Data processing method and data processing chip
The method and chip design optimize Merkle tree processing by determining and outputting verification nodes sequentially, reducing storage and resource consumption while maintaining signature security and efficiency.
Patent Information
- Application Number
- CN202510121563.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-01-26
AI Technical Summary
In the prior art, a separate storage space is required to store verification nodes when signing using a Merkel tree, resulting in large storage space, high resource consumption and low signature efficiency.
By determining the signature node from the leaf node of the Merkel tree, and when determining the parent node, if the node is a verification node, output the node first and then determine its parent node, ensuring that the output order of the verification node is upward in sequence, avoiding the need for additional storage of verification nodes.
Reduces storage space requirements, reduces resource consumption, and improves signature efficiency while ensuring signature security.
Smart Images

Figure CN119557260B_ABST
Abstract
Description
Technical Field
[0001] This application relates to, but is not limited to, the field of information security technology, and in particular, to a data processing method and a data processing chip. Background Art
[0002] In the related art, during the process of signing using a Merkle tree, a separate storage space is required to store each verification node in the Merkle tree, which increases the storage space. Moreover, subsequently, it is also necessary to read and output each verification node from this storage space in the order from bottom to top, which not only increases the resource consumption but also reduces the signing efficiency. Summary of the Invention
[0003] Embodiments of this application provide a data processing method and a data processing chip to solve the problems in the related art, such as large storage space, high resource consumption, and low signing efficiency, due to the need for a separate storage space to store each verification node in the Merkle tree.
[0004] The technical solution of the embodiments of this application is implemented as follows:
[0005] Embodiments of this application provide a data processing method, including:
[0006] Determine signature nodes from at least two leaf nodes of the current Merkle tree;
[0007] Based on the signature nodes, determine at least one verification node from multiple nodes of the current Merkle tree;
[0008] During the process of determining the parent node of the first node, if the first node is one of the at least one verification node, output the first node, and based on the first node, determine the parent node of the first node, where the first node is one of the multiple nodes.
[0009] Embodiments of this application provide a data processing chip, in which a processing unit is deployed, where:
[0010] The processing unit is configured to: determine signature nodes from at least two leaf nodes of the current Merkle tree; based on the signature nodes, determine at least one verification node from multiple nodes of the current Merkle tree; during the process of determining the parent node of the first node, if the first node is one of the at least one verification node, output the first node, and based on the first node, determine the parent node of the first node, where the first node is one of the multiple nodes.
[0011] In the embodiments of the present application, signature nodes are determined from at least two leaf nodes of the current Merkle tree; based on the signature nodes, at least one verification node is determined from multiple nodes of the current Merkle tree; in the process of determining the parent node of the first node, if the first node is one of the at least one verification nodes, the first node is output, and based on the first node, the parent node of the first node is determined. In this way, on the one hand, at least one verification node is determined in real time according to the signature nodes, improving the security of the verification nodes; on the other hand, in the process of determining the parent node of a certain node upward, if the node is a verification node, the node is output first and then the parent node of the node is determined to ensure that the output order of each verification node is in the upward order. The present application does not require additional storage space to separately store each verification node. Compared with the related art that requires additional storage space to store each verification node in the Merkle tree, the storage space is reduced. At the same time, in the process of determining the parent node upward in the present application, each verification node has been output in the upward order. Compared with the related art that requires reading and outputting each verification node in the upward order from additional storage space, while ensuring the security of the signature, the resource consumption is reduced and the signature efficiency is improved.
[0012] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification. These drawings illustrate embodiments consistent with the present application and, together with the specification, are used to explain the technical solutions of the present application.
[0014] Figure 1 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 1 ;
[0015] Figure 2 Schematic diagram of a Merkle tree provided by an embodiment of the present application;
[0016] Figure 3 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 2 ;
[0017] Figure 4 Storage schematic diagram of a Merkle tree in the related art;
[0018] Figure 5 Storage schematic diagram of a Merkle tree provided by an embodiment of the present application;
[0019] Figure 6Schematic diagram of the composition structure of a data processing chip provided by an embodiment of the present application;
[0020] Figure 7 Schematic diagram of the process of signature generation provided by an embodiment of the present application;
[0021] Figure 8 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 3 ;
[0022] Figure 9 Schematic diagram of the process of public key generation provided by an embodiment of the present application;
[0023] Figure 10 Schematic diagram of the composition structure of a data processing system provided by an embodiment of the present application. Detailed implementation manners
[0024] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be construed as limitations on the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.
[0025] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.
[0026] In the following description, the terms "first / second / third" are only used to distinguish similar objects and do not represent a specific order for the objects. It can be understood that "first / second / third" can be interchanged with a specific order or sequence when permitted, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0028] With the application and development of quantum computers, post-quantum signature algorithms have received extensive attention. Post-quantum signature algorithms are a class of digital signature algorithms designed to resist attacks from quantum computers. They are implemented by using hash functions to improve the efficiency and security of signatures. Post-quantum signature algorithms can provide stronger security guarantees when facing the threat of quantum computing technology. Post-quantum signature algorithms can include, but are not limited to, LMS (Leighton-Micali Signature), Falcon, SPHINCS+, etc.
[0029] The SPHINCS+ algorithm is a hash-based digital signature algorithm with high security and anti-quantum characteristics, and is selected by NIST as one of the standard algorithms for its post-quantum cryptography standardization program. The SPHINCS+ algorithm inherits the advantages of traditional hash signatures and improves the security and efficiency of the algorithm by introducing new technologies and methods.
[0030] SPHINCS+ adopts a hypertree structure to manage one-time signatures. By combining multiple one-time signatures (WOTS, Winternitz One-Time Signature) into a hypertree structure, the signature efficiency is improved. The outer layer structure of the SPHINCS+ hypertree can be a k-ary tree with a total of d layers. Each node of the k-ary tree is a Merkle tree, where both k and d are positive integers not less than 2.
[0031] In related technologies, during the process of signing using a Merkle tree, separate storage space is required to store each verification node in the Merkle tree, which increases the storage space. Moreover, subsequently, it is necessary to read and output each verification node from this storage space in the order of going up one by one, which not only increases resource consumption but also reduces the signature efficiency.
[0032] The embodiment of the present application provides a data processing method. During the process of determining the parent node of a certain node upwards, if the node is a verification node, the node is output first and then its parent node is determined to ensure that the output order of each verification node is the order of going up one by one. The present application does not require additional storage space to separately store each verification node. Compared with related technologies that require additional storage space to store each verification node in the Merkle tree, the storage space is reduced. At the same time, in the process of determining the parent node upwards in the present application, each verification node has been output in the order of going up one by one. Compared with related technologies that require reading and outputting each verification node from additional storage space in the order of going up one by one, while ensuring the security of the signature, the resource consumption is reduced and the signature efficiency is improved.
[0033] The method provided by the embodiments of this application can be executed by a data processing chip. Next, in conjunction with the accompanying drawings in the embodiments of this application, the technical solutions in the embodiments of this application will be clearly and completely described.
[0034] Figure 1 It is a schematic implementation process of a data processing method provided by the embodiments of this application Figure 1 , such as Figure 1 shown. The method includes steps S11 to S13, where:
[0035] Step S11: Determine a signature node from at least two leaf nodes of the current Merkle tree.
[0036] Here, the current Merkle tree is one of the Merkle trees in the supertree. A Merkle tree is a tree-like data structure, usually used to verify the integrity and consistency of large-scale data sets. A Merkle tree is a hash binary tree with a height of h. In computer science, a binary tree is an important data structure, which consists of multiple nodes, and each node has at most two child nodes, which are respectively called the left child node and the right child node. A child node refers to the node connected below a certain node. A parent node refers to the node connected above a certain node.
[0037] A Merkle tree includes multiple nodes, and the multiple nodes include at least two leaf nodes and at least one non-leaf node. A leaf node refers to the bottommost node of the binary tree and has no child nodes, and the height of the leaf node is 0. The height of a node refers to the number of edges of the longest simple path from this node to the leaf node. The at least one non-leaf node includes a root node, a non-root node, etc. The root node is the top node of the binary tree and has no parent node, and the height of the root node is the height of the tree.
[0038] The signature node can be any one of the leaf nodes. Each leaf node of this Merkle tree is a one-time key, which is used to generate a public key for the child nodes of the outer structure. In implementation, the signature node can be a certain leaf node among the unused one-time keys.
[0039] The determination method of the signature node can be any suitable method.
[0040] In some embodiments, according to the custom configuration information, a certain leaf node can be used as the signature node.
[0041] In some embodiments, a certain leaf node can be randomly selected from the leaf nodes of multiple unused one-time keys as the signature node.
[0042] In some embodiments, the adjacent leaf node of the previous signature node can be used as the signature node according to the usage order of each leaf node. The usage order can include, but is not limited to, from left to right, from right to left, etc. For example, the Merkle tree includes 8 leaf nodes, and the 3rd leaf node was used as the signature node last time. Then, this time, the 4th leaf node can be used as the signature node.
[0043] In some embodiments, the signature node can be determined according to the message to be processed. The message to be processed can be a piece of message sent by the client.
[0044] During implementation, those skilled in the art can independently select the method for determining the signature node according to actual needs, and the embodiments of the present application do not make any limitations.
[0045] Step S12: Based on the signature node, determine at least one verification node from multiple nodes of the current Merkle tree.
[0046] Here, the number of verification nodes is adapted to the height of the current Merkle tree. For example, if the height of the current Merkle tree is 3, then the number of verification nodes can be 3.
[0047] In some embodiments, one of the multiple nodes at the same height is a verification node. For example, if the height of the Merkle tree is 2, then the Merkle tree includes 7 nodes, namely: 4 leaf nodes, 2 intermediate nodes (refer to nodes other than leaf nodes and root nodes), and 1 root node. Then, the number of verification nodes can be 2. One verification node can be one of the 4 leaf nodes, and the other verification node can be one of the 2 intermediate nodes.
[0048] In some embodiments, a corresponding relationship between the signature node and the verification node can be established in advance. According to this corresponding relationship, at least one verification node adapted to the signature node can be obtained.
[0049] For example, the corresponding relationship includes: signature node A1 corresponds to verification nodes B1 and B2, signature node A2 corresponds to verification nodes C1 and C2... Then, if the signature node is A2, at this time, both verification nodes C1 and C2 can be used as one verification node.
[0050] During implementation, those skilled in the art can independently set this corresponding relationship according to actual needs, and the embodiments of the present application do not make any limitations.
[0051] In some embodiments, based on the signature node, a verification node is determined from at least two leaf nodes; when the parent node of the signature node is a non-root node, based on the parent node of the signature node, at least one verification node is determined from at least one non-leaf node.
[0052] Here, when the parent node of the signature node is a root node, the number of verification nodes is one. When the parent node of the signature node is a non-root node, the number of verification nodes can be at least two.
[0053] In some embodiments, a leaf node can be randomly selected from at least two leaf nodes as the verification node. Among them, the verification node is different from the signature node.
[0054] In some embodiments, the sibling node of the signature node can be used as a verification node.
[0055] In some embodiments, a verification node can be determined from at least two leaf nodes according to the position index of the signature node. The position index of a node refers to the position of the node in the binary tree. Usually, the position index of the leftmost node is 0, and the position index increases sequentially from left to right.
[0056] For example, the position index of the signature node is XORed with a preset value to obtain an XOR value, and the verification node is determined based on the XOR value. The preset value can be any suitable value, for example, 1.
[0057] For example, if the position index of the signature node is 3 and the preset value is 1, then 011 (3) is XORed with 001 (1) to obtain 010 (2). Then, the leaf node with the position index of 2 can be used as the verification node.
[0058] In some embodiments, the parent node of the signature node is used as the third node. Based on the third node, a verification node is determined from at least two intermediate nodes with the same height as the third node; if the parent node of the third node is a root node, the traversal stops; otherwise, if the parent node of the third node is a non-root node, the parent node of the third node is used as the new third node, and in the same way, continue to traverse upward to determine the verification node until the parent node of the third node is a root node.
[0059] Figure 2 A schematic diagram of a Merkle tree provided by an embodiment of the present application is as Figure 2 shown. The height of the Merkle tree is 3. Then, the Merkle tree includes:
[0060] Eight leaf nodes with a height of 0, namely: node (0, 0), node (0, 1), node (0, 2), node (0, 3), node (0, 4), node (0, 5), node (0, 6), node (0, 7);
[0061] Four intermediate nodes with a height of 1, namely: node (1, 0), node (1, 1), node (1, 2), node (1, 3);
[0062] Two intermediate nodes with a height of 2, namely: node (2, 0), node (2, 1);
[0063] One root node, namely: node (3, 0),
[0064] At this time, the number of verification nodes can be 3. If the signature node is node (0, 2), where 0 is the height of this node and 2 is the position index of this node, then the determination process of this verification node is as follows:
[0065] For the eight leaf nodes with a height of 0, according to the signature node (0, 2), a verification node is determined to be (0, 3). Since the parent node (1, 1) of the signature node (0, 2) is not the root node, continue to traverse upward;
[0066] For the four intermediate nodes with a height of 1, according to the node (1, 1), a verification node is determined to be (1, 0). Since the parent node (2, 0) of the node (1, 1) is not the root node, continue to traverse upward;
[0067] For the two intermediate nodes with a height of 2, according to the node (2, 0), a verification node is determined to be (2, 1). Since the parent node of the node (2, 0) is the root node (3, 0), stop traversing upward.
[0068] Step S13, during the process of determining the parent node of the first node, if the first node is one of at least one verification node, output the first node, and based on the first node, determine the parent node of the first node.
[0069] Here, it can be first determined whether the first node is a verification node. If it is a verification node, then use the first node (i.e., the value of the first node) as the signature output; if it is not a verification node, then based on the first node, determine the parent node of the first node (i.e., determine the value of the parent node of the first node).
[0070] The determination method of the parent node of the first node can be any suitable method. For example, perform a hash operation between the first node and the sibling node of the first node to obtain a first hash value, and determine the parent node of the first node according to this first hash value. For example, use the first hash value as the parent node of the first node. Or, use the weighted value of the first hash value as the parent node of the first node.
[0071] For example, for the Merkle tree shown as Figure 2 below, if the signature node is node (0, 4), then the number of verification nodes is three, namely: node (0, 5), node (1, 3), and node (2, 0). The process of determining each non-leaf node upwards is as follows:
[0072] Determine node (1, 0) based on node (0, 0) and node (0, 1);
[0073] Determine node (1, 1) based on node (0, 2) and node (0, 3);
[0074] Determine node (2, 0) based on node (1, 0) and node (1, 1). Although node (2, 0) is a verification node, it is not output at this time. Instead, it is determined whether it is a verification node again when determining its parent node based on node (2, 0);
[0075] Determine node (1, 2) based on node (0, 4) and node (0, 5). Since node (0, 5) is a verification node, at this time, first output node (0, 5), and then determine node (1, 2);
[0076] Determine node (1, 3) based on node (0, 6) and node (0, 7);
[0077] Determine node (2, 1) based on node (1, 2) and node (1, 3). Since node (1, 3) is a verification node, at this time, first output node (1, 3), and then determine node (2, 1);
[0078] Determine node (3, 0) based on node (2, 0) and node (2, 1). Since node (2, 0) is a verification node, at this time, first output node (2, 0), and then determine node (3, 0);
[0079] It can be seen from this that the output order of each verification node is node (0, 5), node (1, 3), and node (2, 0) in sequence, that is: each verification node is output in ascending order of the height of the node. In implementation, the signature of the current Merkle tree at least includes each verification node output in ascending order of the height of the node.
[0080] In some implementation manners, when the parent node of the first node is a non-root node, the parent node of the first node can be used as the new first node, and step S13 is continued to output the next verification node until all verification nodes of the current Merkle tree are output, so as to ensure the correctness and integrity of the signature of the current Merkle tree.
[0081] In an embodiment of the present application, on the one hand, at least one verification node is determined in real time according to the signature node, which improves the security of the verification node; on the other hand, in the process of determining the parent node of a certain node upward, if the node is a verification node, the node is output first and then its parent node is determined to ensure that the output order of each verification node is in the upward order in turn. The present application does not require additional storage space to separately store each verification node. Compared with the related art that requires additional storage space to store each verification node in the Merkle tree, not only the storage space is reduced, but also, in the process of determining the parent node upward in the present application, each verification node has been output in the upward order in turn. Compared with the related art that needs to sequentially read and output each verification node from additional storage space in the upward order in turn, while ensuring the security of the signature, the resource consumption is reduced and the signature efficiency is improved.
[0082] In some embodiments, step S11 includes step S111 and step S112, where:
[0083] Step S111: Determine the second hash value of the message to be processed.
[0084] Here, the message to be processed can be a piece of message sent by the client. The message to be processed can include any appropriate content. In implementation, the message to be processed can be subjected to a hash operation to obtain the second hash value.
[0085] Step S112: Based on the second hash value, determine the signature node from at least two leaf nodes of the current Merkle tree.
[0086] Here, the signature node is any one of the leaf nodes. In implementation, the signature node is a certain leaf node in the unused one-time key.
[0087] In some embodiments, several bits can be selected from the second hash value to determine the signature node. For example, the leaf node adapted to the several bits is used as the signature node.
[0088] In an embodiment of the present application, by determining the signature node according to the second hash value of the message to be processed, the accuracy and security of the signature node are improved.
[0089] In some embodiments, step S12 includes step S121 and step S122, where:
[0090] Step S121: Based on the signature node, determine the second node from at least two leaf nodes, and use the second node as a verification node.
[0091] Here, among multiple nodes at the same height, one node can be a verification node. During implementation, the signature node and the verification node can be different nodes.
[0092] The second node can be any leaf node other than the signature node. The determination method of the second node can be any suitable method. In some embodiments, a certain leaf node can be randomly used as the second node. In some embodiments, the sibling node of the signature node can be used as the second node. In some embodiments, the second node can be determined according to the position index of the signature node. During implementation, those skilled in the art can independently select the determination method of the second node according to actual needs, and the embodiments of the present application do not make limitations.
[0093] Step S122, when the parent node of the signature node is a non-root node, based on the parent node of the signature node, determine at least one verification node from at least one non-leaf node.
[0094] Here, when the parent node of the signature node is the root node, there is no need to continue traversing; on the contrary, when the parent node of the signature node is a non-root node, it is necessary to continue traversing upward to determine the remaining verification nodes.
[0095] The number of the verification nodes is adapted to the height of the Merkle tree. For example, if the height of the Merkle tree is 3, then the number of the verification nodes can be 3, that is: among the 8 leaf nodes at height 0, one is a verification node; among the 4 intermediate nodes at height 1, one is a verification node; among the 2 intermediate nodes at height 2, one is a verification node.
[0096] In some embodiments, the verification nodes can be determined by traversing upward in turn in a loop manner. The end conditions of the loop can include but are not limited to the height of the node, whether the parent node of a certain node is the root node, etc.
[0097] For example, take the parent node of the signature node as a target node; according to the target node, determine one verification node from at least two intermediate nodes at the same height as the target node; if the parent node of the target node is the root node, stop traversing; on the contrary, if the parent node of the target node is a non-root node, take the parent node of the target node as a new target node, and continue traversing upward to determine the verification node in the same way until the parent node of the target node is the root node.
[0098] For another example, the height of the parent node of the signature node is used as the target height; one verification node is determined from multiple intermediate nodes at the target height. If the target height is the height of the Merkle tree, the traversal stops; otherwise, if the target height is less than the height of the Merkle tree, the next height (target height + 1) is used as the new target height, and in the same way, the traversal continues upward to determine the verification node until the target height is the height of the Merkle tree.
[0099] When implemented, the method for determining the verification node among at least two non-leaf nodes at the same height is similar to the method for determining the verification node based on the signature node. When implemented, the specific implementation manner of step S121 described above can be referred to.
[0100] In the embodiment of the present application, by sequentially determining each verification node in the order from the leaf node to the non-leaf node, the accuracy of the verification node is improved.
[0101] In some embodiments, the step of "determining the second node from at least two leaf nodes based on the signature node" in step S121 includes step S1211 or step S1212, where:
[0102] Step S1211: Use the sibling node of the signature node as the second node.
[0103] Here, the second node is located on the left or right of the signature node, and the signature node and the second node are two child nodes of the same parent node. When implemented, when the signature node is the left node, the node located on the right of the signature node can be used as the second node. When the signature node is the right node, the node located on the left of the signature node can be used as the second node.
[0104] Step S1212: Determine the second node from at least two leaf nodes based on the position index of the signature node.
[0105] Here, the position index refers to the position of the node in the binary tree. Usually, the position index of the leftmost node is 0, and the position index increases sequentially from left to right.
[0106] In some embodiments, the position index of the signature node can be incremented or decremented by 1 to obtain the first position index. If the position index of a certain node matches the first position index, then the node is used as the second node. For example, if the signature node is the left node, the position index of the signature node is incremented by 1 to obtain the first position index; if the signature node is the right node, the position index of the signature node is decremented by 1 to obtain the first position index.
[0107] In some embodiments, the position index of the signature node can be XORed with a preset value to obtain an XOR value, and a second node is determined based on the XOR value. Here, the preset value can be any suitable value. For example, if the position index of a certain node is adapted to the XOR value, then this node is used as the second node.
[0108] For example, if the position index of the signature node is 4 and the preset value is 1, then, XOR 100(4) with 001(1) to obtain 110(5), then, the leaf node with the position index of 5 can be used as the verification node.
[0109] In the embodiments of the present application, the second node is determined in different ways, which improves the determination efficiency and flexibility of the second node.
[0110] In some embodiments, step S1212 includes step S141 and step S142, where:
[0111] Step S141: Determine a target position index based on the position index of the signature node.
[0112] Here, the target position index is different from the position index of the signature node. The determination method of the target position index can include but is not limited to adding 1 to the position index of the signature node, subtracting 1 from the position index of the signature node, the XOR value of the position index of the signature node and the preset value, the weighting of the XOR value, etc. In implementation, those skilled in the art can independently select the determination method of the target position index according to actual needs, and the embodiments of the present application do not make limitations. For example, adding 1 to the position index of the signature node is used as the target position index.
[0113] In some embodiments, step S141 includes step S1411, where:
[0114] Step S1411: Determine the XOR value between the position index of the signature node and the preset value, and use the XOR value as the target position index.
[0115] Here, the preset value can be any suitable value, for example, 1. In implementation, the position index of the signature node and the preset value can be both converted into corresponding binary numbers for XOR to obtain the XOR value.
[0116] In the embodiments of the present application, the target position index is determined according to the position index of the signature node and the preset value, which improves the accuracy of the target position index, and thus improves the accuracy of the second node.
[0117] Step S142: Determine the second node from at least two leaf nodes based on the target position index.
[0118] Here, the position index of each leaf node is compared with the target position index. If the position index of a certain leaf node is the same as the target position index, then this leaf node is used as the second node.
[0119] In the embodiment of the present application, the second node is determined in real time according to the position index of the signature node, which improves the accuracy of the second node.
[0120] In some embodiments, this step S122 includes step S1221 to step S1223, where:
[0121] Step S1221: Use the parent node of the signature node as the third node.
[0122] Here, the third node is an intermediate node, and the height of this third node is less than the height of the Merkle tree.
[0123] Step S1222: Based on the third node, determine the fourth node from at least one non-leaf node with the same height as the third node, and use the fourth node as a verification node.
[0124] Here, the fourth node can be an intermediate node, and the height of the fourth node is the same as the height of the third node. In implementation, the fourth node and the third node can be different nodes.
[0125] The determination method of the fourth node can be any suitable method. In some embodiments, a certain node can be randomly used as the fourth node. In some embodiments, the sibling node of the third node can be used as the fourth node. In some embodiments, the fourth node can be determined according to the position index of the third node. In implementation, those skilled in the art can independently select the determination method of the fourth node according to actual needs, and the embodiments of the present application do not make limitations.
[0126] Step S1223: In the case where the parent node of the third node is a non-root node, use the parent node of the third node as the new third node.
[0127] Here, if the parent node of the third node is the root node, stop traversing; on the contrary, if the parent node of the third node is a non-root node, use the parent node of the third node as the new third node, and in the same way, continue to traverse upward to determine the verification node until the parent node of the third node is the root node. In implementation, the method of determining the verification node among at least two non-leaf nodes at the same height is similar to the method of determining the fourth node according to the third node, and in implementation, the specific implementation manner of the foregoing step S1222 can be referred to.
[0128] In the embodiment of the present application, each verification node is determined by traversing upward in turn, which improves the accuracy and integrity of the verification node.
[0129] In some embodiments, "determining a fourth node from at least one non-leaf node having the same height as the third node based on the third node" in step S1222 includes step S151 and step S152, where:
[0130] Step S151: Use the sibling node of the third node as the fourth node.
[0131] Here, the fourth node is located on the left or right of the third node, and the third node and the fourth node are two child nodes of the same parent node. In implementation, when the third node is a left node, the node located on the right of the third node can be used as the fourth node. When the third node is a right node, the node located on the left of the third node can be used as the fourth node.
[0132] Step S152: Determine the fourth node from at least one non-leaf node having the same height as the third node based on the position index of the third node.
[0133] Here, the position index refers to the position of the node in the binary tree. Usually, the position index of the leftmost node is 0, and the position index increases sequentially from left to right.
[0134] In some embodiments, the position index of the third node can be incremented or decremented by 1 to obtain a second position index. If the position index of a certain node matches the second position index, then that node is used as the fourth node. For example, if the third node is a left node, the position index of the third node is incremented by 1 to obtain the second position index; if the third node is a right node, the position index of the third node is decremented by 1 to obtain the second position index.
[0135] In some embodiments, the position index of the third node can be XORed with a preset value to obtain an XOR value, and the fourth node is determined based on the XOR value. Wherein, the preset value can be any suitable value. For example, if the position index of a certain node matches the XOR value, then that node is used as the fourth node.
[0136] In the embodiments of the present application, different methods are used to determine the fourth node, which improves the determination efficiency and flexibility of the fourth node.
[0137] In some embodiments, the method further includes step S14 and / or step S15, where:
[0138] Step S14: If the first node is a non-root node and not a verification node, determine the parent node of the first node based on the first node.
[0139] Here, in the process of determining the parent node of the first node, it can be first determined whether the first node is the root node. If it is not the root node, it is then determined whether it is a verification node. If it is not a verification node, the parent node of the first node is directly determined. If the first node is the root node, there is no need to determine whether it is a verification node, nor is it necessary to determine its parent node. In implementation, the method for determining the parent node of the first node can refer to the specific implementation in the foregoing step S13.
[0140] Step S15: If the first node is the root node and the current Merkle tree is a super tree, use the first node as the public key.
[0141] Here, if the first node is the root node of the super tree, then use the first node as the public key. If the first node is the root node of a non-super tree, the first node can be used to sign the leaf nodes of the upper-layer Merkle tree.
[0142] In some embodiments, the order of determining the root node of the Merkle tree is consistent with the order of generating the signature of the Merkle tree.
[0143] For example, as Figure 2 shown in the Merkle tree, the process of determining the root node (3, 0) is as follows:
[0144] Determine node (1, 0) based on node (0, 0) and node (0, 1);
[0145] Determine node (1, 1) based on node (0, 2) and node (0, 3);
[0146] Determine node (2, 0) based on node (1, 0) and node (1, 1);
[0147] Determine node (1, 2) based on node (0, 4) and node (0, 5);
[0148] Determine node (1, 3) based on node (0, 6) and node (0, 7);
[0149] Determine node (2, 1) based on node (1, 2) and node (1, 3);
[0150] Determine node (3, 0) based on node (2, 0) and node (2, 1).
[0151] In some embodiments, for any Merkle tree in the super tree, the root node of the Merkle tree can be calculated synchronously during the process of determining the signature, so as to achieve the efficient unification of the root calculation and signature generation.
[0152] In the implementation manner of the present application, the first node is processed according to whether the first node is the root node of the supertree, whether it is a verification node, etc., thereby improving the accuracy and reliability of the processing of the first node.
[0153] Figure 3 A schematic diagram of an implementation process of a data processing method provided in an embodiment of the present application Figure 2 ,like Figure 3 As shown, the method includes steps S31 to S33, wherein:
[0154] Step S31: Determine a signature node from at least two leaf nodes of the current Merkle tree.
[0155] Step S32: Based on the signature node, determine at least one verification node from multiple nodes of the current Merkle tree.
[0156] Here, the above steps S31 to S32 correspond to the above steps S11 to S12 respectively. When implementing, reference may be made to the specific implementation of the above steps S11 to S12.
[0157] Step S33. In the process of determining the parent node of the first node, if the first node is a verification node in at least one verification node, the first node is output, and when the position index of the first node satisfies a first preset condition, the brother node of the first node is obtained from the target storage position of the target storage block, and the parent node of the first node is determined based on the first node and the brother node of the first node; wherein the target storage block includes multiple storage locations, the number of the multiple storage locations is adapted to the height of the current Merkle tree, all nodes at the same height in the current Merkle tree correspond to one storage location, and the target storage location is a storage location adapted to the height of the first node.
[0158] Here, the process of outputting the first node may refer to the specific implementation of the aforementioned step S13.
[0159] The position index of a node refers to the position of the node in the binary tree. Usually, the position index of the leftmost node is 0, and the position index increases from left to right.
[0160] The first preset condition may be any appropriate condition, for example, an odd number, or a number that is not divisible by 2.
[0161] The target storage block can be a section of storage space in a storage unit. Herein, the storage unit can be any suitable unit capable of implementing a storage function. For example, a random access memory. In some embodiments, different Merkle trees can correspond to different storage blocks or reuse the same storage block. During implementation, the storage block can be reused to further reduce the demand for storage space; or the storage block can not be reused to improve the independence of the values of each node, thereby reducing the possibility of data anomalies.
[0162] In some embodiments, the number of storage locations included in the target storage block is adapted to the height of the current Merkle tree. For example, if the height of the current Merkle tree is 3, then the number of storage locations can be 3, that is: for the 8 leaf nodes with a height of 0, they share one storage location P0; for the 4 intermediate nodes with a height of 1, they share one storage location P1; for the 2 intermediate nodes with a height of 2, they share one storage location P2.
[0163] During implementation, when the position index of the first node does not meet the first preset condition, the first node can be stored in the target storage location first; when the position index of the first node meets the first preset condition, it is not necessary to store the first node in the target storage location, but directly obtain the sibling node of the first node from the target storage location, so as to realize that multiple nodes at the same height share one storage location.
[0164] Figure 4 A storage schematic diagram of a Merkle tree in the related art is shown as Figure 4 shown. The height of this Merkle tree is 3. Then, the target storage block needs to include 2 3 storage locations, that is: P0 to P7. During implementation, P0 to P7 are first used to store each leaf node. As the height increases, fewer and fewer storage locations are needed. When reaching the top layer, the target storage block only needs to store one root node. It can be seen that the storage space of the target storage block is large and the utilization rate is low.
[0165] Figure 5 A storage schematic diagram of a Merkle tree provided by an embodiment of the present application is shown as Figure 5 shown. The height of this Merkle tree is 3. Then, the target storage block only needs 3 storage locations, that is: P0 to P2. The storage process of each node is as follows:
[0166] Since the node (0, 0) does not meet the first preset condition, the node (0, 0) is stored in P0;
[0167] Since the node (0, 1) satisfies the first preset condition, the node (1, 0) is determined based on the node (0, 0) and the node (0, 1). Since the node (1, 0) does not satisfy the first preset condition, the node (1, 0) is stored in P1;
[0168] Since the node (0, 2) does not satisfy the first preset condition, the node (0, 2) is stored in P0 to replace the original node (0, 0);
[0169] Since the node (0, 3) satisfies the first preset condition, the node (1, 1) is determined based on the node (0, 2) and the node (0, 3). Since the node (1, 1) satisfies the first preset condition, the node (2, 0) is determined based on the node (1, 0) and the node (1, 1). Since the node (2, 0) does not satisfy the first preset condition, the node (2, 0) is stored in P2;
[0170] Since the node (0, 4) does not satisfy the first preset condition, the node (0, 4) is stored in P0 to replace the original node (0, 2);
[0171] Since the node (0, 5) satisfies the first preset condition, the node (1, 2) is determined based on the node (0, 4) and the node (0, 5). Since the node (1, 2) does not satisfy the first preset condition, the node (1, 2) is stored in P1 to replace the original node (1, 0);
[0172] Since the node (0, 6) does not satisfy the first preset condition, the node (0, 6) is stored in P0 to replace the original node (0, 4);
[0173] Since the node (0, 7) satisfies the first preset condition, the node (1, 3) is determined based on the node (0, 6) and the node (0, 7). Since the node (1, 3) satisfies the first preset condition, the node (2, 1) is determined based on the node (1, 2) and the node (1, 3). Since the node (2, 1) satisfies the first preset condition, the node (3, 0) is determined based on the node (2, 0) and the node (2, 1).
[0174] It can be seen from this that for any node (i, j), only when j is an even number, the node (i, j) needs to be stored at the storage location p = i. Once its right node (i, j + 1) is generated, their parent node (i + 1, j / 2) can be calculated through the hash calculation of the node (i, j) and its right node (i, j + 1). If j / 2 is an even number, the node (i + 1, j / 2) will be stored at the storage location p = i + 1. Otherwise, if j / 2 is an odd number, its sibling node (i + 1, j / 2 - 1) can be obtained from the storage location p = i + 1 to calculate the parent node (i + 2, (j / 2 - 1) / 2) of the node (i + 1, j / 2)...... Continuing upward according to the above logic until the root node is calculated. Among them, both i and j are integers not less than 0, i is the height of the node, and j is the position index of the node.
[0175] Therefore, once the parent node is calculated, its child node is no longer needed. Then, the storage location occupied by the child node can store the values of other child nodes at the same height, and only one storage location in the storage block is required for the same node height.
[0176] The determination method of the parent node of the first node can be any suitable method. For example, a hash operation is performed between the first node and the sibling node of the first node to obtain the first hash value, and the parent node of the first node is determined according to the first hash value. For example, the first hash value is used as the parent node of the first node. Another example is that the weighted value of the first hash value is used as the parent node of the first node.
[0177] In the embodiment of the present application, by setting the number of storage locations to the tree height, compared with the number of storage locations being the total number of leaf nodes, the number of storage locations is greatly reduced, the size of the storage space is reduced, thereby improving the utilization rate of the storage space while reducing resource consumption.
[0178] In some embodiments, the "determining the parent node of the first node based on the first node and the sibling node of the first node" in step S33 includes step S331 and step S332, where:
[0179] Step S331: Determine the first hash value between the first node and the sibling node of the first node.
[0180] Here, a hash operation can be performed on the first node and the sibling node of the first node to obtain the first hash value.
[0181] Step S332: Determine the parent node of the first node based on the first hash value.
[0182] Here, the method for determining the parent node of the first node may include, but is not limited to, the first hash value, the weighting of the first hash value, etc. In implementation, those skilled in the art can independently select the method for determining the parent node of the first node according to actual needs, and the embodiments of the present application do not make any limitations. For example, the first hash value is used as the parent node of the first node.
[0183] In the implementation manner of the present application, the parent node of the first node is determined by the first hash value between the first node and the sibling node of the first node, which improves the accuracy and security of the parent node of the first node.
[0184] In some implementation manners, the method further includes step S34 and / or step S35, where:
[0185] Step S34: When the position index of the first node does not meet the first preset condition, store the first node in the target storage location.
[0186] Here, the target storage location can be used to store at least one node. For example, if the height of the Merkle tree is 3, the target storage location is P0, and the first preset condition is an odd number, then P0 is respectively used to store nodes (0, 0), (0, 2), (0, 4), and (0, 6).
[0187] Step S35: When the first node meets the second preset condition, stop refreshing the target storage block.
[0188] Here, the second preset condition can be any suitable condition, such as the penultimate leaf node, a preset index value, etc. In implementation, those skilled in the art can independently set the second preset condition according to actual needs, and the embodiments of the present application do not make any limitations.
[0189] In implementation, if the first node does not meet the second preset condition, the target storage block needs to be continuously refreshed; if the first node meets the second preset condition, the target storage block is no longer refreshed.
[0190] In the implementation manner of the present application, on the one hand, it is determined whether to store the first node according to the position index of the first node and the first preset condition, which improves the accuracy of storing the first node; on the other hand, it is determined whether to refresh the corresponding storage block according to the first node and the second preset condition, which improves the accuracy of refreshing the storage block.
[0191] Based on the above embodiments, the embodiments of the present application further provide a data processing chip. Figure 6 The following is a schematic diagram of the composition structure of a data processing chip provided by the embodiments of the present application. As Figure 6 shown, a processing unit 61 is deployed in the data processing chip 60, where:
[0192] The processing unit 61 is configured to: determine signature nodes from at least two leaf nodes of the current Merkle tree; determine at least one verification node from multiple nodes of the current Merkle tree based on the signature nodes; in the process of determining the parent node of the first node, if the first node is one of the at least one verification node, output the first node, and determine the parent node of the first node based on the first node, where the first node is one of the multiple nodes.
[0193] Here, the processing unit can be any suitable hardware unit capable of implementing this function. For example, digital circuits, analog circuits, etc.
[0194] The signature node can be any one of the leaf nodes, and the signature node can be a leaf node in an unused one-time key. In implementation, the process for the processing unit to determine the signature node can refer to the specific implementation manner of the foregoing step S11.
[0195] In some implementation manners, the processing unit 61 is further configured to: in response to receiving a signature request transmitted by the server through the processor, determine signature nodes from at least two leaf nodes of the current Merkle tree based on the message to be processed transmitted by the server through direct memory access.
[0196] Here, the server can be any suitable unit capable of implementing this function. For example, an electronic device.
[0197] The processor can be any suitable processor capable of implementing this function. For example, a CPU (Central Processing Unit, central processor), a DSP (Digital Signal Processing, digital signal processor), etc. The processor can be communicatively connected to the processing unit through a bus, hardwiring, an interface, etc.
[0198] The message to be processed can be any suitable message.
[0199] Direct Memory Access (DMA) is a function provided by some computer bus architectures. It enables data to be directly sent from an attached device (such as a disk drive) to the memory of the computer motherboard to reduce data latency and improve the real-time performance and effectiveness of the data.
[0200] The signature request can be any suitable request capable of implementing signature. After receiving the signature request, the processing unit determines the signature nodes according to the message to be processed, and finally returns the output verification nodes to the server. In implementation, the process for the processing unit to determine the signature nodes according to the message to be processed can refer to the specific implementation manners of the foregoing steps S111 to S112.
[0201] In some embodiments, the processing unit may have a built-in processing module dedicated to performing signature operations, key generation operations, and the like.
[0202] In the embodiments of the present application, on the one hand, DMA is used to transfer the message to be processed, reducing the latency of the message to be processed and improving the real-time performance and effectiveness of the message to be processed; on the other hand, the server controls the processing unit to perform signature operations through the processor, so as to make full use of the high-speed processing ability and low latency of the processor, not only improving the overall signature efficiency, but also enhancing the performance and stability of the signature operation.
[0203] The number of verification nodes is adapted to the height of the current Merkle tree, and the verification nodes are different from the signature nodes. In implementation, the process of the processing unit determining the verification nodes can refer to the specific implementation manner of the foregoing step S12.
[0204] In some embodiments, the processing unit 61 is further configured to: when the position index of the first node satisfies a first preset condition, obtain the sibling node of the first node from the target storage location of the target storage block of the storage unit, and send the first node and the sibling node of the first node to the calculation unit, so that the calculation unit determines the parent node of the first node based on the first node and the sibling node of the first node; wherein, the target storage block includes multiple storage locations, the number of the multiple storage locations is adapted to the height of the current Merkle tree, all nodes at the same height in the current Merkle tree correspond to one storage location, and the target storage location is a storage location adapted to the height of the first node.
[0205] Here, the calculation unit can be any suitable unit capable of implementing this function. For example, a hardware circuit, a hash core, etc. The calculation unit is mainly used to determine the parent node of the first node. The calculation unit can be communicatively connected to the processing unit through a bus, hard wire, interface, etc. In implementation, the process of the calculation unit determining the parent node of the first node can refer to the specific implementation manner of the foregoing step S33.
[0206] The first preset condition can be any suitable condition. For example, an odd number, not divisible by 2, etc.
[0207] The storage unit can be any suitable unit capable of implementing a storage function. For example, a random access memory. The storage unit at least includes the target storage block. In some embodiments, different Merkle trees may correspond to different storage blocks or reuse the same storage block. In implementation, the number of storage locations included in the target storage block is adapted to the height of the current Merkle tree. For example, the number of storage locations included in the target storage block is the same as the height of the current Merkle tree. Or, for example, the number of storage locations included in the target storage block is 1 more than the height of the current Merkle tree.
[0208] In some embodiments, the computing unit needs to return the parent node of the first node to the processing unit. The processing unit may first determine whether the parent node of the first node is the root node. If it is not the root node, the parent node of the first node may be used as the new first node, and the next verification node may be output continuously until all the verification nodes of the current Merkle tree are output, so as to ensure the correctness and integrity of the signature of the current Merkle tree.
[0209] In the embodiments of the present application, by setting the number of storage locations to the tree height, compared with the number of storage locations being the total number of leaf nodes, the number of storage locations is greatly reduced, the size of the storage space is reduced, thereby improving the utilization rate of the storage space while reducing the resource consumption.
[0210] In some embodiments, the processing unit 61 is further configured to: when the position index of the first node does not meet the first preset condition, store the first node at the target storage location.
[0211] Here, the target storage location can be used to store at least one node. For example, if the height of the Merkle tree is 3, the target storage location is P0, and the first preset condition is an odd number, then P0 is respectively used to store the nodes (0, 0), (0, 2), (0, 4), (0, 6).
[0212] In the embodiments of the present application, determining whether to store the first node according to the position index of the first node and the first preset condition improves the accuracy of storing the first node.
[0213] Figure 7 It is a schematic flowchart of a signature generation provided by an embodiment of the present application, as Figure 7 shown, the user 71 sends a message to the server 72 and initiates a signature request. The server 72 sends the message to the processing unit 61 through DMA, and at the same time controls the processing unit 61 to execute the signature operation through the processor. The processing unit 61 will repeatedly call the processing module 611 multiple times to respectively determine and output each verification node of each Merkle tree in the supertree, and finally return all the verification nodes to the user 71.
[0214] Figure 8 It is a schematic implementation flowchart of a data processing method provided by an embodiment of the present application Figure 3 as Figure 8 shown, the method includes steps S800 to S811, where:
[0215] Step S800, determine the signature node according to the message to be processed;
[0216] Step S801: Determine at least one verification node according to the signature node;
[0217] Step S802: Obtain a node;
[0218] Here, this node can be sent by other units to the processing unit, or can be actively obtained by the processing unit from other units. These other units can be any suitable units capable of generating nodes.
[0219] Step S803: Determine whether the position index of this node is odd (corresponding to the aforementioned first preset condition). If not, proceed to Step S804; otherwise, proceed to Step S805;
[0220] Step S804: Store this node at the storage location corresponding to the height of this node, and proceed to Step S802;
[0221] Step S805: Obtain the sibling node of this node from the storage location corresponding to the height of this node;
[0222] Step S806: Determine whether this node is a verification node. If so, proceed to Step S807; otherwise, proceed to Step S808;
[0223] Step S807: Output this node, and proceed to Step S808;
[0224] Step S808: Determine the parent node of this node according to this node and the sibling node of this node;
[0225] Step S809: Determine whether the parent node of this node is the root node. If not, proceed to Step S810; otherwise, if so, proceed to Step S811;
[0226] Step S810: Take the parent node of this node as the new node, and proceed to Step S803;
[0227] Step S811: End.
[0228] Next, take Figure 2 the Merkle tree shown as an example to illustrate the process of the generation module of the present application performing the signature operation.
[0229] 1) According to the message to be processed, determine the node (0, 4) as the signature node;
[0230] 2) According to the signature node (0, 4), determine that the verification nodes are node (0, 5), node (1, 3), and node (2, 0) respectively;
[0231] 3) When receiving the node (0, 0), store the node (0, 0) in the storage address P0;
[0232] When receiving node (0, 1), node (1, 0) is obtained by hashing node (0, 0) and node (0, 1), and node (1, 0) is stored at storage address P1;
[0233] When receiving node (0, 2), node (0, 2) replaces node (0, 0) at storage address P0;
[0234] When receiving node (0, 3), node (1, 1) is obtained by hashing node (0, 2) and node (0, 3), node (2, 0) is obtained by hashing node (1, 0) and node (1, 1), and node (2, 0) is stored at storage address P2;
[0235] When receiving node (0, 4), node (0, 4) replaces node (0, 2) at storage address P0;
[0236] When receiving node (0, 5), node (0, 5) is output, and node (1, 2) is obtained by hashing node (0, 4) and node (0, 5), and node (1, 2) replaces node (1, 0) at storage address P1;
[0237] When receiving node (0, 6), node (0, 6) replaces node (0, 4) at storage address P0, and at this time, the refresh of each node stored in the RAM will stop;
[0238] When receiving node (0, 7), node (1, 3) is obtained by hashing node (0, 6) and node (0, 7), node (1, 3) is output, and node (2, 1) is obtained by hashing node (1, 2) and node (1, 3), node (2, 0) is output, and the root node (3, 0) is obtained by hashing node (2, 0) and node (2, 1).
[0239] In some embodiments, the processing unit 61 is further configured to: in response to receiving a key request transmitted by the server through the processor, determine the root node of the supertree corresponding to the current Merkle tree, and use the root node of the supertree as the public key corresponding to the key request.
[0240] Here, the key request can be any suitable request for obtaining a public key. In implementation, the server controls the processing unit to perform the public key generation operation through the processor. When the processing unit generates the public key, it returns it to the server. In some embodiments, if the current Merkle tree is a supertree, then, according to the first node, its parent node is determined until the root node, and the root node of the current Merkle tree is used as the public key; if the current Merkle tree is not a supertree, the root node of the current Merkle tree can be used to sign the leaf nodes of the upper-layer Merkle tree.
[0241] Figure 9A schematic flowchart of public key generation provided by an embodiment of the present application is as follows Figure 9 As shown, user 91 sends a key request to server 72. Server 72 controls processing unit 61 to perform key generation operations through a processor. Processing unit 61 will call processing module 611 once to calculate the root node of the hypertree, and finally return this root node as the public key to user 91.
[0242] In the embodiment of the present application, the corresponding public key is generated in real time according to the key request, improving the security and reliability of the public key.
[0243] Figure 10 A schematic structural diagram of a data processing system provided by an embodiment of the present application is as follows Figure 10 As shown, the data processing system includes processing unit 61, server 72, CPU 73 (corresponding to the aforementioned processor), hash core 74 (corresponding to the aforementioned computing unit), and memory 75 (corresponding to the aforementioned storage unit) located in the algorithm core of post-quantum SPHINCS+. The algorithm core supports DMA and the CPU to transfer data to the algorithm core through the bus, and at the same time externally connects a standard hash core 74 and memory 75 for data operation and storage. Processing unit 61 is an important part of the algorithm core and is used for key generation and signature of the post-quantum SPHINCS+ algorithm. When generating a key, only the root node of the hypertree needs to be calculated, and when signing, both the signature and the root node are calculated, achieving an efficient unity of tree root calculation and signature generation.
[0244] In the embodiment of the present application, on the one hand, at least one verification node is determined in real time according to the signature node, improving the security of the verification node; on the other hand, in the process of determining the parent node of a certain node upward, if the node is a verification node, the node is output first and then its parent node is determined to ensure that the output order of each verification node is in the upward order. The present application does not require additional storage space to separately store each verification node. Compared with the related art that requires additional storage space to store each verification node in the Merkle tree, not only is the storage space reduced, but also in the present application, each verification node has been output in the upward order in the process of determining the parent node upward. Compared with the related art that needs to sequentially read and output each verification node from the additional storage space in the upward order, while ensuring the security of the signature, the resource consumption is reduced and the signature efficiency is improved.
[0245] In some embodiments, multiple nodes of the current Merkle tree include at least two leaf nodes and at least one non-leaf node; the processing unit 61 is further configured to: based on the signature node, determine a second node from at least two leaf nodes, and use the second node as a verification node; in the case where the parent node of the signature node is a non-root node, based on the parent node of the signature node, determine at least one verification node from at least one non-leaf node.
[0246] In some embodiments, the processing unit 61 is further configured to: use the parent node of the signature node as a third node; based on the third node, determine a fourth node from at least one non-leaf node having the same height as the third node, and use the fourth node as a verification node; in the case where the parent node of the third node is a non-root node, use the parent node of the third node as a new third node.
[0247] In some embodiments, the processing unit 61 is further configured to do one of the following: use the sibling node of the signature node as the second node; based on the position index of the signature node, determine the second node from at least two leaf nodes.
[0248] In some embodiments, the processing unit 61 is further configured to: based on the position index of the signature node, determine a target position index; based on the target position index, determine the second node from at least two leaf nodes.
[0249] In some embodiments, the processing unit 61 is further configured to: determine the exclusive OR value between the position index of the signature node and a preset value, and use the exclusive OR value as the target position index.
[0250] In some embodiments, the processing unit 61 is further configured to do one of the following: use the sibling node of the third node as the fourth node; based on the position index of the third node, determine the fourth node from at least one non-leaf node having the same height as the third node.
[0251] In some embodiments, the processing unit 61 is further configured to: determine a first hash value between the first node and the sibling node of the first node; based on the first hash value, determine the parent node of the first node.
[0252] In some embodiments, the processing unit 61 is further configured to: in the case where the first node meets a second preset condition, stop refreshing the target storage block.
[0253] In some embodiments, the processing unit 61 is further configured to: determine a second hash value of the message to be processed; based on the second hash value, determine the signature node from at least two leaf nodes of the current Merkle tree.
[0254] In some embodiments, the processing unit 61 is further configured to: if the first node is a non-root node and a non-verification node, determine the parent node of the first node based on the first node; if the first node is a root node and the current Merkle tree is a super tree, use the first node as the public key.
[0255] The description of the above chip embodiments is similar to the description of the above method embodiments and has similar beneficial effects to those of the method embodiments. For the technical details not disclosed in the chip embodiments of this application, please refer to the description of the method embodiments of this application for understanding.
[0256] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures, or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the appearances of "in one embodiment" or "in an embodiment" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. It should be understood that in various embodiments of the present application, the order numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The serial numbers of the embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0257] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0258] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed with each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be electrical, mechanical, or other forms.
[0259] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units; they may be located in one place or distributed across multiple network units; some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0260] In addition, each functional unit in the embodiments of the present application may be all integrated in a processing unit, or each unit may be separately regarded as a unit alone, or two or more units may be integrated in one unit; the above-mentioned integrated units may be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0261] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including the above method embodiments; and the foregoing storage medium includes: removable storage devices, read-only memory (ROM), magnetic disks, or optical disks and other various media that can store program codes.
[0262] Alternatively, if the above-mentioned integrated units of the present application are implemented in the form of software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application essentially or the part that contributes to the related technology can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. And the foregoing storage medium includes: removable storage devices, ROM, magnetic disks, or optical disks and other various media that can store program codes.
[0263] The above is only the implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all of them should be covered by the protection scope of the present application.
Claims
1. A data processing method, characterized in that, Including: Determine signature nodes from at least two leaf nodes of the current Merkle tree, where the current Merkle tree is a binary tree; Based on the signature nodes, determine at least one verification node from multiple nodes of the current Merkle tree, and the number of the at least one verification node is the same as the height of the current Merkle tree; In the process of determining the parent node of the first node, if the first node is one of the at least one verification nodes, output the first node as the signature of the current Merkle tree, determine the parent node of the first node based on the first node, and if the parent node of the first node is not the root node of the current Merkle tree, use the parent node of the first node as the new first node until the parent node of the first node is the root node of the current Merkle tree; The determining the parent node of the first node based on the first node includes: When the position index of the first node satisfies a first preset condition, obtain the sibling node of the first node from the target storage location of the target storage block, and determine the parent node of the first node based on the first node and the sibling node of the first node; Wherein, the target storage block includes multiple storage locations, the number of the multiple storage locations is adapted to the height of the current Merkle tree, all nodes at the same height in the current Merkle tree correspond to one storage location, and the target storage location is a storage location adapted to the height of the first node.
2. The data processing method according to claim 1, wherein The multiple nodes of the current Merkle tree include the at least two leaf nodes and at least one non-leaf node; The determining at least one verification node from multiple nodes of the current Merkle tree based on the signature nodes includes: Based on the signature nodes, determine a second node from the at least two leaf nodes, and use the second node as a verification node; When the parent node of the signature node is a non-root node, determine at least one verification node from the at least one non-leaf node based on the parent node of the signature node.
3. The data processing method according to claim 2, wherein The determining at least one verification node from the at least one non-leaf node based on the parent node of the signature node includes: Use the parent node of the signature node as a third node; Based on the third node, determine a fourth node from at least one non-leaf node at the same height as the third node, and use the fourth node as a verification node; When the parent node of the third node is a non-root node, use the parent node of the third node as the new third node.
4. The data processing method according to claim 2, wherein The determining a second node from the at least two leaf nodes based on the signature nodes includes one of the following: Use the sibling node of the signature node as the second node; Based on the position index of the signature node, determine the second node from the at least two leaf nodes.
5. The data processing method according to claim 4, wherein The determining the second node from the at least two leaf nodes based on the position index of the signature node includes: Based on the position index of the signature node, determine a target position index; Based on the target position index, determine the second node from the at least two leaf nodes.
6. The data processing method according to claim 5, wherein Determining a target position index based on the position index of the signature node includes: Determining an exclusive OR value between the position index of the signature node and a preset value, and using the exclusive OR value as the target position index.
7. The data processing method according to claim 3, wherein Determining a fourth node from at least one non-leaf node having the same height as the third node based on the third node includes one of the following: Using the sibling node of the third node as the fourth node; Determining the fourth node from at least one non-leaf node having the same height as the third node based on the position index of the third node.
8. The data processing method according to any one of claims 1 to 7, characterized in that Determining the parent node of the first node based on the first node and the sibling node of the first node includes: Determining a first hash value between the first node and the sibling node of the first node; Determining the parent node of the first node based on the first hash value.
9. The data processing method according to any one of claims 1 to 7, characterized in that The data processing method further includes at least one of the following: When the position index of the first node does not meet the first preset condition, storing the first node at the target storage position; When the first node meets the second preset condition, stopping refreshing the target storage block.
10. The data processing method according to any one of claims 1 to 7, characterized in that Determining a signature node from at least two leaf nodes of the current Merkle tree includes: Determining a second hash value of the message to be processed; Determining the signature node from at least two leaf nodes of the current Merkle tree based on the second hash value.
11. The data processing method according to any one of claims 1 to 7, characterized in that The data processing method further includes: If the first node is a non-root node and a non-verification node, determining the parent node of the first node based on the first node; If the first node is a root node and the current Merkle tree is a super tree, using the first node as the public key.
12. A data processing chip, characterized in that, A processing unit is deployed in the data processing chip, where: The processing unit is configured to: determine a signature node from at least two leaf nodes of the current Merkle tree, where the current Merkle tree is a binary tree; determine at least one verification node from multiple nodes of the current Merkle tree based on the signature node, and the number of the at least one verification node is the same as the height of the current Merkle tree; during the process of determining the parent node of the first node, if the first node is one of the at least one verification nodes, using the first node as the signature output of the current Merkle tree, determining the parent node of the first node based on the first node, where the first node is one of the multiple nodes, and when the parent node of the first node is not the root node of the current Merkle tree, using the parent node of the first node as the new first node until the parent node of the first node is the root node of the current Merkle tree; The processing unit is further configured to: when the position index of the first node meets a first preset condition, obtain the sibling node of the first node from the target storage location of the target storage block of the storage unit, and send the first node and the sibling node of the first node to the calculation unit, so that the calculation unit determines the parent node of the first node based on the first node and the sibling node of the first node; wherein, the target storage block includes a plurality of storage locations, the number of the plurality of storage locations is adapted to the height of the current Merkle tree, all nodes at the same height in the current Merkle tree correspond to one storage location, and the target storage location is a storage location adapted to the height of the first node.
13. The data processing chip according to claim 12, characterized in that, The processing unit is further configured to perform at least one of the following: In response to receiving a signature request transmitted by the server through the processor, determine the signature node from at least two leaf nodes of the current Merkle tree based on the message to be processed transmitted by the server through direct memory access; When the position index of the first node does not meet the first preset condition, store the first node in the target storage location.
14. The data processing chip according to claim 12 or 13, wherein The processing unit is further configured to: In response to receiving a key request transmitted by the server through the processor, determine the root node of the supertree corresponding to the current Merkle tree, and use the root node of the supertree as the public key corresponding to the key request.