Data processing method and data processing chip

By parallel computing the nodes and sequential chains of the Merkle tree when the computing unit is idle, the problem of large storage space and poor parallel effects in the SPHINCS+ algorithm is solved, and efficient computing efficiency is improved.

CN119557261BActive Publication Date: 2025-07-22OPEN SECURITY RES INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510123041.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-07-22
Estimated Expiration
2045-01-26

AI Technical Summary

Technical Problem

In the process of implementing the SPHINCS+ algorithm, the existing technology has problems such as large storage space, poor parallel effect and low computing efficiency.

Method used

When the operation unit is idle, the nodes or sequential chains in the Merkle tree are used as operation objects to realize horizontal and vertical parallel operations of nodes and sequential chains, reducing storage space and making full use of the operation unit.

Benefits of technology

Implementing high parallel computing in a smaller storage space improves the utilization rate and parallel effect of the computing unit, thereby improving the computing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119557261B_ABST
    Figure CN119557261B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a data processing method and a data processing chip, including: when the state of the first arithmetic unit is an idle state, determining a first arithmetic object corresponding to the first arithmetic unit, where the first arithmetic unit is any one of at least two arithmetic units, and the first arithmetic object includes one of the following: a first node in a first Merkle tree, a target sequential chain of a second node in the first Merkle tree; using the first arithmetic unit to perform an operation on the first arithmetic object to obtain an operation result. In this way, when any arithmetic unit is in an idle state, using a node or a sequential chain in the Merkle tree as the arithmetic object of the arithmetic unit can not only reduce the storage space, achieve high parallel operations with a smaller storage space, but also make full use of all arithmetic units, improve the utilization rate of the arithmetic units while enhancing the parallel effect, thereby improving the operation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to, but is not limited to, the field of information security technology, and in particular, to a data processing method and a data processing chip. Background Art

[0002] In related technologies, due to the large computational complexity of the SPHINCS+ algorithm, hardware parallelism can be used to improve computational performance. Currently, basically, N leaf nodes in a Merkle tree are simultaneously computed in parallel according to the parallelism degree N. Then, the storage space needs to store all the sequential chains of at least N leaf nodes, resulting in a large storage space. At the same time, in the Merkle tree, since the number of nodes in the upper layer is less than that in the lower layer, when computing the nodes in the upper layer in parallel, the parallelism degree of the nodes in the upper layer will be lower than that of the nodes in the lower layer, resulting in poor parallelism effect and thus reducing the computational efficiency. Summary of the Invention

[0003] Embodiments of this application provide a data processing method and a data processing chip to solve problems such as large storage space, poor parallelism effect, and low computational efficiency in the process of implementing the SPHINCS+ algorithm in related technologies.

[0004] The technical solution of the embodiments of this application is implemented as follows:

[0005] Embodiments of this application provide a data processing method, including:

[0006] When the state of the first arithmetic unit is the idle state, determine the first arithmetic object corresponding to the first arithmetic unit. The first arithmetic unit is any one of at least two arithmetic units, and the first arithmetic object includes one of the following: the first node in the first Merkle tree, the target sequential chain of the second node in the first Merkle tree. The first Merkle tree includes at least two leaf nodes and at least one non-leaf node, and each leaf node includes at least two sequential chains;

[0007] Use the first arithmetic unit to perform an operation on the first arithmetic object to obtain an operation result.

[0008] Embodiments of this application provide a data processing chip, in which a processing unit is deployed, where:

[0009] The processing unit is configured to: when the first arithmetic unit is in an idle state, determine a first arithmetic object corresponding to the first arithmetic unit, where the first arithmetic unit is any one of at least two arithmetic units, and the first arithmetic object includes one of the following: a first node in a first Merkle tree, a target sequence chain of a second node in the first Merkle tree, the first Merkle tree includes at least two leaf nodes and at least one non-leaf node, and each leaf node includes at least two sequence chains; use the first arithmetic unit to perform an operation on the first arithmetic object to obtain an operation result.

[0010] In an embodiment of the present application, when any arithmetic unit is in an idle state, a node or a sequence chain in the Merkle tree is used as the arithmetic object of the arithmetic unit. On the one hand, since each arithmetic unit of the present application can simultaneously perform parallel operations on multiple sequence chains in a leaf node, the present application only needs to store the operation results of the arithmetic objects corresponding to each arithmetic unit, while in the related art, since each arithmetic unit simultaneously performs parallel operations on one sequence chain of multiple leaf nodes, all sequence chains in multiple leaf nodes need to be stored. Therefore, the solution of the present application can reduce the storage space and achieve high parallel operations with a smaller storage space. On the other hand, since each arithmetic unit of the present application can simultaneously perform parallel operations on sequence chains and nodes, the purpose of horizontal parallel operation of sequence chains and vertical parallel operation of nodes is achieved, making full use of all arithmetic units, and the parallelism will not decrease as the height of the node increases. In the related art, since all arithmetic units are used to simultaneously perform parallel operations on sequence chains or nodes, the parallelism will decrease as the height of the node increases. Therefore, the present application improves the utilization rate of arithmetic units while enhancing the parallel effect, thereby improving the operation efficiency.

[0011] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification. These drawings illustrate embodiments consistent with the present application and, together with the specification, are used to explain the technical solutions of the present application.

[0013] Figure 1 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 1 ;

[0014] Figure 2 Schematic diagram of a Merkle tree provided by an embodiment of the present application;

[0015] Figure 3 Schematic diagram of a leaf node provided by an embodiment of the present application;

[0016] Figure 4Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 2 ;

[0017] Figure 5 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 3 ;

[0018] Figure 6 Schematic diagram of the component structure of a data processing chip provided by an embodiment of the present application;

[0019] Figure 7 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 4 ;

[0020] Figure 8 Schematic diagram of the operation process of a Merkle tree provided by an embodiment of the present application;

[0021] Figure 9 Schematic diagram of the component structure of a data processing system provided by an embodiment of the present application. Detailed implementation manners

[0022] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be construed as limiting the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present application.

[0023] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0024] In the following description, the terms "first / second / third" are only used to distinguish similar objects and do not represent a specific order for the objects. It can be understood that "first / second / third" can be interchanged with a specific order or sequence when allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0025] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.

[0026] With the application and development of quantum computers, post-quantum signature algorithms have received extensive attention. Post-quantum signature algorithms are a class of digital signature algorithms designed to resist attacks from quantum computers. They are implemented by using hash functions to improve the efficiency and security of signatures. Post-quantum signature algorithms can provide stronger security guarantees when facing the threats of quantum computing technology. Post-quantum signature algorithms can include, but are not limited to, LMS (Leighton-Micali Signature), Falcon, SPHINCS+, etc.

[0027] The SPHINCS+ algorithm has high security and anti-quantum characteristics and has been selected by NIST as one of the standard algorithms for its post-quantum cryptography standardization program. The SPHINCS+ algorithm is a post-quantum algorithm based on hash operations. It includes multiple XMSS (eXtended Merkle Signature Scheme) trees. The XMSS tree is an extended Merkle tree. Each leaf node of the Merkle tree includes a one-time signature (WOTS, Winternitz One-Time Signature) operation. Therefore, the computational complexity of the SPHINCS+ algorithm is very high.

[0028] In related technologies, due to the high computational complexity of the SPHINCS+ algorithm, the hardware parallel method can be used to improve the computational performance. Currently, common parallel schemes include:

[0029] Scheme 1: First, according to the parallelism N, perform simultaneous operations on a sequential chain in N leaf nodes until all leaf nodes are processed. Then, perform parallel operations on the parent nodes of the leaf nodes until the entire Merkle tree is processed.

[0030] Scheme 2: First, according to the parallelism N, perform simultaneous operations on a sequential chain in N leaf nodes. After the operations of N leaf nodes are completed, take the N leaf nodes as subtrees and perform parallel operations to complete the root calculation of the subtrees (i.e., vertically calculate their parent nodes until it is no longer possible to go up). Then, perform the operations on the remaining leaf nodes, and repeat until the entire Merkle tree is processed;

[0031] Scheme 3: Perform simultaneous operations on N chains. After the Chain operations of all leaf nodes are completed, perform parallel operations on other nodes of the entire Merkle tree horizontally or vertically.

[0032] As can be seen from the above, in all of the first to third solutions, it is necessary to store the operation results of all Chains of at least N leaf nodes, which results in a large storage space. At the same time, in a Merkle tree, since the number of nodes in the upper layer is less than that in the lower layer, when calculating the nodes in the upper layer in parallel, the parallelism of the nodes in the upper layer will be lower than that of the nodes in the lower layer, resulting in a poor parallel effect and thus reducing the operation efficiency.

[0033] An embodiment of the present application provides a data processing method. When any operation unit is in an idle state, a node or a sequential chain in a Merkle tree is used as the operation object of the operation unit. On the one hand, since each operation unit of the present application can simultaneously perform parallel operations on multiple sequential chains in a leaf node, the present application only needs to store the operation results of the operation objects corresponding to each operation unit. In the related art, since each operation unit simultaneously performs parallel operations on one sequential chain of multiple leaf nodes, it is necessary to store all sequential chains in multiple leaf nodes. Therefore, the solution of the present application can reduce the storage space and achieve high parallel operations with a smaller storage space. On the other hand, since each operation unit of the present application can simultaneously perform parallel operations on sequential chains and nodes, the purpose of horizontal parallel operation of sequential chains and vertical parallel operation of nodes is achieved, making full use of all operation units. The parallelism will not decrease as the height of the nodes increases. In the related art, since all operation units are used to simultaneously perform parallel operations on sequential chains or nodes, the parallelism will decrease as the height of the nodes increases. Therefore, the present application improves the parallel effect while improving the utilization rate of operation units, thereby improving the operation efficiency.

[0034] The method provided by the embodiment of the present application can be executed by a data processing chip. Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application.

[0035] Figure 1 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 1 , as Figure 1 shown, the method includes step S11 and step S12, where:

[0036] Step S11: When the state of the first operation unit is an idle state, determine the first operation object corresponding to the first operation unit. The first operation unit is any one of at least two operation units. The first operation object includes one of the following: the first node in the first Merkle tree, the target sequential chain of the second node in the first Merkle tree. The first Merkle tree includes at least two leaf nodes and at least one non-leaf node, and each leaf node includes at least two sequential chains.

[0037] Here, the arithmetic unit can be any suitable unit capable of performing operations, which is mainly used for operations such as key generation and signature. For example, a hash core, a digital circuit, an analog circuit, etc. The arithmetic unit is mainly used for performing hash operations on Chains, nodes, etc. The number of arithmetic units can be any suitable number, for example, 2, 4, 8, etc. In implementation, those skilled in the art can set the number of arithmetic units independently according to actual needs, and the embodiments of the present application do not make limitations. In some embodiments, each arithmetic unit can be integrated into a data processing chip, or can be communicatively connected to the data processing chip through a bus, hard wire, interface, etc. In some embodiments, the number of arithmetic units is not less than the parallelism. For example, the number of arithmetic units is the same as the parallelism. Or, for another example, the number of arithmetic units is greater than the parallelism.

[0038] The state of the arithmetic unit can include but is not limited to an idle state, a working state, etc. Among them, the idle state indicates that the arithmetic unit is not occupied and can be allocated for operations. The working state indicates that the arithmetic unit is currently performing operations. In some embodiments, the state of the arithmetic unit can be determined according to its working identifier, and different values of the working indication are used to represent the state of the arithmetic unit. For example, when the working identifier is a first value, it indicates that the arithmetic unit is in an idle state; when the working identifier is a second value, it indicates that the arithmetic unit is in a working state. In implementation, the value of the working identifier can be represented by any suitable method. For example, the first value is 0 and the second value is 1. Or, for another example, the first value is "TURE" and the second value is "FALSE".

[0039] The Merkle tree (including the first Merkle tree and other Merkle trees in the following text) is a tree-like data structure, usually used to verify the integrity and consistency of large-scale data sets. The Merkle tree is a hash binary tree with a height of h (not less than 1). In computer science, a binary tree is an important data structure, which consists of multiple nodes, and each node has at most two child nodes, which are respectively called the left child node and the right child node. A child node refers to the node connected below a certain node. A parent node refers to the node connected above a certain node.

[0040] The Merkle tree includes at least two leaf nodes and at least one non-leaf node. A leaf node refers to the bottommost node of the binary tree and has no child nodes, and the height of the leaf node is 0. The height of a node refers to the number of edges of the longest simple path from this node to the leaf node. The at least one non-leaf node includes a root node, intermediate nodes, etc. The root node is the top node of the binary tree and has no parent node, and the height of the root node is the height of the tree. An intermediate node refers to the remaining nodes except the root node. The height of this intermediate node is greater than 0 and less than the height of the tree.

[0041] Figure 2 A schematic diagram of a Merkle tree provided by an embodiment of the present application, as Figure 2 shown, the height of the Merkle tree is 3. Then, the Merkle tree includes:

[0042] 8 leaf nodes with a height of 0, namely: node (0, 0), node (0, 1), node (0, 2), node (0, 3), node (0, 4), node (0, 5), node (0, 6), node (0, 7), and each leaf node includes three sequential chains;

[0043] 4 intermediate nodes with a height of 1, namely: node (1, 0), node (1, 1), node (1, 2), node (1, 3);

[0044] 2 intermediate nodes with a height of 2, namely: node (2, 0), node (2, 1);

[0045] 1 root node, namely: node (3, 0).

[0046] The operation objects (including the first operation object and other operation objects) can be any suitable objects in the Merkle tree that need to be operated. For example, nodes, Chains, etc. The first node can be any non-leaf node in the first Merkle tree. The second node can be any leaf node in the first Merkle tree. In implementation, the number of Chains of a node can be any suitable number, such as 3, 5, etc.

[0047] The determination method of the first operation object can be any suitable determination method.

[0048] In some embodiments, based on the first object set, the first operation object can be determined. Among them, the first object set can be empty or include at least one second operation object that has completed the operation. In some embodiments, if the first object set meets the first preset condition, the first node is used as the first operation object; if the first object set does not meet the first preset condition, the target sequential chain of the second node is used as the first operation object. Among them, the first preset condition can be any suitable condition representing the ability to perform vertical upward operations. For example, the first preset condition represents that the first object set includes the first node and the sibling node of the first node.

[0049] In some embodiments, when initializing or when the entire Merkle tree operation is completed, the first object set may be empty. In some embodiments, after the operation of a certain operation object is completed, the first object set may be updated based on the operation object. The update methods may include but are not limited to addition, deletion, etc. For example, after obtaining a certain parent node after the operation is completed, the two child nodes of the parent node may be deleted from the first object set, and the parent node may be added to the first object set. For another example, when a Chain of a certain leaf node is completed, the Chain may be added to the first object set. For still another example, after the operation of a leaf node is completed, all Chains of the leaf node may be deleted from the first object set.

[0050] In some embodiments, the first operation object may be determined based on the operation objects corresponding to all other operation units. For example, according to the operation object corresponding to the third operation unit, the first operation object is determined, and the third operation unit may be the operation unit that has most recently determined the operation object. For example, in the case where the operation object corresponding to the third operation unit is a Chain of a certain leaf node, if the Chain is not the last Chain of the leaf node, then the next Chain of the Chain may be used as the first operation object; if the Chain is the last Chain of the leaf node, then the first Chain of the next leaf node may be used as the first operation object.

[0051] In some embodiments, the first operation object may be determined based on the first object set and the operation objects corresponding to all other operation units. For example, if the first object set is empty and the operation object corresponding to the third operation unit is the first Chain of a certain leaf node, then the second Chain of the leaf node may be used as the first operation object.

[0052] In some embodiments, for the operations of each leaf node in the Merkle tree, the operations may be performed in the order from left to right. For example, in Figure 2 the Merkle tree shown, when the number of operation units is 3, then: First, the three Chains of node (0, 0) may be used as the first operation objects corresponding to the three operation units respectively; after the operation of node (0, 0) is completed, since it is not possible to perform an upward operation, at this time, the three Chains of node (0, 1) may be used as the first operation objects corresponding to the three operation units respectively; after the operation of node (0, 1) is completed, since it is possible to perform an upward operation, at this time, node (0, 1) may be used as the first operation object corresponding to one operation unit, and the two Chains of node (0, 2) may be used as the first operation objects corresponding to the other two operation units... and so on in a loop until the root node to complete the operation of the entire Merkle tree.

[0053] In some embodiments, a first operand is determined according to a chain indication identifier and a node indication identifier. The chain indication identifier is used to identify the Chain of the current latest operation, and the node indication identifier is used to identify the node whose operation has been completed. During implementation, when it is determined that the operand corresponding to a certain operation unit is a Chain, the chain indication identifier is used to identify the Chain; when the operation of a certain node is completed, the node indication identifier is used to represent the node. In this way, the first operand is determined according to these two indication identifiers, shortening the determination duration of the first operand and improving the operation efficiency.

[0054] For example, when the node indication identifier is an even number, the node pointed to by the node indication identifier is used as the first node; when the node indication identifier is an odd number, the first operand is determined according to the chain indication identifier. For example, the next Chain of the Chain currently identified by the chain indication identifier is used as the first operand. During implementation, each sequential chain of each leaf node is arranged from left to right.

[0055] In some embodiments, the first operand may also be empty. For example, when it is impossible to perform vertical upward operations and all Chain operations are completed, at this time, the first operand may be empty. Wait until vertical upward operations can be performed, then re-determine the first node, and use the first node as the first operand corresponding to the first operation unit.

[0056] Step S12: Use the first operation unit to perform an operation on the first operand to obtain an operation result.

[0057] Here, the operation result may include but is not limited to the parent node of the first node, the second node, the chain tail corresponding to the second node, etc. In some embodiments, the chain tail corresponding to the second node is determined based on at least one sequential chain of the completed operation of the second node.

[0058] In some embodiments, if the first operand is the first node, then the operation result is the parent node of the first node. For example, in Figure 2 the Merkle tree shown, if the first operand corresponding to a certain operation unit is the node (0, 1), then the operation result of this operation unit is the parent node (1, 0) of the node (0, 1).

[0059] In some embodiments, if the first operand is the target sequential chain of the second node, then the operation result may be the second node or the chain tail corresponding to the second node. For example, in Figure 2In the Merkle tree shown, if the first operand corresponding to a certain operation unit is the first Chain of node (0, 1), then the operation result of this operation unit is the end of the first Chain of node (0, 1), and the end of the first Chain of node (0, 1) can be used as the corresponding end of node (0, 1); if the first operand corresponding to a certain operation unit is the last Chain of node (0, 2), then the operation result of this operation unit can be node (0, 2).

[0060] In some embodiments, after obtaining the end of a sequential chain of a second node through operation, the end of the sequential chain of the second node can be used to update the corresponding end of the second node. For example, if the second node includes 4 Chains, after obtaining the end of the second Chain through operation, the corresponding end of the second node can be updated according to the end of the second Chain. For example, the corresponding end of the second node and the end of the second Chain are hashed to obtain the updated corresponding end of the second node.

[0061] In some embodiments, when the first operand is not empty, the first operation unit is used to operate on the first operand. At this time, the state of the first operation unit needs to be switched from the idle state to the working state; when the first operand is empty, no operation is required. At this time, the state of the first operation unit does not need to be switched, but remains in the idle state.

[0062] In the embodiments of the present application, when any operation unit is in the idle state, a node or a sequential chain in the Merkle tree is used as the operation object of this operation unit. On the one hand, since each operation unit of the present application can simultaneously and parallelly operate on multiple sequential chains in a leaf node, the present application only needs to store the operation results of the operation objects corresponding to each operation unit. In the related art, since each operation unit simultaneously and parallelly operates on one sequential chain of multiple leaf nodes, all sequential chains in multiple leaf nodes need to be stored. Therefore, the solution of the present application can reduce the storage space and achieve high parallel operation with a smaller storage space. On the other hand, since each operation unit of the present application can simultaneously and parallelly operate on sequential chains and nodes, the purpose of horizontal parallel operation of sequential chains and vertical parallel operation of nodes is achieved, and all operation units are fully utilized. The parallelism will not decrease as the height of the node increases. In the related art, since all operation units are used to simultaneously and parallelly operate on sequential chains or nodes, the parallelism will decrease as the height of the node increases. Therefore, the present application improves the utilization rate of operation units and at the same time enhances the parallel effect, thereby improving the operation efficiency.

[0063] In some embodiments, the step of "determining the first operation object corresponding to the first operation unit based on the first object set" in step S11 includes step S111 and step S112, where:

[0064] Step S111: When the first object set meets the first preset condition, use the first node as the first operation object corresponding to the first operation unit.

[0065] Here, the first preset condition can be any suitable condition representing the ability to perform vertical upward operations. In some embodiments, the first preset condition indicates that the first object set includes the first node and the sibling node of the first node. For example, in Figure 2 the Merkle tree shown, if the first object set includes node (0, 1) (corresponding to the first node) and node (0, 0) (corresponding to the sibling node of the first node), then node (0, 1) is used as the first operation object.

[0066] Step S112: When the first object set does not meet the first preset condition, determine the target order chain of the second node based on the operation objects corresponding to all other operation units except the first operation unit among at least two operation units, and use the target order chain of the second node as the first operation object corresponding to the first operation unit.

[0067] Here, since the first preset condition for vertical upward operations is not met, at this time, the target order chain can be determined according to the operation objects corresponding to other respective operation units. For example, determine the target order chain according to the operation object corresponding to the third operation unit, and the third operation unit can be the operation unit whose operation object was most recently determined. Another example is to determine at least one second operation unit from each operation unit, and determine the target order chain according to the operation objects corresponding to each second operation unit. The operation object corresponding to the second operation unit is a Chain. For example, sort the operation objects corresponding to each second operation unit, and use the next Chain of the operation object corresponding to the target second operation unit as the first operation object. The target second operation unit is the operation unit whose most recently determined operation object is a Chain.

[0068] In the embodiments of the present application, the operation object of the first operation unit is accurately determined according to whether the first object set meets the first preset condition, improving the accuracy of the operation object and thus the operation efficiency.

[0069] In some embodiments, the step of "determining the target order chain of the second node based on the operation objects corresponding to all other operation units except the first operation unit among at least two operation units" in step S112 includes step S1121 and step S1122, where:

[0070] Step S1121: Determine a second operation unit from all other operation units based on the operation objects corresponding to all other operation units.

[0071] Here, the operation object corresponding to the second operation unit is a Chain. The number of the second operation units can be 0 or at least one. For example, during the first parallel operation, when determining the operation object corresponding to the first operation unit, the number of the second operation units is 0. Another example is that after all Chain operations are completed, the number of the second operation units is 0. In implementation, if the operation object corresponding to an operation unit is a Chain, then this operation unit is taken as a second operation unit.

[0072] Step S1122: Determine the target sequence chain of the second node based on the operation object corresponding to the second operation unit.

[0073] Here, the target sequence chain can be any sequence chain in the second node. In implementation, if the number of the second operation units is 0, then the first sequence chain of the first leaf node can be taken as the target sequence chain of the second node; if the number of the second operation units is at least one, then the next Chain of the operation object corresponding to the target second operation unit can be taken as the target sequence chain of the second node, and the target second operation unit is the operation unit whose operation object is newly determined to be a Chain. In some implementation manners, the operation object corresponding to the target second operation unit and the target sequence chain of the second node can be the same node or different nodes. For example, if the operation object corresponding to the target second operation unit is the last Chain of the target node, then the second node is different from the target node; if the operation object corresponding to the target second operation unit is a non-last Chain of the target node, then the second node is the same as the target node.

[0074] In the implementation manner of the present application, the target sequence chain is accurately determined according to the operation objects corresponding to all other operation units, which improves the accuracy of the target sequence chain, thereby ensuring the effectiveness of the operation while improving the operation efficiency.

[0075] In some implementation manners, the data processing method further includes steps S131 to S133, where:

[0076] Step S131: When the operation result is a non-root node, switch the state of the first operation unit to the idle state.

[0077] Here, after the first operation unit completes the operation, it is necessary to recycle the first operation unit in time, that is: switch the state of the first operation unit from the working state to the idle state to facilitate the next operation.

[0078] Step S132: Update the first object set based on the operation result.

[0079] Here, the update method may include, but is not limited to, addition, deletion, etc. For example, when the first operand is the first node, the parent node of the first node can be added to the first object set, and the first node and the sibling nodes of the first node can be deleted from the first object set. Another example is that when the first operand is the target Chain, the target Chain is added to the first object set.

[0080] Step S133: Determine the first operand corresponding to the first operation unit based on the updated first object set.

[0081] Here, the updated first object set is used as the new first object set, and the first operand corresponding to the first operation unit is re-determined according to the new first object set. In implementation, the determination process of the new first operand can refer to the specific implementation manner of the foregoing step S11.

[0082] In the embodiments of the present application, first, by promptly switching the state of the first operation unit to the idle state, it is convenient for the first operation unit to then process the next operand, thereby improving the operation efficiency; second, the first object set is updated in a timely manner according to the operation result of the first operation unit to improve the accuracy of the operation unit in determining the corresponding operand; finally, the operands corresponding to each operation unit are determined in a cyclic manner to ensure the accuracy and integrity of the entire Merkle tree operation.

[0083] In some embodiments, when the operation result is the second node and the second node is a signature node, the data processing method further includes step S141 and step S142, where:

[0084] Step S141: Obtain the hash values of the signature operation nodes corresponding to at least two sequential chains of the second node from the chain storage block.

[0085] Here, the signature node can be any leaf node. Each leaf node of this Merkle tree is a one-time key, which is used to generate a public key for the child nodes of the outer structure. In implementation, the signature node can be a certain leaf node among the unused one-time keys.

[0086] The determination method of the signature node can be any suitable method. In some embodiments, a certain leaf node can be used as the signature node according to custom configuration information. In some embodiments, a certain leaf node can be randomly selected from the leaf nodes of multiple unused one-time keys as the signature node. In some embodiments, according to the usage order of each leaf node, the adjacent leaf node of the previous signature node can be used as the signature node. Among them, the usage order can include but is not limited to from left to right, from right to left, etc. For example, the Merkle tree includes 8 leaf nodes, and the 3rd leaf node was used as the signature node last time, then this time the 4th leaf node can be used as the signature node. In some embodiments, the signature node can be determined according to the message to be processed. The message to be processed can be a piece of message sent by the client. In implementation, those skilled in the art can independently select the determination method of the signature node according to actual needs, and the embodiments of the present application do not make limitations.

[0087] The chain storage block includes at least two storage locations. In some embodiments, the number of storage locations of the chain storage block is adapted to the number of at least two sequential chains of leaf nodes, and each sequential chain can correspond to a storage location. For example, if the leaf nodes include three Chains, then the chain storage block can include 3 storage locations, each Chain corresponds to a storage location, and each storage location is used to store the hash value of the signature operation node in the corresponding Chain.

[0088] Each Chain includes a plurality of operation nodes connected in sequence. In implementation, the number of operation nodes can be any suitable number, such as 8, 16, 24, etc. The number of operation nodes included in each Chain is the same. The hash value of the operation node can include but is not limited to the hash value of the operation node, the hash value obtained by performing a hash operation on the hash value of the previous operation node, etc. For example, the hash value of the first operation node is the hash value obtained by performing a hash operation on the first operation node, and the hash values of other operation nodes are the hash values obtained by performing a hash operation on the hash value of the previous operation node. Among them, the first operation node can be determined according to a random number generated by the private key. For example, the random number generated by the private key is used as the first operation node. Another example is that the random number generated by the private key is weighted and then used as the first operation node.

[0089] The signature operation node is an operation node in the Chain. The positions of the signature operation nodes corresponding to different Chains are different.

[0090] Figure 3 A schematic diagram of a leaf node provided by an embodiment of the present application is as Figure 3As shown in the figure, the leaf node includes 16 Chains, namely: Chain0 to Chain15. Each Chain includes 16 operation nodes. Then: The signature operation node corresponding to Chain0 can be the first operation node (0, 0), the signature operation node corresponding to Chain1 can be the second operation node (1, 1)... The signature operation node corresponding to Chain15 can be the last operation node (15, 15). In some embodiments, the starting points of the 16 Chains of Chain0 to Chain15 can be 16 random numbers generated based on the private key. Each Chain performs 16 hash operations to obtain the corresponding chain tail (i.e., the hash value of the last operation node).

[0091] In some embodiments, during the process of Chain operation, after determining the hash value of the signature operation node, the hash value of the signature operation node can be directly output, or the hash value of the signature operation node can be stored in the chain storage block.

[0092] Step S142: Use the hash values of the signature operation nodes corresponding to at least two sequential chains of the second node as the signature output.

[0093] Here, the hash values of each signature operation node can be output sequentially, or the hash values of each signature operation node can be concatenated and then output.

[0094] In the embodiments of the present application, during the signature process, by timely outputting the hash values of the signature operation nodes in each sequential chain of the signature node, the accuracy and integrity of the signature are ensured, thereby improving the signature efficiency.

[0095] In some embodiments, the data processing method further includes step S151 and step S152, where:

[0096] Step S151: Receive the signature sent by the sender; where the signature includes the hash values of the signature operation nodes corresponding to at least two sequential chains of the third node in the second Merkle tree.

[0097] Here, the operation unit can also verify the signature sent by the sender. The signature can be generated by the sender, and the generation process of the signature is similar to the aforementioned signature generation process. The signature of the sender at least includes the hash values of each signature operation node.

[0098] Step S152: Determine the verification result corresponding to the signature based on the hash values of the signature operation nodes corresponding to at least two sequential chains of the third node.

[0099] Here, the signature verification result may include, but is not limited to, the first signature verification result, the second signature verification result, etc. The first signature verification result indicates successful verification, and the second signature verification result indicates failed verification. Based on this signature, not only can the identity of the sender be verified, but also the integrity of the message can be determined.

[0100] In some embodiments, the hash values of each signature operation node can be used as the starting point of the corresponding Chain. Each Chain performs M (not less than 0) hash operations to obtain the end of each Chain, and the signature verification result is determined according to the end of each Chain. The number of hash operations performed by each Chain is different. During implementation, the number of hash operations can be determined according to the starting point of the Chain and the number of operation nodes of the Chain. For example, in Figure 3 the leaf nodes shown, the number of operation nodes of the Chain is 16. Then each Chain needs to perform 16 - X hash operations, where X refers to the position where the starting point of the Chain is located, that is:

[0101] Since the signature operation node corresponding to Chain0 is the first operation node, then, this Chain0 needs to perform 16 hash operations;

[0102] Since the signature operation node corresponding to Chain1 is the second operation node, then, this Chain1 needs to perform 15 hash operations;

[0103] ……

[0104] Since the signature operation node corresponding to Chain14 is the 15th operation node, then, this Chain14 needs to perform 1 hash operation;

[0105] Since the signature operation node corresponding to Chain15 is the last operation node, then, this Chain15 needs to perform 0 hash operations, that is, the hash value of the signature operation node corresponding to Chain15 is used as the end of the Chain.

[0106] In the embodiments of the present application, during the signature verification process, the hash values of each signature operation node are verified to obtain the corresponding signature verification result, so as to ensure the accuracy and integrity of the signature verification, thereby improving the signature verification efficiency.

[0107] In some embodiments, this step S152 includes steps S1521 to S1523, where:

[0108] Step S1521, for each sequential chain of at least two sequential chains of the third node, based on the hash value of the signature operation node corresponding to the sequential chain, determine the end of the sequential chain.

[0109] Here, performing the hash operation M times on the hash value of the signature operation node can obtain the end of the chain of the Chain, where M is an integer not less than 0. For example, for the last Chain, since the signature operation node corresponding to this Chain is the last operation node, then the hash value of this signature operation node can be used as the end of the Chain; for non-last Chains, the hash value of the signature operation node can be repeatedly hashed to obtain the end of the Chain.

[0110] Step S1522: Determine the second public key based on the end of each sequential chain of the third node.

[0111] Here, the second public key may include but is not limited to the first hash value, the weighting of the first hash value, etc. The first hash value refers to the hash value obtained by hashing the end of each Chain. For example, the first hash value is used as the second public key.

[0112] Step S1523: Determine the verification result corresponding to the signature based on the second public key and the third public key sent by the sender.

[0113] Here, the second public key and the third public key are compared to obtain the verification result. In implementation, if the second public key and the third public key are the same, the first verification result is used as the verification result; otherwise, the second verification result is used as the verification result.

[0114] In the embodiment of the present application, during the verification process, the verification result is obtained by comparing the public key obtained from the end of each sequential chain with the public key sent by the sender, which improves the accuracy of the verification result and thus improves the verification efficiency.

[0115] Figure 4 Schematic diagram of the implementation process of a data processing method provided by an embodiment of the present application Figure 2 , as Figure 4 shown, the method includes step S41 and step S43, where:

[0116] Step S41: When the state of the first operation unit is the idle state, determine the first operation object corresponding to the first operation unit. The first operation unit is any one of at least two operation units, and the first operation object includes one of the following: the first node in the first Merkle tree, the target sequential chain of the second node in the first Merkle tree. The first Merkle tree includes at least two leaf nodes and at least one non-leaf node, and each leaf node includes at least two sequential chains.

[0117] Here, the above step S41 corresponds to the foregoing step S11, and in implementation, the specific implementation manner of the foregoing step S11 can be referred to.

[0118] Step S42: When the first operand is the first node, obtain the sibling node of the first node from the first storage location of the node storage block; wherein, the node storage block includes multiple storage locations, the number of storage locations of the node storage block is adapted to the height of the first Merkle tree, all nodes at the same height in the first Merkle tree correspond to one storage location, and the first storage location is the storage location adapted to the height of the first node.

[0119] Here, the node storage block can be a section of storage space in a storage unit. Among them, the storage unit can be any suitable unit capable of implementing the storage function. For example, a random access memory. In some embodiments, different Merkle trees can correspond to different node storage blocks or share the same node storage block. During implementation, the node storage block can be reused to further reduce the storage space requirements; or the node storage block can not be reused to improve the independence of the values of each node, thereby reducing the possibility of data anomalies.

[0120] In some embodiments, the number of storage locations included in the node storage block is adapted to the height of the first Merkle tree. For example, if the height of the first Merkle tree is 3, then the number of storage locations can be 3, that is: 8 leaf nodes at height 0 share one storage location P0, 4 intermediate nodes at height 1 share one storage location P1, and 2 intermediate nodes at height 2 share one storage location P2.

[0121] In some embodiments, when calculating any node of the Merkle tree, once its parent node is calculated, its child node is no longer needed. Then, the storage location occupied by the child node can store the values of other child nodes at the same height, and only one storage location in the node storage block is required for the same node height.

[0122] For example, in Figure 2 the Merkle tree shown, for any node (i, j), when j is even, store the node (i, j) in the storage location p = i. Once its right node (i, j + 1) is generated, their parent node (i + 1, j / 2) can be calculated by hashing the node (i, j) and its right node (i, j + 1). At this time, the storage location p = i can be used to store other nodes at the same height. Among them, both i and j are integers not less than 0, i is the height of the node, and j is the position index of the node. The position index of the node refers to the position of the node in the binary tree. Usually, the position index of the leftmost node is 0, and this position index increases sequentially from left to right.

[0123] Step S43: Use the first arithmetic unit to calculate the first node and the sibling node of the first node to obtain the parent node of the first node.

[0124] Here, a hash operation is performed between the first node and the sibling node of the first node to obtain a second hash value, and the parent node of the first node is determined according to the second hash value. For example, the second hash value is used as the parent node of the first node. Another example is that the weighted value of the second hash value is used as the parent node of the first node.

[0125] In the embodiments of the present application, by setting the number of storage positions of the node storage block to the tree height, compared with the number of storage positions being the total number of leaf nodes, the number of storage positions is greatly reduced, the size of the storage space is reduced, thereby improving the utilization rate of the storage space while reducing resource consumption.

[0126] In some embodiments, when the parent node of the first node is a non-root node, the data processing method further includes step S44, where:

[0127] Step S44: When the position index of the parent node of the first node meets the second preset condition, store the parent node of the first node in the second storage position of the node storage block; where the second storage position is a storage position adapted to the height of the parent node of the first node.

[0128] Here, the second preset condition can be any suitable condition. For example, an even number, divisible by 2, etc. The second storage position can be used to store at least one node. For example, in Figure 2 the Merkle tree shown, if the second storage position is P1 and the second preset condition is an odd number, the P1 is respectively used to store the node (1, 0) and the node (1, 2).

[0129] In some embodiments, when the position index of the parent node of the first node does not meet the second preset condition, it indicates that the vertical upward operation can continue. At this time, the parent node of the first node can be used as the new first node, and step S43 is continued until the vertical upward operation cannot be performed.

[0130] In the embodiments of the present application, determining whether to store the parent node of the first node according to the position index of the parent node of the first node and the second preset condition improves the accuracy of storing the parent node of the first node.

[0131] Figure 5 Schematic of the implementation process of a data processing method provided by an embodiment of the present application Figure 3 , as Figure 5 shown, the method includes step S51 and step S53, where:

[0132] Step S51, when the state of the first operation unit is an idle state, determine the first operation object corresponding to the first operation unit, the first operation unit is any one operation unit of at least two operation units, and the first operation object includes one of the following: the first node in the first Merkle tree, the target sequence chain of the second node in the first Merkle tree, the first Merkle tree includes at least two leaf nodes and at least one non-leaf node, and each leaf node includes at least two sequence chains.

[0133] Here, the above step S51 corresponds to the above step S11. When implementing, please refer to the specific implementation of the above step S11.

[0134] Step S52: When the first operation object is the target sequence chain of the second node, use the first operation unit to operate on the target sequence chain of the second node to obtain the tail of the target sequence chain of the second node.

[0135] Here, the target Chain includes multiple computing nodes connected in sequence. In implementation, the first computing unit can be used to perform multiple hash operations on multiple computing nodes of the target Chain to obtain the tail of the target Chain.

[0136] Step S53: Determine the operation result based on the tail of the target sequence chain of the second node.

[0137] Here, the operation result may include but is not limited to the second node, the tail of the chain corresponding to the second node, etc. The tail of the chain corresponding to the second node is determined based on at least one sequence chain of the completed operation of the second node. In implementation, the tail of the chain corresponding to the second node may be the tail of a chain or the hash value of the tails of multiple chains.

[0138] In the embodiment of the present application, the calculation result is determined according to the tail of the target sequence chain of the second node, which improves the accuracy of the calculation result and thus improves the calculation efficiency.

[0139] In some implementations, the target sequence chain of the second node includes a plurality of computing nodes connected in sequence, and step S52 includes steps S521 to S523, wherein:

[0140] Step S521: Use the first operation unit to perform a hash operation on a first operation node among the multiple operation nodes to obtain a hash value of the first operation node.

[0141] Here, the first operation node is determined based on a random number generated from a private key. For example, the random number is used as the hash value of the first operation node. Another example is that the weighted value of the random number is used as the hash value of the first operation node. In some embodiments, any suitable hash function can be used for the hash operation.

[0142] Step S522: For each operation node among the multiple operation nodes except the first operation node, use the first operation unit to determine the hash value of the operation node based on the hash value of the previous operation node of the operation node.

[0143] Here, for non-first operation nodes, the determination methods of the hash values of the remaining operation nodes may include, but are not limited to, the third hash value, the weighting of the third hash value, etc. The third hash value refers to the hash value obtained by performing a hash operation on the hash value of the previous operation node.

[0144] Step S523: Use the hash value of the last operation node among the multiple operation nodes as the tail of the target sequence chain of the second node.

[0145] Here, use the hash value of the last operation node as the tail of the target Chain. For example, in Figure 3 In the leaf nodes shown, for Chain0, 16 hash operations can be performed on the operation node (0, 0) to obtain the hash value of the node (0, 15), and use the hash value of the node (0, 15) as the tail of Chain0.

[0146] In the embodiments of the present application, determining the tail of the target sequence chain according to the hash values of each operation node improves the accuracy of the tail, thereby improving the operation efficiency.

[0147] In some embodiments, when the second node is a signature node, the data processing method further includes Step S541 and Step S542, where:

[0148] Step S541: Determine the signature operation node corresponding to the target sequence chain from the multiple operation nodes of the target sequence chain of the second node.

[0149] Here, the signature operation node is an operation node in the target Chain. The positions of the signature operation nodes corresponding to different target Chains are different.

[0150] The determination method of the signature operation node can be any suitable method, such as random, sequential, custom, etc. For example, in Figure 3Among the leaf nodes shown, in order, the signature operation node corresponding to Chain0 can be the first operation node (0, 0), the signature operation node corresponding to Chain1 can be the second operation node (1, 1)... The signature operation node corresponding to Chain15 can be the last operation node (15, 15).

[0151] Step S542: Store the hash value of the signature operation node corresponding to the target sequential chain in the third storage location of the chain storage block; wherein, the chain storage block includes at least two storage locations, the number of storage locations of the chain storage block is adapted to the number of at least two sequential chains, each sequential chain corresponds to one storage location, and the third storage location is adapted to the storage location corresponding to the target sequential chain.

[0152] Here, each Chain corresponds to one storage location, and each storage location is used to store the hash value of the signature operation node in the corresponding Chain.

[0153] In the embodiment of the present application, by setting the number of storage locations of the chain storage block to be adapted to the total number of sequential chains of the nodes, compared with the case where the number of storage locations is for all sequential chains, the number of storage locations is greatly reduced, and the size of the storage space is further reduced, thereby improving the utilization rate of the storage space while reducing resource consumption.

[0154] In some embodiments, step S53 includes step S531 and step S532, wherein:

[0155] Step S531: When the target sequential chain of the second node is the first sequential chain of the second node, use the chain tail of the target sequential chain of the second node as the chain tail corresponding to the second node, and use the chain tail corresponding to the second node as the operation result.

[0156] Here, for the first Chain in the node, the chain tail of this Chain can be used as the chain tail corresponding to the node. For example, in Figure 3 the leaf nodes shown, the chain tail of Chain0 can be used as the chain tail corresponding to the leaf node first.

[0157] Step S532: When the target sequential chain of the second node is other sequential chains of the second node, obtain the chain tail corresponding to the second node from the fourth storage location of the chain tail storage block, and use the first operation unit to perform an operation on the chain tail corresponding to the second node and the chain tail of the target sequential chain of the second node to obtain the operation result; wherein, the chain tail storage block includes at least one storage location, the number of storage locations of the chain tail storage block is determined based on the number of at least two sequential chains of the second node and the number of at least two operation units, and all sequential chains of one node correspond to one storage location.

[0158] Here, the tail storage block is at least used to store the tails of each leaf node. The number of storage locations included in the tail storage block can be any suitable number. For example, 4, 8, etc. In some embodiments, the number of storage locations of the tail storage block can be adapted to the total number of leaf nodes. For example, in the Figure 2 Merkle tree shown, the Merkle tree includes 8 leaf nodes. Then, the tail storage block can also include 8 storage locations, and each storage location is used to store the tail corresponding to a leaf node.

[0159] In some embodiments, the number of storage locations of the tail storage block can be adapted to the total number of arithmetic units and the number of Chains included in the node. For example, if the total number of arithmetic units is 4 and the node includes 3 Chains, then the tail storage block can also include at least two storage locations. Another example is that if the total number of arithmetic units is 4 and the node includes 4 Chains, then the tail storage block can also include at least one storage location. In implementation, by reusing the storage locations of the tail storage block, the storage of the tails corresponding to multiple leaf nodes is realized.

[0160] The operation result can include but is not limited to the second node, the tail corresponding to the second node, etc. In implementation, if the target Chain is not the last Chain, then the operation result can be the tail corresponding to the second node; if the target Chain is the last Chain, then the operation result can be the second node.

[0161] In the embodiments of the present application, on the one hand, determining the operation result according to the position of the target sequential chain improves the accuracy of the operation result; on the other hand, determining the number of storage locations of the tail storage block in real time according to the number of sequential chains included in the node and the parallelism, compared with the number of storage locations for all leaf nodes, greatly reduces the number of storage locations, further reducing the size of the storage space, thereby improving the utilization rate of the storage space while reducing resource consumption.

[0162] In some embodiments, when the first operation object is the last sequential chain of the second node, the operation result includes the second node, and the data processing method further includes step S551 and / or step S552, where:

[0163] Step S551, when the position index of the second node meets the second preset condition, store the second node to the fifth storage location of the node storage block, and the fifth storage location is a storage location adapted to the height of the second node.

[0164] Here, the second preset condition can be any suitable condition. For example, an even number, divisible by 2, etc. In implementation, if the position index of the second node meets this second preset condition, the second node needs to be stored in the fifth storage location. In some implementation manners, only one storage location in the node storage block is required for the same node height, then this fifth storage location is the storage location corresponding to the leaf node. For example, in Figure 2 the Merkle tree shown in

[0165] Step S552, when the second node is the node corresponding to the key request, use the second node as the first public key.

[0166] Here, the key request can be any suitable request for obtaining a public key. In implementation, different key requests correspond to different leaf nodes, and one leaf node can only be used to generate a public key once. The determination method of the node corresponding to the key request can be any suitable method, such as random, sequential, custom, etc.

[0167] In the implementation manners of the present application, the second node is processed according to whether the position index of the second node meets the second preset condition, whether the second node is the node corresponding to the key request, etc., improving the accuracy and reliability of the processing of the second node.

[0168] In some implementation manners, when the first operand is the non-last sequential chain of the second node, this data processing method further includes step S561, where:

[0169] Step S561, store the chain tail corresponding to the second node in the fourth storage location of the chain tail storage block.

[0170] Here, when the target Chain is not the last Chain, it is necessary to store the chain tail corresponding to the second node until the second node is calculated.

[0171] In the implementation manners of the present application, it is determined whether to store the chain tail corresponding to the second node according to whether the first operand is the last sequential chain, improving the accuracy of the chain tail storage of the second node.

[0172] Based on the above embodiments, the embodiments of the present application further provide a data processing chip, Figure 6 which is a schematic diagram of the composition structure of a data processing chip provided by the embodiments of the present application. As Figure 6 shown, a processing unit 61 is deployed in this data processing chip 60, where:

[0173] The processing unit 61 is configured to: when the state of the first arithmetic unit is the idle state, determine a first arithmetic object corresponding to the first arithmetic unit, where the first arithmetic unit is any one of at least two arithmetic units, and the first arithmetic object includes one of the following: a first node in the first Merkle tree, a target sequence chain of a second node in the first Merkle tree, the first Merkle tree includes at least two leaf nodes and at least one non-leaf node, and each leaf node includes at least two sequence chains; use the first arithmetic unit to perform an operation on the first arithmetic object to obtain an operation result.

[0174] Here, the processing unit can be any suitable hardware unit capable of implementing this function. For example, digital circuits, analog circuits, etc.

[0175] The arithmetic unit can be any suitable unit capable of performing operations. This arithmetic unit is mainly used for operations such as key generation, signature, and signature verification. For example, hash cores, digital circuits, analog circuits, etc. The state of the arithmetic unit can include but is not limited to the idle state, working state, etc. In some embodiments, the processing unit is externally connected to at least two arithmetic units, and during implementation, the arithmetic units are communicatively connected to the processing unit through buses, hardwires, interfaces, etc.

[0176] The first arithmetic object can be any suitable object in the Merkle tree that needs to be operated on. For example, nodes, Chains, etc. During implementation, the process by which the processing unit determines the first arithmetic object can refer to the specific implementation manner of the foregoing step S11.

[0177] The operation result can include but is not limited to the parent node of the first node, the second node, the chain tail corresponding to the second node, etc. During implementation, the process by which the processing unit determines the operation result can refer to the specific implementation manners of the foregoing step S12, step S42 to step S43, or step S52 to step S53.

[0178] In some embodiments, the processing unit 61 is further configured to: in response to receiving a signature request transmitted by the server through the processor, based on the message to be processed transmitted by the server through direct memory access, determine a signature node from at least two leaf nodes of the first Merkle tree; when the operation result is the second node and the second node is the signature node, obtain the hash values of the signature operation nodes corresponding to at least two sequence chains of the second node from the chain storage block, and use the hash values of the signature operation nodes corresponding to at least two sequence chains of the second node as the signature output.

[0179] Here, the server can be any suitable unit capable of implementing this function. For example, an electronic device.

[0180] The processor can be any suitable processor capable of implementing this function. For example, a CPU (Central Processing Unit), a DSP (Digital Signal Processing), etc. The processor can be communicatively connected to the processing unit through a bus, hardwiring, an interface, etc.

[0181] The message to be processed can include any suitable content.

[0182] Direct Memory Access (DMA) is a function provided by some computer bus architectures. It enables data to be sent directly from an attached device (such as a disk drive) to the memory of the computer motherboard, reducing data latency and improving the real-time performance and effectiveness of the data.

[0183] The determination method of the signature node can be any suitable method. In some embodiments, a hash operation can be performed on the message to be processed to obtain the hash value of the message to be processed, and several bits are selected from the hash value of the message to be processed to determine the signature node. For example, the leaf node adapted to the several bits is used as the signature node.

[0184] The signature request can be any suitable request capable of implementing signature. After receiving the signature request, the processing unit determines the signature node according to the message to be processed, and finally returns the hash values of the output signature operation nodes to the server.

[0185] In some embodiments, the processing unit can have a built-in processing module dedicated to performing signature operations, key generation operations, signature verification operations, etc.

[0186] In the embodiments of the present application, on the one hand, DMA is used to transfer the message to be processed, reducing the latency of the message to be processed and improving the real-time performance and effectiveness of the message to be processed; on the other hand, the server controls the processing unit to perform signature operations through the processor, making full use of the high-speed processing ability and low latency of the processor, not only improving the overall signature efficiency, but also enhancing the performance and stability of the signature operation.

[0187] In some embodiments, when the first operand is the first node, the operation result includes the parent node of the first node; the processing unit 61 is further configured to: obtain the sibling node of the first node from the first storage location of the node storage block in the storage unit, and send the first node and the sibling node of the first node to the first operation unit, so that the first operation unit performs an operation on the first node and the sibling node of the first node to obtain the parent node of the first node; wherein, the node storage block includes a plurality of storage locations, the number of storage locations in the node storage block is adapted to the height of the first Merkle tree, all nodes at the same height in the first Merkle tree correspond to one storage location, and the first storage location is a storage location adapted to the height of the first node.

[0188] Here, the storage unit can be any suitable unit capable of implementing a storage function. For example, a random access memory. The storage unit at least includes the node storage block. In some embodiments, different Merkle trees can correspond to different node storage blocks or share the same node storage block. In implementation, the number of storage locations included in the node storage block is adapted to the height of the first Merkle tree.

[0189] In some embodiments, the first operation unit needs to return the parent node of the first node to the processing unit. The processing unit can first determine whether the parent node of the first node is the root node. If it is a non-root node and the position index does not meet the second preset condition, the parent node of the first node can be used as the new first node, and continue to perform vertical upward operations until no upward operation can be performed; if it is a non-root node and the position index meets the second preset condition, the parent node of the first node is stored in the second storage location of the node storage block, and the second storage location is a storage location adapted to the height of the parent node of the first node.

[0190] In the embodiments of the present application, by setting the number of storage locations in the node storage block to the tree height, compared with the number of storage locations being the total number of leaf nodes, the number of storage locations is greatly reduced, the size of the storage space is reduced, thereby improving the utilization rate of the storage space while reducing resource consumption.

[0191] Figure 7 Schematic of the implementation process of a data processing method provided for an embodiment of the present application Figure 4 , such as Figure 7 shown, the method includes steps S700 to S714, wherein:

[0192] Step S700, start;

[0193] Step S701, when the state of the first operation unit is the idle state, determine the first operation object corresponding to the first operation unit;

[0194] Step S702: When the first operand is the first node, obtain the sibling node of the first node from the node storage block, and use the first arithmetic unit to perform a hash operation on the first node and its sibling node to obtain the parent node of the first node;

[0195] Step S703: Determine whether the parent node of the first node is the root node. If so, proceed to step S714; otherwise, proceed to step S704;

[0196] Step S704: Determine whether the position index of the parent node of the first node is even (corresponding to the aforementioned second preset condition). If so, proceed to step S705; if not, proceed to step S706;

[0197] Step S705: Store the parent node of the first node in the second storage location of the node storage block, and proceed to step S701;

[0198] Step S706: Take the parent node of the first node as the new first node, and proceed to step S702;

[0199] Step S707: When the first operand is the target sequence chain of the second node, use the first arithmetic unit to perform a hash operation on the target sequence chain of the second node to obtain the tail of the target sequence chain of the second node;

[0200] Step S708: Determine whether the target sequence chain of the second node is the first sequence chain. If so, proceed to step S709; if not, proceed to step S710;

[0201] Step S709: Take the tail corresponding to the second node as the operation result, and store the tail corresponding to the second node in the fourth storage location of the tail storage block, and proceed to step S701;

[0202] Step S710: Determine whether the target sequence chain of the second node is the last sequence chain. If so, proceed to step S711; if not, proceed to step S712;

[0203] Step S711: Take the second node as the operation result, and proceed to step S701;

[0204] Step S712: Determine whether the position index of the second node is even. If so, proceed to step S713; if not, proceed to step S701;

[0205] Step S713: Store the second node in the fifth storage location of the node storage block, and proceed to step S701;

[0206] Step S714: End.

[0207] According to the characteristics of horizontal data independence and vertical data dependence, this application implements the operation of the SPHINCS+ algorithm by using the parallel order chain of node integration and the pipeline of the Merkle tree. Generally speaking, the entire XMSS tree (an extended Merkle tree) is regarded as a whole, and the parallel operations of the Chain are executed in parallel. When a certain leaf node is completed, it is preferentially used for the node operations upward in the Merkle tree. After completion, the Chain operation continues until all node operations are completed.

[0208] The following takes the operation of two operation units (operation unit A and operation unit B) Figure 2 The Merkle tree shown as an example to illustrate the implementation process of the technical solution of this application.

[0209] Figure 8 It is a schematic diagram of the operation process of a Merkle tree provided by an embodiment of this application, as Figure 8 shown:

[0210] In the S1 stage, the two operation units continue to perform parallel operations on the two Chains of node (0, 0) simultaneously, that is: operation unit A operates on the first Chain of node (0, 0), and operation unit B operates on the second Chain of node (0, 0);

[0211] In the S2 stage, the two operation units continue to perform parallel operations on two Chains simultaneously, that is: operation unit A operates on the third Chain of node (0, 0), and operation unit B operates on the first Chain of node (0, 1);

[0212] In the S3 stage, operation unit A is used to operate on node (0, 0) according to the end of the third Chain of node (0, 0), and operation unit B is used to operate on the second Chain of node (0, 1);

[0213] In the S4 stage, since the node operation is faster than the operation of the sequential chain, therefore, operation unit A is used to operate on the third Chain of node (0, 1), and operation unit B continues to be used to operate on the second Chain of node (0, 1);

[0214] In the S5 stage, since the three Chains of node (0, 1) have all been operated to obtain node (0, 1), then, operation unit A is used to operate on node (0, 0) and node (0, 1), and operation unit B is used to operate on the first Chain of node (0, 2);

[0215] ……

[0216] And so on until all operations are completed. During implementation, when there are idle computing units, they immediately enter the operation. It is judged whether upward operation can be performed currently. If upward operation cannot be performed, this computing unit is assigned to perform the Chain operation. After completing a Chain operation, resources are recycled, and the status of this computing unit is returned to the idle state, and the next judgment is entered. If upward operation can be performed, this computing unit is assigned to the node operation. After completing a node operation, it is judged whether this node is the root node. If not, resources are recycled, and the status of this computing unit is returned to the idle state, and the next judgment is entered. If multiple nodes can be executed continuously, this computing unit will perform the node operation multiple times until it cannot go upward and then enter the Chain operation. If this node is the root node, the operation of the entire XMSS tree is completed.

[0217] It can be seen from this that the parallelism of this application can be any suitable parallelism. The overall operation logic is consistent (prioritizing vertically and then horizontally), the storage space is small, and during the entire operation process, only the number of chains executed at the end does not match the parallelism, and the order of execution from the last leaf node to the root node. The operations at other times are all parallel, and the parallel performance is efficient.

[0218] In some embodiments, the processing unit 61 is further configured to: in response to receiving a key request transmitted by the server through the processor, determine the key node corresponding to the key request; in the case where the second node is the key node, use the second node as the first public key.

[0219] Here, the key request can be any suitable request for obtaining a public key. During implementation, the server controls the processing unit to perform the public key generation operation through the processor. When the processing unit generates the first public key, it returns it to the server.

[0220] Figure 9 FIG. is a schematic structural diagram of a composition of a data processing system provided by an embodiment of this application, as Figure 9 shown. The data processing system includes a processing unit 61 located in the algorithm core of the post-quantum SPHINCS+, a server 92, a CPU 93 (corresponding to the aforementioned processor), a hash core 94 having at least two computing units, and a memory 95 (corresponding to the aforementioned storage unit). The algorithm core supports DMA and the CPU to transfer data to the algorithm core through the bus. At the same time, an external standard hash core 94 and memory 95 are used for data operation and storage. The processing unit 61 is an important part of the algorithm core and is used for key generation, signature, and signature verification of the post-quantum SPHINCS+ algorithm.

[0221] In the embodiments of the present application, when any arithmetic unit is in an idle state, a node in the Merkle tree or a sequential chain is used as the arithmetic object of the arithmetic unit. On the one hand, since each arithmetic unit in the present application can simultaneously and parallelly operate on multiple sequential chains in a leaf node, the present application only needs to store the operation results of the arithmetic objects corresponding to each arithmetic unit. In the related art, since each arithmetic unit simultaneously and parallelly operates on one sequential chain of multiple leaf nodes, all sequential chains in multiple leaf nodes need to be stored. Therefore, the solution of the present application can reduce the storage space and achieve high parallel operation with a smaller storage space. On the other hand, since each arithmetic unit in the present application can simultaneously and parallelly operate on sequential chains and nodes, the purpose of horizontal parallel operation of sequential chains and vertical parallel operation of nodes is achieved, and all arithmetic units are fully utilized. The parallelism will not decrease as the node height increases. In the related art, since all arithmetic units are used to simultaneously and parallelly operate on sequential chains or nodes, the parallelism will decrease as the node height increases. Therefore, the present application improves the utilization rate of arithmetic units and at the same time enhances the parallel effect, thereby improving the operation efficiency.

[0222] In some embodiments, the processing unit 61 is further configured to: when the first object set meets the first preset condition, use the first node as the first arithmetic object corresponding to the first arithmetic unit; wherein, the first preset condition indicates that the first object set includes the first node and the sibling node of the first node; when the first object set does not meet the first preset condition, determine the target sequential chain of the second node based on the arithmetic objects corresponding to all other arithmetic units except the first arithmetic unit among at least two arithmetic units, and use the target sequential chain of the second node as the first arithmetic object corresponding to the first arithmetic unit.

[0223] In some embodiments, when the parent node of the first node is a non-root node, the processing unit 61 is further configured to: when the position index of the parent node of the first node meets the second preset condition, store the parent node of the first node in the second storage position of the node storage block; wherein, the second storage position is a storage position adapted to the height of the parent node of the first node.

[0224] In some embodiments, when the first arithmetic object is the target sequential chain of the second node, the processing unit 61 is further configured to: use the first arithmetic unit to operate on the target sequential chain of the second node to obtain the chain tail of the target sequential chain of the second node; determine the operation result based on the chain tail of the target sequential chain of the second node.

[0225] In some embodiments, the target sequential chain of the second node includes a plurality of arithmetic nodes connected in sequence; the processing unit 61 is further configured to: use the first arithmetic unit to perform a hash operation on the first arithmetic node among the plurality of arithmetic nodes to obtain a hash value of the first arithmetic node; wherein, the first arithmetic node is determined based on a random number generated by a private key; for each arithmetic node other than the first arithmetic node among the plurality of arithmetic nodes, use the first arithmetic unit to determine the hash value of the arithmetic node based on the hash value of the previous arithmetic node of the arithmetic node; use the hash value of the last arithmetic node among the plurality of arithmetic nodes as the tail of the target sequential chain of the second node.

[0226] In some embodiments, when the second node is a signature node, the processing unit 61 is further configured to: determine a signature arithmetic node corresponding to the target sequential chain from the plurality of arithmetic nodes of the target sequential chain of the second node; store the hash value of the signature arithmetic node corresponding to the target sequential chain in the third storage location of the chain storage block; wherein, the chain storage block includes at least two storage locations, the number of storage locations of the chain storage block is adapted to the number of at least two sequential chains, each sequential chain corresponds to one storage location, and the third storage location is adapted to the storage location corresponding to the target sequential chain.

[0227] In some embodiments, the processing unit 61 is further configured to: when the target sequential chain of the second node is the first sequential chain of the second node, use the tail of the target sequential chain of the second node as the tail corresponding to the second node, and use the tail corresponding to the second node as the operation result; when the target sequential chain of the second node is another sequential chain of the second node, obtain the tail corresponding to the second node from the fourth storage location of the tail storage block, and use the first arithmetic unit to perform an operation on the tail corresponding to the second node and the tail of the target sequential chain of the second node to obtain an operation result; wherein, the tail storage block includes at least one storage location, the number of storage locations of the tail storage block is determined based on the number of at least two sequential chains of the second node and the number of at least two arithmetic units, and all sequential chains of one node correspond to one storage location.

[0228] In some embodiments, when the first operation object is the last sequential chain of the second node, the operation result includes the second node; the processing unit 61 is further configured to perform at least one of the following: when the position index of the second node meets a second preset condition, store the second node in the fifth storage location of the node storage block, and the fifth storage location is a storage location adapted to the height of the second node; when the second node is the node corresponding to the key request, use the second node as the first public key.

[0229] In some embodiments, when the first operand is a non-last sequential chain of the second node, the operation result includes the chain tail corresponding to the second node, and the processing unit 61 is further configured to: store the chain tail corresponding to the second node in the fourth storage location of the chain tail storage block.

[0230] In some embodiments, the processing unit 61 is further configured to: determine a second hash value of the message to be processed; and determine a signature node from at least two leaf nodes of the current Merkle tree based on the second hash value.

[0231] In some embodiments, when the operation result is a non-root node, the processing unit 61 is further configured to: switch the state of the first operation unit to an idle state; update the first object set based on the operation result; and determine a first operand corresponding to the first operation unit based on the updated first object set.

[0232] In some embodiments, when the operation result is the second node and the second node is a signature node, the processing unit 61 is further configured to: obtain hash values of signature operation nodes corresponding to at least two sequential chains of the second node from the chain storage block; and use the hash values of the signature operation nodes corresponding to at least two sequential chains of the second node as a signature output.

[0233] In some embodiments, the processing unit 61 is further configured to: receive a signature sent by a sender; the signature includes hash values of signature operation nodes corresponding to at least two sequential chains of a third node in a second Merkle tree; and determine a signature verification result corresponding to the signature based on the hash values of the signature operation nodes corresponding to at least two sequential chains of the third node.

[0234] In some embodiments, for each of at least two sequential chains of the third node, the processing unit 61 is further configured to: determine a chain tail of the sequential chain based on the hash value of the signature operation node corresponding to the sequential chain; determine a second public key based on the chain tail of each sequential chain of the third node; and determine a signature verification result corresponding to the signature based on the second public key and a third public key sent by the sender.

[0235] The description of the above chip embodiments is similar to the description of the above method embodiments and has similar beneficial effects to the method embodiments. For technical details not disclosed in the chip embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0236] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the appearances of "in one embodiment" or "in an embodiment" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics may be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the magnitude of the serial numbers of the above processes does not mean the order of execution, and the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.

[0237] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0238] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the couplings, direct couplings, or communication connections between the components shown or discussed may be through some interfaces, and the indirect couplings or communication connections of devices or units may be electrical, mechanical or other forms.

[0239] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units; they may be located in one place or distributed to multiple network units; some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0240] In addition, each functional unit in the embodiments of the present application can be all integrated in a processing unit, or each unit can be separately a unit, or two or more units can be integrated in one unit; the above integrated units can be implemented in the form of hardware, or in the form of hardware plus software functional units.

[0241] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including those of the above method embodiments. The foregoing storage medium includes various media that can store program codes, such as removable storage devices, read-only memory (ROM), magnetic disks, or optical discs.

[0242] Alternatively, if the above integrated units of the present application are implemented in the form of software function modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that makes contributions to the related art can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. The foregoing storage medium includes various media that can store program codes, such as removable storage devices, ROM, magnetic disks, or optical discs.

[0243] The above is only the implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application.

Claims

1. A data processing method, characterized in that, Applied to the SPHINCS+ algorithm, including: When the state of the first operation unit is the idle state, determine the first operation object corresponding to the first operation unit, where the first operation unit is any one of at least two operation units, and the first operation object includes one of the following: the first node in the first Merkle tree, the target sequential chain of the second node in the first Merkle tree. The first Merkle tree includes at least two leaf nodes and at least one non-leaf node. Each leaf node includes at least two sequential chains. The first node is one of the at least one non-leaf nodes, and the second node is one of the at least two leaf nodes; Use the first operation unit to perform an operation on the first operation object to obtain an operation result; Wherein, when the first operation object is the first node, the operation result includes the parent node of the first node; the using the first operation unit to perform an operation on the first operation object to obtain an operation result includes: obtaining the sibling node of the first node from the first storage location of the node storage block; wherein, the node storage block includes a plurality of storage locations, the number of storage locations of the node storage block is adapted to the height of the first Merkle tree, all nodes at the same height in the first Merkle tree correspond to one storage location, and the first storage location is a storage location adapted to the height of the first node; use the first operation unit to perform an operation on the first node and the sibling node of the first node to obtain the parent node of the first node; the method further includes: when the parent node of the first node is not the root node and the position index of the parent node of the first node is not an even number, use the parent node of the first node as the new first node; When the first operation object is the target sequential chain of the second node, the using the first operation unit to perform an operation on the first operation object to obtain an operation result includes: using the first operation unit to perform an operation on the target sequential chain of the second node to obtain the chain tail of the target sequential chain of the second node; when the target sequential chain of the second node is the first sequential chain of the second node, use the chain tail of the target sequential chain of the second node as the chain tail corresponding to the second node, and use the chain tail corresponding to the second node as the operation result; when the target sequential chain of the second node is other sequential chains of the second node, obtain the chain tail corresponding to the second node from the fourth storage location of the chain tail storage block, and use the first operation unit to perform an operation on the chain tail corresponding to the second node and the chain tail of the target sequential chain of the second node to obtain the operation result; wherein, the chain tail storage block includes at least one storage location, the number of storage locations of the chain tail storage block is determined based on the number of at least two sequential chains of the second node and the number of at least two operation units, and the storage locations of the chain tail storage block are reused to realize the storage of the chain tails corresponding to multiple second nodes.

2. The data processing method according to claim 1, wherein Determining the first operation object corresponding to the first operation unit includes: When the first object set meets the first preset condition, using the first node as the first operation object corresponding to the first operation unit; wherein, the first preset condition indicates that the first object set includes the first node and the sibling node of the first node; When the first object set does not meet the first preset condition, based on the operation objects corresponding to all other operation units except the first operation unit among the at least two operation units, determining the target sequence chain of the second node, and using the target sequence chain of the second node as the first operation object corresponding to the first operation unit.

3. The data processing method according to claim 2, wherein The determining the target sequence chain of the second node based on the operation objects corresponding to all other operation units except the first operation unit among the at least two operation units includes: Based on the operation objects corresponding to all other operation units, determining a second operation unit from all other operation units; Based on the operation object corresponding to the second operation unit, determining the target sequence chain of the second node.

4. The data processing method according to claim 1, characterized in that When the parent node of the first node is a non-root node, the data processing method further includes: When the position index of the parent node of the first node is an even number, storing the parent node of the first node to the second storage position of the node storage block; wherein, the second storage position is a storage position adapted to the height of the parent node of the first node.

5. The data processing method according to claim 1, wherein The target sequence chain of the second node includes a plurality of operation nodes connected in sequence; Using the first operation unit to operate on the target sequence chain of the second node to obtain the tail of the target sequence chain of the second node includes: Using the first operation unit to perform a hash operation on the first operation node among the plurality of operation nodes to obtain the hash value of the first operation node; wherein, the first operation node is determined based on a random number generated by a private key; For each operation node except the first operation node among the plurality of operation nodes, using the first operation unit to determine the hash value of the operation node based on the hash value of the previous operation node of the operation node; Using the hash value of the last operation node among the plurality of operation nodes as the tail of the target sequence chain of the second node.

6. The data processing method according to claim 5, wherein When the second node is a signature node, the data processing method further includes: Determining the signature operation node corresponding to the target sequence chain from the plurality of operation nodes of the target sequence chain of the second node; Storing the hash value of the signature operation node corresponding to the target sequence chain to the third storage position of the chain storage block.

7. The data processing method according to claim 1, wherein When the first operation object is the last sequence chain of the second node, the operation result includes the second node; the data processing method further includes at least one of the following: When the position index of the second node is an even number, storing the second node to the fifth storage position of the node storage block, and the fifth storage position is a storage position adapted to the height of the second node; In the case where the second node is the node corresponding to the key request, use the second node as the first public key.

8. The data processing method according to claim 2, wherein The data processing method further includes: In the case where the operation result is a non-root node, switch the state of the first operation unit to the idle state; Update the first object set based on the operation result; Determine the first operation object corresponding to the first operation unit based on the updated first object set.

9. The data processing method according to any one of claims 1 to 8, characterized in that In the case where the operation result is the second node and the second node is a signature node, the data processing method further includes: Obtain the hash values of the signature operation nodes corresponding to at least two sequential chains of the second node from the chain storage block; Use the hash values of the signature operation nodes corresponding to at least two sequential chains of the second node as the signature output.

10. The data processing method according to any one of claims 1 to 8, characterized in that, The data processing method further includes: Receive the signature sent by the sender; wherein the signature includes the hash values of the signature operation nodes corresponding to at least two sequential chains of the third node in the second Merkle tree; Determine the signature verification result corresponding to the signature based on the hash values of the signature operation nodes corresponding to at least two sequential chains of the third node.

11. The data processing method according to claim 10, wherein The determining the signature verification result corresponding to the signature based on the hash values of the signature operation nodes corresponding to at least two sequential chains of the third node includes: For each of the at least two sequential chains of the third node, determine the end of the chain based on the hash value of the signature operation node corresponding to the sequential chain; Determine the second public key based on the end of each sequential chain of the third node; Determine the signature verification result corresponding to the signature based on the second public key and the third public key sent by the sender.

12. A data processing chip, characterized in that, Applied to the SPHINCS+ algorithm, a processing unit is deployed in the data processing chip, wherein: The processing unit is configured to, when the state of the first operation unit is the idle state, determine the first operation object corresponding to the first operation unit, where the first operation unit is any one of at least two operation units, and the first operation object includes one of the following: the first node in the first Merkle tree, the target sequential chain of the second node in the first Merkle tree, the first Merkle tree includes at least two leaf nodes and at least one non-leaf node, each leaf node includes at least two sequential chains, the first node is one of the at least one non-leaf node, and the second node is one of the at least two leaf nodes; perform an operation on the first operation object using the first operation unit to obtain an operation result; Wherein, when the first operand is the first node, the operation result includes the parent node of the first node; the operation of the first operand by the first operation unit to obtain an operation result includes: obtaining the sibling node of the first node from the first storage location of the node storage block; wherein, the node storage block includes a plurality of storage locations, the number of storage locations of the node storage block is adapted to the height of the first Merkle tree, all nodes at the same height in the first Merkle tree correspond to one storage location, and the first storage location is a storage location adapted to the height of the first node; using the first operation unit to operate on the first node and the sibling node of the first node to obtain the parent node of the first node; the processing unit is further configured to: when the parent node of the first node is not the root node and the position index of the parent node of the first node is not an even number, use the parent node of the first node as the new first node; When the first operand is the target sequence chain of the second node, the operation of the first operand by the first operation unit to obtain an operation result includes: using the first operation unit to operate on the target sequence chain of the second node to obtain the chain tail of the target sequence chain of the second node; when the target sequence chain of the second node is the first sequence chain of the second node, using the chain tail of the target sequence chain of the second node as the chain tail corresponding to the second node, and using the chain tail corresponding to the second node as the operation result; when the target sequence chain of the second node is another sequence chain of the second node, obtaining the chain tail corresponding to the second node from the fourth storage location of the chain tail storage block, and using the first operation unit to operate on the chain tail corresponding to the second node and the chain tail of the target sequence chain of the second node to obtain the operation result; wherein, the chain tail storage block includes at least one storage location, the number of storage locations of the chain tail storage block is determined based on the number of at least two sequence chains of the second node and the number of at least two operation units, and the storage locations of the chain tail storage block are reused to realize the storage of the chain tails corresponding to multiple second nodes.

Citation Information

Patent Citations

  • Method and system for distributed block chain function

    CN118633258A