
[0104] (3) The number d output by the function i The new value ρ makes the next implementation of operations 201 to 203 generate a significant number d. l′ ∈D, such that the predicate C(d) l′-c+1, ..., d l′ It was established.
[0105] In one example, the algorithm's output is expected to be represented as τNAF, which corresponds to for all indices i, D = {-1, 0, 1}, c = 2, and... In this case, the function CORRECT, for example, in d l′ +ρ≡0(modτ) or d l′-1 =0, return (d) l′-1 If ρ remains unchanged, and otherwise, return
[0106] Once the stopping criterion is reached, the process terminates, for example, in operation 206 (END). In this stage, the values of the last n coefficients of the accumulator remain their initial values, such as 0. During operation 206, as... Figure 2 As shown, the last n coefficients (d1, ..., dn) of the accumulator l+n-1 The value ρ is set to the current value. The output data of the method is the accumulator (d). l , ..., d l+n-1 ), where the coefficients d0 to d l+n-1 The number representing the reduced sum and -τ-adic transformation of the value k:
[0107] Formula 11
[0108]
[0109] In this embodiment, the coefficients d0 to d l′-c For example, only one input data value is taken and processed. In fact, once the coefficients d0 to d... l-1 If each value in the accumulator is provided once as input data, then only the last m+c-1 coefficients (d) of the accumulator are considered. l′-c+1, ..., d l-1 In each new loop of the algorithm, the values are used as input data one after another until the stopping criterion is reached.
[0110] about Figure 2 and Figure 4 The described embodiments allow for τ-based i and τ imod(m) moduloτ m The equivalence of -1 is achieved by using the same sequence of operations to reduce and convert scalar k or its equivalents one by one to the τ-adic representation.
[0111] Figure 2 and / or Figure 4 The result of this method can be used, for example, for scalar multiplication of points on a Koblitz curve, now referred to Figure 6To describe in more detail. Such scalar multiplication can, for example, be used as part of elliptic curve cryptography operations.
[0112] Figure 6 The illustration depicts an embodiment of performing and protecting cryptographic operations. Specifically, Figure 6 This is a flowchart illustrating an example of scalar multiplication according to an embodiment of the present disclosure.
[0113] For example, Figure 6 The method shown in the flowchart is by Figure 1 This is achieved through electronic device 100.
[0114] For example, in operation 600 (receiving k and P), electronic device 100 receives, for example, a data value corresponding to an integer or τ-adic integer k and encoded data or plaintext to be encoded via communication interface 110. In another example, the scalar k has been stored in memory 106, and only the point is received via communication interface 110. The cryptographic key k and the point are then sent, for example, to cryptographic coprocessor 104.
[0115] In operation 601 (reduction and τ-adic transformation) following operation 600, the cryptographic coprocessor 104, according to... Figure 2 The described embodiments or based on the information provided... Figure 4 The described embodiments perform reduction and transformation of scalar k to generate a more appropriate representation of scalar k.
[0116] In operation 602 (scalar multiplication of P) following operation 601, the cryptographic coprocessor 104 performs, for example, a multiplication of the modified scalar k with point P. The result of the operation is then used, for example, in cryptographic operation 604 according to the relevant protocol. In some cases, the multiplication is performed according to the method described in the patent application "Protection d'une opérationcryptographique sur une courbe elliptique" filed on August 31, 2021, filed in the name of the current applicant and assigned application number FR2109096 (Attorney's No. B20909).
[0117] One advantage of this embodiment is that τ-adic can be performed dynamically, one digit at a time, during scalar reduction. Furthermore, the length of the transformed scalar does not depend on the size of the input scalar.
[0118] Another advantage of these embodiments is that they make it difficult to utilize differential power analysis and related attacks. In fact, in every cryptographic operation involving a scalar k, a random multiple τ is added to the scalar k. m-1 will change the visible operation of the device. Furthermore, in some τ-adic representations, such as τNAF and its variants, a random multiple τ is generated. m -1 includes the random number generated by l'.
[0119] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these embodiments can be combined and other variations will be apparent to those skilled in the art.
[0120] Finally, the actual implementation methods of the embodiments and variations described herein are based on the functional descriptions provided above, and are within the capabilities of those skilled in the art. Specifically, regarding the generation of random numbers.
[0121] A cryptographic method can be summarized as including implementing an algorithm applied to a scalar (k) via a cryptographic circuit (104) to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes iteration i, where each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Make:
[0122] Where m is a positive integer and each iteration i includes: a) calculating a first intermediate data value (u) by applying a first operation, modulo τ, to the first input data (ρ) and the input vector, where τ is a complex number; b) updating the value of the first input data value (ρ) by applying a second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and c) changing the number (d) of the output vector at position i. i The value is updated to be equal to the first intermediate data value (u), where the total number of iterations is determined by the cryptographic circuit based on a stopping index.
[0123] Each iteration may further include d) updating i to i+1; e) when i = l, resetting i to im.
[0124] The first integer 1 can be greater than the second integer m. The method further includes: after implementing step e) of iteration l-1, applying the function (CORRECT) to the c-1 numbers of the output vector (d0, ..., dl+n-1) at position j along with the first input data value (ρ), where j belongs to {lm-c+1, ..., lm}, and updating these numbers of the output vector and the first input data value (ρ) by applying the result of the function, the function making the output vector c-1 numbers c-1, ..., dl+n-1 along with the first input data value (ρ) c-1, ..., lm. Equal quantities remain unchanged before and after the function updates the number, and the updated number d l-m-c+1 to d l-m It satisfies the predicate C, and the predicate C depends on the base-τ representation.
[0125] Cryptographic methods may include setting the last n coordinates of the output vector to a base-τ representation of the first input data value (ρ) from the last iteration.
[0126] Output vector (d0, ..., d l+n-1 The coordinates of ) can correspond to the numbers in the reduced τ-adic form of the scalar (k).
[0127] The length of the τ-adic reduction transformation of a scalar (k) may not depend on the value of the scalar.
[0128] Stopping criteria can include a first input data value (ρ) that is low enough to be represented as a base-τ number.
[0129] The result of the first operation can be the first input data value (ρ) and the input vector (d′). i The remainder of Euclidean division of the first number of a complex number (τ) is not necessarily the smallest.
[0130] An integer m can be defined by a Koblitz curve (E), which is defined by a set of points of the following form:
[0131] Formula 9
[0132] {(x,y)∈K×K:y 2 +xy=x 3 +ax 2 +1}, Where a equals 0 or 1, and K = GF(2 m () is the base 2 m A finite field.
[0133] Cryptographic methods may include scalar multiplication, which multiplies a reference point corresponding to a point P belonging to the Koblitz curve (E) by a scalar (k).
[0134] The complex number τ can be equal to Where μ equals (-1) 1-a .
[0135] The scalar (k) can be a cryptographic key stored in the memory of an electronic device.
[0136] The integer 1 can be equal to m, and the output vector can consist of m+n coordinates, and each coordinate is equal to 0 before steps a) to c) of the first iteration i=0.
[0137] The first integer l can be larger than the second integer m, and before implementing the first iteration i=0 steps a) to c), the output vector (d0, ..., d...) is... l+n-1 The first digit of ) can be τ-adic form τ m A number that is a multiple of -1.
[0138] Before implementing steps a) to c) of the first iteration i=0, the output vector (d0, ..., d...) is... l+n-1 The first digit of j is such that when j is between 0 and 1-m-1, the digit at position j can be the opposite of the digit at position m+j; and when j is between 1-m and m-1, each digit at position j can be equal to 0.
[0139] Non-transitory memory can be broadly defined as containing storage instructions for implementing cryptographic methods, when these instructions are executed by cryptographic circuitry.
[0140] Electronic devices can be broadly categorized as including cryptographic circuits configured to implement cryptographic methods.
[0141] In one embodiment, the method includes performing cryptographic operations and protecting the execution of the cryptographic operations. Performing the cryptographic operations and protecting the operations includes: implementing an algorithm applied to a scalar via cryptographic circuitry to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Determined according to the following equation:
[0142] Where m, l, and n are positive integers and each iteration i includes:
[0143] a) Calculate the first intermediate data value (u) by applying the first operation moduloτ to the first input data (ρ) and the input vector, where τ is a complex number;
[0144] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0145] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0146] The number of iterations is determined by the cryptographic circuit based on a stopping index.
[0147] In one embodiment, each iteration may include d) updating i to i+1; e) when i = l, resetting i to im. In one embodiment, the integer l may be greater than the integer m, and the method further includes: after performing step e) of iteration l-1, applying the function (CORRECT) to the c-1 numbers of the output vector (d0, ... dl+n-1) at position j along with the first input data value (ρ), where j belongs to {lm-c+1, ..., lm}, and updating these numbers of the output vector and the first input data value (ρ) by means of the result of applying the function, the function being such that... Equal quantities remain unchanged before and after the function updates the number, and the updated number d l-m-c+1 to d l-m The predicate C is satisfied, and the predicate C depends on the base-τ representation. In one embodiment, the method may include setting the last n coordinates of the output vector to the base-τ representation of the first input data value (ρ) of the last iteration. In one embodiment, the output vector (d0, ..., d...) satisfies the predicate C, which depends on the base-τ representation. l+n-1 The coordinates of ) can correspond to numbers in the reduced τ-adic form of a scalar. In one embodiment, the length of the τ-adic reduction transformation of the scalar (k) may not depend on the value of the scalar. In one embodiment, a stopping index can be satisfied when the first input data value (ρ) can be represented by n base-τ numbers. In one embodiment, the result of the first operation is the first input data value (ρ) and the input vector (d′). i The remainder of the sum of the first digits of (x, y) divided by the Euclidean division of the complex number (τ). In one embodiment, the result of the first operation is not the minimum result of the Euclidean division. In one embodiment, the integer m is defined according to the Koblitz curve (E) with a point set of the following form: {(x, y) ∈ K × K: y 2 +xy=x 3 +ax 2 +1}, where a equals 0 or 1, and K = GF(2 m () is the base 2 m The finite field. In one embodiment, the cryptographic method includes a scalar multiplication of a reference point corresponding to a point P belonging to the Koblitz curve (E) by a scalar (k). In one embodiment, the complex number τ is equal to Where μ equals (-1) 1-a In one embodiment, the scalar (k) may be a cryptographic key stored in the electronic device's memory. In another embodiment, the integer 1 may be equal to m, and the output vector (d0, ..., d...) may be... m+n-1The output vector (d0, ..., dn) consists of m+n coordinates, and each coordinate is equal to 0 before steps a) to c) of the first iteration i=0. In one embodiment, the first integer l is greater than the second integer m, and the output vector (d0, ..., dn) is set to m+n before steps a) to c) of the first iteration i=0. l+n-1 The first l number can be τ-adic form τ m A number that is a multiple of -1. In one embodiment, before implementing steps a) to c) of the first iteration i = 0, the output vector (d0, ..., d...) is... l+n-1 The first l digits of j satisfy the following: when j is between 0 and 1-m-1, the digit at position j is the opposite of the digit at position m+j; and when j is between 1-m and m-1, each digit at position j is equal to 0.
[0148] In one embodiment, the content of a non-transitory computer-readable medium leads to a cryptographic circuit executing a method, the method comprising: performing cryptographic operations and protecting the execution of the cryptographic operations. Performing the cryptographic operations and protecting the operations includes: implementing an algorithm applied to a scalar to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Determined according to the following equation:
[0149] Where m, l, and n are positive integers and each iteration i includes:
[0150] a) Calculate the first intermediate data value (u) by applying the first operation moduloτ to the first input data (ρ) and the input vector, where τ is a complex number;
[0151] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0152] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0153] The number of iterations is determined by the cryptographic circuit based on a stopping index. In one embodiment, each iteration may include d) updating i to i+1; e) resetting i to im when i = l. In one embodiment, the integer l may be greater than the integer m, and the method further includes: after performing step e) of iteration l-1, applying the function (CORRECT) to the c-1 numbers of the output vector (d0, ..., dl+n-1) at position j along with the first input data value (ρ), where j belongs to {lm-c+1, ..., lm}, and updating these numbers of the output vector and the first input data value (ρ) by means of the result of applying the function, the function being such that... Equal quantities remain unchanged before and after the function updates the number, and the updated number d l-m-c+1 to d l-m The predicate C is satisfied, and the predicate C depends on the base-τ representation. In one embodiment, the method may include setting the last n coordinates of the output vector to the base-τ representation of the first input data value (ρ) of the last iteration. In one embodiment, the stopping criterion may be satisfied when the first input data value (ρ) can be represented by n base-τ numbers. In one embodiment, the result of the first operation is the first input data value (ρ) and the input vector (d′). i The remainder of the sum of the first digits of (x, y) divided by the Euclidean division of the complex number (τ). In one embodiment, the integer m is defined according to a Koblitz curve (E) with a point set of the following form: {(x, y) ∈ K × K: y 2 xy = x 3 +ax 2 +1}, where a equals 0 or 1, and K = GF(2 m () is the base 2 m A finite field. In one embodiment, the complex number τ equals Where μ equals (-1) 1-a In one embodiment, the content includes instructions that can be implemented by cryptographic circuitry.
[0154] In one embodiment, the device includes a memory and cryptographic circuitry coupled to the memory. The cryptographic circuitry performs cryptographic operations during operation and protects the execution of these operations. Performing the cryptographic operations and protecting the operations includes: implementing an algorithm applied to a scalar to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′j Determined according to the following equation:
[0155] Where m, l, and n are positive integers and each iteration i includes:
[0156] a) Calculate the first intermediate data value (u) by applying the first operation moduloτ to the first input data (ρ) and the input vector, where τ is a complex number;
[0157] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0158] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0159] The number of iterations is determined by the cryptographic circuit based on a stopping indicator. In one embodiment, each iteration may include:
[0160] d) Update i to i+1;
[0161] e) When i = l, reset i to im.
[0162] In one embodiment, the integer l is greater than the integer m, and the method includes: after performing step e) of iteration l-1, applying the function (CORRECT) to the c-1 numbers of the output vector (d0, ..., dl+n-1) at position j along with the first input data value (ρ), where j belongs to {lm-c+1, ..., lm}, and updating these numbers of the output vector and the first input data value (ρ) by means of the result of applying the function, the function such that:
[0163] and Equal quantities remain unchanged before and after the function updates the number, and
[0164] Updated number d l-m-c+1 to d l+m Satisfying predicate C,
[0165] The predicate C depends on the base-τ representation.
[0166] In one embodiment, the cryptographic circuit sets the last n coordinates of the output vector to a base-τ representation of the first input data value (ρ) from the last iteration. In one embodiment, a stopping criterion is satisfied when the first input data value (ρ) can be represented by n base-τ numbers. In one embodiment, the result of the first operation is the first input data value (ρ) and the input vector (d′). iThe remainder of the sum of the first digits of (x, y) divided by the Euclidean division of the complex number (τ). In one embodiment, the integer m is defined according to a Koblitz curve (E) with a point set of the following form: {(x, y) ∈ K × K: y 2 xy = x 3 +ax 2 +1}, where a equals 0 or 1, and K = GF(2 m () is the base 2 m A finite field. In one embodiment, the complex number τ equals Where μ equals (-1) 1-a .
[0167] In one embodiment, the system includes a host processor and cryptographic circuitry coupled to the host processor. The cryptographic circuitry performs cryptographic operations and protects the execution of these operations during operation. Performing the cryptographic operations and protecting the operations includes: implementing an algorithm applied to a scalar to generate an output vector of length l+n, the output vector having digits d0, ..., dn. l+n-1 The algorithm includes multiple iterations i. Each iteration i takes an input data value (ρ) and an input vector of length c. The input data value is initially equal to the scalar, and the input vector has a number d′. i ,...,d′ i+c-1 For each j∈{i, ...,i+c-1}, the number d′ j Determined according to the following equation:
[0168] Where m, l, and n are positive integers and each iteration i includes:
[0169] a) Calculate the first intermediate data value (u) by applying the first operation moduloτ to the first input data (ρ) and the input vector, where τ is a complex number;
[0170] b) Update the value of the first input data value (ρ) by applying the second operation to the first input data value, the input vector, the first intermediate data value (u), and τ; and
[0171] c) Output the number at position i in the output vector (d i Set it to be equal to the first intermediate data value (u).
[0172] The number of iterations is determined by the cryptographic circuit based on a stopping index.
[0173] In one embodiment, each iteration further includes:
[0174] d) Update i to i+1; and
[0175] e) When i = l, reset i to im.
[0176] In one embodiment, during operation, an application running on the host processor initiates the execution of cryptographic operations via cryptographic circuitry.
[0177] Some embodiments may take the form of a computer program product. For example, according to one embodiment, a computer-readable medium is provided, which includes a computer program adapted to perform one or more of the methods or functions described above. The medium may be a physical storage medium, such as a read-only memory (ROM) chip or a disc such as a digital multifunction disk (DVD ROM), optical disc (CD-ROM), hard disk, memory, network, or a portable media article read by a suitable drive or via a suitable connection, including other related codes encoded in one or more barcodes or stored in one or more computer-readable media and read by a suitable reader device.
[0178] Furthermore, in some embodiments, some or all of the methods and / or functions may be implemented or provided in other ways, such as being implemented or provided at least in part in firmware and / or hardware, including but not limited to one or more application-specific integrated circuits (ASICs), digital signal processors, discrete circuits, logic gates, standard integrated circuits, controllers (e.g., by implementing appropriate instructions, and including microcontrollers and / or embedded controllers), field-programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), and devices employing RFID technology and various combinations thereof.
[0179] The various embodiments described above can be combined to provide further embodiments. As needed, aspects of the embodiments can be modified to incorporate concepts from various patents, applications, and publications to provide further embodiments.
[0180] These and other modifications can be made to the embodiments based on the detailed description above. Generally, the terminology used in the appended claims should not be construed as limiting the claims to the specific embodiments disclosed in the specification and claims, but should be interpreted to include all possible embodiments and the full scope of equivalents claimed. Therefore, the claims are not limited by this disclosure.
Claims
1. A method for implementing cryptographic operations, comprising: Perform password operation; as well as Protecting the execution of the cryptographic operation, the execution of the cryptographic operation and the protection include: An algorithm applied to scalars is implemented using cryptographic circuits to generate an output vector of length L+n, the output vector having digits d0,…,dn. L+n-1 The algorithm includes multiple iterations i, with each iteration i taking the input data value. and an input vector of length c, wherein the input data values are initially equal to the scalar, and the input vector has numerical values. For each The number Determined according to the following formula: Where m, L, and n are positive integers and each iteration i includes: a) By processing the input data values The first operation, modulo, is applied to the input vector. Calculate the first intermediate data value u, where It is a complex number; b) By analyzing the input data values, the input vector, the first intermediate data value u, and... A second operation is performed to update the input data value. The value; and c) The number at position i of the output vector Set it to be equal to the first intermediate data value u. The number of iterations is determined by the cryptographic circuit based on a stopping index, and the output vectors d0,…,d... L+n-1 The coordinates correspond to the scalar after reduction. Numbers in -adic form.
2. The method of claim 1, wherein each iteration further comprises: d) Update i to i+1; as well as e) When , reset i to im.
3. The method according to claim 2, wherein the integer L is greater than the integer m, the method comprising: After performing step e) of iteration L-1, the function CORRECT is applied to the output vector d0, … d at position j. L+n-1 The c-1 number together with the input data value , where j belongs to And by applying the results generated by the function, update these numbers in the output vector and the input data values. The function makes: and Equal quantities remain unchanged before and after the number is updated via the function, and Updated figures d L-m-c+1 to d L-m Satisfy predicate C; The predicate C depends on base- express.
4. The method according to claim 1, comprising: Set the last n coordinates of the output vector to the input data values of the last iteration. base- express.
5. The method of claim 4, wherein the scalar The length of the -adic reduction transformation does not depend on the value of the scalar.
6. The method of claim 1, wherein the stopping indicator is the input data value Able to base- The condition is satisfied when represented by numbers.
7. The method of claim 1, wherein the result of the first operation is the input data value. and the input vector d′ i The sum of the first digits divided by the complex number The remainder of Euclidean division.
8. The method of claim 7, wherein the result of the first operation is not the minimum result of the Euclidean division.
9. The method of claim 1, wherein the integer m is defined according to the Koblitz curve E, the Koblitz curve E being defined by a set of points having the following form: , in It equals 0 or 1, and It is a base 2 m A finite field.
10. The method of claim 9, comprising: Multiply the reference point corresponding to the point P belonging to the Koblitz curve E by a scalar multiplication of scalar k.
11. The method of claim 9, wherein the complex number equal ,in equal .
12. The method of claim 1, wherein the scalar k is a cryptographic key stored in the electronic device memory.
13. The method of claim 1, wherein the integer L is equal to m, and wherein the output vector d0,…,d m+n-1 It consists of m+n coordinates, and each coordinate is equal to 0 before the first iteration i=0 steps a) to c).
14. The method of claim 1, wherein the integer L is greater than the integer m, and wherein the output vector d0,…,d is defined before steps a) to c) of the first iteration i=0. L+n-1 The first L number is -adic form A number that is a multiple of itself.
15. The method of claim 14, wherein before performing steps a) to c) of the first iteration i=0, the output vector d0,…,d L+n-1 The first L numbers satisfy: When j is between 0 and Lm-1, the digit at position j is the opposite of the digit at position m+j; and When j is between Lm and m-1, each number at position j is equal to 0.
16. A non-transitory computer-readable medium having content that causes a cryptographic circuit to perform a method, the method comprising: Perform password operation; as well as Protecting the execution of the cryptographic operation, the execution of the cryptographic operation and the protection include: Implement an algorithm applied to scalars to generate an output vector of length L+n, the output vector having numbers d0,…,d L+n-1 The algorithm includes multiple iterations i, with each iteration i taking the input data value. And an input vector of length c, wherein the input data values are initially equal to the scalar, and the input vector has numerical values. For each The number Determined according to the following formula: Where m, L, and n are positive integers and each iteration i includes: a) By processing the input data values The first operation, modulo, is applied to the input vector. Calculate the first intermediate data value u, where It is a complex number; b) By analyzing the input data values, the input vector, the first intermediate data value u, and... A second operation is performed to update the input data value. The value; and c) The number at position i of the output vector Updated to be equal to the first intermediate data value u. The number of iterations is determined by the cryptographic circuit based on a stopping index, and the output vector is... The coordinates correspond to the scalar reduced to Numbers in -adic form.
17. The non-transitory computer-readable medium of claim 16, wherein each iteration comprises: d) Update i to i+1; as well as [01]e) When , reset i to im.
18. The non-transitory computer-readable medium of claim 17, wherein the integer L is greater than the integer m, and the method comprises: After performing step e) of iteration L-1, the function CORRECT is applied to the output vector d0, … d at position j. L+n-1 The c-1 number together with the input data value , where j belongs to And by applying the results generated by the function, update these numbers in the output vector and the input data values. The function makes: and Equal quantities remain unchanged before and after the function updates the number, and Updated figures to Satisfy predicate C; The predicate C depends on base- express.
19. The non-transitory computer-readable medium of claim 16, wherein the method comprises: Set the last n coordinates of the output vector to the input data values of the last iteration. base- express.
20. The non-transitory computer-readable medium of claim 16, wherein the stop index is in the input data value Able to base- The condition is satisfied when represented by numbers.
21. The non-transitory computer-readable medium of claim 16, wherein the result of the first operation is the input data value. and the input vector d′ i The sum of the first digits divided by the complex number The remainder of Euclidean division.
22. The non-transitory computer-readable medium of claim 16, wherein the integer m is defined according to a Koblitz curve E, the Koblitz curve E being defined by a set of points having the following form: , in It equals 0 or 1, and It is a cardinality A finite field.
23. The non-transitory computer-readable medium of claim 22, wherein the complex number equal ,in equal .
24. The non-transitory computer-readable medium of claim 16, wherein the content includes instructions executable by the cryptographic circuitry.
25. An apparatus for implementing cryptographic operations, comprising: Memory, and A cryptographic circuit coupled to the memory, wherein the cryptographic circuit performs cryptographic operations during operation and protects the execution of the cryptographic operations, the execution of the cryptographic operations and the protection comprising: Implement an algorithm applied to scalars to generate an output vector of length L+n, the output vector having digits d0,…,d L+n-1 The algorithm includes multiple iterations i, with each iteration i taking the input data value. And an input vector of length c, wherein the input data values are initially equal to the scalar, and the input vector has numerical values. For each The number Determined according to the following formula: Where m, L, and n are positive integers and each iteration i includes: a) By processing the input data values The first operation, modulo, is applied to the input vector. Calculate the first intermediate data value u, where It is a complex number; b) By analyzing the input data values, the input vector, the first intermediate data value u, and... A second operation is performed to update the input data value. The value; and c) The number at position i of the output vector Updated to be equal to the first intermediate data value u. The number of iterations is determined by the cryptographic circuit based on a stopping index, and the output vector is... The coordinates correspond to the scalar after reduction. Numbers in -adic form.
26. The device of claim 25, wherein each iteration comprises: d) Update i to i+1; as well as [02]e) When , reset i to im.
27. The device of claim 26, wherein the integer L is greater than the integer m, and the device comprises: After performing step e) of iteration L-1, the function CORRECT is applied to the output vector d0, … d at position j. L+n-1 The c-1 number together with the input data value , where j belongs to And by applying the results generated by the function, these numbers in the output vector and the input data values are updated. The function makes: and Equal quantities remain unchanged before and after the function updates the number, and Updated figures to Satisfy predicate C; The predicate C depends on base- express.
28. The device of claim 25, wherein the cryptographic circuit, in operation, sets the last n coordinates of the output vector to the input data values of the last iteration. base- express.
29. The device of claim 25, wherein the stop indicator is the input data value Able to base- The condition is satisfied when represented by numbers.
30. The device of claim 25, wherein the result of the first operation is the input data value. and the input vector d′ i The sum of the first digits divided by the complex number The remainder of Euclidean division.
31. The device of claim 25, wherein the integer m is defined according to a Koblitz curve E, the Koblitz curve E being defined by a set of points of the form: , in It equals 0 or 1, and It is a cardinality A finite field.
32. The device according to claim 31, wherein the plurality of equal ,in equal .
33. A system for implementing cryptographic operations, comprising: Host processor; as well as A cryptographic circuit coupled to the host processor, wherein the cryptographic circuit performs cryptographic operations and protects the execution of the cryptographic operations during operation, the execution of the cryptographic operations and the protection including: Implement an algorithm applied to scalars to generate an output vector of length L+n, the output vector having numbers d0,…,d L+n-1 The algorithm includes multiple iterations i, with each iteration i taking the input data value. And an input vector of length c, wherein the input data values are initially equal to the scalar, and the input vector has numerical values. For each The number Determined according to the following formula: Where m, L, and n are positive integers and each iteration i includes: a) By processing the input data values The first operation, modulo, is applied to the input vector. Calculate the first intermediate data value u, where It is a complex number; b) By analyzing the input data values, the input vector, the first intermediate data value u, and... A second operation is performed to update the input data value. The value; and c) The number at position i of the output vector Updated to be equal to the first intermediate data value u. The number of iterations is determined by the cryptographic circuit based on a stopping index, and the output vector is... The coordinates correspond to the scalar reduced to Numbers in -adic form.
34. The system of claim 33, wherein each iteration comprises: d) Update i to i+1; as well as e) When , reset i to im.
35. The system of claim 33, wherein, in operation, an application implemented on the host processor initiates the execution of the cryptographic operation via the cryptographic circuit.