A2b mask conversion method and device based on lookup table, equipment, medium and product

CN117254895BActive Publication Date: 2026-09-25TSINGHUA UNIVERSITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210659870.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-10
Publication Date
2026-09-25
Estimated Expiration
2042-06-10

Smart Images

  • Figure CN117254895B_ABST
    Figure CN117254895B_ABST
Patent Text Reader

Abstract

The application provides an A2B mask conversion method based on a lookup table, applied to the technical field of computers and comprising the following steps: obtaining a Boolean carry value in a Boolean mask domain in an iteration process; converting the Boolean carry value in the Boolean mask domain into an arithmetic carry value in an arithmetic mask domain; adding the arithmetic carry value in the arithmetic mask domain and other intermediate variables in the arithmetic mask domain to obtain an addition result; and using the addition result for the next iteration. The application also provides an A2B mask conversion device, equipment, medium and program product based on a lookup table, which does not need a carry lookup table to protect the generated carry, thereby saving the entire carry lookup table, avoiding the increase of the size of the carry lookup table along with the increase of the conversion data bit width, and reducing the memory overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to an A2B mask conversion method, apparatus, device, medium, and program product based on a lookup table. Background Technology

[0002] Masking is a common method for protecting cryptographic devices against side-channel attacks (SCA). Masks are generally divided into two main categories: arithmetic masks and Boolean masks. However, in different cryptographic algorithms implementing SCA protection, it is often necessary to convert between these two types of masks. The arithmetic-to-Boolean (A2B) conversion method based on lookup tables has been widely studied due to its fast computation speed.

[0003] Existing A2B conversion methods based on lookup tables often require a carry lookup table to protect the carry generated in the method. However, as the bit width of the converted data increases, the size of the carry lookup table also increases, which is not friendly to resource-constrained devices. Summary of the Invention

[0004] The main objective of this invention is to provide an A2B mask conversion method, apparatus, device, medium, and program product based on a lookup table, so as to solve the technical problem that existing mask conversion methods cannot meet the needs of devices with limited memory resources.

[0005] To achieve the above objectives, a first aspect of the present invention provides an A2B mask conversion method based on a lookup table, comprising:

[0006] Obtain the Boolean carry value in the Boolean mask field during the iteration process;

[0007] Convert the Boolean carry value in the Boolean mask field to the arithmetic carry value in the arithmetic mask field;

[0008] The arithmetic carry value in the arithmetic mask field is added to other intermediate variables in the arithmetic mask field to obtain the sum;

[0009] The summation result is used for the next iteration to achieve A2B mask conversion.

[0010] In one embodiment of the present invention, obtaining the Boolean carry value in the Boolean mask field during the iteration process includes:

[0011] Obtain the Boolean shared value D and Boolean shared value R that are in the Boolean mask field during the iteration process.

[0012] In one embodiment of the present invention, converting the Boolean carry value in the Boolean mask field to the arithmetic carry value in the arithmetic mask field includes:

[0013] A random number η is randomly selected from the n′ bits of uniformly distributed data;

[0014] Perform an XOR operation between the random number η and the Boolean shared value D to obtain the first XOR result;

[0015] The first XOR result is modulo 2 with the random number η. n′ The modulo-subtraction operation is performed to obtain the first modulo-subtraction result;

[0016] Perform an XOR operation between the first modulo subtraction result and the Boolean shared value D to obtain the second XOR result;

[0017] Perform an XOR operation between the random number η and the Boolean shared value R to obtain a third XOR result;

[0018] Perform an XOR operation between the third XOR result and the Boolean shared value D to obtain the fourth XOR result;

[0019] The fourth XOR result is modulo 2 with the third XOR result. n′ The modulo-subtraction operation is performed to obtain the second modulo-subtraction result;

[0020] Perform an XOR operation between the second modulo subtraction result and the second XOR result to obtain a fifth XOR result, which represents the arithmetic carry value Temp corresponding to the Boolean shared value D in the arithmetic mask field.

[0021] In one embodiment of the present invention, the step of adding the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result includes:

[0022] The pre-input data is modulo 2 with the Boolean shared value R. n The modulo operation is performed to obtain the first modulo result;

[0023] The first modulo addition result is modulo 2 with the arithmetic carry value Temp. n The modulo addition operation is performed to obtain a second modulo addition result, which represents the addition result.

[0024] In one embodiment of the present invention, after adding the value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result, the method further includes:

[0025] Generate a k-bit random number r that follows a uniform distribution;

[0026] Generate a 1-bit random number ρ that follows a uniform distribution;

[0027] Iterate through all the 2s of the k-bit temporary intermediate variable m, starting from 0. k One possible value;

[0028] In each iteration, the modulo addition result of the intermediate variable m and the random number r is XORed with the concatenation result of the random number ρ and the random number r to obtain the sixth XOR result. The k+1 bits of the sixth XOR result are stored in a lookup table T with the value of the intermediate variable m as the address.

[0029] In one embodiment of the present invention, the step of using the addition result for the next iteration to achieve A2B mask conversion includes:

[0030] Randomly select an input number from the nk-bit uniformly distributed data;

[0031] The random numbers r generated in each iteration are concatenated to obtain the first concatenation result. The input number is then modulo 2 with the first concatenation result. nk The modulo subtraction operation is performed to obtain the third modulo subtraction result. The third modulo subtraction result and the Boolean shared value R both include n data segments, each data segment is k bits, and n and k are both integers not less than 0, n = 0, 1, 2, ..., n-1;

[0032] Iterate through all the 2s of the k-bit temporary intermediate variable m, starting from 0. k One possible value;

[0033] In each iteration, the segment data with the smallest segment count in the third modulo subtraction result and the segment data with the smallest segment count in the Boolean shared value R are modulo 2. (n-m)k The modulo addition operation is performed to obtain the third modulo addition result. The segment data with the smallest segment number in the third modulo addition result is used as the address input of the lookup table T to obtain the output result. The output result of the k-th bit is XORed with the segment data with the smallest segment number in the Boolean shared value R to obtain the seventh XOR result. The third modulo addition result is right-shifted by k bits to obtain the right-shifted result. The addition result is added to the right-shifted result to obtain the iteration result of the third modulo addition result. The Boolean shared value R is right-shifted by k bits to obtain the iteration result of the Boolean shared value R. The iteration result of the third modulo addition result is used as the third modulo addition result for the next iteration. The iteration result of the Boolean shared value R is used as the Boolean shared value R for the next iteration.

[0034] The seventh XOR result obtained from n iterations is concatenated sequentially to obtain a second concatenation result. The second concatenation result is then XORed with the first concatenation result to obtain the arithmetic shared value in the arithmetic mask field.

[0035] A second aspect of the present invention provides an A2B mask conversion device based on a lookup table, comprising:

[0036] The acquisition module is used to obtain the Boolean carry value in the Boolean mask field during the iteration process.

[0037] A conversion module is used to convert the Boolean carry value in the Boolean mask field into the arithmetic carry value in the arithmetic mask field.

[0038] The addition module is used to add the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result.

[0039] An iterative module is used to perform the next iteration using the summation result to achieve A2B mask conversion.

[0040] In one embodiment of the present invention, the acquisition module is specifically used to acquire the Boolean shared value D and Boolean shared value R that are in the Boolean mask field during the iteration process.

[0041] In one embodiment of the present invention, the conversion module includes:

[0042] The random selection module is used to randomly select a random number η from n′ bits of uniformly distributed data.

[0043] The first XOR module is used to perform an XOR operation between the random number η and the Boolean shared value D to obtain the first XOR result;

[0044] The first modulo-subtraction module is used to perform a modulo-2 operation between the first XOR result and the random number η. n′ The modulo-subtraction operation is performed to obtain the first modulo-subtraction result;

[0045] The second XOR module is used to perform an XOR operation between the first modulo subtraction result and the Boolean shared value D to obtain the second XOR result.

[0046] The third XOR module is used to perform an XOR operation between the random number η and the Boolean shared value R to obtain the third XOR result.

[0047] The fourth XOR module is used to perform an XOR operation between the third XOR result and the Boolean shared value D to obtain the fourth XOR result;

[0048] The second modulo-subtraction module is used to perform a modulo-2 operation on the fourth XOR result and the third XOR result. n′The modulo-subtraction operation is performed to obtain the second modulo-subtraction result;

[0049] The fifth XOR module is used to perform an XOR operation between the second modulo subtraction result and the second XOR result to obtain the fifth XOR result, which represents the arithmetic carry value Temp corresponding to the Boolean shared value D in the arithmetic mask field.

[0050] In one embodiment of the present invention, the addition module includes:

[0051] The first module is used to perform a modulo-2 operation between the pre-input data and the Boolean shared value R. n The modulo operation is performed to obtain the first modulo result;

[0052] The second modulo addition module is used to perform a modulo-2 operation on the first modulo addition result and the arithmetic carry value Temp. n The modulo addition operation is performed to obtain a second modulo addition result, which represents the addition result.

[0053] In one embodiment of the present invention, the device further includes:

[0054] The first generation module is used to generate a k-bit random number r that follows a uniform distribution;

[0055] The second generation module is used to generate a 1-bit random number ρ that follows a uniform distribution;

[0056] The first traversal module is used to iterate through all 2s of the k-bit temporary intermediate variable m, starting from 0. k One possible value;

[0057] The first iteration module is used to perform an XOR operation on the modulo addition result of the intermediate variable m and the random number r with the concatenation result of the random number ρ and the random number r in each iteration to obtain the sixth XOR result, and store the k+1 bits of the sixth XOR result in a lookup table T with the value of the intermediate variable m as the address.

[0058] In one embodiment of the present invention, the iteration module is configured to include:

[0059] The selection module is used to randomly select an input number from a uniformly distributed nk-bit data set.

[0060] The third module is used to concatenate the random numbers r generated in each iteration to obtain a first concatenation result, and then modulo 2 the input number with the first concatenation result. nkThe modulo subtraction operation is performed to obtain the third modulo subtraction result. The third modulo subtraction result and the Boolean shared value R both include n data segments, each data segment is k bits, and n and k are both integers not less than 0, n = 0, 1, 2, ..., n-1;

[0061] The second traversal module is used to traverse all 2s of the k-bit temporary intermediate variable m, starting from 0. k One possible value;

[0062] The second iteration module is used, in each iteration, to perform a modulo operation on the segment data with the smallest segment count in the third modulo subtraction result and the segment data with the smallest segment count in the Boolean shared value R. (n-m)k The modulo addition operation is performed to obtain the third modulo addition result. The segment data with the smallest segment number in the third modulo subtraction result is used as the address input of the lookup table T to obtain the output result. The k-th bit output result is XORed with the segment data with the smallest segment number in the Boolean shared value R to obtain the seventh XOR result. The third modulo addition result is right-shifted by k bits to obtain the right-shifted result. The addition result is added to the right-shifted result to obtain the current iteration result of the third modulo addition result. The Boolean shared value R is right-shifted by k bits to obtain the current iteration result of the Boolean shared value R. The current iteration result of the third modulo addition result is used as the third modulo addition result for the next iteration. The current iteration result of the Boolean shared value R is used as the Boolean shared value R for the next iteration.

[0063] The XOR module is used to concatenate the seventh XOR result obtained from n iterations to obtain a second concatenation result, and then perform an XOR operation between the second concatenation result and the first concatenation result to obtain the arithmetic shared value in the arithmetic mask field.

[0064] In one embodiment of the present invention, the lookup table-based A2B mask conversion device is used to defend against side-channel attacks.

[0065] A third aspect of the present invention provides an electronic device, comprising: one or more processors; and a memory for storing one or more programs, wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the above-described lookup table-based A2B mask conversion method.

[0066] A fourth aspect of the present invention also provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the above-described lookup table-based A2B mask conversion method.

[0067] A fifth aspect of the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described lookup table-based A2B mask conversion method.

[0068] According to embodiments of the present invention, the A2B mask conversion method, apparatus, device, medium, and program product based on a lookup table provided by the present invention obtains the Boolean carry value in the Boolean mask field during the iteration process, converts the Boolean carry value in the Boolean mask field into the arithmetic carry value in the arithmetic mask field, adds the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result, and uses the addition result for the next iteration. This eliminates the need for a carry lookup table to protect the generated carry, thereby saving the entire carry lookup table and preventing the size of the carry lookup table from increasing with the increase of the converted data bit width, thus reducing memory overhead. Attached Figure Description

[0069] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0070] Figure 1 This is a flowchart illustrating an A2B mask conversion method based on a lookup table provided in an embodiment of the present invention.

[0071] Figure 2 This is a schematic diagram of the structure of an A2B mask conversion device based on a lookup table provided in an embodiment of the present invention;

[0072] Figure 3 A schematic diagram of the hardware structure of an electronic device is shown. Detailed Implementation

[0073] To make the objectives, features, and advantages of this invention more apparent and understandable, the technical solutions of the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0074] This invention provides an A2B mask conversion method based on a lookup table, comprising: obtaining the Boolean carry value in the Boolean mask field during the iteration process; converting the Boolean carry value in the Boolean mask field into the arithmetic carry value in the arithmetic mask field; adding the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the sum result; and using the sum result for the next iteration. This eliminates the need for a carry lookup table to protect the generated carry, thus saving the entire carry lookup table and preventing the size of the carry lookup table from increasing with the increase in the bit width of the converted data, thereby reducing memory overhead.

[0075] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Where there is no conflict between the embodiments, the following embodiments and features thereof can be combined with each other.

[0076] Please see Figure 1 , Figure 1 The following is a flowchart illustrating an A2B mask conversion method based on a lookup table according to an embodiment of the present invention. The method includes the following operations:

[0077] Operation S110: Obtain the Boolean carry value in the Boolean mask field during the iteration process.

[0078] Operation S120 converts the Boolean carry value in the Boolean mask field to the arithmetic carry value in the arithmetic mask field.

[0079] Operation S130 adds the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the sum.

[0080] Operation S140 uses the sum result for the next iteration to convert arithmetic operations into Boolean operations (A2B mask conversion).

[0081] In one embodiment of the present invention, operation S110, obtaining the Boolean carry value in the Boolean mask field during the iteration process includes: obtaining the Boolean shared value D and Boolean shared value R in the Boolean mask field during the iteration process.

[0082] In one embodiment of the present invention, operation S120, which converts the Boolean carry value in the Boolean mask field to the arithmetic carry value in the arithmetic mask field, includes operations S121 to S128. The following description uses n′=8, D=0xac, and R=0x25 as an example to illustrate this embodiment:

[0083] Operation S121 randomly selects a random number η from the n′ bits of uniformly distributed data. In this example, η = 0x30 is selected.

[0084] Operation S122 involves performing an XOR operation between the random number η and the Boolean shared value D to obtain the first XOR result. In this example,

[0085] Operation S123: Perform a modulo operation on the first XOR result and the random number η, with a modulo of 2. n′ The modulo subtraction operation yields the first modulo subtraction result. In this example, the first modulo subtraction result = 0x9c - 0x30mod2 8 =0x6c.

[0086] Operation S124 performs an XOR operation between the first modulo subtraction result and the Boolean shared value D to obtain the second XOR result. In this example,

[0087] Operation S125 performs an XOR operation between the random number η and the Boolean shared value R to obtain the third XOR result. In this example,

[0088] Operation S126 performs an XOR operation between the third XOR result and the Boolean shared value D to obtain the fourth XOR result. In this example,

[0089] Operation S127: Perform a modulo operation between the fourth XOR result and the third XOR result, with a modulus of 2. n′ The modulo subtraction operation yields the second modulo subtraction result. In this example, the second modulo subtraction result = 0xb9 - 0x15mod2 8 =0xa4.

[0090] Operation S128 performs an XOR operation between the second modulo subtraction result and the second XOR result to obtain the fifth XOR result. In this example,

[0091] The fifth XOR result is the arithmetic carry value Temp corresponding to the Boolean shared value D in the arithmetic mask field. In this example, 0x64 is used as the arithmetic carry value Temp corresponding to the Boolean shared value 0xac in the arithmetic mask field.

[0092] Understandably, in the embodiments of the present invention, n′, D, and R satisfy... Temp and R satisfy X = Temp + R mod 2 n′ .

[0093] In one embodiment of the present invention, operation S130 adds the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result, including operations S131 to S132. The following example, using pre-input data = 0xc3, n′ = 8, D = 0xac, R = 0x25, illustrates this embodiment:

[0094] Operation S131 modulo 2 is performed by combining the pre-input data with the Boolean shared value R. n The modulo addition operation yields the first modulo addition result. In this example, the first modulo addition result = 0xc3 + 0x25mod2 8 =0xe8.

[0095] Operation S132 performs a modulo operation on the first modulo addition result and the arithmetic carry value Temp, with a modulo of 2. n The modulo addition operation yields a second modulo addition result, which represents the sum of the two operations. In this example, the second modulo addition result = 0xc3 + 0x64mod2 8 =0x4c.

[0096] In one embodiment of the present invention, operation S130 is followed by operations S201 to S204. The following description uses k=4 as an example to illustrate this embodiment:

[0097] Operation S201 generates a k-bit random number r that follows a uniform distribution. In this example, the random number r can take the value 0xe, i.e., r = 0xe. Understandably, the random number r can also be equal to other values.

[0098] Operation S202 generates a 1-bit random number ρ that follows a uniform distribution. In this example, the random number ρ can be 0x1, that is, ρ = 0x1. Understandably, this random number ρ can also be equal to other values.

[0099] Operation S203 iterates through all 2s of the k-bit temporary intermediate variable m, starting from 0. k There are 2 possible values. In this example, 2 k =16, which means iterating through all 16 possible values ​​of the 8-bit temporary intermediate variable m, starting from 0.

[0100] Operation S204: In each iteration, the modulo addition result of the intermediate variable m and the random number r is XORed with the concatenation result of the random number ρ and the random number r to obtain the sixth XOR result. The k+1 bits of the sixth XOR result are stored in the lookup table T with the value of the intermediate variable m as the address. In this example, T[0] = 0x10, T[1] = 0x11, T[2] = 0xe, T[3] = 0xf, T[4] = 0xc, T[5] = 0xd, T[6] = 0xa, T[7] = 0xb, T[8] = 0x8, T[9] = 0x9, T

[10] = 0x6, T

[11] = 0x7, T

[12] = 0x4, T

[13] = 0x5, T

[14] = 0x2, T

[15] = 0x3.

[0101] In one embodiment of the present invention, operation S140 uses the addition result for the next iteration to achieve A2B mask conversion, including operations S141 to S145. The following description uses k=4, n=2, and r=0xe as an example to illustrate this embodiment:

[0102] Operation S141 randomly selects an input number from the uniformly distributed nk-bit data. In this example, nk = 8, meaning an input number is randomly selected from the uniformly distributed nk-bit data; let's assume this input number is 0xac.

[0103] Operation S142 concatenates the random numbers r generated in each iteration to obtain the first concatenation result, and modulo 2 is used to divide the input number and the first concatenation result. nk The modulo-subtraction operation yields a third modulo-subtraction result. Both this third modulo-subtraction result and the Boolean shared value R consist of n data segments, each segment being k bits, where n and k are integers not less than 0, and n = 0, 1, 2, ..., n-1. In this example, the third modulo-subtraction result = 0xac - (0xe||...||0xe) mod 2 8 =0xbe.

[0104] Operation S143 iterates through all 2s of the k-bit temporary intermediate variable m, starting from 0. k There are 2 possible values. In this example, 2 k =16, which means iterating through all 16 possible values ​​of the 4-bit temporary intermediate variable m, starting from 0.

[0105] Operation S144 involves, in each iteration, performing a modulo operation on the segment data with the smallest segment count in the third modulo subtraction result and the segment data with the smallest segment count in the Boolean shared value R. (n-m)k The modulo addition operation is performed to obtain the third modulo addition result. The segment with the smallest segment number in the third modulo addition result is used as the address input of the lookup table T to obtain the output result. The k-th bit output result is XORed with the segment with the smallest segment number in the Boolean shared value R to obtain the seventh XOR result. The third modulo addition result is shifted right by k bits to obtain the right shift result. The sum result is added to the right shift result to obtain the iteration result of the third modulo addition result. The Boolean shared value R is shifted right by k bits to obtain the iteration result of the Boolean shared value R. The iteration result of the third modulo addition result is used as the third modulo addition result for the next iteration. The iteration result of the Boolean shared value R is used as the Boolean shared value R for the next iteration.

[0106] Understandably, when n is 2, the iteration loop occurs twice, n = 0, 1. That is, the result of the third modulo subtraction and the Boolean shared value R are each divided into two segments: Ah||Al and Rh||Rl, respectively. Al and Rl have k bits each, and Ah and Rh have k+1 bits each. In this example, in the 0th iteration, m = 0, and the result of the third modulo addition = 0xbe + Rlmod2. 8 =0xc3, output result =0xf, seventh XOR result =0xa, right shift result =0xc, iteration result of the 0th iteration loop with respect to the third modulo sum result =0xd, iteration result of the 0th iteration loop with respect to the Boolean shared value R =0x2. In the 1st iteration loop, m = 1, third modulo sum result =0xbe + Rhmod2 4 =0xf, output result =0x3, seventh XOR result =0x1a, right shift result =0x0, first iteration loop result about the third modulo addition result =0x1, first iteration loop result about the Boolean shared value R =0x0.

[0107] Operation S145 involves sequentially concatenating the seventh XOR result obtained from n iterations to obtain a second concatenated result. This second concatenated result is then XORed with the first concatenated result to obtain the arithmetic shared value within the arithmetic mask field. Following the example above, the arithmetic shared value within the arithmetic mask field is 0xf4.

[0108] According to an embodiment of the present invention, the A2B mask conversion method based on a lookup table provided by the present invention requires only 2... k The (k+1)-bit conversion is smaller than all existing solutions and is independent of the number of segments n, therefore it does not increase with the conversion bit width, making it suitable for memory-constrained devices. Compared to existing low-memory-overhead conversion algorithms, when k=4, the memory overhead of this algorithm is reduced by 9.1%, 23.1%, 41.2%, and 60% for 8-bit, 16-bit, 32-bit, and 64-bit conversions, respectively.

[0109] In one embodiment of the present invention, the lookup table-based A2B masking method provided by the present invention can be used to defend against side-channel attacks. Furthermore, the lookup table-based A2B masking method provided by the present invention is applicable not only to traditional cryptographic algorithms but also to new post-quantum cryptographic algorithms.

[0110] Please see Figure 2 , Figure 2 This is a schematic diagram of an A2B mask conversion device based on a lookup table according to an embodiment of the present invention. The device includes:

[0111] The acquisition module 210 is used to acquire the Boolean carry value in the Boolean mask field during the iteration process.

[0112] The conversion module 220 is used to convert the Boolean carry value in the Boolean mask field into the arithmetic carry value in the arithmetic mask field.

[0113] The addition module 230 is used to add the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result.

[0114] The iteration module 240 is used to perform the next iteration using the summation result to achieve A2B mask conversion.

[0115] In one embodiment of the present invention, the acquisition module 210 is specifically used to acquire the Boolean shared value D and Boolean shared value R that are in the Boolean mask field during the iteration process.

[0116] In one embodiment of the present invention, the conversion module 220 includes:

[0117] The random selection module is used to randomly select a random number η from n′ bits of uniformly distributed data.

[0118] The first XOR module is used to perform an XOR operation between the random number η and the Boolean shared value D to obtain the first XOR result.

[0119] The first modulo-subtraction module is used to perform a modulo-2 operation between the first XOR result and the random number η. n′ The modulo-subtraction operation is performed to obtain the first modulo-subtraction result;

[0120] The second XOR module is used to perform an XOR operation between the first modulo subtraction result and the Boolean shared value D to obtain the second XOR result.

[0121] The third XOR module is used to perform an XOR operation between the random number η and the Boolean shared value R to obtain the third XOR result.

[0122] The fourth XOR module is used to perform an XOR operation between the third XOR result and the Boolean shared value D to obtain the fourth XOR result;

[0123] The second modulo-subtraction module is used to perform a modulo-2 operation between the fourth XOR result and the third XOR result. n′ The modulo-subtraction operation is performed to obtain the second modulo-subtraction result;

[0124] The fifth XOR module is used to perform an XOR operation between the second modulo subtraction result and the second XOR result to obtain the fifth XOR result, which represents the arithmetic carry value Temp corresponding to the Boolean shared value D in the arithmetic mask field.

[0125] In one embodiment of the present invention, the addition module 230 includes:

[0126] The first module is used to perform a modulo-2 operation between the pre-input data and the Boolean shared value R. n The modulo operation is performed to obtain the first modulo result;

[0127] The second modulo addition module is used to perform a modulo-2 operation on the result of the first modulo addition and the arithmetic carry value Temp. n The modulo addition operation yields a second modulo addition result, which represents the addition result.

[0128] In one embodiment of the present invention, the device further includes:

[0129] The first generation module is used to generate a k-bit random number r that follows a uniform distribution;

[0130] The second generation module is used to generate a 1-bit random number ρ that follows a uniform distribution;

[0131] The first traversal module is used to iterate through all 2s of the k-bit temporary intermediate variable m, starting from 0. k One possible value;

[0132] The first iteration module is used to perform an XOR operation on the modulo addition result of the intermediate variable m and the random number r with the concatenation result of the random number ρ and the random number r in each iteration to obtain the sixth XOR result, and store the k+1 bits of the sixth XOR result in a lookup table T with the value of the intermediate variable m as the address.

[0133] In one embodiment of the present invention, the iteration module 240 includes:

[0134] The selection module is used to randomly select an input number from a uniformly distributed nk-bit data set.

[0135] The third module, which performs a modulo-2 subtraction, concatenates the random numbers r generated in each iteration to obtain a first concatenation result, and then modulo 2 the input number and the first concatenation result. nk The modulo subtraction operation yields a third modulo subtraction result. Both the third modulo subtraction result and the Boolean shared value R consist of n data segments, each segment being k bits. Both n and k are integers not less than 0, where n = 0, 1, 2, ..., n-1.

[0136] The second traversal module is used to traverse all 2s of the k-bit temporary intermediate variable m, starting from 0. k One possible value;

[0137] The second iteration module is used, in each iteration, to modulo 2 the segment data with the smallest segment count in the third modulo subtraction result and the segment data with the smallest segment count in the Boolean shared value R. (n-m)kThe modulo addition operation is performed to obtain the third modulo addition result. The segment with the smallest segment number in the third modulo addition result is used as the address input of the lookup table T to obtain the output result. The k-th bit output result is XORed with the segment with the smallest segment number in the Boolean shared value R to obtain the seventh XOR result. The third modulo addition result is shifted right by k bits to obtain the right shift result. The sum result is added to the right shift result to obtain the iteration result of the third modulo addition result. The Boolean shared value R is shifted right by k bits to obtain the iteration result of the Boolean shared value R. The iteration result of the third modulo addition result is used as the third modulo addition result for the next iteration. The iteration result of the Boolean shared value R is used as the Boolean shared value R for the next iteration.

[0138] The XOR module is used to concatenate the seventh XOR result obtained from n iterations to obtain a second concatenation result, and then perform an XOR operation between the second concatenation result and the first concatenation result to obtain the arithmetic shared value in the arithmetic mask field.

[0139] In one embodiment of the present invention, the lookup table-based A2B mask conversion device is used to defend against side-channel attacks.

[0140] According to embodiments of the present invention, any plurality of modules among the acquisition module 210, conversion module 220, addition module 230, and iteration module 240 can be combined into one module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of the present invention, at least one of the acquisition module 210, conversion module 220, addition module 230, and iteration module 240 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in software, hardware, or firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the acquisition module 210, conversion module 220, addition module 230, and iteration module 240 can be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0141] Figure 3 A block diagram schematically illustrates an electronic device suitable for implementing a lookup table-based A2B mask conversion method according to an embodiment of the present invention.

[0142] like Figure 3As shown, an electronic device 300 according to an embodiment of the present invention includes a processor 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage portion 308 into a random access memory (RAM) 303. The processor 301 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 301 may also include onboard memory for caching purposes. The processor 301 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.

[0143] RAM 303 stores various programs and data required for the operation of electronic device 300. Processor 301, ROM 302, and RAM 303 are interconnected via bus 304. Processor 301 executes various operations of the method flow according to embodiments of the present invention by executing programs in ROM 302 and / or RAM 303. It should be noted that the program may also be stored in one or more memories other than ROM 302 and RAM 303. Processor 301 may also execute various operations of the method flow according to embodiments of the present invention by executing programs stored in said one or more memories.

[0144] According to an embodiment of the present invention, the electronic device 300 may further include an input / output (I / O) interface 305, which is also connected to a bus 304. The electronic device 300 may also include one or more of the following components connected to the I / O interface 305: an input section 306 including a keyboard, mouse, etc.; an output section 307 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN card, modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 310 as needed so that computer programs read from it can be installed into the storage section 308 as needed.

[0145] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present invention.

[0146] According to embodiments of the present invention, a computer-readable storage medium may be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of the present invention, a computer-readable storage medium may include ROM 302 and / or RAM 303 and / or one or more memories other than ROM 302 and RAM 303 described above.

[0147] Embodiments of the present invention also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code is used to cause the computer system to implement the item recommendation method provided in the embodiments of the present invention.

[0148] When the computer program is executed by the processor 301, it performs the functions defined in the system / apparatus of this invention. According to embodiments of the invention, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0149] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via communication section 309, and / or installed from removable medium 311. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0150] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 309, and / or installed from the removable medium 311. When the computer program is executed by the processor 301, it performs the functions defined in the system of this embodiment of the invention. According to embodiments of the invention, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0151] According to embodiments of the present invention, program code for executing the computer programs provided in the embodiments of the present invention can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0152] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0153] Those skilled in the art will understand that the features described in the various embodiments and / or claims of the present invention can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in the present invention. In particular, the features described in the various embodiments and / or claims of the present invention can be combined or combined in various ways without departing from the spirit and teachings of the present invention. All such combinations and / or combinations fall within the scope of the present invention.

[0154] The embodiments of the present invention have been described above. However, these embodiments are merely illustrative and not intended to limit the scope of the invention. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of the invention is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of the invention, and all such substitutions and modifications should fall within the scope of the invention.

Claims

1. An A2B mask conversion method based on a lookup table, characterized in that, include: Obtain the Boolean carry value in the Boolean mask field during the iteration process, wherein the Boolean carry value includes the Boolean shared value D and the Boolean shared value R; Convert the Boolean carry value in the Boolean mask field to the arithmetic carry value in the arithmetic mask field; The arithmetic carry value in the arithmetic mask field is added to other intermediate variables in the arithmetic mask field to obtain the sum; The summation result is used for the next iteration to convert arithmetic operations into Boolean operations (A2B mask conversion). The memory overhead of the conversion process is independent of the number of segments n of the converted data and does not increase with the increase of the bit width of the converted data; The step of converting the Boolean carry value in the Boolean mask field to the arithmetic carry value in the arithmetic mask field includes: from Randomly select a random number from a uniformly distributed data set. ; Perform an XOR operation between the random number η and the Boolean shared value D to obtain the first XOR result; The first XOR result is combined with the random number. Modulus is The modulo-subtraction operation is performed to obtain the first modulo-subtraction result; Perform an XOR operation between the first modulo subtraction result and the Boolean shared value D to obtain the second XOR result; Perform an XOR operation between the random number η and the Boolean shared value R to obtain a third XOR result; Perform an XOR operation between the third XOR result and the Boolean shared value D to obtain the fourth XOR result; The modulus of the fourth XOR result and the third XOR result is... The modulo-subtraction operation is performed to obtain the second modulo-subtraction result; Perform an XOR operation between the second modulo subtraction result and the second XOR result to obtain a fifth XOR result, which represents the arithmetic carry value Temp corresponding to the Boolean shared value D in the arithmetic mask field.

2. The A2B mask conversion method based on a lookup table according to claim 1, characterized in that, After adding the value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the sum, the method further includes: Generate a k-bit random number r that follows a uniform distribution; Generate a 1-bit random number that follows a uniform distribution. ; Iterate through all the k temporary intermediate variables m starting from 0. One possible value; In each iteration, the modulo sum of the intermediate variable m and the random number r is multiplied by the random number r. Perform an XOR operation on the concatenation result of the random number r to obtain the sixth XOR result, and store the k+1 bits of the sixth XOR result in a lookup table T with the value of the intermediate variable m as the address.

3. The A2B mask conversion method based on a lookup table according to claim 1, characterized in that, The step of adding the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result includes: The pre-input data is modulo 2 with the Boolean shared value R. n The modulo operation is performed to obtain the first modulo result; The first modulo addition result is modulo 2 with the arithmetic carry value Temp. n The modulo addition operation is performed to obtain a second modulo addition result, which represents the addition result.

4. The A2B mask conversion method based on a lookup table according to claim 3, characterized in that, The step of using the summation result for the next iteration to achieve A2B mask conversion includes: Randomly select an input number from the nk-bit uniformly distributed data; The random numbers r generated in each iteration are concatenated to obtain the first concatenation result. The input number is then modulo 2 with the first concatenation result. nk The modulo subtraction operation is performed to obtain the third modulo subtraction result. The third modulo subtraction result and the Boolean shared value R both include n data segments, each data segment is k bits, and n and k are integers not less than 0, n=0, 1, 2, ..., n-1; Iterate through all the k temporary intermediate variables m starting from 0. One possible value; In each iteration, the segment data with the smallest segment count in the third modulo subtraction result and the segment data with the smallest segment count in the Boolean shared value R are modulo 2. (n-m)k The modulo addition operation is performed to obtain the third modulo addition result. The segment data with the smallest segment number in the third modulo addition result is used as the address input of the lookup table T to obtain the output result. The output result of the k-th bit is XORed with the segment data with the smallest segment number in the Boolean shared value R to obtain the seventh XOR result. The third modulo addition result is right-shifted by k bits to obtain the right-shifted result. The addition result is added to the right-shifted result to obtain the iteration result of the third modulo addition result. The Boolean shared value R is right-shifted by k bits to obtain the iteration result of the Boolean shared value R. The iteration result of the third modulo addition result is used as the third modulo addition result for the next iteration. The iteration result of the Boolean shared value R is used as the Boolean shared value R for the next iteration. The seventh XOR result obtained from n iterations is concatenated sequentially to obtain a second concatenation result. The second concatenation result is then XORed with the first concatenation result to obtain the arithmetic shared value in the arithmetic mask field.

5. An A2B mask conversion device based on a lookup table, characterized in that, include: The acquisition module is used to acquire the Boolean carry value in the Boolean mask field during the iteration process, wherein the Boolean carry value includes the Boolean shared value D and the Boolean shared value R; A conversion module is used to convert the Boolean carry value in the Boolean mask field into the arithmetic carry value in the arithmetic mask field; The addition module is used to add the arithmetic carry value in the arithmetic mask field to other intermediate variables in the arithmetic mask field to obtain the addition result; An iterative module is used to perform the next iteration using the summation result to achieve A2B mask conversion; The memory overhead of the conversion process is independent of the number of segments n of the converted data and does not increase with the increase of the bit width of the converted data; The step of converting the Boolean carry value in the Boolean mask field to the arithmetic carry value in the arithmetic mask field includes: from Randomly select a random number from a uniformly distributed data set. ; Perform an XOR operation between the random number η and the Boolean shared value D to obtain the first XOR result; The first XOR result is combined with the random number. Modulus is The modulo-subtraction operation is performed to obtain the first modulo-subtraction result; Perform an XOR operation between the first modulo subtraction result and the Boolean shared value D to obtain the second XOR result; Perform an XOR operation between the random number η and the Boolean shared value R to obtain a third XOR result; Perform an XOR operation between the third XOR result and the Boolean shared value D to obtain the fourth XOR result; The modulus of the fourth XOR result and the third XOR result is... The modulo-subtraction operation is performed to obtain the second modulo-subtraction result; Perform an XOR operation between the second modulo subtraction result and the second XOR result to obtain a fifth XOR result, which represents the arithmetic carry value Temp corresponding to the Boolean shared value D in the arithmetic mask field.

6. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 4.

7. A computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 4.

8. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 4.