An RSA-CRT cryptographic data processing method and a cryptographic chip

By randomizing the private key in the RSA-CRT key, the problem of private key leakage in the RSA-CRT algorithm when facing side channel attacks is solved, and the security of the cryptographic device is improved.

CN119728113BActive Publication Date: 2025-06-10OPEN SECURITY RES INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510222309.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-10
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

When facing side channel attacks, the RSA-CRT algorithm has the risk of private key leakage, which threatens the security of the cryptographic device.

Method used

By randomizing the private key in the RSA-CRT key, it increases the difficulty of the attacker to analyze and crack, and implements this method in the cryptographic chip to resist side channel attacks.

Benefits of technology

It effectively reduces the possibility that the attacker obtains the key information of the RSA private key through side channel analysis, and improves the security of RSA-CRT operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728113B_ABST
    Figure CN119728113B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose an RSA-CRT password data processing method and a password chip. The method includes: in response to a password service request, obtaining an RAS-CRT key corresponding to the request identifier carried in the password service request, where the RAS-CRT key includes a private key; performing a randomization process on the first part of the private key value in the private key to obtain a randomized private key value of the first part of the private key value; based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, performing a private key operation on the data to be processed carried in the password service request to obtain target data, and sending password service response data corresponding to the password service request; where the password service response data includes the target data; where the target private key value is the first part of the private key value or the randomized private key value of the first part of the private key value, and the target data is obtained based on one or more randomized private key values of the first part of the private key value.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to, but is not limited to, the field of information security, and particularly relates to an RSA-CRT cryptographic data processing method and a cryptographic chip. Background Art

[0002] The RSA algorithm is a widely used public-key cryptographic algorithm at present. Generally, in the decryption or signature stage, in order to improve the signature or decryption efficiency, the Chinese Remainder Theorem (CRT) can be introduced to accelerate it. The RSA algorithm with the method of introducing the Chinese Remainder Theorem (abbreviated as RSA-CRT) has a performance speed advantage of about 4 to 8 times compared with the traditional RSA algorithm. Therefore, RSA-CRT is more widely applied.

[0003] The RSA-CRT algorithm in the related art is vulnerable to side channel attacks (SCA), also known as side-channel attacks. This attack is a method in which an attacker uses side-channel information leakage such as time consumption, power consumption, or electromagnetic radiation during the operation of a cryptographic device. By analyzing this leaked information, the attacker obtains the private key or part of the private key information, and then attacks the cryptographic device, posing a serious threat to the cryptographic device. Therefore, in order to resist side-channel attacks, there is an urgent need to provide a new RSA-CRT cryptographic data processing method at present. Summary of the Invention

[0004] To solve the above technical problems, embodiments of this application provide at least an RSA-CRT cryptographic data processing method and a cryptographic chip.

[0005] The technical solution of the embodiments of this application is implemented as follows:

[0006] In a first aspect, embodiments of this application provide an RSA-CRT cryptographic data processing method, and the method includes:

[0007] In response to a cryptographic service request, obtain an RAS-CRT key corresponding to the request identifier carried in the cryptographic service request, where the RAS-CRT key includes a private key;

[0008] Randomize a first part of the private key value in the private key to obtain a randomized private key value of the first part of the private key value;

[0009] Based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, perform a private key operation on the data to be processed carried in the cryptographic service request to obtain target data, and send cryptographic service response data corresponding to the cryptographic service request; where the cryptographic service response data includes the target data;

[0010] Wherein, the target private key value is the first part of the private key value or the randomized private key value of the first part of the private key value, and the target data is obtained based on the randomized private key value of one or more private key values in the first part of the private key value.

[0011] In a second aspect, an embodiment of the present application provides a cryptographic chip, which includes:

[0012] A response module, configured to respond to a cryptographic service request;

[0013] An acquisition module, configured to acquire a RAS-CRT key corresponding to a request identifier carried in the cryptographic service request, where the RAS-CRT key includes a private key;

[0014] A processing module, configured to perform a randomization process on the first part of the private key value in the private key to obtain the randomized private key value of the first part of the private key value;

[0015] The processing module is further configured to perform a private key operation on the data to be processed carried in the cryptographic service request based on the target private key value of the first part of the private key value and the second part of the private key value in the private key to obtain target data; wherein, the target private key value is the private key value or the randomized private key value of the private key value, and the target data is obtained based on the randomized private key value of one or more private key values in the first part of the private key value;

[0016] A sending module, configured to send cryptographic service response data corresponding to the cryptographic service request; wherein, the cryptographic service response data includes the target data.

[0017] In a third aspect, an embodiment of the present application provides a cryptographic chip, which includes a memory and a processor,

[0018] The memory stores a computer program that can run on the processor,

[0019] When the processor executes the program, it implements some or all of the steps in the method described in the first aspect.

[0020] In a fourth aspect, an embodiment of the present application provides a cryptographic device, which includes a cryptographic chip.

[0021] In a fifth aspect, an embodiment of the present application provides a storage medium, which stores one or more computer programs, and the one or more computer programs can be executed by one or more processors to implement some or all of the steps in the method described in the first aspect.

[0022] In a sixth aspect, an embodiment of the present application provides a computer program product, including a computer program or instruction, which when executed by a processor, implements some or all of the steps in the method described in the first aspect.

[0023] An embodiment of the present application provides at least one RSA-CRT password data processing method and a password chip. In response to a password service request, an RAS-CRT key corresponding to the request identifier carried in the password service request is obtained, where the RAS-CRT key includes a private key; the first part of the private key value in the private key is randomized to obtain a randomized private key value of the first part of the private key value; based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, a private key operation is performed on the data to be processed carried in the password service request to obtain target data, and password service response data corresponding to the password service request is sent; where the password service response data includes the target data; where the target private key value is the first part of the private key value or the randomized private key value of the first part of the private key value, and the target data is obtained based on one or more randomized private key values in the first part of the private key value. In the embodiment of the present application, part of the private key values in the private key participating in the operation are randomly transformed, and modular exponentiation is performed on the data to be processed at least according to the randomized private key value of one private key value, increasing the difficulty of attacker analysis and cracking, reducing the possibility that the attacker obtains the key information of the RSA private key through side-channel analysis, and improving the security of applying RSA-CRT operations.

[0024] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and do not limit the technical solution of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The drawings herein are incorporated into the specification and constitute a part of this specification. These drawings illustrate embodiments consistent with the present application and are used together with the specification to explain the technical solution of the present application.

[0026] Figure 1 It is a schematic structural diagram of an optional password chip provided by an embodiment of the present application;

[0027] Figure 2 It is a schematic flowchart of an optional RSA-CRT password data processing method provided by an embodiment of the present application;

[0028] Figure 3 It is a schematic flowchart of another optional RSA-CRT password data processing method provided by an embodiment of the present application;

[0029] Figure 4 It is a schematic flowchart of yet another optional RSA-CRT password data processing method provided by an embodiment of the present application;

[0030] Figure 5 Schematic flow chart of an alternative RSA-CRT cryptographic data processing method provided by another embodiment of the present application;

[0031] Figure 6 Schematic flow chart of another alternative RSA-CRT cryptographic data processing method provided by another embodiment of the present application;

[0032] Figure 7 Schematic flow chart of yet another alternative RSA-CRT cryptographic data processing method provided by another embodiment of the present application;

[0033] Figure 8 Schematic structural diagram of another alternative cryptographic chip provided by an embodiment of the present application;

[0034] Figure 9 Schematic diagram of the hardware entity of a cryptographic chip provided by an embodiment of the present application;

[0035] Figure 10 Schematic diagram of the hardware entity of a cryptographic device provided by an embodiment of the present application. Detailed implementation manners

[0036] In order to make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be further elaborated in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be construed as limitations on the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.

[0037] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict. The terms "first / second / third" involved are only used to distinguish similar objects and do not represent a specific order for the objects. It can be understood that "first / second / third" can be interchanged with a specific order or sequence when allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.

[0038] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs. The terms used herein are only for the purpose of describing this application and are not intended to limit this application.

[0039] The RSA encryption algorithm is currently the most widely used public-key cryptography algorithm. To improve the operational security, the RSA non-CRT secure operation method was proposed in traditional technologies. This method is implemented based on a cryptographic hardware accelerator. Specifically, by randomly splitting the private key exponent d into two components d1 and d2 in modular exponentiation, introducing a random number k, and performing modular exponentiation in combination with the public key e. For example, for , the private key exponent d is transformed as described above to obtain, for example, . Combining with the RSA operation characteristics, equivalent calculations are achieved. However, this method still has the problems of low computational efficiency and possible leakage of key information.

[0040] In modern scenarios with high security requirements, RSA cryptographic calculations are widely used in multiple fields such as Public Key Infrastructure (PKI), blockchain, servers, various terminal devices, cryptographic machines (cryptographic acceleration cards), secure communication, and digital payment. Especially in fields such as banks, governments, and enterprises that need to process sensitive data, while ensuring high security and taking performance into account at the same time, the RSA-CRT algorithm replacing the traditional RSA algorithm has become a trend.

[0041] The RSA-CRT algorithm is an optimization technique in the RSA encryption algorithm. Especially during the modular exponentiation process of large integers, it accelerates the RSA signature and decryption operations (private key operations) through the Chinese Remainder Theorem (CRT). RSA-CRT is particularly suitable for reducing the calculation time and improving performance, especially when the modulus bits are large, significantly enhancing the performance of private key operations and being widely used in practical applications.

[0042] Therefore, related technologies have proposed the technology of RSA-CRT secure operation, which relies on a hardware side accelerator with resistance to side-channel attacks, thus enabling a Montgomery ladder modular exponentiation hardware accelerator that can reduce risks such as Simple Power Analysis (SPA), Differential Power Analysis (DPA), and timing analysis attacks. However, for hardware accelerators with ordinary modular exponentiation functions in non-high-security versions, they are more vulnerable to SPA, DPA, or timing analysis attacks. Since the RSA-CRT operation process requires the use of a large amount of secret information including p, q, dp, and dq, which are respectively applied to the modulus and exponent, and these values are all closely related to the private key. There are more or less secret information leakage problems when cryptographic devices execute cryptographic algorithms. And existing side-channel analysis means enable attackers to obtain the possibility of leaking key information through various information.

[0043] Here, the key generation process of the RSA algorithm, RSA-CRT, the RSA-CRT private key operation process, and the problems existing in the private key operation using RSA-CRT are described.

[0044] 1) Regarding the key generation process of the RSA algorithm

[0045] The first step: Select two large prime numbers p and q;

[0046] The second step: Calculate the modulus N, where the modulus N can be obtained through the following formula (1);

[0047]

[0048] The third step: Calculate the Euler's totient function , where the Euler's totient function can be obtained through the following formula (2);

[0049]

[0050] The fourth step: Select a public key e, which satisfies , and ;

[0051] The fifth step: Calculate the private key d, which can be obtained through the following formula (3).

[0052]

[0053] Encryption or signature verification (public key operation) can be calculated through the following formula (4):

[0054]

[0055] Among them, in the public key operation, M represents the data to be processed, and the data to be processed can be plaintext data or signed data. C represents the target data after the public key operation, and the target data can be ciphertext data or data after signature verification. e represents the public key, and N represents the modulus;

[0056] Decryption or signature (private key operation) can be calculated through the following formula (5):

[0057]

[0058] Among them, in the private key operation, C represents the data to be processed, and the data to be processed can be ciphertext data or data to be signed. M represents the target data after the private key operation, and the target data can be plaintext data or signed data. e represents the public key, and N represents the modulus.

[0059] 2) Regarding RSA-CRT

[0060] RSA-CRT is an optimization technique introduced in the RSA encryption algorithm. Based on the Chinese Remainder Theorem, it decomposes the calculations during the private key operations (RSA decryption and signature) into multiple smaller modular operations, thus accelerating the modular arithmetic of large numbers and significantly improving the computational efficiency, especially in cases where large integers need to be processed. With RSA-CRT, an acceleration factor of 4 is usually achieved, and it approaches 8 times if modular exponentiation can be parallelized.

[0061] 3) For the RSA-CRT private key operation

[0062] First step: Determine the private key quintuple (p, q, dp, dq, qInv) corresponding to the private key d; where p and q are two randomly generated large prime numbers, and dp, dq, and qInv can be obtained through the following formula (6).

[0063]

[0064]

[0065]

[0066] Second step: Calculate m1, and m1 can be obtained through the following formula (7).

[0067]

[0068] Third step: Calculate m2, and m2 can be obtained through the following formula (8).

[0069]

[0070] Fourth step: Calculate h, and h can be obtained through the following formula (9).

[0071]

[0072] Fifth step: Calculate M, and M can be obtained through the following formula (10).

[0073]

[0074] For RSA-CRT private key operations, the private key quintuple cannot be made public because it contains the critical information of the private key. If any value is obtained through any side-channel analysis attack, there will be a serious security risk of private key leakage. RSA-CRT operations use p and q as moduli. As the RSA cracking problem of factoring large numbers, which is the essence of RSA, p and q directly determine the security of the RSA system. Attacks on p and q are often the key to cracking the RSA private key. Therefore, to enhance the security of RSA-CRT, especially in side-channel attacks such as inferring p, q, dp, and dq information through time analysis, power analysis, etc., scrambling needs to be adopted for protection.

[0075] 4) Problems existing in using RSA-CRT for private key operations

[0076] If dp or dq is inferred through analysis, there will also be a serious security risk of private key leakage. For example, given the modulus N (public), the public key e (public), the ciphertext C (stolen), and dp (obtained through analysis), the private key can be inferred. Assume d is the RSA-non-CRT private key, satisfying the relationship shown in formula (11):

[0077]

[0078] Continuing to derive formula (11), formula (12) is obtained.

[0079]

[0080] where k is For the quotient.

[0081] Since the RSA-CRT key generation satisfies formula (2), formula (12) is transformed as follows.

[0082]

[0083] where k in the above formula is the quotient of d*e divided by (p - 1), and , formula (13) is transformed as follows.

[0084]

[0085] Continuing to derive formula (14).

[0086]

[0087] Moving the terms in formula (15).

[0088]

[0089] Extract the common term (p - 1) from formula (16).

[0090]

[0091] From the above premises, it is known that the attacker has obtained dp and the public key e. Assume , transform formula (17).

[0092]

[0093] In the RSA-CRT private key operation , so dp < p - 1. From formula (18), it can be obtained that e > x.

[0094] Therefore, given dp, e, and both p and x are positive integers, the attacker can iterate through , and there must be an x that satisfies formula (18), thereby calculating p, and then cracking q from the modulus N, and the private key is deduced. Generally, the public key exponent e in the industry is mostly 65537, and the calculation cost is not high. If it is changed from knowing dp and not knowing dq to knowing dq and not knowing dp, there is also a possibility of private key leakage.

[0095] In view of one or more of the above problems, the exemplary embodiments of the present application first provide an RSA-CRT cryptographic data processing method. Combining existing modular exponentiation, modular multiplication, and modular addition and subtraction hardware accelerators, introducing random numbers, and performing randomization transformation on the data participating in the operation, such as the private key values in the private key used as the exponent and modulus, to increase the difficulty of analysis and cracking, and to minimize the possibility that the attacker obtains the key information of the RSA private key through side-channel analysis, thereby improving the security of the application of RSA-CRT operations.

[0096] Before introducing the embodiments of the present application, Fermat's little theorem and some properties of modular arithmetic are briefly described.

[0097] 1) Regarding Fermat's little theorem

[0098] For any prime number s and integer ( is the integer ring modulo s, ), there is the following formula (19)

[0099]

[0100] Multiply both sides of formula (19) by , and obtain formula (20):

[0101]

[0102] Among them, the Euler's totient function can be expressed by formula (21).

[0103]

[0104] For a prime number s, if , assume , where k is an integer, , by using Fermat's little theorem combined with the properties of modular exponentiation, the following formula (22) can be obtained.

[0105]

[0106]

[0107]

[0108]

[0109] Among them, k is the quotient of t divided by s - 1, and n is the remainder, where .

[0110] If , the following formula (23) can be obtained in reverse

[0111]

[0112]

[0113]

[0114] Among them, k is any positive integer.

[0115] 2) Regarding the properties of modular arithmetic

[0116]

[0117]

[0118] Among them, q3 is the quotient of A divided by B, and u is the remainder of A modulo B ( ), because and are both multiples of B, and the remainder of the final modular arithmetic is also u.

[0119] Figure 1 FIG. is a schematic structural diagram of an optional cryptographic chip provided by an embodiment of the present application. Here, the cryptographic chip 100 includes a software logic module 110, a hardware cryptographic module 120, and a storage module 130 connected by a bus.

[0120] Among them, the software logic module 110 can be configured to control the hardware cryptographic module 120 to obtain data from the storage module 130 to execute the RSA-CRT cryptographic data processing method provided by the embodiments of the present application. The software logic module 110 can be in the form of a processor (Central Processing Unit, CPU), etc.

[0121] Among them, the hardware cryptographic module 120 includes multiple arithmetic units and a generation unit. A part of the arithmetic units in the hardware cryptographic module 120 can be configured to perform modular exponentiation operations in the RSA-CRT algorithm. Another part of the arithmetic units can be configured to perform operations such as modular exponentiation, modular addition, modular subtraction, modular inverse, and modular multiplication related to the embodiments of the present application; here, the arithmetic units can be hardware accelerators. The generation unit in the hardware cryptographic module 120 is used to generate true random numbers or true random values. Here, the generation unit can be a true random number generator.

[0122] Among them, the storage module 130 is configured to store the acquired data to be processed and the private key of the RSA-CRT algorithm, as well as the sub-private key values of each private key value included in the private key and multiple random values. A part of the arithmetic units is configured to perform private key operation processing using the data to be processed and the private key of the RSA-CRT algorithm, and after operations such as modular exponentiation, modular addition, modular subtraction, modular inverse, and modular multiplication performed by another part of the arithmetic units based on the random values and sub-private key values, output the target data.

[0123] Refer to Figure 2 , Figure 2 FIG. is a schematic implementation flowchart of an RSA-CRT cryptographic data processing method provided by the embodiments of the present application, which is applied to a cryptographic chip. Here, it will be described in combination with Figure 2 the steps shown.

[0124] Step 201, in response to a cryptographic service request, obtain an RAS-CRT key corresponding to the request identifier carried in the cryptographic service request.

[0125] Among them, the RSA-CRT key includes a private key.

[0126] In the embodiments of the present application, the cryptographic service request carries the data to be processed and a request identifier. The cryptographic service request is used to request the cryptographic chip to perform private key operation on the data to be processed. Among them, the cryptographic service request can be a signature service request for signing the data to be processed, or the cryptographic service request can also be a decryption service request for decrypting the data to be processed. In this regard, the present application does not make specific limitations.

[0127] In the embodiments of the present application, if the password service request is a signature service request, the data to be processed may be the plaintext data to be signed; if the password service request is a decryption service request, the data to be processed may be the ciphertext data to be decrypted.

[0128] In the embodiments of the present application, the request identifier is used to obtain the RAS-CRT key corresponding to the data to be processed, and the request identifier and the RAS-CRT key are in one-to-one correspondence.

[0129] In the embodiments of the present application, the RSA-CRT key includes a public key and a private key, and the public key and the private key are in one-to-one correspondence. In the RSA-CRT algorithm, the public key is (N, e), where N is the first public key value and e is the second public key value. In the RSA-CRT algorithm, the private key d is a private key quintuple (p, q, dp, dq, qInv), where p is the first private key value, q is the second private key value, dp is the third private key value, dq is the fourth private key value, and qInv is the fifth private key value. Here, p and q are both large prime numbers, N can be obtained through the above formula (1), and dp, dq, and qInv can be obtained through the above formula (6).

[0130] It should be noted that according to the quantity relationship of the modulo operation in the above formula (6), the first private key value corresponds to the third private key value, and the second private key value corresponds to the fourth private key value.

[0131] In the embodiments of the present application, the private key in the RSA-CRT key can be pre-stored in the storage module of the password chip, such as a memory, and the private key can be obtained from the storage module. The public key in the RSA-CRT key can be public.

[0132] In some embodiments, the password chip can be built into the server or the client.

[0133] In one case, the password chip is built into the server. The manufacturer requests the server with the built-in password chip to perform RSA-CRT private key operations on data such as firmware, and the Certificate Authority (CA) signs the application identifier message when issuing a certificate. The server with the built-in password chip stores the RSA-CRT key of this data. The process of the private key operation includes: the client sends a password service request to the server with the built-in password chip, where the password service request carries the data to be signed / data to be decrypted, and the request identifier. Here, the data to be signed can be the firmware image / request identifier information, and the data to be decrypted can be the firmware ciphertext / key ciphertext. Further, the server with the built-in password chip responds to the password service request, uses the RSA-CRT key corresponding to the request identifier, performs a private key operation on the data to be signed / data to be decrypted, and returns the result of the private key operation to the client.

[0134] In another example, a password chip is built into a client such as a Ukey. The client with the built-in password chip performs RSA-CRT private key operations on the transaction information of a server such as an online bank. The client with the built-in password chip stores the RSA-CRT key of the client. The private key operation process includes: the client with the built-in password chip receives a password service request sent by the server. Here, the password service request carries data to be signed / data to be decrypted, and a request identifier. Here, the data to be signed / data to be decrypted can be online bank transaction information. Further, the client with the built-in password chip responds to the password service request, uses the RSA-CRT key corresponding to the request identifier, performs private key operations on the data to be signed / data to be decrypted, and returns the result of the private key operation to the server.

[0135] Step 202: Randomize the first part of the private key value in the private key to obtain a randomized private key value of the first part of the private key value.

[0136] In the embodiments of the present application, the first part of the private key value in the private key may include a first private key value p, a second private key value q, a third private key value dp, and a fourth private key value dq.

[0137] In the embodiments of the present application, after the password chip obtains the RAS-CRT key including the private key corresponding to the request identifier in the password service request, it randomizes each private key value in the first part of the private key value in the private key to obtain a randomized private key value for each private key value. That is to say, the target private key values corresponding to the first private key value, the second private key value, the third private key value, and the fourth private key value in the private key are obtained.

[0138] Step 203: Based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, perform private key operations on the data to be processed carried in the password service request to obtain target data, and send password service response data corresponding to the password service request.

[0139] Among them, the password service response data includes the target data.

[0140] Among them, the target private key value is the first part of the private key value or the randomized private key value of the first part of the private key value, and the target data is obtained based on one or more randomized private key values in the first part of the private key value.

[0141] In the embodiments of the present application, the target private key value may be each private key value in the first part of the private key value, or the corresponding randomized private key value obtained by randomizing each private key value in the first part of the private key value.

[0142] In the embodiments of the present application, the target private key values of the first part of the private key values may include: the target private key value of the first private key value, the target private key value of the second private key value, the target private key value of the third private key value, and the target private key value of the fourth private key value. Here, the target private key value of the first private key value may be the first private key value or the randomized private key value of the first private key value; the target private key value of the second private key value may be the second private key value or the randomized private key value of the second private key value; the target private key value of the third private key value may be the third private key value or the randomized private key value of the third private key value; the target private key value of the fourth private key value may be the fourth private key value or the randomized private key value of the fourth private key value. It should be noted that in different operation processes, the target private key values used for different operations may be the same or different. In this regard, the embodiments of the present application do not make specific restrictions.

[0143] In the embodiments of the present application, the private key d may further include a second part of the private key value, and the second part of the private key value may be the fifth private key value qInv.

[0144] In the embodiments of the present application, the target data may be the plaintext data obtained by decrypting the data to be processed, or the signature data obtained by signing the plaintext data. In this regard, the present application does not make specific restrictions.

[0145] In the embodiments of the present application, the target data may be obtained based on the target private key value in the first part of the private key values and the fifth private key value, and the target data is obtained based on the randomized private key value of one or more private key values in the first part of the private key values.

[0146] In the embodiments of the present application, the cryptographic chip performs a private key operation on the data to be processed carried in the cryptographic service request based on the target private key value of the first part of the private key values and the second part of the private key value in the private key, obtains the target data, generates the cryptographic service response data carrying the target data corresponding to the cryptographic service request, and sends the cryptographic service response data.

[0147] An embodiment of the present application provides an RSA-CRT cryptographic data processing method. In response to a cryptographic service request, an RAS-CRT key corresponding to the request identifier carried in the cryptographic service request is obtained, where the RAS-CRT key includes a private key; the first part of the private key value in the private key is randomized to obtain a randomized private key value of the first part of the private key value; based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, a private key operation is performed on the data to be processed carried in the cryptographic service request to obtain target data, and a cryptographic service response data corresponding to the cryptographic service request is sent; where the cryptographic service response data includes the target data; where the target private key value is the first part of the private key value or the randomized private key value of the first part of the private key value, and the target data is obtained based on one or more randomized private key values in the first part of the private key value. In the embodiment of the present application, part of the private key values in the private key participating in the operation are randomly transformed, and modular exponentiation is performed on the data to be processed at least according to the randomized private key value of one private key value, increasing the difficulty for an attacker to analyze and crack, reducing the possibility for an attacker to obtain key information of the RSA private key through side-channel analysis, and improving the security of applying RSA-CRT operations.

[0148] In some embodiments, the process of step 202 of randomizing the first part of the private key value in the private key to obtain a randomized private key value of the first part of the private key value is described in conjunction with Figure 3 the following.

[0149] Step 301: For any reference private key value in the first part of the private key value, obtain a first reference random value, a second reference random value, a reference sub-private key value, and a data type that are pre-stored and corresponding to the reference private key value.

[0150] In the embodiment of the present application, the reference private key value may be any private key value in the first part of the private key value. For example, the reference value may be one of the first private key value p, the second private key value q, the third private key value dp, and the fourth private key value dq.

[0151] In the embodiment of the present application, the first reference random value and the second reference random value corresponding to the reference private key value are pre-stored in the storage module of the cryptographic chip. The first reference random value and the second reference random value may be random numbers randomly generated by a generating unit in the hardware cryptographic module in the cryptographic chip. The first reference random value and the second reference random value may be random prime numbers or other random numbers that are not random prime numbers.

[0152] In the embodiment of the present application, the reference sub-private key value corresponding to the reference private key value is pre-stored in the storage module of the cryptographic chip, and the reference sub-private key value corresponds to the reference private key value one by one. It should be noted that the reference sub-private key value may be a positive number.

[0153] In the embodiments of the present application, the data types include a first data type and a second data type. The data of the first data type may include a first private key value and a second private key value, and the data of the second data type may include a third private key value and a fourth private key value.

[0154] Step 302: Based on the first reference random value, the second reference random value, and the reference sub-private key value, use the calculation method corresponding to the data type to perform randomization processing on the reference private key value to obtain the reference randomized private key value of the reference private key value.

[0155] In the embodiments of the present application, the calculation methods corresponding to different data types are different.

[0156] In the first case, if the data type is the first data type, the calculation method corresponding to the first data type can be implemented through the following process:

[0157] Calculate the product of the second reference random value and the reference sub-private key value to obtain the first reference product; calculate the product of the first reference random value and the second reference random value to obtain the second reference product; calculate the sum of the first reference product and the second reference product to obtain the reference randomized private key value.

[0158] In an example, if the reference private key value is the first private key value, the first reference random value can be the first random value, the second reference random value can be the second random value, and the reference sub-private key value can be the first sub-private key value. Since the data type of the first private key value belongs to the first data type, using the calculation method corresponding to the first data type, the first randomized private key value of the first private key value can be obtained through the following formula (26):

[0159]

[0160] where is the first randomized private key value, is the first random value, is the second random value, is the first sub-private key value, is the first private key value.

[0161] In another example, if the reference private key value is the second private key value, the first reference random value can be the third random value, the second reference random value can be the fourth random value, and the reference sub-private key value can be the second sub-private key value. Since the data type of the second private key value belongs to the first data type, using the calculation method corresponding to the first data type, the second randomized private key value of the second private key value can be obtained through the following formula (27):

[0162]

[0163] where is the second randomized private key value, is the third random value, is the fourth random value, is the second sub-private key value, is the second private key value.

[0164] In the second case, if the data type is the second data type, the calculation method corresponding to the second data type can be implemented through the following process:

[0165] Calculate the product of the first reference random value and the second reference random value to obtain the third reference product; calculate the product of the first reference random value and the reference sub-private key value to obtain the fourth reference product; calculate the sum of the reference private key value, the third reference product, and the fourth reference product to obtain the reference randomized private key value.

[0166] In one example, if the reference private key value is the third private key value, the first reference random value can be the fifth random value, the second reference random value can be the sixth random value, and the reference sub-private key value can be the third sub-private key value. Since the data type of the third private key value belongs to the second data type, using the calculation method corresponding to the second data type, the third randomized private key value of the third private key value can be obtained through the following formula (28),

[0167]

[0168] where, is the third randomized private key value, is the third private key value, is the fifth random value, is the sixth random value, is the third sub-private key value.

[0169] In another example, if the reference private key value is the fourth private key value, the first reference random value can be the seventh random value, the second reference random value can be the eighth random value, and the reference sub-private key value can be the fourth sub-private key value. Since the data type of the fourth private key value belongs to the second data type, using the calculation method corresponding to the second data type, the fourth randomized private key value of the fourth private key value can be obtained through the following formula (29),

[0170]

[0171] where, is the fourth randomized private key value, is the fourth private key value, is the seventh random value, is the eighth random value, is the fourth sub-private key value.

[0172] As described above, the embodiments of the present application pre-store the reference sub-private key values, the first reference random value, and the second reference random value corresponding to each reference private key value. By introducing the reference sub-private key value, the first reference random value, and the second reference random value, a random transformation is performed on the corresponding reference private key value to achieve scrambling, thereby reducing the risk of side-channel analysis of the reference private key value. At the same time, the actual effective bits of the random number are flexibly controlled, the actual effective bit length of the reference private key value used as the modulus exponentiation modulus is increased, the analysis and cracking difficulty for the attacker is increased, and the possibility that the attacker obtains the key information of the RSA private key through side-channel analysis is minimized, thereby improving the security of the application of the RSA-CRT operation.

[0173] In some embodiments, step 203 performs a private key operation on the data to be processed carried in the password service request based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, and the process of obtaining the target data is described in conjunction with Figure 4 explanation.

[0174] Step 401: Perform modular exponentiation on the data to be processed based on the target private key value of the first part of the private key value to obtain the first intermediate data and the second intermediate data.

[0175] In the embodiments of the present application, the first intermediate data can be obtained based on the target private key value of the first private key value and the target private key value of the third private key value, and the second intermediate data can be obtained based on the target private key value of the second private key value and the target private key value of the fourth private key value.

[0176] Here, the obtaining method of the first intermediate data may include the following various situations:

[0177] Situation 1: The first intermediate data can be obtained based on the first private key value and the third private key value;

[0178] Situation 2: The first intermediate data can be obtained based on the randomized private key values of the first private key value and the third private key value;

[0179] Situation 3: The first intermediate data can be obtained based on the randomized private key value of the first private key value and the third private key value;

[0180] Situation 4: The first intermediate data can be obtained based on the randomized private key values of the first private key value and the third private key value.

[0181] Here, the obtaining method of the second intermediate data may include the following various situations:

[0182] Situation 1: The second intermediate data can be obtained based on the second private key value and the fourth private key value;

[0183] Situation 2: The second intermediate data can be obtained based on the randomized private key values of the second private key value and the fourth private key value;

[0184] Case 3: The second intermediate data can be obtained based on the randomized private key value of the second private key value and the fourth private key value;

[0185] Case 4: The second intermediate data can be obtained based on the randomized private key value of the second private key value and the randomized private key value of the fourth private key value.

[0186] It should be noted that the ways to obtain the first intermediate data and the second intermediate data can be obtained by pairwise combination of any case of obtaining the first intermediate data and any case of obtaining the second intermediate data.

[0187] In the embodiment of the present application, after obtaining the data to be processed and the RSA-CRT key, based on the target private key value of the first private key value and the target private key value of the third private key value, modular exponentiation is performed on the data to be processed to obtain the first intermediate data; based on the target private key value of the second private key value and the target private key value of the fourth private key value, modular exponentiation is performed on the data to be processed to obtain the second intermediate data.

[0188] It can be understood that the first part of the private key values includes the first private key value, the second private key value, the third private key value, and the fourth private key value. In step 401, based on the target private key value of the first part of the private key values in the private key, modular exponentiation is performed on the data to be processed to obtain the first intermediate data and the second intermediate data, and the process is described in combination with Figure 5 for illustration.

[0189] Step 501: Using the target private key value of the first private key value as the modulus, and / or using the target private key value of the third private key value as the exponent, perform modular exponentiation on the data to be processed to obtain the first intermediate data.

[0190] It can be understood that step 501 uses the target private key value of the first private key value as the modulus, and / or uses the target private key value of the third private key value as the exponent, and performs modular exponentiation on the data to be processed to obtain the first intermediate data. This can be achieved through the following process:

[0191] Using the target private key value of the first private key value as the modulus, and / or using the target private key value of the third private key value as the exponent, perform modular exponentiation on the data to be processed to obtain the first reference intermediate data; using the first private key value as the modulus, perform modular operation on the first reference intermediate data to obtain the first intermediate data.

[0192] In the embodiment of the present application, the first reference intermediate data can be obtained through the following formula (30):

[0193]

[0194] where, is the first reference intermediate data, is the data to be processed, The target private key value that is the third private key value, can be the third private key value dp or the third randomized private key value ; The target private key value that is the first private key value, can be the first private key value p or the first randomized private key value .

[0195] In the embodiments of the present application, the first intermediate data can be obtained through the following formula (31),

[0196]

[0197] wherein, is the first intermediate data, is the first reference intermediate data, and p is the first private key value.

[0198] In some embodiments, taking the target private key value of the first private key value as the modulus, and / or taking the target private key value of the third private key value as the exponent, performing modular exponentiation on the data to be processed to obtain the first reference intermediate data, which can be implemented in any of the following ways:

[0199] Method 1: Taking the first private key value as the modulus and the third private key value as the exponent, performing modular exponentiation on the data to be processed to obtain the first reference intermediate data;

[0200] Method 2: Taking the first private key value as the modulus and the randomized private key value of the third private key value as the exponent, performing modular exponentiation on the data to be processed to obtain the first reference intermediate data;

[0201] Method 3: Taking the randomized private key value of the first private key value as the modulus and the third private key value as the exponent, performing modular exponentiation on the data to be processed to obtain the first reference intermediate data;

[0202] Method 4: Taking the randomized private key value of the first private key value as the modulus and the randomized private key value of the third private key value as the exponent, performing modular exponentiation on the data to be processed to obtain the first reference intermediate data.

[0203] As can be seen from the above, in the embodiments of the present application, by using the randomized transformed first private key value as the modulus, and / or using the randomized transformed third private key value as the exponent to participate in the operation, the difficulty of analysis and cracking by attackers is increased, and the possibility that attackers obtain the key information of the RSA private key through side-channel analysis is minimized, thereby improving the security of the application of RSA-CRT operations.

[0204] Step 502: Based on the target private key value of the second private key value as the modulus, and / or the target private key value of the fourth private key value as the exponent, performing modular exponentiation on the data to be processed to obtain the second intermediate data.

[0205] Understandably, the step 502 performs modular exponentiation on the data to be processed using the target private key value of the second private key value as the modulus and / or the target private key value of the fourth private key value as the exponent, and the second intermediate data can be obtained through the following process:

[0206] Perform modular exponentiation on the data to be processed using the target private key value of the second private key value as the modulus and / or the target private key value of the fourth private key value as the exponent to obtain the second reference intermediate data; perform a modulo operation on the second reference intermediate data using the second private key value as the modulus to obtain the second intermediate data.

[0207] In the embodiments of the present application, the second reference intermediate data can be obtained through the following formula (32):

[0208]

[0209] Wherein, is the second reference intermediate data, is the data to be processed, is the target private key value of the fourth private key value, can be the fourth private key value dq or the fourth randomized private key value ; is the target private key value of the second private key value, can be the second private key value q or the second randomized private key value .

[0210] In the embodiments of the present application, the second intermediate data can be obtained through the following formula (33):

[0211]

[0212] Wherein, is the second intermediate data, is the second reference intermediate data, and q is the second private key value.

[0213] In some embodiments, performing modular exponentiation on the data to be processed using the target private key value of the second private key value as the modulus and / or the target private key value of the fourth private key value as the exponent to obtain the second reference intermediate data can be implemented in any of the following ways:

[0214] Way 1: Perform modular exponentiation on the data to be processed using the second private key value as the modulus and the fourth private key value as the exponent to obtain the second reference intermediate data; or,

[0215] Way 2: Perform modular exponentiation on the data to be processed using the second private key value as the modulus and the randomized private key value of the fourth private key value dq as the exponent to obtain the second reference intermediate data; or,

[0216] Method 3: Using the randomized private key value of the second private key value as the modulus and the fourth private key value as the exponent, perform modular exponentiation on the data to be processed to obtain the second reference intermediate data; or,

[0217] Method 4: Using the randomized private key value of the second private key value as the modulus and the randomized private key value of the fourth private key value as the exponent, perform modular exponentiation on the data to be processed to obtain the second reference intermediate data.

[0218] As can be seen from the above, in the embodiments of the present application, by using the randomized second private key value as the modulus and / or the randomized fourth private key value as the exponent to participate in the operation, the difficulty of analysis and cracking by the attacker is increased, and the possibility that the attacker obtains the key information of the RSA private key through side-channel analysis is minimized, thereby improving the security of the application of RSA-CRT operation.

[0219] Step 402: Based on the first intermediate data, the second intermediate data, and the second partial private key value, perform private key operation on the data to be processed to obtain the target data.

[0220] In the embodiments of the present application, performing private key operation on the data to be processed based on the first intermediate data, the second intermediate data, and the second partial private key value to obtain the target data may include:

[0221] If at least one of the first intermediate data and the second intermediate data is obtained based on one or more randomized private key values of the first partial private key value, private key operation may be performed on the data to be processed based on the first intermediate data, the second intermediate data, the fifth private key value, and the first private key value in the first partial private key value to obtain the target data.

[0222] If both the first intermediate data and the second intermediate data are obtained based on multiple private key values in the first partial private key value, private key operation may be performed on the data to be processed based on the first intermediate data, the second intermediate data, the fifth private key value, and the randomized private key value of the first private key value in the first partial private key value to obtain the target data.

[0223] In the embodiments of the present application, after the cryptographic chip performs modular exponentiation on the data to be processed based on the target private key value of the first partial private key value in the private key to obtain the first intermediate data and the second intermediate data, private key operation is performed on the data to be processed based on the first intermediate data, the second intermediate data, and the fifth private key value to obtain the target data after the operation.

[0224] In some embodiments, the process of step 402 performing private key operation on the data to be processed based on the first intermediate data, the second intermediate data, and the second partial private key value to obtain the target data is described in conjunction with Figure 6 for illustration.

[0225] Step 601: Obtain the ninth random value and the fifth sub-private key value corresponding to the fifth private key value that are pre-stored, as well as the target private key value of the first private key value in the first part of the private key value.

[0226] In the embodiments of the present application, the ninth random value is pre-stored in the storage module of the cryptographic chip, and the ninth random value is a random number randomly generated by the generation unit in the hardware cryptographic module. The ninth random value can be a random prime number or other random numbers that are not random prime numbers. In this regard, the present application does not make specific limitations.

[0227] In the embodiments of the present application, the fifth sub-private key value is pre-stored in the storage module of the cryptographic chip. The fifth sub-private key value is determined based on the fifth private key value and the ninth random value. The fifth sub-private key value can be the difference obtained by subtracting the ninth random value from the fifth private key value. It should be noted that the ninth random value is less than the fifth private key value, so as to ensure that the fifth sub-private key value is a positive number.

[0228] Step 602: Randomize the difference between the first intermediate data and the second intermediate data based on the ninth random value, the fifth sub-private key value, and the target private key value of the first private key value to obtain the third intermediate data.

[0229] It can be understood that step 602 randomizes the difference between the first intermediate data and the second intermediate data based on the ninth random value, the fifth sub-private key value, and the target private key value of the first private key value to obtain the third intermediate data, which can be implemented through the following steps:

[0230] Step 621: Perform a modulo operation on the difference between the first intermediate data and the second intermediate data with the target private key value of the first private key value as the modulus to obtain the fourth intermediate data.

[0231] In the embodiments of the present application, the fourth intermediate data can be obtained through the following formula (34),

[0232]

[0233] where, is the fourth intermediate data, is the first intermediate data, is the second intermediate data, is the difference between the first intermediate data and the second intermediate data, is the target private key value of the first private key value, can be the first private key value p or the randomized private key value of the first private key value .

[0234] Step 622: Calculate the product of the fourth intermediate data and the ninth random value to obtain the first product;

[0235] Step 623: Calculate the product of the fourth intermediate data and the fifth sub-private key value to obtain the second product;

[0236] Step 624: Based on the first product, the second product, the first private key value, and the randomized private key value of the first private key value, obtain the third intermediate data.

[0237] In one case, step 624 based on the first product, the second product, the first private key value, and the randomized private key value of the first private key value to obtain the third intermediate data can be implemented through the following process:

[0238] Calculate the sum value of the first product and the second product, and perform two modulo operations on this sum value with the first private key value and the randomized private key value of the first private key value respectively to obtain the third intermediate data. Specifically, sum the first product and the second product to obtain the sum value; perform a modulo operation on this sum value with the randomized private key value of the first private key value to obtain the fourth operation result, and perform a modulo operation on the fourth operation result with the first random value to obtain the third intermediate result.

[0239] In the embodiments of the present application, the third intermediate data can be obtained through the following formula (35)

[0240]

[0241] where, is the third intermediate data, is the fourth intermediate data, is the ninth random value, is the fifth sub-private key value, is the first private key value, is the randomized private key value of the first private key value.

[0242] In another case, in order to reduce the occupation of bit width and improve the calculation efficiency, step 624 based on the first product, the second product, the first private key value, and the randomized private key value of the first private key value to obtain the third intermediate data can also be implemented through the following process:

[0243] Perform two modulo operations on the first product with the first private key value and the randomized private key value of the first private key value respectively to obtain the first operation result; perform two modulo operations on the second product with the first private key value and the randomized private key value of the first private key value respectively to obtain the second operation result; determine the sum of the first operation result and the second operation result as the third intermediate data.

[0244] Specifically, taking the randomized private key value of the first private key value as the modulus, performing a modulo operation on the first product to obtain a first intermediate operation result, and then taking the first random value as the modulus, performing a modulo operation on the first intermediate operation result to obtain a first operation result; taking the randomized private key value of the first private key value as the modulus, performing a modulo operation on the second product to obtain a second intermediate operation result, and then taking the first random value as the modulus, performing a modulo operation on the second intermediate operation result to obtain a second operation result.

[0245] In the embodiment of the present application, the third intermediate data can be obtained through the following formula (36)

[0246]

[0247] where is the third intermediate data, is the first operation result, is the second operation result, is the fourth intermediate data, is the ninth random value, is the fifth sub-private key value, is the first private key value, is the randomized private key value of the first private key value. In this way, in order to reduce the bit-width occupation and improve the calculation efficiency.

[0248] Step 603: Based on the second intermediate data, the third intermediate data, and the public key in the RAS-CRT key, perform a private key operation on the data to be processed to obtain the target data.

[0249] It can be understood that step 603, based on the second intermediate data, the third intermediate data, and the public key in the RAS-CRT key, performing a private key operation on the data to be processed to obtain the target data, can be implemented through the following process:

[0250] Calculate the product between the third intermediate data and the second private key value in the first part of the private key value to obtain a third product; calculate the sum of the second intermediate data and the third product to obtain the target data.

[0251] In the embodiment of the present application, the target data can be obtained through the following formula (37),

[0252]

[0253] where is the target data, is the second intermediate data, is the third intermediate data, is the second private key value.

[0254] As described above, in the embodiments of the present application, in combination with existing modular exponentiation, modular multiplication, and modular addition / subtraction hardware accelerators, random numbers generated by a true random number generator, Fermat's little theorem, and the mathematical properties of modular exponentiation and modular operations are introduced, and the exponents and / or moduli involved in the operations are randomly transformed, where the actual effective bit lengths of the moduli and exponents are expanded, the difficulty of analysis and cracking is increased, and the possibility that an attacker obtains the key information of the RSA private key through side-channel analysis is minimized to improve the security of applying RSA-CRT operations.

[0255] In some embodiments, step 203 combines the process of performing a private key operation on the data to be processed carried in the password service request based on the target private key value of the first part of the private key value and the second part of the private key value in the private key to obtain the target data. Figure 7 for illustration.

[0256] Step 701: Randomize the data to be processed based on the public key in the RAS-CRT key to obtain randomized data.

[0257] In the embodiments of the present application, the randomized data may be data obtained by randomizing the data to be processed based on the public key.

[0258] It can be understood that step 701 of randomizing the data to be processed based on the public key in the RAS-CRT key to obtain randomized data can be implemented through the following process:

[0259] Step 711: Obtain the multiplicative inverse of the tenth random value pre-stored.

[0260] In the embodiments of the present application, the multiplicative inverse of the tenth random value is pre-stored in the storage module of the password chip, and the tenth random value is a random number randomly generated by the generation unit in the hardware password module. The tenth random value may be a random prime number or other random numbers that are not random prime numbers.

[0261] In the embodiments of the present application, the multiplicative inverse of the tenth random value is a number obtained by performing a modular inverse operation on the tenth random value with the first public key value as the modulus. It should be noted that in the embodiments of the present application, the tenth random value and the multiplicative inverse of the tenth random value are pre-stored, so as to avoid the computational overhead of generating the tenth random value and the multiplicative inverse of the tenth random value in the RSA-CRT algorithm process and improve the computational efficiency.

[0262] Step 712: Randomize the data to be processed based on the multiplicative inverse and the second public key value in the public key to obtain intermediate randomized data.

[0263] It can be understood that based on the multiplicative inverse and the second public key value in the public key, the data to be processed is processed to obtain intermediate randomized data. This process can be achieved as follows: taking the second public key value as the power, performing a power operation on the multiplicative inverse to obtain a third operation result; calculating the product of the third operation result and the data to be processed to obtain the intermediate randomized data.

[0264] Here, taking the second public key value as the power, performing a power operation on the multiplicative inverse to obtain a third operation result; calculating the product of the third operation result and the data to be processed to obtain the intermediate randomized data. In this way, by introducing the second public key value and a random number, the base of the data to be processed is scrambled, increasing the difficulty for an attacker to crack, and minimizing the possibility for the attacker to obtain the key information of the RSA private key through side-channel analysis, thereby improving the security of applying the RSA-CRT operation.

[0265] Step 713: Taking the first public key value in the public key as the modulus, performing a modulo operation on the intermediate randomized data to obtain the randomized data.

[0266] It can be understood that in combination with the characteristics of the RSA non-CRT algorithm, introducing public-private key operations can obtain the following formula (38).

[0267]

[0268] Among them, r is the tenth random value, e and d are the public and private key pairs of the RSA key pair, C is the base, and C can be the data to be processed, for example. Since RSA-CRT is an optimized method for accelerating modular exponentiation and is equivalent to RSA-non-CRT operation, it can be transformed into RSA-CRT base scrambling.

[0269] In the embodiments of the present application, in combination with the characteristics of the RSA non-CRT algorithm, according to formula (38), data scrambling is performed on the data to be processed, and the randomized data can be obtained through the following formula (39).

[0270]

[0271] Among them, is the randomized data, r is the tenth random value, is the data to be processed, N is the first public key value, e is the second public key value, is the third operation result, is the intermediate randomized data.

[0272] It should be noted that the randomized data is obtained by performing data scrambling on the data to be processed, and no expansion processing is performed on the data bit length of the data to be processed. Therefore, the data bit length of the randomized data is the same as that of the data to be processed.

[0273] As can be seen from the above, in the embodiment of the present application, by introducing the first public key value, the second public key value, and a random number, the data to be processed is scrambled at the base, increasing the difficulty for attackers to crack, and minimizing the possibility for attackers to obtain the key information of the RSA private key through side-channel analysis, thereby improving the security of applying the RSA-CRT operation.

[0274] Step 702: Based on the target private key value of the first part of the private key value, the second part of the private key value in the private key, and the public key, perform a private key operation on the randomized data to obtain target data.

[0275] It can be understood that step 702, based on the target private key value of the first part of the private key value, the second part of the private key value in the private key, and the public key, performs a private key operation on the randomized data to obtain target data, which can be achieved through the following process:

[0276] Step 721: Based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, perform a private key operation on the randomized data to obtain reference target data.

[0277] In the embodiment of the present application, after performing randomization processing on the data to be processed based on the public key in the RAS-CRT key to obtain randomized data, the randomized data is used as the data to be processed. Based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, a private key operation is performed on the randomized data to obtain reference target data. It should be noted that the process of performing a private key operation on the randomized data to obtain reference target data is similar to the process of performing a private key operation on the data to be processed to obtain target data in the foregoing embodiment. That is to say, the steps of performing a private key operation on the randomized data to obtain reference target data are the same as or similar to the steps of performing a private key operation on the data to be processed to obtain target data in the foregoing embodiment.

[0278] Step 722: Using the first public key value as the modulus, perform a modulus operation on the product of the tenth random value and the reference target data to obtain target data.

[0279] In the embodiment of the present application, the target data can be obtained through the following formula (40):

[0280]

[0281] Wherein, is the target data, is the tenth random value, is the reference target data, and N is the first public key value.

[0282] It should be noted that since the data to be processed has been scrambled, after obtaining the reference target data, the reference target data needs to be restored through the tenth random value and the first public key value to obtain the final calculation result.

[0283] Here, in an implementable scenario, a method for processing RSA-CRT cipher data provided by an embodiment of the present application will be described.

[0284] RSA-CRT is an optimization technique in the RSA encryption algorithm. Especially in the modular exponentiation operation of large integers, the Chinese Remainder Theorem is used to accelerate the RSA signature and decryption operations (private key operations). RSA-CRT is particularly suitable for reducing calculation time and improving performance, especially when the modulus bits are large, significantly enhancing the performance of private key operations and being widely used in practical applications.

[0285] In modern scenarios with high security requirements, RSA cryptographic calculations are widely used in multiple fields such as public key infrastructure, blockchain, servers, various terminal computing devices, cryptographic machines (cryptographic acceleration cards), secure communication, and digital payment. Especially in fields such as banks, governments, and enterprises that need to process sensitive data, while ensuring high security and taking performance into account, the replacement of traditional RSA methods with RSA-CRT has become a trend.

[0286] On these existing microcontroller unit (MCU) devices with high security requirements, if there are accelerators that support modular exponentiation, modular addition / subtraction, and modular multiplication operations, the data processing method provided by the embodiment of the present application can be used to implement the secure operation of RSA-CRT through a software data processing solution, improve the security of RSA-CRT operations in applications, and reduce the risk of key information leakage due to side-channel analysis attacks.

[0287] Continue to refer to Figure 1 As shown, it can be understood as a product schematic diagram of the cryptographic chip of the embodiment of the present application. The application scenarios of the cryptographic chip include but are not limited to the following examples.

[0288] 1) The cryptographic chip is built into the server. The manufacturer requests the signature / decryption server to perform RSA-CRT private key operations (signature / decryption) on data such as firmware, and the CA signs the application identification message, etc. when issuing a certificate (for the public key infrastructure (PKI) system). Specifically, the client sends the data to be signed / decrypted (data to be signed such as firmware image / application identification information, data to be decrypted such as firmware ciphertext / key ciphertext) to the server (secure signature / decryption server). The signature / decryption server uses its own private key to perform private key operations (signature / decryption) on the data to be signed / decrypted and returns the result to the client.

[0289] 2) The password chip is built into the client. The Ukey signs / decrypts online banking transaction information, etc. The Ukey stores the user's RSA-CRT private key internally. After receiving the data to be signed / decrypted from the online banking (server), the Ukey uses the private key to perform RSA-CRT private key operations (signing / decryption).

[0290] Among them, the software password control module contains the security solutions mentioned in the embodiments of the present application. The hardware password module contains the hardware accelerator and true random number generator mentioned in the embodiments of the present application. Among them, operations such as modular exponentiation, modular addition and subtraction, modular multiplication, and modular inversion used in RSA-CRT signing can be calculated by the hardware accelerator, and the random numbers used in RSA-CRT signing can be generated by the true random number generator. The storage module includes, for example, flash memory (FLASH), static random access memory (Static Random Access Memory, SRAM), and / or dynamic random access memory (Dynamic Random Access Memory, DRAM), etc.

[0291] In an implementable scenario, the server receives external data (data to be signed / decrypted). The server CPU executes the software logic module, obtains the private key from the secure storage module, and executes the security solution to perform RSA-CRT private key operations, including obtaining the required random numbers from the hardware password module (it is not necessary to obtain all the required random numbers at one time, and the random numbers can be obtained when needed in the current calculation step). Write the data involved in each operation step into the storage module, write the modular operation mode configuration into the password register in the hardware password module, start the hardware password module to perform operations such as modular exponentiation, modular addition and subtraction, modular multiplication, and modular inversion, and wait for the operation results to be written into the storage module by polling the password register. The software logic module reads the results from the storage module. Repeatedly execute the above steps until the final result is calculated. Finally, the software logic module reads the final calculation result from the storage module, and the server returns the RSA-CRT private key operation result to the client. Among them, the hardware password module is implemented by a hardware circuit and can access the storage module.

[0292] The operation steps of the RSA-CRT operation in the embodiments of the present application are as follows:

[0293] The first step: Obtain a five-tuple (p, q, dp, dq, qInv) of the data to be processed, the public key (N, e), and the private key d corresponding to the public key, where, .

[0294] The second step: Introduce a random number r, transform the data to be processed C to obtain randomized data, which can be achieved through the following formula (41),

[0295]

[0296] Step 3: Introduce random numbers k1, h1, p1, y1, where, , , transform the above formula (7) through the random numbers k1, h1, p1, y1 to obtain formula (42),

[0297]

[0298]

[0299] Step 4: Introduce random numbers k2, h2, q1, y2, where, , , transform the above formula (8) through the random numbers k2, h2, q1, y2 to obtain formula (43),

[0300]

[0301]

[0302] Step 5: Introduce random number u1, where, , transform the above formula (9) through u1, m1, m2 to obtain formula (44),

[0303]

[0304]

[0305] Step 6: Through formula (45), use the random number r introduced in Step 2 to obtain the result after private key operation, and transform and restore the result after private key operation to obtain the target data.

[0306]

[0307] It should be noted that the above-mentioned random numbers are taken from a true random number generator, and modular multiplication, modular exponentiation, and modular addition and subtraction are implemented using existing hardware accelerators. Combining with the security scheme on the software side, the bases, exponents, and moduli involved in the operation are all randomly transformed, and the actual effective bits of the random numbers can be flexibly controlled. Among them, the actual effective bit lengths of the modulus and exponent are expanded, increasing the difficulty of analysis and cracking by attackers, and minimizing the possibility that attackers can obtain the key information of the RSA private key through side-channel analysis, thereby improving the security of applying RSA-CRT operations.

[0308] On an MCU device with high security requirements, if there is an accelerator for modular exponentiation, modular addition / subtraction, and modular multiplication operations in the ordinary function version or the secure version, the method of the present invention can be used to implement the secure operation of RSA-CRT through a software security solution, improve the security of RSA-CRT private key operations, and reduce the risk of key information leakage through side-channel analysis.

[0309] In the embodiments of the present application, by setting the thresholds of the scrambled modular exponent and the modulus random value, the bit sizes of the modular exponent and the modulus after being scrambled and enlarged can be controlled. In practical applications, appropriate thresholds can be selected by weighing performance and security. While taking performance into account, security is guaranteed.

[0310] For RSA-CRT secure operations, generally existing hardware accelerators will implement Montgomery ladder secure modular exponentiation. For the scrambling of the base and the modulus, these two processes can be designed with dedicated hardware acceleration to further reduce software operations and continue to improve the performance of RSA-CRT secure operations.

[0311] Refer to Figure 8 , Figure 8 FIG.

[0312] A response module 801, configured to respond to a cryptographic service request;

[0313] An obtaining module 802, configured to obtain a RAS-CRT key corresponding to the request identifier carried in the cryptographic service request, where the RAS-CRT key includes a private key;

[0314] A processing module 803, configured to perform a randomization process on the first part of the private key value in the private key to obtain a randomized private key value of the first part of the private key value;

[0315] The processing module 803 is further configured to perform a private key operation on the data to be processed carried in the cryptographic service request based on the target private key value of the first part of the private key value and the second part of the private key value in the private key to obtain target data; where the target private key value is the private key value or the randomized private key value of the private key value, and the target data is obtained based on one or more randomized private key values of the first part of the private key value;

[0316] A sending module 804, configured to send cryptographic service response data corresponding to the cryptographic service request; where the cryptographic service response data includes the target data.

[0317] The embodiments of the present application provide a cryptographic chip, including a memory and a processor, where,

[0318] The memory stores a computer program that can run on a processor. When the processor executes the program, some or all of the steps in the above method are implemented.

[0319] An embodiment of the present application provides a cryptographic device, and the cryptographic device includes a cryptographic chip.

[0320] An embodiment of the present application provides a storage medium that stores one or more computer programs. The one or more computer programs can be executed by one or more processors to implement some or all of the steps in the above method. The storage medium can be transient or non-transient.

[0321] An embodiment of the present application provides a computer program, including computer-readable code. When the computer-readable code runs in a computer device, the processor in the computer device executes to implement some or all of the steps in the above method.

[0322] An embodiment of the present application provides a computer program product. The computer program product includes a non-transient computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, some or all of the steps in the above method are implemented. The computer program product can be specifically implemented in a manner of hardware, software, or a combination thereof. In some embodiments, the computer program product is specifically embodied as a computer storage medium. In other embodiments, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.

[0323] It should be noted here that the descriptions of the above embodiments tend to emphasize the differences between the embodiments, and their similarities can be referred to each other. The descriptions of the above embodiments of the device, storage medium, computer program, and computer program product are similar to the descriptions of the above method embodiments and have similar beneficial effects to the method embodiments. For the technical details not disclosed in the embodiments of the device, storage medium, computer program, and computer program product of the present application, please refer to the descriptions of the method embodiments of the present application for understanding.

[0324] Figure 9 It is a schematic diagram of the hardware entity of a cryptographic chip provided by an embodiment of the present application. As Figure 9 shown, the hardware entity of the cryptographic chip 100 includes: a processor 901 and a memory 902. Among them, the memory 902 stores a computer program that can run on the processor 901. When the processor 901 executes the program, the following steps are implemented.

[0325] In response to a password service request, obtain the RAS-CRT key corresponding to the request identifier carried in the password service request, where the RAS-CRT key includes a private key;

[0326] Randomize the first part of the private key value in the private key to obtain a randomized private key value for the first part of the private key value;

[0327] Based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, perform a private key operation on the data to be processed carried in the password service request to obtain target data, and send password service response data corresponding to the password service request; where the password service response data includes the target data;

[0328] Wherein, the target private key value is the first part of the private key value or the randomized private key value of the first part of the private key value, and the target data is obtained based on one or more randomized private key values in the first part of the private key value.

[0329] Wherein, the memory 902 stores a computer program that can run on the processor. The memory 902 is configured to store instructions and applications executable by the processor 901, and can also cache data to be processed or already processed by the processor 901 and each module in the password chip 100 (for example, image data, audio data, voice communication data, and video communication data), and can be implemented by flash memory (FLASH) or random access memory (Random Access Memory, RAM).

[0330] Wherein, when the processor 901 executes the program, it implements the steps of the method in any of the above items. The processor 901 generally controls the overall operation of the password chip 100.

[0331] Figure 10 This is a schematic diagram of the hardware entity of a password device provided by an embodiment of the present application, as Figure 10 shown, the password device 10 includes a password chip 100.

[0332] The embodiment of the present application provides a computer storage medium. The computer storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the steps of the method in any of the above embodiments.

[0333] It should be pointed out here that: the descriptions of the above storage medium and device embodiments are similar to the descriptions of the above method embodiments, and have beneficial effects similar to those of the method embodiments. For the technical details not disclosed in the storage medium and device embodiments of the present application, please refer to the descriptions of the method embodiments of the present application for understanding.

[0334] The above-mentioned processor may be at least one of an Application Specific Integrated Circuit (ASIC), a Digital Signal Processor (DSP), a Digital Signal Processing Device (DSPD), a Programmable Logic Device (PLD), a Field Programmable Gate Array (FPGA), a Central Processing Unit (CPU), a controller, a microcontroller, and a microprocessor. It can be understood that the electronic device implementing the functions of the above-mentioned processor may also be other devices, and the embodiments of the present application do not make specific limitations.

[0335] The above-mentioned computer storage medium / memory may be a Read Only Memory (ROM), a Programmable Read-Only Memory (PROM), an Erasable Programmable Read-Only Memory (EPROM), an Electrically Erasable Programmable Read-Only Memory (EEPROM), a Ferromagnetic Random Access Memory (FRAM), a Flash Memory, a magnetic surface memory, an optical disc, or a Compact Disc Read-Only Memory (CD-ROM), etc.; it may also be various terminals including one or any combination of the above-mentioned memories, such as a mobile phone, a computer, a tablet device, a personal digital assistant, etc.

[0336] It should be understood that the "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the appearances of "in one embodiment" or "in an embodiment" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics may be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the magnitude of the serial numbers of the above steps / processes does not mean the order of execution. The order of execution of each step / process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.

[0337] It should be noted that in this article, the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.

[0338] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the couplings, direct couplings, or communication connections between the components shown or discussed may be through some interfaces, and the indirect couplings or communication connections of the devices or units may be electrical, mechanical or other forms.

[0339] The units described as separate components above may or may not be physically separated, and the components shown as units may or may not be physical units; they may be located in one place or distributed to multiple network units; some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0340] In addition, each functional unit in the embodiments of the present application can be all integrated in a processing unit, or each unit can be separately used as a unit, or two or more units can be integrated in a unit; the above integrated units can be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.

[0341] Those of ordinary skill in the art can understand that all or part of the steps for implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps including those of the above method embodiments; and the aforementioned storage medium includes: removable storage devices, read-only memory (ROM), magnetic disks, or optical discs and other various media that can store program codes.

[0342] Alternatively, if the above integrated units of the present application are implemented in the form of software function modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the related technology, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a vehicle-mounted terminal (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the various embodiments of the present application. And the aforementioned storage medium includes: removable storage devices, ROM, magnetic disks, or optical discs and other various media that can store program codes.

[0343] As described above, only the embodiments of the present application are provided, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application.

Claims

1. A RSA-CRT cryptographic data processing method, characterized in that: Applied to a cryptographic chip, the method comprises: In response to the cryptographic service request, obtaining a RAS-CRT key corresponding to the request identifier carried in the cryptographic service request, wherein the RAS-CRT key includes a private key; Randomizing the first part of the private key value in the private key to obtain a randomized private key value of the first part of the private key value; Based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, perform a private key operation on the data to be processed carried by the cryptographic service request to obtain the target data, and send cryptographic service response data corresponding to the cryptographic service request; wherein the cryptographic service response data includes the target data; The target private key value is the first part of the private key value or a randomized private key value of the first part of the private key value, and the target data is obtained based on a randomized private key value of one or more private key values ​​in the first part of the private key value.

2. The method according to claim 1, characterized in that The step of performing random processing on the first part of the private key value to obtain a randomized private key value of the first part of the private key value includes: For any reference private key value in the first part of the private key value, obtain a pre-stored first reference random value, a second reference random value, a reference sub-private key value, and a data type corresponding to the reference private key value; Based on the first reference random value, the second reference random value and the reference sub-private key value, the reference private key value is randomized using a calculation method corresponding to the data type to obtain a reference randomized private key value of the reference private key value.

3. The method according to claim 2, characterized in that The data type is a first data type, and the calculation method corresponding to the first data type includes: Calculate the product of the second reference random value and the reference sub-private key value to obtain a first reference product; calculate the product of the first reference random value and the second reference random value to obtain a second reference product; calculate the sum of the first reference product and the second reference product to obtain the reference randomized private key value; The data type is a second data type, and the calculation method corresponding to the second data type includes: Calculate the product of the first reference random value and the second reference random value to obtain a third reference product; calculate the product of the first reference random value and the reference sub-private key value to obtain a fourth reference product; calculate the sum of the reference private key value, the third reference product and the fourth reference product to obtain the reference randomized private key value.

4. The method according to claim 1, characterized in that: The target private key value based on the first part of the private key value and the second part of the private key value in the private key, performing a private key operation on the data to be processed carried by the cryptographic service request to obtain the target data, includes: Based on the target private key value of the first part of the private key value, performing a modular exponentiation operation on the data to be processed to obtain first intermediate data and second intermediate data; Based on the first intermediate data, the second intermediate data and the second part of the private key value, a private key operation is performed on the data to be processed to obtain the target data.

5. The method according to claim 4, characterized in that The first part of the private key value includes a first private key value, a second private key value, a third private key value and a fourth private key value, and the target private key value based on the first part of the private key value in the private key performs a modular exponentiation operation on the data to be processed to obtain the first intermediate data and the second intermediate data, including: Based on the target private key value of the first private key value as a modulus and / or the target private key value of the third private key value as a power, performing a modular exponentiation operation on the data to be processed to obtain the first intermediate data; Based on the target private key value of the second private key value as a modulus and / or the target private key value of the fourth private key value as a power, a modular exponentiation operation is performed on the data to be processed to obtain the second intermediate data.

6. The method according to claim 5, characterized in that The step of performing a modular exponentiation operation on the data to be processed using the target private key value based on the first private key value as a modulus and / or the target private key value of the third private key value as a power to obtain the first intermediate data includes: Using the target private key value of the first private key value as a modulus and / or using the target private key value of the third private key value as a power, performing a modular exponentiation operation on the data to be processed to obtain first reference intermediate data; using the first private key value as a modulus, performing a modular operation on the first reference intermediate data to obtain the first intermediate data; The step of performing a modular exponentiation operation on the data to be processed using the target private key value based on the second private key value as a modulus and / or the target private key value of the fourth private key value as a power to obtain the second intermediate data includes: Using the target private key value of the second private key value as a modulus, and / or using the target private key value of the fourth private key value as a power, perform a modular exponentiation operation on the data to be processed to obtain second reference intermediate data; using the second private key value as a modulus, perform a modular operation on the second reference intermediate data to obtain the second intermediate data.

7. The method according to claim 4, characterized in that The second part of the private key value includes a fifth private key value, and based on the first intermediate data, the second intermediate data and the second part of the private key value, a private key operation is performed on the data to be processed to obtain the target data, and the method includes: Obtaining a pre-stored ninth random value and a fifth sub-private key value corresponding to the fifth private key value, and a target private key value of the first private key value in the first part of the private key values; Based on the ninth random value, the fifth sub-private key value, and the target private key value of the first private key value, randomizing the difference between the first intermediate data and the second intermediate data to obtain third intermediate data; Based on the second intermediate data, the third intermediate data and the public key in the RAS-CRT key, a private key operation is performed on the data to be processed to obtain the target data.

8. The method according to claim 7, characterized in that The step of performing random processing on a difference between the first intermediate data and the second intermediate data based on the ninth random value, the fifth sub-private key value, and the target private key value of the first private key value to obtain third intermediate data includes: Using the target private key value of the first private key value as a modulus, performing a modulus operation on the difference between the first intermediate data and the second intermediate data to obtain fourth intermediate data; Calculating a product of the fourth intermediate data and the ninth random value to obtain a first product; Calculate the product of the fourth intermediate data and the fifth sub-private key value to obtain a second product; The third intermediate data is obtained based on the first product, the second product, the first private key value and a randomized private key value of the first private key value.

9. The method according to claim 8, characterized in that The obtaining the third intermediate data based on the first product, the second product, the first private key value, and the randomized private key value of the first private key value comprises: Taking the first private key value and the randomized private key value of the first private key value as moduli, respectively, performing a modulo operation on the first product twice to obtain a first operation result; Taking the first private key value and the randomized private key value of the first private key value as moduli, respectively, performing a modulo operation twice on the second product to obtain a second operation result; The sum of the first operation result and the second operation result is determined as the third intermediate data.

10. The method according to claim 8, characterized in that The step of performing a private key operation on the data to be processed based on the second intermediate data, the third intermediate data and the public key in the RAS-CRT key to obtain the target data includes: Calculate the product of the third intermediate data and the second private key value in the first part of the private key value to obtain a third product; The sum of the second intermediate data and the third product is calculated to obtain the target data.

11. The method according to any one of claims 1 to 10, characterized in that: The target private key value based on the first part of the private key value and the second part of the private key value in the private key, performing a private key operation on the data to be processed carried by the cryptographic service request to obtain the target data, includes: Based on the public key in the RAS-CRT key, randomizing the data to be processed to obtain randomized data; Based on the target private key value of the first part of the private key value, the second part of the private key value in the private key and the public key, a private key operation is performed on the randomized data to obtain the target data.

12. The method according to claim 11, characterized in that The method of performing random processing on the data to be processed based on the public key in the RAS-CRT key to obtain randomized data includes: Obtaining a multiplicative inverse element of a pre-stored tenth random value; Based on the multiplication inverse element and the second public key value in the public key, randomizing the data to be processed to obtain intermediate randomized data; A modulus operation is performed on the intermediate randomized data using the first public key value in the public key as a modulus to obtain the randomized data.

13. The method according to claim 12, characterized in that The step of performing random processing on the data to be processed based on the multiplication inverse element and the second public key value in the public key to obtain intermediate randomized data includes: Using the second public key value as a power, performing a power operation on the multiplication inverse element to obtain a third operation result; The product of the third operation result and the data to be processed is calculated to obtain the intermediate randomized data.

14. The method according to claim 12, characterized in that The step of performing a private key operation on the randomized data based on the target private key value of the first part of the private key value, the second part of the private key value in the private key, and the public key to obtain the target data includes: Based on the target private key value of the first part of the private key value and the second part of the private key value in the private key, performing a private key operation on the randomized data to obtain reference target data; Using the first public key value as a modulus, a modulus operation is performed on the product of the tenth random value and the reference target data to obtain the target data.

15. A cryptographic chip, characterized in that: The password chip comprises: A response module, used for responding to a password service request; An obtaining module, used to obtain a RAS-CRT key corresponding to the request identifier carried in the cryptographic service request, wherein the RAS-CRT key includes a private key; A processing module, configured to perform randomization processing on a first part of a private key value in the private key to obtain a randomized private key value of the first part of the private key value; The processing module is further configured to perform a private key operation on the data to be processed carried by the cryptographic service request based on a target private key value of the first part of the private key value and a second part of the private key value in the private key to obtain target data; wherein the target private key value is the private key value or a randomized private key value of the private key value, and the target data is obtained based on a randomized private key value of one or more private key values ​​in the first part of the private key value; A sending module is used to send cryptographic service response data corresponding to the cryptographic service request; wherein the cryptographic service response data includes the target data.

Citation Information

Patent Citations

  • Password card switching method and device, computer equipment and storage medium

    CN117834137A

  • Method, system and medium for realizing unified encryption, decryption and desensitization of data across terminals

    CN119276502A