True random number generator, true random number generation method, and encryption device
Patent Information
- Application Number
- CN202310388786.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-04-12
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2043-04-12
AI Technical Summary
[0004]然而,现有的真随机数生成器结构资源开销大、能耗高,并且在每个执行周期中生成的随机位少,能效低,吞吐量低,无法保证高效的生产速率
[0022] The true random number generator mentioned in this invention includes an entropy source module and a digitization module. The digitization module includes a sampling ring oscillator, multiple intermediate D flip-flops, an XOR operator, and output D flip-flops. The entropy source module has N input ring oscillators, which randomly generate N sets of oscillation input signals upon receiving an enable signal. The sampling ring oscillator is designed to consist of M logic operators with NOT operation functions connected in series, end to end. Upon receiving an enable signal, each logic operator can output an oscillation clock signal, thus outputting M sets of oscillation clock signals. The intermediate D flip-flops form an N*(M-1) matrix, meaning the matrix contains N*(M-1) intermediate D flip-flops. The D inputs of the M-1 intermediate D flip-flops in each row receive the same oscillation input signal, and the clock signal inputs of the N intermediate D flip-flops in each column receive the same oscillation clock signal. Based on this:
Smart Images

Figure CN116521130B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of encryption security technology, and more specifically, relates to a true random number generator, a true random number generation method, and an encryption device. Background Technology
[0002] In recent years, with the rapid development of technologies such as big data, the Internet of Things, cloud computing, and edge computing, information security issues have become increasingly serious. People have put forward increasingly higher requirements for system security, and random number generators, as a key basic component of security systems, are widely used in various devices.
[0003] Random numbers are fundamental to security systems, including authentication protocols, encryption algorithms, and secure key management mechanisms. Currently, random number generators mainly include pseudo-random number generators (PRNGs) and true random number generators (TRNGs). Traditional pseudo-random number generators generate random bits using deterministic algorithms in each execution cycle, offering advantages such as simple structure and high throughput. However, because each random bit is generated by a deterministic algorithm, it possesses a degree of predictability, posing a security vulnerability to the application of random numbers in secure systems. True random number generators, on the other hand, utilize inherent physical random processes to generate truly random numbers with statistical significance. Even if an adversary has some understanding of the system generating the random numbers, they cannot predict them, thus increasing the unpredictability of random numbers.
[0004] However, existing true random number generators suffer from high resource consumption and energy consumption, and generate only a few random bits per execution cycle, resulting in low energy efficiency and low throughput, failing to guarantee a high production rate. Therefore, there is an urgent need for a high-throughput and high-energy-efficiency true random number generator that can improve the unpredictability of random numbers while maintaining low power consumption. Summary of the Invention
[0005] In view of the above-mentioned defects or improvement needs of the existing technology, the present invention provides a true random number generator, a true random number generation method and an encryption device, the purpose of which is to improve the throughput and energy efficiency of the true random number generator, and improve the unpredictability of random numbers while ensuring low power consumption.
[0006] To achieve the above objectives, according to one aspect of the present invention, a true random number generator is provided, comprising an entropy source module and a digitization module, wherein the digitization module includes a sampling ring oscillator, a plurality of intermediate D flip-flops, an XOR operator, and an output D flip-flop, wherein...
[0007] The entropy source module includes N input ring oscillators. Each input ring oscillator outputs an oscillation input signal after receiving an enable signal and ends oscillation after the enable signal is removed, where N≥3.
[0008] The sampling ring oscillator is composed of M logic operators with NOT operation function connected in series and end to end. After receiving an enable signal, the sampling ring oscillator causes each logic operator to output an oscillation clock signal and ends oscillation after the enable signal is removed. M is an odd number greater than 5.
[0009] The intermediate D flip-flops constitute an N*(M-1) matrix. Each row of the matrix has M-1 intermediate D flip-flops, and each column has N intermediate D flip-flops. The D input terminals of the intermediate D flip-flops in each row are connected to the output terminals of the same input ring oscillator. The N rows of intermediate D flip-flops are connected one-to-one with the N input ring oscillators. The clock signal input terminals of the intermediate D flip-flops in each column are connected to the output terminals of the same logic unit. The M-1 columns of intermediate D flip-flops are connected one-to-one with the first M-1 logic units in the sampling ring oscillator.
[0010] The XOR operator is connected to the Q output of each intermediate D flip-flop and performs an XOR operation.
[0011] The D input terminal of the output D flip-flop is connected to the output terminal of the XOR operator, the clock signal input terminal is connected to the output terminal of the terminal logic operator of the sampling ring oscillator, and the Q output terminal outputs a true random number.
[0012] In one embodiment, the input ring oscillator includes a series NAND gate and a buffer, wherein the first input of the NAND gate is used to receive an enable signal and the second input is connected to the output of the buffer.
[0013] In one embodiment, in the sampling ring oscillator, at least one of the logic operators is a NAND gate, wherein one NAND gate serves as the first logic operator, with its first input connected to the enable signal and its second input connected to the output of the last logic operator to achieve a head-to-tail connection.
[0014] In one embodiment, the sampling ring oscillator is composed of multiple NAND gates and multiple NOT gates connected in series, wherein a NAND gate is set every two NOT gates, and the first input terminal of each NAND gate is connected to the output terminal of the previous NOT gate, and the second input terminal is used to receive an enable signal.
[0015] In one embodiment, N=4 and M=9.
[0016] In one embodiment, the true random number generator is implemented based on an FPGA.
[0017] In one embodiment, an enable signal generation module is further included, which is used to apply an enable signal to the entropy source module and the sampling ring oscillator when an encryption request instruction is received, and to deactivate the enable signal after receiving an encryption completion instruction.
[0018] In one embodiment, the enable signal generation module outputs a high level as an enable signal and outputs a low level as a deactivation enable signal.
[0019] According to another aspect of the present invention, a method for generating true random numbers is provided, wherein an enable signal is applied to a true random number generator to obtain true random numbers, wherein the true random number generator is the aforementioned true random number generator.
[0020] According to another aspect of the present invention, an encryption device is provided, comprising the above-described true random number generator, wherein the encryption device generates true random numbers using the true random number generator and then performs encryption processing based on the true random numbers.
[0021] In summary, compared with the prior art, the above-described technical solutions conceived by this invention can achieve the following beneficial effects:
[0022] The true random number generator mentioned in this invention includes an entropy source module and a digitization module. The digitization module includes a sampling ring oscillator, multiple intermediate D flip-flops, an XOR operator, and output D flip-flops. The entropy source module has N input ring oscillators, which randomly generate N sets of oscillation input signals upon receiving an enable signal. The sampling ring oscillator is designed to consist of M logic operators with NOT operation functions connected in series, end to end. Upon receiving an enable signal, each logic operator can output an oscillation clock signal, thus outputting M sets of oscillation clock signals. The intermediate D flip-flops form an N*(M-1) matrix, meaning the matrix contains N*(M-1) intermediate D flip-flops. The D inputs of the M-1 intermediate D flip-flops in each row receive the same oscillation input signal, and the clock signal inputs of the N intermediate D flip-flops in each column receive the same oscillation clock signal. Based on this:
[0023] (1) A sampler with multiple sampling points is formed by a sampling ring oscillator and N*(M-1) intermediate D flip-flops, which is used to sample the random sequence of time jitter in the entropy source module. Compared with a normal true random number generator, the sampling ring oscillator provides M uncorrelated sampling clock signals. For the same oscillation input signal, it can perform M uncorrelated samplings, which has high energy conversion efficiency and low circuit energy loss, thus greatly improving energy efficiency.
[0024] (2) Since one sampling clock signal can control N D flip-flops to sample N sets of oscillating input signals simultaneously, N random sampled signals are obtained. Compared with one clock signal controlling only one random sampled signal, if the same number of random sampled signals are to be obtained, the design of this scheme can reduce the number of NOT logic devices in the sampling ring oscillator. The fewer the number of NOT logic devices in the ring oscillator, the higher the oscillation frequency is generated, that is, the higher the sampling frequency, which further improves the throughput of random sampling.
[0025] (3) Since the same oscillating input signal can be sampled M times without correlation, and a sampling clock signal can control N D flip-flops to sample N sets of oscillating input signals at the same time, a large number of random samplings can be achieved by using N input ring oscillators and setting M logic units in the sampling ring oscillators, which simplifies the structural design and reduces power consumption.
[0026] (4) In this invention, a true random number generator is constructed using a D flip-flop and a ring oscillator, which eliminates the dependence on a phase-locked loop (PLL). The overall structure is simple, and based on a matrix row and column control method, it reduces the structural resource overhead while ensuring the number of random samples. Attached Figure Description
[0027] Figure 1 This is a block diagram of a true random number generator according to one embodiment;
[0028] Figure 2 A detailed structural diagram of a true random number generator according to one embodiment;
[0029] Figure 3 This is a sampling schematic diagram of a D flip-flop according to an embodiment. Detailed Implementation
[0030] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. Furthermore, the technical features involved in the various embodiments of this invention described below can be combined with each other as long as they do not conflict with each other.
[0031] like Figure 1 The diagram shows the structure of a true random number generator, which includes an entropy source module and a digitization module. The signal it relies on is an enable signal, and the digitization module ultimately outputs a true random number sequence.
[0032] like Figure 2 The diagram shown is a structural diagram of a true random number generator in one embodiment. Wherein,
[0033] The entropy source module includes N input ring oscillators (hereinafter referred to as input ROs). Each input ring oscillator outputs an oscillating input signal upon receiving an enable signal and stops oscillating upon deactivation of the enable signal. Understandably, signal oscillation refers to high-low level transitions, such as a rectangular wave; the end of oscillation indicates a sustained high or low level. The output oscillation of the ring oscillator is random, and the output oscillation input signal is unpredictable. The ring oscillator can employ a conventional design, with its input and output short-circuited and controlled by the enable signal. When an enable signal is received, the output is out of phase with the input; when the enable signal is deactivated, the output is continuously pulled high or low by the enable signal.
[0034] In one embodiment, taking a high level as the enable signal and a low level as the deactivation signal, the input ring oscillator consists of a NAND gate and a buffer module. The first input of the NAND gate is used to receive the enable signal, and the second input is connected to the output of the buffer. The structure is simple and can generate oscillation when the enable signal (enable=1) is received. When the enable signal (enable=0) is deactivated, the output is kept at a high level, thereby ending the oscillation.
[0035] The sampling ring oscillator consists of M logic operators with NOT operation functions connected in series, end to end. Upon receiving an enable signal, each logic operator outputs an oscillation clock signal; oscillation ends upon deactivation of the enable signal. M is an odd number greater than 5. Therefore, upon receiving an enable signal, the sampling ring oscillator can output M oscillation clock signals with different timings. The odd number M ensures that the sampling ring oscillator oscillates upon receiving the enable signal, and N≥3 and M>5 guarantee the randomness test of the true random number generator.
[0036] In one embodiment, taking a high-level signal as an enable signal and a low-level signal as a deactivation signal, in the sampling ring oscillator, at least one of the logic units is a NAND gate. One of the NAND gates serves as the first logic unit, with its first input connected to the enable signal and its second input connected to the output of the last logic unit to achieve a head-to-tail connection. When the enable signal is received, the NAND gate acts as a NOT gate, and each logic unit of the sampling ring oscillator outputs an oscillation clock signal. When the enable signal is deactivated, the NAND gate outputs a constant high level, causing the output levels of each logic unit to stop oscillating.
[0037] Multiple intermediate D flip-flops form an N*(M-1) matrix. Each row of the matrix has M-1 intermediate D flip-flops, and each column has N intermediate D flip-flops. The D inputs of the intermediate D flip-flops in each row are connected to the outputs of the same input ring oscillator, and the N rows of intermediate D flip-flops are connected one-to-one with the N input ring oscillators. The clock signal inputs of the intermediate D flip-flops in each column are connected to the outputs of the same logic unit, and the M-1 columns of intermediate D flip-flops are connected one-to-one with the first M-1 logic units in the sampling ring oscillator. Based on the performance of the D flip-flops, when a transition occurs at the clock signal input, the Q output signal follows the D input signal.
[0038] In this embodiment, sampling of a D flip-flop is taken as an example, such as... Figure 3 As shown, when an enable signal is received, the D input terminal of the D flip-flop obtains the oscillation input signal from the entropy source module, and its clock signal input terminal obtains the oscillation clock signal from the sampling ring oscillator. The oscillation input signal is sampled at the edge of the oscillation clock signal and output at the Q output terminal to obtain a random sampled output. This invention has N*(M-1) D flip-flops forming N*(M-1) sampling points. Due to the random time deviation caused by the Gaussian-distributed electrons or thermal noise in the circuit deviating from their theoretical positions, the randomness of the clock jitter jumping in the RO gradually accumulates over time, resulting in a random sequence of jitter that cannot be predicted. Therefore, a large number of random sampled outputs can be obtained within one execution cycle, that is, an unpredictable 0 and 1 sequence can be obtained.
[0039] In traditional techniques, N*(M-1) sampling points require only N*(M-1) logic gates to output N*(M-1) clock signals, with each clock signal controlling the sampling of one sampling point. This invention, through structural optimization, requires only M logic units in the sampling ring oscillator for N*(M-1) sampling points. The fewer the number of logic units in the sampling ring oscillator, the higher the oscillation frequency, i.e., the higher the random sampling frequency. Therefore, high-throughput random sampling can be achieved. Simultaneously, for the same oscillating input signal, M uncorrelated samples can be performed, resulting in high energy conversion efficiency and low circuit energy loss, significantly improving energy efficiency. Furthermore, by simplifying the structure to achieve a large number of random samplings, the structural design is simplified, and power consumption is reduced.
[0040] The XOR operator is connected to the Q output of each intermediate D flip-flop and performs an XOR operation. That is, the XOR operator obtains the sampling results of N*(M-1) sampling points, performs an XOR operation, and outputs the XOR result.
[0041] The D input of the output D flip-flop is connected to the output of the XOR operator, the clock signal input is connected to the output of the final logic unit of the sampling ring oscillator, and the Q output outputs a true random number. After stabilizing the output sampled values through the D flip-flop, the obtained sampled values are XORed and output. At this point, the sequence output by the last D flip-flop is a random sequence that meets the high entropy requirement. Furthermore, the clock used by the D flip-flops is provided by the sampling RO, ensuring the stability of the output.
[0042] In one embodiment, the true random number generator is implemented based on an FPGA.
[0043] In one embodiment, N=4 and M=9, meaning that 8 sampling points are used to sample the oscillation input signals of 4 input ring oscillators. This is equivalent to providing the equivalent entropy of sampling the clock jitter of 32 high-speed ring oscillators with 1 sampling point, thus significantly improving energy efficiency. Furthermore, this architecture is built using only ring oscillators and D flip-flops, eliminating the dependency on PLLs and ensuring portability across different FPGA platforms. It also generates a sampling frequency close to 300MHz, significantly improving throughput.
[0044] In one embodiment, the true random number generator further includes an enable signal generation module, used to apply an enable signal to the entropy source module and the sampling ring oscillator upon receiving an encryption request instruction, and to deactivate the enable signal upon receiving an encryption completion instruction. Specifically, the enable signal generation module outputs a high level as the enable signal and outputs a low level as the deactivation signal.
[0045] Accordingly, the present invention also relates to a true random number generation method, which, based on the true random number generator described above, applies an enable signal to the true random number generator when encryption is required, thereby obtaining true random numbers.
[0046] Accordingly, the present invention also relates to an encryption device, comprising the true random number generator described above, wherein the encryption device generates true random numbers using the true random number generator and then performs encryption processing based on the true random numbers. This encryption device may be, for example, a USB key (U-shield).
[0047] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A true random number generator, characterized in that, It includes an entropy source module and a digitization module. The digitization module includes a sampling ring oscillator, multiple intermediate D flip-flops, an XOR operator, and an output D flip-flop. The entropy source module includes N input ring oscillators. Each input ring oscillator outputs an oscillation input signal after receiving an enable signal and ends oscillation after the enable signal is removed, where N≥3. The sampling ring oscillator is composed of M logic operators with NOT operation function connected in series and end to end. After receiving an enable signal, the sampling ring oscillator causes each logic operator to output an oscillation clock signal and ends oscillation after the enable signal is removed. M is an odd number greater than 5. The intermediate D flip-flops constitute an N*(M-1) matrix. Each row of the matrix has M-1 intermediate D flip-flops, and each column has N intermediate D flip-flops. The D input terminals of the intermediate D flip-flops in each row are connected to the output terminals of the same input ring oscillator. The N rows of intermediate D flip-flops are connected one-to-one with the N input ring oscillators. The clock signal input terminals of the intermediate D flip-flops in each column are connected to the output terminals of the same logic unit. The M-1 columns of intermediate D flip-flops are connected one-to-one with the first M-1 logic units in the sampling ring oscillator. The XOR operator is connected to the Q output of each intermediate D flip-flop and performs an XOR operation. The D input terminal of the output D flip-flop is connected to the output terminal of the XOR operator, the clock signal input terminal is connected to the output terminal of the terminal logic operator of the sampling ring oscillator, and the Q output terminal outputs a true random number.
2. The true random number generator as described in claim 1, characterized in that, The input ring oscillator includes a NAND gate and a buffer connected in series. The first input terminal of the NAND gate is used to receive an enable signal, and the second input terminal is connected to the output terminal of the buffer.
3. The true random number generator as described in claim 1, characterized in that, In the sampling ring oscillator, at least one of the logic operators is a NAND gate, wherein one of the NAND gates serves as the first logic operator, with its first input terminal connected to the enable signal and its second input terminal connected to the output terminal of the last logic operator to achieve a head-to-tail connection.
4. The true random number generator as described in claim 3, characterized in that, The sampling ring oscillator is composed of multiple NAND gates and multiple NOT gates connected in series. A NAND gate is set every two NOT gates. The first input terminal of each NAND gate is connected to the output terminal of the previous NOT gate, and the second input terminal is used to receive the enable signal.
5. The true random number generator as described in any one of claims 1 to 4, characterized in that, N=4, M=9.
6. The true random number generator as described in any one of claims 1 to 4, characterized in that, The true random number generator is implemented based on FPGA.
7. The true random number generator as described in any one of claims 1 to 4, characterized in that, It also includes an enable signal generation module, which applies an enable signal to the entropy source module and the sampling ring oscillator when an encryption request instruction is received, and removes the enable signal after receiving an encryption completion instruction.
8. The true random number generator as described in claim 7, characterized in that, The enable signal generation module outputs a high level as the enable signal and outputs a low level as the deactivation signal.
9. A method for generating truly random numbers, characterized in that, An enable signal is applied to a true random number generator to obtain true random numbers, wherein the true random number generator is the true random number generator according to any one of claims 1 to 6.
10. An encryption device, characterized in that, The device includes a true random number generator as described in any one of claims 1 to 8, wherein the encryption device generates a true random number using the true random number generator and then performs encryption processing based on the true random number.