Modular multiplication mask circuits for side-channel attack resistance in post-quantum cryptography

By introducing random number generation and modular multiplication mask circuits into post-quantum cryptographic algorithms, the problem of post-quantum cryptographic algorithms being vulnerable to side channel attacks is solved, and the security and computational efficiency of the system are improved.

CN119728072BActive Publication Date: 2025-09-12HUAZHONG UNIV OF SCI & TECH +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410940552.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2024-04-30
Filing Date
2024-07-15
Publication Date
2025-09-12
Estimated Expiration
2044-07-15

AI Technical Summary

Technical Problem

Existing post-quantum cryptographic algorithms are vulnerable to side-channel attacks during execution and lack effective protection measures.

Method used

A modular multiplication mask circuit is designed for post-quantum cryptographic algorithms to resist side channel attacks. Pseudo-random numbers are generated by a random number generation unit, and modular multiplication operations are performed using the modular multiplication unit. The operation process is controlled by a control logic unit, and the device behavior is interfered with to improve the resistance capability.

Benefits of technology

It effectively protects the system from side-channel attacks, improves system security and anti-attack performance, and at the same time improves the efficiency of modular multiplication operations and reduces the risk of system attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728072B_ABST
    Figure CN119728072B_ABST
Patent Text Reader

Abstract

The present invention discloses a modular multiplication mask circuit for use in post-quantum cryptographic algorithms that is resistant to side-channel attacks. The circuit is characterized by comprising: a random number generation unit, a modular multiplication unit, and a control logic unit. The random number generation module is configured to generate pseudo-random numbers. The modular multiplication unit is configured to perform a modular multiplication operation on first input data and the pseudo-random number to obtain first preliminary processed data, and to perform a modular multiplication operation on second input data and the inverse element of the pseudo-random number to obtain second preliminary processed data. The first preliminary processed data and the second preliminary processed data are then modularly multiplied to obtain final output data. The control logic unit is configured to control the operation of the random number generation unit and the modular multiplication unit. The embodiments of the present invention introduce pseudo-random numbers to increase the randomness of the calculation process, thereby improving resistance to side-channel attacks such as template attacks, significantly enhancing the security and anti-attack performance of the system and effectively protecting the system from side-channel attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the fields of post-quantum information security algorithms, digital signal processing and circuit implementation, and in particular relates to a modular multiplication mask circuit that is resistant to side channel attacks and is applied to post-quantum cryptographic algorithms. Background Art

[0002] A side-channel attack is a cryptanalysis technique that attempts to crack an encryption system by monitoring "side channel" information generated by the physical implementation of the encryption system (such as current, voltage, and processing time). This attack exploits information leaked by the encryption device when performing encryption operations, rather than directly attacking the algorithm itself.

[0003] Rather than mathematically analyzing encryption algorithms to crack passwords, side-channel attacks analyze the behavior of actual devices to obtain encryption keys or other sensitive information. These "side channels" may include electromagnetic radiation, power consumption analysis, timing analysis, and more. A key characteristic of side-channel attacks is that they typically do not rely on knowledge of the specific implementation details of the encryption algorithm or the key. Instead, attackers can analyze and infer keys or other sensitive information simply by monitoring the actual device's operation.

[0004] Because side-channel attacks are a highly effective attack method, when designing secure cryptographic systems, in addition to considering the security of the encryption algorithm itself, it is also necessary to consider and defend against side-channel attacks. This may involve protecting the physical implementation, using anti-side-channel techniques, or considering the potential impact of side-channel attacks when designing the encryption algorithm. To this end, the present invention provides a modular multiplication mask circuit that resists side-channel attacks by introducing random numbers. This circuit is applied to post-quantum cryptographic algorithms and is capable of providing protection against side-channel attacks during encryption algorithm operations. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to protect against side channel attacks when a post-quantum cryptographic algorithm is operated. The present invention provides a modular multiplication mask circuit that is resistant to side channel attacks and is applied to a post-quantum cryptographic algorithm, comprising: a random number generation unit, a modular multiplication unit, and a control logic unit;

[0006] The random number generating unit is used to generate a pseudo-random number;

[0007] The modular multiplication unit is configured to perform a modular multiplication operation on the first input data and the pseudo-random number to obtain first preliminary processed data, and perform a modular multiplication operation on the second input data and the inverse element of the pseudo-random number to obtain second preliminary processed data; and then perform a modular multiplication operation on the first preliminary processed data and the second preliminary processed data to obtain final output data;

[0008] The control logic unit is used to control the operation of the random number generation unit and the modular multiplication unit;

[0009] The output end of the random number generation unit is connected to the output end of the modular multiplication unit; the output end of the control logic unit is connected to the input end of the modular multiplication unit and the random number generation unit; and the input end of the modular multiplication unit is also connected to the first input data and the second input data.

[0010] Preferably, the modular multiplication unit includes a first modular multiplier, a second modular multiplier, a third modular multiplier and a first register;

[0011] Among them, the first modular multiplier is used to perform modular multiplication operations on the first input data and the pseudo-random number; the second modular multiplier is used to perform modular multiplication operations on the second input data and the inverse element of the pseudo-random number; the third modular multiplier is used to perform modular multiplication operations on the first pre-processed data and the second pre-processed data; the first register is used to output the inverse element of the pseudo-random number according to the input pseudo-random number.

[0012] Preferably, the first modular multiplier input end is connected to the pseudo-random number and the first input data respectively; the first register input end is connected to the random number generation unit output end and the control logic unit output end; the first register output end is connected to the second modular multiplier input end; the third modular multiplier input end is connected to the first modular multiplier output end and the second modular multiplier output end; the third modular multiplier is used to output the final output data.

[0013] Preferably, the modular multiplication unit further includes a second register; the second register is connected to the first register and is used to transmit the inverse element of the pseudo-random number to the second modular multiplier.

[0014] Preferably, the first modular multiplier includes a first multiplier, a first adder, a second adder, a third adder, a third register, a fourth register, a fifth register, a sixth register, a seventh register, a first subtractor, a first selector, a second selector and a first modular adder;

[0015] The first multiplier input is connected to the pseudo-random number and the first input data, and the output is connected to the third register input; the third register output is respectively connected to the fourth register, the fifth register, the sixth register, and the second adder input; the fourth register and the fifth register output are respectively connected to the first adder input; the sixth register output is connected to the second adder input; the first adder and the second adder output are connected to the third adder input; the third adder output is connected to the seventh register input; the seventh register output is respectively connected to the first selector selection terminal, the second selector input terminal, and the first subtractor minuend terminal; the first selector output terminal and the second selector output terminal are connected to the first analog adder input; the first subtractor subtrahend terminal is connected to the first reference number, the output terminal is connected to the second selector input terminal, and the borrow terminal is connected to the second selector selection terminal; the first analog adder output outputs the first preliminary processed data.

[0016] Preferably, the fourth register stores all 4 bits*2 20 Modulo q = 3329 result; the fifth register stores all 4 bits * 2 16 Modulo q = 3329 result; the sixth register stores all 4 bits * 2 12 The result of q=3329 on the module; the first selector input is all 2bits*2 12 Modulo the result of q=3329; the first reference number is the number 3329.

[0017] Preferably, the third register is used to store the 24-bit data output by the first multiplier, and transmit the 1st to 12th bits of the 24-bit data to the second adder, the 13th to 16th bits of the 24-bit data to the sixth register, the 17th to 20th bits of the 24-bit data to the fifth register, and the 21st to 24th bits of the 24-bit data to the fourth register.

[0018] Preferably, the seventh register is used to store the 14-bit data output by the third adder, and transmit the 1st to 12th bits of the 14-bit data to the second selector input end and the minuend end of the first subtractor, and transmit the 13th to 14th bits of the 14-bit data to the selection end of the first selector; the first modular multiplier, the second modular multiplier, and the third modular multiplier have the same structure.

[0019] Preferably, the random number generation unit includes an eighth register, a ninth register, a first Keccak core, and a second Keccak core;

[0020] Among them, the eighth register input end is connected to external data and the control logic unit, and the output end is connected to the ninth register input end; the ninth register output end is connected to the first Keccak core input end; the second Keccak core input end is connected to the first Keccak core output end, and the output ends are respectively connected to the ninth register input end and the modular multiplication unit input end; the ninth register input end is also connected to the control logic unit.

[0021] Preferably, the eighth register is used to roll the externally input 64-bit data 25 times according to the control logic unit instruction to generate 1600-bit data;

[0022] The ninth register is used to input the 1600 bits of data into the first Keccak core and the second Keccak core for circulation according to the control logic unit instruction;

[0023] The first Keccak core and the second Keccak core are used to generate a 1600-bit pseudo-random number according to the 1600-bit data, and transmit the 1589th to 1600th pseudo-random numbers to the modular multiplication unit.

[0024] The implementation of the embodiments of the present invention has the following beneficial effects:

[0025] (1) In an embodiment of the present invention, a pseudo-random number is introduced through a random number generation unit. A modular multiplication unit performs a modular multiplication operation on the first input data and the pseudo-random number to obtain first preliminary processed data. A modular multiplication operation is performed on the second input data and the inverse element of the pseudo-random number to obtain second preliminary processed data. The first preliminary processed data and the second preliminary processed data are then modularly multiplied to replace the original modular multiplication operation between the first input data and the second input data. The randomness of the pseudo-random number is used to interfere with the behavior of the actual device, thereby improving the resistance to side channel attacks such as template attacks. This effectively protects the system from side channel attacks, improves the security and anti-attack performance of the system, and reduces the risk of the system being attacked.

[0026] (2) The embodiment of the present invention stores all 4 bits*2 in advance by setting the fourth register, the fifth register, and the sixth register in the modular multiplier. 20 Modulo q = 3329, all 4 bits * 2 16 Modulo q = 3329, 4 bits * 2 12The result of q=3329 is obtained by modulo. Different data are transmitted from the third register to the fourth register, the fifth register, and the sixth register, which then output corresponding data. This avoids processing the data transmitted from the third register, thereby improving the efficiency of the modular multiplication operation in the modular multiplier and thus achieving overall operational efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0028] Figure 1 This is a diagram of the modular multiplication mask circuit architecture for resisting side channel attacks applied to the post-quantum cryptographic algorithm of the present invention;

[0029] Figure 2 This is a diagram of the modular multiplier architecture in the modular multiplication mask circuit for resisting side channel attacks applied to the post-quantum cryptographic algorithm of the present invention;

[0030] Figure 3 This is a diagram of the attack results of the modular multiplication mask circuit used in the post-quantum cryptography algorithm to resist side channel attacks under 1200 energy trajectories of the correlated power attack. DETAILED DESCRIPTION

[0031] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0032] like Figure 1 As shown, this embodiment discloses a modular multiplication and masking circuit for resisting side channel attacks in a post-quantum cryptographic algorithm. The modular multiplication and masking circuit for resisting side channel attacks in a post-quantum cryptographic algorithm includes: a random number generation unit 10, a modular multiplication unit 20, and a control logic unit 30. The output of the random number generation unit 10 is connected to the output of the modular multiplication unit 20. The output of the control logic unit 30 is connected to the input of the modular multiplication unit 20 and the random number generation unit 10. The input of the modular multiplication unit 20 is also connected to first input data and second input data.

[0033] The random number generating unit 10 is used to generate a pseudo random number. The modular multiplication unit 20 is used to convert the first input data (s * ) is modularly multiplied with a pseudo-random number to obtain first preliminary processed data, and second preliminary processed data is modularly multiplied with the inverse element of the pseudo-random number to obtain second preliminary processed data, wherein the inverse element of the pseudo-random number is the result of multiplying the pseudo-random number with the inverse element of the pseudo-random number and then taking the modulus of the modulus as 1. The first preliminary processed data and the second preliminary processed data are then modularly multiplied to obtain final output data. The control logic unit is used to control the operation of the random number generation unit and the modular multiplication unit.

[0034] The modular multiplication mask circuit for resisting side channel attacks applied to the post-quantum cryptographic algorithm increases the pseudo-random number by * ×u is changed to (r×s * )×(rinv×u). Wherein, the s * is the first input data, u is the second input data, r is a pseudorandom number, and rinv is the inverse element of the pseudorandom number. The randomness of the pseudorandom number r is used to interfere with the actual device behavior, thereby improving resistance to side-channel attacks such as template attacks. This effectively protects the system from side-channel attacks, improves system security and anti-attack performance, and reduces the risk of system attacks.

[0035] The modular multiplication unit 20 includes a first modular multiplier 210, a second modular multiplier 220, a third modular multiplier 230 and a first register 240. The first modular multiplier 210 input terminal is respectively connected to the pseudo random number r, the first input data s * connected to the first input data s * Perform modular multiplication with the pseudo-random number r and output the first preliminary processed data (r×s * ). The input end of the first register 240 is connected to the output end of the random number generation unit 10 and the output end of the control logic unit 30, and is used to output the corresponding inverse element rinv of the pseudo-random number according to the input pseudo-random number r and the control signal output by the control logic unit 30. Among them, the first register 240 stores the results of the inverse elements rinv of all pseudo-random numbers. The output end of the first register 240 is connected to the input end of the second modular multiplier 220, and is used to perform modular multiplication operation on the second input data u and the inverse element rinv of the pseudo-random number, and output the second preliminary processed data (rinv×u). The input end of the third modular multiplier 230 is connected to the output end of the first modular multiplier 210 and the output end of the second modular multiplier 220, and is used to perform modular multiplication operation on the first preliminary processed data (r×s * ) performs modular multiplication operation with the second preliminary processed data (rinv×u) and outputs the final output data.

[0036] In some embodiments, the modular multiplication unit 20 further includes a second register 250. The second register 250 is located between the first register 240 and the second modular multiplier 220, with its input connected to the output of the first register 240 and its output connected to the input of the second modular multiplier 220. The second register 250 is used to transmit the inverse element rinv of the pseudorandom number to the second modular multiplier 220, thereby increasing the transmission speed of the first register 240 and improving overall efficiency.

[0037] The random number generation unit 10 includes an eighth register 110, a ninth register 120, and a pair of Keccak cores 130. The eighth register 110 has an input connected to external data (Din) and the control logic unit 30, and an output connected to the input of the ninth register 120. The eighth register 110 is configured to tumble 64 bits of external data 25 times according to instructions from the control logic unit 30, padding the data to generate 1600 bits of data, and then transmit the 1600 bits of data to the ninth register 120. The output of the ninth register 120 is connected to the inputs of the pair of Keccak cores 130, and the inputs are also connected to the control logic unit 30. The ninth register 120 is configured to input the 1600 bits of data into the pair of Keccak cores 130 for looping according to instructions (round) from the control logic unit 30. The instructions (round) can control the number of loops for the pair of Keccak cores 130, ranging from 1 to 8. The pair of Keccak cores 130 are connected in series. The second Keccak core input is connected to the first Keccak core output. The outputs of the pair of Keccak cores 130 are respectively connected to the ninth register input and the input of the modular multiplication unit 20. The pair of Keccak cores 130 is configured to generate a 1600-bit pseudo-random number using the Keccak algorithm based on the 1600-bit data, and transmit the pseudo-random number from bits 1589 to 1600 to the modular multiplication unit 20, i.e., the pseudo-random number r.

[0038] In some embodiments, the random number generation unit 10 further includes a tenth register 140. The tenth register 140 is located between the pair of Keccak cores 130 and the modular multiplication unit 20, with its input end connected to the output ends of the pair of Keccak cores 130 and its output end connected to the modular multiplication unit 20, and is used to speed up the transmission speed of the first register 240 and improve overall efficiency.

[0039] See also Figure 2The first modular multiplier 210, the second modular multiplier 220, and the third modular multiplier 230 have the same structure. The modular multiplier includes: a first multiplier 201, a first adder 202, a second adder 203, a third adder 204, a third register 205, a fourth register 206, a fifth register 207, a sixth register 208, a seventh register 209, a first subtractor 211, a first selector 212, a second selector 213, and a first modular adder 214. The multiplier is used for multiplication. The adder is used for addition. The subtractor is used for subtraction. The selector is used to selectively output input data based on the selected end. The modular adder is used for modular addition, that is, adding the input data and then taking the modulus.

[0040] In the first modular multiplier 210, the first multiplier 201 input terminal is connected to the pseudo random number r and the first input data s * In the second modular multiplier 220 and the third modular multiplier 230, the input terminals are connected to the second input data u and the inverse element rinv of the pseudo-random number, the first preliminary processed data (r×s * ) is connected to the second pre-processed data (rinv×u). The output of the first multiplier 201 is connected to the input of the third register 205. The output of the third register 205 is respectively connected to the fourth register 206, the fifth register 207, the sixth register 208, and the input of the second adder 203. The fourth register 206, the fifth register 207, and the sixth register 208 all output corresponding data based on the output data of the third register 205. The output of the fourth register 206 and the fifth register 207 are connected to the input of the first adder 202. The output of the sixth register 208 is connected to the input of the second adder 203. The output of the first adder 202 and the second adder 203 are connected to the input of the third adder 204. The output of the third adder 204 is connected to the input of the seventh register 209. The output of the seventh register 209 is connected to the selection terminal of the first selector 212, the input terminal of the second selector 213, and the subtrahend terminal of the first subtractor 211, respectively. The output of the first selector 212 and the output of the second selector 213 are connected to the input terminal of the first modular adder 214. The subtrahend terminal of the first subtractor 211 is connected to the first reference number, the output terminal is connected to the input terminal of the second selector 213, and the borrow terminal is connected to the selection terminal of the second selector 213. The first reference number is 3329. In the first modular multiplier 210, the output terminal of the first modular adder 214 outputs the first pre-processed data.

[0041] The fourth register stores all 4 bits*2 20 The result of q=3329 modulo q is the number 0-15 multiplied by 220 The result of modulo q=3329 is 16 data in total. The fifth register stores all 4 bits*2 16 The result of modulo q=3329. The sixth register stores all 4 bits*2 12 Result modulo q=3329.

[0042] The third register 205 is used to store the 24 bits of data output by the first multiplier 201, and transmits the 1st to 12th bits of the 24 bits of data to the second adder 203, i.e., the lowest 12 bits of data (referred to as low 12 bits of data). The third register 205 transmits the 13th to 16th bits of the 24 bits of data to the sixth register 208, i.e., the middle 4 bits of data (referred to as middle 4 bits of data). The third register 205 transmits the 17th to 20th bits of the 24 bits of data to the fifth register 207, i.e., the middle and high 4 bits of data (referred to as middle and high 4 bits of data). The third register 205 transmits the 21st to 24th bits of the 24 bits of data to the fourth register 206, i.e., the highest 4 bits of data (referred to as high 4 bits of data).

[0043] The seventh register 209 is used to store the 14-bit data output by the third adder 204, and transmit the 14-bit data from the 1st to the 12th bit to the input end of the second selector 213 and the minuend end of the first subtractor 211, and transmit the 13th to the 14th bit to the selection end of the first selector 212. The first selector input end is all 2 bits*2 12 The result of q=3329 modulo q is the number 0-3 multiplied by 2 12 The result of q=3329 modulo q is 4 data in total.

[0044] When the modular multiplier is running, the 12-bit data a and b are input through the first multiplier 201 to obtain 24-bit data, which is stored in the third register 205. The third register 205 divides the 24-bit data into four parts, namely the lower 12 bits, the middle 4 bits, the middle and upper 4 bits, and the upper 4 bits. The upper 4 bits have 16 possible values, namely the numbers 0-15. The fourth register 206 stores all 4 bits*2 20 The result of modulo q=3329. When the upper 4 bits of data are input to the fourth register 206, the fourth register 206 will output the corresponding number multiplied by 2. 20The result of q=3329 on the module. The fifth register 207 and the sixth register 208 are similar and output the corresponding data. By storing the data that needs to be calculated in advance to replace the modular multiplication operation, the modular multiplication efficiency of the modular multiplier is significantly improved, thereby improving the overall efficiency of the system. The output data (h) of the fourth register 206 and the output data m of the fifth register 207 will enter the first adder 202 for addition operation. The output data (l) of the sixth register 208 and the lower 12 bits of data will enter the second adder 203 for addition operation. The output results of the first adder 202 and the second adder 203 will enter the third adder 204 for addition operation, and output 14 bits of data (s) to the seventh register 209. The seventh register 209 divides the 14 bits of data into two parts, namely 12 bits of data and 2 bits of data. There are 4 cases for the 2 bits of data, namely the numbers 0-3. The input end of the first selector 212 is all 2 bits*2 12 When the seventh register 209 transmits the 2-bit data to the selection terminal of the first selector 212, the first selector 212 outputs the corresponding number multiplied by 2. 12 The result of q=3329 on the module. By storing the data that needs to be calculated in advance to replace the modular multiplication operation, the modular multiplication efficiency of the modular multiplier is significantly improved. The 12-bit data is transmitted to the second selector 213 and the first subtractor 211 respectively, serving as the input and minuend data. The subtrahend terminal of the first subtractor 211 is the first reference number q=3329. The output data of the first subtractor 211 will be transmitted to the second selector 213 as the input terminal. The borrow terminal of the first subtractor 211 is connected to the selection terminal of the second selector 213, and the 12-bit data or the 12-bit data minus the first reference number is selected by whether to borrow. When borrowing is required, the 12-bit data is selected, otherwise the 12-bit data minus the first reference number is selected. The output data (j) of the first selector 212 and the output data (k) of the second selector 213 are input to the first modular adder 214 for modular addition operation to output final data a·b mod q.

[0045] See also Figure 3 The attack results of the modular multiplication mask circuit for post-quantum cryptography algorithms, which is resistant to side-channel attacks, under 1200 energy traces of a correlated power attack are shown in the figure. The figure shows the minimum exposure trace of the correlated power attack on the modular multiplier using the above structure. Attackers cannot predict the correct results. This shows that the modular multiplication mask circuit for post-quantum cryptography algorithms can effectively protect the Kyber modular multiplication process from side-channel attacks, improving the security and reliability of the system.

[0046] In summary, the embodiment of the present invention adopts the modular multiplication mask circuit for resisting side channel attacks applied to the post-quantum cryptographic algorithm to make the original s * ×u is changed to (r×s * )×(rinv×u). After adding a pseudorandom number, the randomness of the pseudorandom number r is used to interfere with the behavior of the actual device, thereby improving resistance to side-channel attacks such as template attacks. Furthermore, the modular multiplier in the modular multiplication mask circuit for post-quantum cryptography that resists side-channel attacks is modified to use registers to store all results, thus avoiding the calculation process. This significantly improves the modular multiplication efficiency of the modular multiplier and, in turn, the overall efficiency of the system. Ultimately, the modular multiplication mask circuit for post-quantum cryptography that resists side-channel attacks is not only resistant to side-channel attacks but also highly efficient.

[0047] The above disclosure is only a preferred embodiment of the present invention, and certainly cannot be used to limit the scope of the rights of the present invention. Ordinary technicians in this field can understand that all or part of the processes of the above embodiment and equivalent changes made in accordance with the claims of the present invention are still within the scope of the invention.

Claims

1. A modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms, characterized in that: include: Random number generation unit, modular multiplication unit and control logic unit; The random number generating unit is used to generate a pseudo-random number; The modular multiplication unit is configured to perform a modular multiplication operation on the first input data and the pseudo-random number to obtain first preliminary processed data, and perform a modular multiplication operation on the second input data and the inverse element of the pseudo-random number to obtain second preliminary processed data; and then perform a modular multiplication operation on the first preliminary processed data and the second preliminary processed data to obtain final output data; The control logic unit is used to control the operation of the random number generation unit and the modular multiplication unit; The output end of the random number generation unit is connected to the output end of the modular multiplication unit; the output end of the control logic unit is connected to the input end of the modular multiplication unit and the random number generation unit; and the input end of the modular multiplication unit is also connected to the first input data and the second input data.

2. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 1, characterized in that: The modular multiplication unit includes a first modular multiplier, a second modular multiplier, a third modular multiplier and a first register; Among them, the first modular multiplier is used to perform modular multiplication operations on the first input data and the pseudo-random number; the second modular multiplier is used to perform modular multiplication operations on the second input data and the inverse element of the pseudo-random number; the third modular multiplier is used to perform modular multiplication operations on the first pre-processed data and the second pre-processed data; the first register is used to output the inverse element of the pseudo-random number according to the input pseudo-random number.

3. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 2, characterized in that: The first modular multiplier input end is connected to the pseudo-random number and the first input data respectively; the first register input end is connected to the random number generation unit output end and the control logic unit output end; the first register output end is connected to the second modular multiplier input end; the third modular multiplier input end is connected to the first modular multiplier output end and the second modular multiplier output end; the third modular multiplier is used to output the final output data.

4. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 2, characterized in that: The modular multiplication unit further includes a second register; the second register is connected to the first register and is used to transmit the inverse element of the pseudo-random number to the second modular multiplier.

5. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 2, characterized in that: The first modular multiplier includes a first multiplier, a first adder, a second adder, a third adder, a third register, a fourth register, a fifth register, a sixth register, a seventh register, a first subtractor, a first selector, a second selector and a first modular adder; The first multiplier input is connected to the pseudo-random number and the first input data, and the output is connected to the third register input; the third register output is respectively connected to the fourth register, the fifth register, the sixth register, and the second adder input; the fourth register and the fifth register output are connected to the first adder input; the sixth register output is connected to the second adder input; the first adder and the second adder output are connected to the third adder input; the third adder output is connected to the seventh register input; the seventh register output is respectively connected to the first selector selection terminal, the second selector input terminal, and the first subtractor minuend terminal; the first selector output terminal and the second selector output terminal are connected to the first modulo adder input; The subtrahend terminal of the first subtractor is connected to the first reference number, the output terminal is connected to the input terminal of the second selector, and the borrow terminal is connected to the selection terminal of the second selector; the output terminal of the first analog adder outputs the first pre-processed data.

6. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 5, characterized in that: The fourth register stores all 4 bits*2 20 Modulo q = 3329 result; the fifth register stores all 4 bits * 2 16 Modulo q = 3329 result; the sixth register stores all 4 bits * 2 12 The result of q=3329 on the module; the first selector input is all 2bits*2 12 Modulo the result of q=3329; the first reference number is the number 3329.

7. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 5, characterized in that: The third register is used to store the 24-bit data output by the first multiplier, and transmit the 1st to 12th bits of the 24-bit data to the second adder, the 13th to 16th bits of the 24-bit data to the sixth register, the 17th to 20th bits of the 24-bit data to the fifth register, and the 21st to 24th bits of the 24-bit data to the fourth register.

8. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 5, characterized in that: The seventh register is used to store the 14-bit data output by the third adder, and transmit the 1st to 12th bits of the 14-bit data to the second selector input end and the minuend end of the first subtractor, and transmit the 13th to 14th bits of the 14-bit data to the selection end of the first selector; the first modular multiplier, the second modular multiplier, and the third modular multiplier have the same structure.

9. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 1, characterized in that: The random number generation unit includes an eighth register, a ninth register, a first Keccak core and a second Keccak core; Among them, the eighth register input end is connected to external data and the control logic unit, and the output end is connected to the ninth register input end; the ninth register output end is connected to the first Keccak core input end; the second Keccak core input end is connected to the first Keccak core output end, and the output ends are respectively connected to the ninth register input end and the modular multiplication unit input end; the ninth register input end is also connected to the control logic unit.

10. The modular multiplication mask circuit for resisting side channel attacks applied to post-quantum cryptographic algorithms according to claim 9, characterized in that: The eighth register is used to roll the externally input 64-bit data 25 times according to the control logic unit instruction to generate 1600-bit data; The ninth register is used to input the 1600 bits of data into the first Keccak core and the second Keccak core for circulation according to the control logic unit instruction; The first Keccak core and the second Keccak core are used to generate a 1600-bit pseudo-random number according to the 1600-bit data, and transmit the 1589th to 1600th pseudo-random numbers to the modular multiplication unit.

Citation Information

Patent Citations

  • Modular multiplier circuit applied to post quantum cryptography algorithm and calculation method thereof

    CN119906541A