Fault Injection Detection Circuit and Operation Method Applied to Post-Quantum Cryptographic Algorithms

By introducing a fault injection detection circuit in the hardware implementation of the post-quantum cryptography algorithm, using the XOR calculation and fault injection in the logic and operation detection state matrix, the side channel security problem in hardware deployment is solved, and the security protection of the post-quantum cryptography chip is achieved.

CN119276623BActive Publication Date: 2025-06-24HUAZHONG UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411671681.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-21
Publication Date
2025-06-24
Estimated Expiration
2044-11-21

AI Technical Summary

Technical Problem

Post-quantum cryptography algorithms face potential side channel security problems in hardware deployment. Attackers can bypass the underlying mathematical problems of the algorithm by analyzing the information leaked by the device during operation, thereby stealing private information, resulting in a significant reduction in security.

Method used

A fault injection detection circuit applied to a post-quantum cryptographic algorithm is provided, including an input unit, a plurality of operation units and an output unit. Through XOR calculation, logic and calculation and wheel constant operations, the calculation unit detects whether there is any fault injection of preset bit data in the state matrix, and compares the calculation results with the precalculated value.

Benefits of technology

By extending the critical path, clock injection can be detected before critical information is leaked, solving the potential side channel leakage problem in algorithm hardware implementation and achieving security protection for post-quantum cryptographic chips.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276623B_ABST
    Figure CN119276623B_ABST
Patent Text Reader

Abstract

The present application provides a fault injection detection circuit and an operation method applied to a post-quantum cryptographic algorithm. The fault injection detection circuit applied to the post-quantum cryptographic algorithm includes: an input unit for inputting a state matrix; a plurality of operation units respectively connected to the input unit, each operation unit being used for calculating preset bit data in the state matrix to obtain a calculation result; an output unit connected to the plurality of operation units for comparing the calculation result with a pre-calculated value to determine whether there is a fault injection; wherein, the state matrix and the pre-calculated value conform to a preset relationship. The fault injection detection circuit applied to the post-quantum cryptographic algorithm provided by the present application has a longer critical path, can detect clock injection before critical information is leaked, solves the potential side-channel leakage problem in the hardware implementation of the algorithm, and realizes the security protection of the post-quantum cryptographic chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of security algorithms, and particularly to a fault injection detection circuit and operation method applied to post-quantum cryptographic algorithms. Background Art

[0002] In today's increasingly digital and interconnected world, digital signatures play an indispensable role. They not only protect sensitive financial transactions and legal contracts, but also maintain the integrity of healthcare and government important documents, becoming the cornerstone of trust and security in various online activities. Digital signatures ensure that only authorized users can access and modify important data by verifying the source and integrity of information, thus effectively preventing forgery and tampering.

[0003] However, with the rapid development of quantum computers, traditional public-key encryption algorithms such as Elliptic Curve Diffie-Hellman (ECDH) and RSA will face major security challenges. Quantum computers have powerful parallel processing capabilities and can break these traditional cryptographic systems in a short time through quantum algorithms (such as Shor's algorithm), making the digital signature mechanisms relying on these algorithms vulnerable. Therefore, there is an urgent need to develop a new generation of cryptographic algorithms that can resist quantum attacks, which is the research background of post-quantum cryptographic algorithms.

[0004] Currently, four algorithms (Kyber, Dilithium, Falcon, and SPHINCS+) have successfully been selected and entered the standardization process. These algorithms have their own characteristics and are suitable for different application scenarios. Among these four algorithms, SPHINCS+ is a hash-based algorithm due to its complete security proof and relatively simple computational operations.

[0005] However, although post-quantum cryptographic algorithms demonstrate strong security, their hardware deployment in practical applications still faces many potential side-channel security issues. Side-channel attacks utilize the information leaked during the operation of encryption devices, such as power consumption, execution time, and electromagnetic waves. Attackers can analyze this information to bypass the underlying mathematical problems of the algorithm and thus steal private information, resulting in a significant reduction in security. Therefore, in order to achieve the wide application of post-quantum cryptographic algorithms and enhance their security in hardware implementation, it has become an urgent challenge to be solved. Summary of the Invention

[0006] In view of the above problems, this application provides a fault injection detection circuit and operation method applied to post-quantum cryptographic algorithms.

[0007] In a first aspect, there is provided a fault injection detection circuit applied to post-quantum cryptographic algorithms, including:

[0008] An input unit for inputting a state matrix;

[0009] A plurality of arithmetic units, each connected to the input unit, and each arithmetic unit is configured to calculate preset bit data in the state matrix to obtain a calculation result;

[0010] An output unit, connected to the plurality of arithmetic units, is configured to compare the calculation result with a pre-calculated value to determine whether there is a fault injection; wherein, the state matrix and the pre-calculated value conform to a preset relationship.

[0011] Wherein, if the calculation result is different from the pre-calculated value, it is determined that there is a fault injection.

[0012] Wherein, the arithmetic unit includes:

[0013] A first calculation module, the first calculation module is configured to perform an exclusive OR calculation on the preset bit data to obtain a first calculation result, denoted as Sum j , j ∈ [0, n], n is the number of columns of the state matrix minus 1;

[0014] A second calculation module, the second calculation module is configured to perform an exclusive OR calculation on each data in the preset bit data and the first calculation result, and re-arrange them to obtain a second calculation result, denoted as E i,j ; wherein, i ∈ [0, m], m is the number of rows of the state matrix minus 1; each data in the preset bit data is denoted as S i,j ;

[0015] A third calculation module, configured to perform a logical AND calculation on the inverted E i,j and E i,j+1 , then perform an exclusive OR calculation with E i,j , and finally perform an exclusive OR calculation with the round constant c to obtain a third calculation result, denoted as P i,j ;

[0016] An expansion path, configured to perform an exclusive OR calculation on the inverted exclusive OR of P i,j and P i,j-1 and S i,j to obtain the calculation result, denoted as P' i,j .

[0017] Wherein, the output unit includes:

[0018] A comparison unit, configured to compare P' i,j with each data in the preset bit data, denoted as S i,j one by one, and if the comparison results are different, it is determined that there is a fault injection.

[0019] Wherein, the first calculation module includes:

[0020] The first exclusive - OR calculation module receives the data S in the preset number of bits i,j , and performs an exclusive - OR calculation to obtain Sum j .

[0021] The second calculation module includes:

[0022] The second exclusive - OR calculation module receives Sum j+1 and Sum j-1 , and performs an exclusive - OR calculation;

[0023] The third exclusive - OR calculation module receives the exclusive - OR calculation result of Sum j+1 and Sum j-1 and S i,j , and performs an exclusive - OR calculation and rearrangement to obtain E i,j .

[0024] Among them, the third calculation module includes:

[0025] The first inverter is used to invert E i,j ;

[0026] The AND gate is used to perform a logical AND calculation on the inverted E i,j and E i,j+1 ;

[0027] The fourth exclusive - OR calculation module is used to perform an exclusive - OR calculation on the output result of the AND gate and E i,j ;

[0028] The fifth exclusive - OR calculation module is used to perform an exclusive - OR calculation on the output result of the fourth exclusive - OR calculation module and the round constant c to obtain P i,j .

[0029] Among them, the extended path includes:

[0030] The sixth exclusive - OR calculation module receives P i,j and P i,j-1 , and performs an exclusive - OR calculation;

[0031] The second inverter inverts the output of the sixth exclusive - OR calculation module;

[0032] The seventh exclusive - OR calculation module performs an exclusive - OR calculation on the output of the second inverter and S i,j to obtain P' i,j .

[0033] In a second aspect, the present application provides an operation method. The operation method is based on the fault injection detection circuit applied to the post - quantum cryptography algorithm described in any one of the above, and the operation method includes:

[0034] The received status matrix and the pre-computed value corresponding to the status matrix; wherein, the status matrix and the pre-computed value conform to a preset relationship;

[0035] Calculate the preset bit data in the status matrix to obtain a calculation result;

[0036] Compare the calculation result with the pre-computed value to determine whether there is a fault injection.

[0037] Wherein, the calculating the preset bit data in the status matrix to obtain a calculation result includes:

[0038] Receive the data S in the preset number of bits i,j , and perform an exclusive OR calculation to obtain Sum j ;

[0039] Receive Sum j+1 and Sum j-1 , and perform an exclusive OR calculation, and receive the exclusive OR calculation result of Sum j+1 and Sum j-1 and S i,j , and perform an exclusive OR calculation, and re-arrange to obtain E i,j ;

[0040] Take the inverse of E i,j and perform a logical AND calculation with E i,j+1 , and perform an exclusive OR calculation on the logical AND calculation result and E i,j , and then perform an exclusive OR calculation with the round constant c to obtain P i,j ;

[0041] Receive P i,j and P i,j-1 , and perform an exclusive OR calculation and then take the inverse, and then perform an exclusive OR calculation with S i,j to obtain the calculation result P' i,j .

[0042] Wherein, comparing the calculation result with the pre-computed value to determine whether there is a fault injection includes:

[0043] Compare P' i,j with each data in the preset bit data denoted as S i,j one by one. If the comparison results are different, it is determined that there is a fault injection.

[0044] The fault injection detection circuit applied to the post-quantum cryptographic algorithm provided by this application has a longer critical path, can detect clock injection before the critical information is leaked, solves the potential side-channel leakage problem in the hardware implementation of the algorithm, and realizes the security protection of the post-quantum cryptographic chip.

[0045] The above description is only an overview of the technical solution of this application. In order to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this application more obvious and understandable, the following specific embodiments of this application are specifically given. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of this application. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0047] Figure 1 is a schematic structural diagram of an embodiment of a fault injection detection circuit applied to a post-quantum cryptographic algorithm provided by this application;

[0048] Figure 2 is a schematic structural diagram of another embodiment of a fault injection detection circuit applied to a post-quantum cryptographic algorithm provided by this application;

[0049] Figure 3 is a schematic flowchart of an embodiment of an operation method provided by this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] Hereinafter, the exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be completely conveyed to those skilled in the art. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.

[0051] Schematic structural diagrams according to embodiments of the present disclosure are shown in the drawings. These figures are not drawn to scale, where for the purpose of clear expression, some details are enlarged and some details may be omitted. The shapes of various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations. And those skilled in the art can design regions / layers with different shapes, sizes and relative positions according to actual needs.

[0052] KECCAK is a cryptographic hash algorithm designed and proposed by a research team in Belgium. It was ultimately selected by NIST as the SHA-3 standard algorithm. KECCAK is based on a design called the "Sponge Construction". This structure gives KECCAK greater flexibility and resistance to attacks, especially in defending against attacks related to quantum computing. In the KECCAK algorithm, the data involved in the calculation is stored in a 1600-bit three-dimensional state matrix, which can be sorted as S x,y,z , where x, y ∈ [0, 4] and z ∈ [0, 63]. Each set of 64 bits with constant {x, y} coordinates is called a "lane". Since the bits in the same "lane" in the KECCAK algorithm do not operate on each other, the iteration can be regarded as 64 sets of parallel operations. It is because of this nature of parallel operations that we first invented a new algorithm that compresses the original 1600-bit three-dimensional state matrix of the KECCAK algorithm into a 25-bit two-dimensional state matrix. Therefore, the amount of computation is 1 / 64 of the KECCAK algorithm, and theoretically, it shares the same critical path as the KECCAK algorithm.

[0053] The following will describe the fault injection detection circuit and operation method applied to the post-quantum cryptographic algorithm of the present application with reference to the accompanying drawings.

[0054] Please refer to Figure 1 , Figure 1 which is a schematic structural diagram of an embodiment of a fault injection detection circuit applied to the post-quantum cryptographic algorithm provided by the present application, specifically including: an input unit 11, a plurality of operation units 12, and an output unit 13. Among them, the input unit 11 is used to input the state matrix; the plurality of operation units 12 are respectively connected to the input unit 11, and each operation unit 12 is used to calculate the preset bit data in the state matrix to obtain a calculation result; the output unit 13 is connected to the plurality of operation units 12 and is used to compare the calculation result with a pre-calculated value to determine whether there is a fault injection; among them, the state matrix and the pre-calculated value conform to a preset relationship.

[0055] Specifically, the above-mentioned state matrix is the 25-bit two-dimensional state matrix of the present application, which is used as the input of the anti-clock injection detection circuit. The 25-bit two-dimensional state matrix is, for example, Figure 2 shown by the 5×5 matrix represented by r in

[0056] In the fault injection detection circuit applied to the post-quantum cryptographic algorithm, the operation process of each operation unit among the plurality of operation units is the same. In the present application, an operation unit is used to calculate S in the 25-bit two-dimensional state matrix 0,0 , S 0,1 , S 0,2 , S 0,3, S 0,4 This will be introduced by taking the calculation of these 5-bit data as an example.

[0057] Please combine with Figure 2 , the arithmetic unit 12 includes: a first calculation module 121, a second calculation module 122, a third calculation module 123, and an extended path 124.

[0058] Among them, the first calculation module 121 is used to perform an exclusive OR calculation on the preset bit data to obtain a first calculation result, denoted as Sum j , j ∈ [0, n], n is the number of columns of the state matrix minus 1. In one embodiment, the state matrix is a 5×5 matrix, then n is 4. In a specific embodiment, the first calculation module includes a first exclusive OR calculation module, and the first exclusive OR calculation module receives the data in the preset bit number path S i ,j , and performs an exclusive OR calculation to obtain Sum j . For example, the first exclusive OR calculation module performs an exclusive OR calculation on S 0,0 , S 0,1 , S 0,2 , S 0,3 , S 0,4 these 5-bit data (i.e., the preset bit data) to obtain Sum0. Similarly, in the first exclusive OR calculation module of other arithmetic units, the first exclusive OR calculation module performs an exclusive OR calculation on S 1,0 , S 1,1 , S 1,2 , S 1,3 , S 1,4 to obtain the result Sum1 of the exclusive OR calculation of these 5-bit data. The same applies to Sum2, Sum3, and Sum4.

[0059] The second calculation module 122 is used to perform an exclusive OR calculation on each data in the preset bit data and the first calculation result, and rearrange them to obtain a second calculation result, denoted as E i,j ; where, i ∈ [0, m], m is the number of rows of the state matrix minus 1, that is, m = 4; each data in the preset bit data is denoted as S i,j .

[0060] In a specific embodiment, the second calculation module 122 includes: a second exclusive OR calculation module and a third exclusive OR calculation module. The second exclusive OR calculation module receives Sum j+1 and Sum j-1 , and performs an exclusive OR calculation; the third exclusive OR calculation module receives the exclusive OR calculation result of Sum j+1 and Sum j-1 and S i,j , and performs an exclusive OR calculation and rearranges them to obtain E i,j .

[0061] Specifically, E i,j is the result of re - arranging the XOR of S i,j with Sum (j-1) and Sum (j+1) . Denote:

[0062] D i,j = S i,j ^ Sum (j-1) ^ Sum (j+1) ; i, j ∈ [0, 4], ^ represents XOR calculation;

[0063] Then the re - arranging method is

[0064] E i,j = D j,(3i+j)

[0065] For example:

[0066] E 00 = D 00 = S 00 ^ Sum1 ^ Sum4;

[0067] E 01 = D 11 = S 11 ^ Sum0 ^ Sum2;

[0068] E 10 = D 03 = S 03 ^ Sum2 ^ Sum4;

[0069] And so on.

[0070] The third calculation module 123 is used to perform a logical AND calculation on the inverted E i,j and E i,j+1 , then perform an XOR calculation with E i,j , and finally perform an XOR calculation with the round constant c to obtain the third calculation result, denoted as P i,j .

[0071] In an embodiment, the third calculation module 123 includes: a first inverter, an AND gate, a fourth XOR calculation module, and a fifth XOR calculation module. Among them, the first inverter is used to invert E i,j ; the AND gate is used to perform a logical AND calculation on the inverted E i,j and E i,j+1 ; the fourth XOR calculation module is used to perform an XOR calculation on the output result of the AND gate and E i,j ; the fifth XOR calculation module is used to perform an XOR calculation on the output result of the fourth XOR calculation module and the round constant c to obtain P i,j . The round constant c is pre - stored data

[0072] Specifically, denote:

[0073] F i,j = E i,j ^(~E i,j+1 ) & E i,j+2) ), i, j ∈ [0, 4], ~ represents taking the inverse, & represents logical AND calculation.

[0074] For the inverse operation and exclusive OR operation performed on E, the rearrangement method is as follows:

[0075] P[5×i + j] = F i,j , i, j ∈ [0, 4]

[0076] For example:

[0077] P 01 = F 0,1 = E 0,1 ^(~E 0,2 & E 0,3 )

[0078] P 02 = F 0,2 = E 0,2 ^(~E 0,3 & E 0,4 )

[0079] And so on.

[0080] Among them, the calculation process of P 00 has particularity. During the calculation process of P 00 , it is necessary to introduce the round constant c for exclusive OR calculation, which can be expressed by the formula as follows

[0081] P 00 = c ^ F 0,0 = c ^ E 0,0 ^(~E 0,1 & E 0,2 )

[0082] The expansion path 124 is used to perform exclusive OR calculation on the result of taking the exclusive OR inverse of P i,j and P i,j-1 and S i,j to obtain the calculation result, denoted as Pu i,j . Specifically, the expansion path 124 includes: the sixth exclusive OR calculation module, the second inverter, and the seventh exclusive OR calculation module. Among them, the sixth exclusive OR calculation module receives P i,j and P i,j-1 and performs exclusive OR calculation; the second inverter takes the inverse of the output of the sixth exclusive OR calculation module; the seventh exclusive OR calculation module performs exclusive OR calculation on the output of the second inverter and S i,j to obtain P′ i,j .

[0083] The extended path is used to extend the combinational logic delay of the critical path by adding two sets of exclusive - OR gates and one set of inverters. Denote the input of the extended path as P i,j , and denote the output of the extended path as P' i,j , then the relationship between the input and output of the extended path can be expressed by the formula:

[0084] P' i,j = ~(P i,j ^ P i,(j-1) ) ^ S i,j , i, j ∈ [0, 4];

[0085] For example,

[0086] P' 0,0 = ~(P 0,0 ^ P 0,4 ) ^ S 0,0 , i, j ∈ [0, 4];

[0087] P' 0,1 = ~(P 0,1 ^ P 0,0 ) ^ S 0,1 , i, j ∈ [0, 4];

[0088] P' 0,2 = ~(P 0,2 ^ P 0,1 ) ^ S 0,2 , i, j ∈ [0, 4];

[0089] And so on.

[0090] The output unit 13 includes: a comparison unit 131, which is used to compare P' i,j with each data in the preset bit data, denoted as S i,j one by one. If the comparison results are different, it is determined that there is a fault injection. Specifically, the comparison unit 131 can be a comparator. The comparator is used to compare the result P' i,j calculated by the extended path with the element S' i,j in the pre - calculated value r' of the input two - dimensional random number matrix r one by one. If there are differences, a warning is issued and the warning signal is pulled high; otherwise, no warning is issued and the warning signal remains low.

[0091] We have implemented the SPHINCS+ algorithm in the Artix-7 FPGA. Without adding the KECCAK-C module to detect clock injection attacks, the maximum operating frequency is about 268 MHz; after adding the protection circuit, the protected overall circuit can work properly only below 254 MHz. As the frequency increases, the circuit occasionally gives warnings of calculation errors, and until 260 MHz, the protection circuit will stably detect clock injection attacks.

[0092] Through experiments, we have obtained the comparison results between the design with an internal clock protection circuit and the design without an internal clock protection circuit. The detection unit consumes 106 / 91 LUT / FF, accounting for 1.9% / 1.7%. Due to the extended path, the maximum operating frequency of the overall circuit drops from 268 MHz to 254 MHz. Therefore, the operation time of Keygen / Sign / Verify increases by 5.5%. Compared with conventional schemes such as instantiated redundancy to resist fault injection, our anti-clock injection protection circuit based on the KECCAK-C algorithm only consumes 5.5% of the additional time, and the resource overhead is almost negligible, having great advantages and application prospects.

[0093] The fault injection detection circuit applied to the post-quantum cryptographic algorithm provided in this application has a longer critical path, can detect clock injection before the leakage of critical information, solves the potential side-channel leakage problem in the hardware implementation of the algorithm, and realizes the security protection of the post-quantum cryptographic chip.

[0094] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of an embodiment of an operation method provided in this application, specifically including:

[0095] Step S31: Receive the state matrix and the pre-computed value corresponding to the state matrix; wherein, the state matrix and the pre-computed value conform to a preset relationship.

[0096] The state matrix is a 5×5 matrix.

[0097] Step S32: Calculate the preset bit data in the state matrix to obtain a calculation result.

[0098] Specifically, receive the data S i,j in the preset number of bits path, and perform an exclusive OR calculation to obtain Sum j .

[0099] Receive Sum j+1 and Sum j-1 , and perform an exclusive OR calculation, and receive the exclusive OR calculation result of Sum j+1 and Sum j-1 and S i,j, perform XOR calculation, and re-arrange to obtain E i,j .

[0100] For E i,j After taking the inverse and E i,j+1 Perform logical AND calculation, and XOR the result of the logical AND calculation with E i,j Perform XOR calculation, and then XOR with the round constant c to obtain P i,j .

[0101] Receive P i,j and P i,j-1 , perform XOR calculation and then take the inverse, and then XOR with S i,j Perform XOR calculation to obtain the calculation result P' i,j .

[0102] The calculation steps and processes here are the same as those in the fault injection detection circuit for post-quantum cryptographic algorithms described above. For details, please refer to [reference], which will not be elaborated here

[0103] Step S33: Compare the calculation result with the pre-calculated value to determine whether there is fault injection

[0104] Compare P' i,j with each data in the preset bit data, denoted as S i,j one by one. If the comparison results are different, it is determined that there is fault injection

[0105] The operation method provided by this application has a longer critical path, can detect clock injection before key information is leaked, solves the potential side-channel leakage problem in the hardware implementation of the algorithm, and realizes the security protection of post-quantum cryptographic chips

[0106] The algorithms and displays provided here are not inherently related to any specific computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings based here. Based on the above description, the structures required to construct such systems are obvious. In addition, this application is not directed to any specific programming language. It should be understood that the content of this application described here can be implemented using various programming languages, and the descriptions of specific languages above are for disclosing the best implementation manners of this application

[0107] In the specification provided here, a large number of specific details are described. However, it can be understood that the embodiments of this application can be practiced without these specific details. In some instances, well-known methods, structures, and technologies are not shown in detail so as not to obscure the understanding of this specification

[0108] Similarly, it should be understood that, for the purpose of streamlining the present disclosure and facilitating the understanding of one or more aspects of each application, in the above description of the exemplary embodiments of the present application, various features of the present application are sometimes grouped together into a single embodiment, figure, or description thereof.

[0109] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all the features disclosed in this specification (including the abstract and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise explicitly stated, each feature disclosed in this specification (including the accompanying abstract and drawings) can be replaced by an alternative feature that provides the same, equivalent, or similar purpose.

[0110] In addition, those skilled in the art can understand that although some of the embodiments herein include certain features included in other embodiments rather than other features, the combination of the features of different embodiments means that it is within the scope of the present application and forms different embodiments.

[0111] It should be noted that the above embodiments illustrate the present application rather than limit the present application. Any reference signs between parentheses should not be construed as limiting the present application. The word "comprising" does not exclude the presence of components or steps not listed in the present application. The word "a" or "an" before a component does not exclude the presence of a plurality of such components. The present application can be implemented by means of hardware including several different components and by means of a suitably programmed computer. In embodiments listing several devices, several of these devices can be embodied by the same hardware item. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.

Claims

1. A fault injection detection circuit applied to a post-quantum cryptographic algorithm, characterized in that: include: An input unit, used for inputting a state matrix; A plurality of operation units are connected to the input units respectively, and each of the operation units is used to calculate the preset bit data in the state matrix to obtain a calculation result; An output unit, connected to the plurality of the computing units, for comparing the calculation result with the pre-calculated value to determine whether there is a fault injection; wherein the state matrix and the pre-calculated value conform to a preset relationship; The computing unit comprises: The first calculation module is used to perform an XOR calculation on the preset bit data to obtain a first calculation result, which is recorded as Sum j , j∈[0,n], n is the number of columns of the state matrix minus 1; A second calculation module, the second calculation module is used to perform an XOR calculation on each data in the preset bit data and the first calculation result, and rearrange them to obtain a second calculation result, which is recorded as E i,j ; Wherein, i∈[0,m], m is the number of rows of the state matrix minus 1; each data in the preset bit data is recorded as S i,j ; The third calculation module is used to calculate E i,j After negation and E i,j+1 Do a logical AND operation, and then AND E i,j Perform XOR calculation, and finally perform XOR calculation with round constant c to obtain the third calculation result, recorded as P i,j ; Extended path for P i,j and P i,j-1 XOR inversion and S i,j Perform XOR calculation to obtain the calculation result, which is recorded as P′ i,j .

2. The fault injection detection circuit for post-quantum cryptographic algorithm according to claim 1, characterized in that: If the calculation result is different from the pre-calculated value, it is determined that a fault is injected.

3. The fault injection detection circuit for post-quantum cryptographic algorithm according to claim 1, characterized in that: The output unit comprises: Comparison unit, used to compare P′ i,j Each data S in the preset bit data i,j Compare them one by one, if the comparison results are different, it is determined that fault injection has occurred.

4. The fault injection detection circuit for post-quantum cryptographic algorithm according to claim 1, characterized in that: The first calculation module includes: The first XOR calculation module receives the data S in the preset bit data. i,j , and perform XOR calculation to get Sum j ; The second calculation module includes: The second XOR calculation module receives Sum j+1 and Sum j-1 , and perform XOR calculation; The third XOR calculation module receives Sum j+1 and Sum j-1 The XOR calculation result and S i,j , and perform XOR calculation and rearrange to get E i,j .

5. The fault injection detection circuit applied to the post-quantum cryptographic algorithm according to claim 1, characterized in that: The third calculation module includes: The first inverter is used to i,j Negate; AND gate for the first inverter output E i,j Negate the result and E i,j+1 Do logic and calculations; The fourth XOR calculation module is used to sum the AND gate output result and E i,j Perform XOR calculation; The fifth XOR calculation module is used to perform XOR calculation on the output result of the fourth XOR calculation module and the round constant c to obtain P i,j .

6. The fault injection detection circuit for post-quantum cryptographic algorithm according to claim 1, characterized in that: The expansion path includes: The sixth XOR calculation module receives P i,j and P i,j-1 , and perform XOR calculation; A second inverter inverts the output of the sixth XOR calculation module; The seventh XOR calculation module calculates the output of the second inverter and S i,j Do XOR calculation and get P′ i,j .

7. A calculation method, characterized in that: The operation method is performed based on the fault injection detection circuit applied to the post-quantum cryptographic algorithm according to any one of claims 1 to 6 above, and the operation method includes: Receiving a state matrix and a pre-calculated value corresponding to the state matrix; wherein the state matrix and the pre-calculated value conform to a preset relationship; Calculating the preset bit data in the state matrix to obtain a calculation result; The calculation result is compared with the pre-calculated value to determine whether there is a fault injection.

8. The calculation method according to claim 7, characterized in that: The calculating the preset bit data in the state matrix to obtain the calculation result includes: Receive the data S in the preset bit data i,j , and perform XOR calculation to get Sum j ; Receive Sum j+1 and Sum j-1 , and perform XOR calculation, and receive Sum j+1 and Sum j-1 The XOR calculation result and S i,j , and perform XOR calculation and rearrange to get E i,j ; For E i,j After negation and E i,j+1 Perform a logical AND calculation and add the result to E i,j Perform XOR calculation, and then perform XOR calculation with round constant c to get P i,j ; Receive P i,j and P i,j-1 , and then XOR calculation and inversion, and then S i,j Perform XOR calculation to get the calculation result P′ i,j .

9. The calculation method according to claim 7, characterized in that: Comparing the calculation result with the pre-calculated value to determine whether there is a fault injection, including: P′ i,j Each data S in the preset bit data i,j Compare them one by one, if the comparison results are different, it is determined that fault injection has occurred.

Citation Information

Patent Citations

  • Circuits and methods for detecting fault injection attacks in integrated circuits

    CN117610090A

  • Cryptographic system for post quantum cryptographic operation

    CN117651949A