A Secure Pseudo-Random Number Generator and Method for High Throughput of FPGA
By designing a secure pseudo-random number generator on the FPGA that includes initial seed input module, round constant generation module, permutation function module and resemble mechanism module, the problems of insufficient throughput and high hardware resource consumption in the prior art are solved, and high-efficiency and low-power high-throughput random number generation are achieved.
Patent Information
- Application Number
- CN202510402023.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-04-01
AI Technical Summary
On the basis of ensuring the quality of random number generation, it is difficult to realize high-efficiency and low-power high-throughput secure pseudo-random number generators, especially in scenarios such as real-time high-density data encryption and Internet of Things device communication, inadequate throughput and high hardware resource consumption.
A secure pseudo-random number generator for FPGA is designed, and is implemented using FPGA-based hardware, including an initial seed input module, a round constant generation module, a permutation function module and a reseed mechanism module. Dynamic wheel constants are generated by nonlinear feedback shift registers and reduces the number of wheels by optimizing the permutation function, thereby increasing throughput and reducing power consumption.
On the basis of ensuring the quality of random number generation, it significantly improves the efficiency and throughput of random number generation, reduces hardware resource consumption, and meets the needs of high-performance random number generation.
Smart Images

Figure CN119917064B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of generating random numbers by FPGA, and particularly to a secure pseudo-random number generator and method for high throughput of FPGA. Background Art
[0002] With the rapid development of information technology, the application of random numbers has become an indispensable part of modern information systems. Random numbers play a key role in many fields, including cryptography, simulation, statistical analysis, distributed systems, and artificial intelligence training. However, the quality of random number generation directly affects the security and performance of information systems. If the random numbers are not random enough or are predictable, the system will be exploited by attackers, thus endangering system security.
[0003] Currently, random number generators are mainly divided into two categories: True Random Number Generator (TRNG) and Pseudo-Random Number Generator (PRNG).
[0004] Although the pseudo-random number generator PRNG has excellent performance, its security highly depends on the quality of the seed and the complexity of the algorithm. To enhance the security of the pseudo-random number generator PRNG, many modern designs introduce a hybrid random number generator (Hybrid RNG), which combines the physical noise input of the true random number generator TRNG and the algorithm generation ability of the pseudo-random number generator PRNG to achieve a balance between security and efficiency.
[0005] Mohamed Gafsi et al. proposed an implementation of a high-performance FPGA pseudo-random number generator (PRNG) based on the Lorenz chaos map. A digital pseudo-random number generator (DPRNG) for high-quality key generation was developed using the Lorenz chaos map. The proposed DPRNG architecture includes three modules: an initial state generator (ISG), a Lorenz chaos map, and a modulation module. This hardware design was implemented on the FPGA-Zynq platform using the Xilinx System Generator (XSG) tool, with low resource utilization.
[0006] Existing solutions, such as the pseudo-random number generator (DPRNG) based on the Lorenz chaotic map proposed by Mohamed Gafsi, perform excellently in throughput, hardware resource utilization, and randomness tests, but there are still some limitations and room for improvement. First, although this design improves the frequency and throughput in hardware implementation, compared with some application scenarios (such as real-time high-density data encryption or large-scale Internet of Things device communication), a throughput of 25702 Mbps may still be insufficient to meet higher performance requirements. Second, the complexity in hardware implementation, such as the use of floating-point operations, although improving the random number accuracy, also increases the hardware design cost and power consumption, and may not be suitable for resource-constrained embedded devices.
[0007] Therefore, the prior art lacks a secure pseudo-random number generator and method that can achieve efficient and low-power random number generation with high throughput while ensuring the quality of random number generation. Summary of the Invention
[0008] To solve the problems existing in the background technology, the present invention provides a secure pseudo-random number generator and method for high throughput of FPGA, which can achieve efficient and low-power random number generation while ensuring the quality of random number generation, and meet the diverse requirements of modern information systems in the fields of communication security, embedded devices, Internet of Things, etc.
[0009] The present invention relates to the fields of communication security and random number generation, especially the design and optimization technology of secure pseudo-random number generators for high-throughput application scenarios. Specifically, the solution of the present invention can meet the requirements for high-speed and secure random number generation in modern information systems, and is widely applicable to security scenarios such as encrypted communication, data integrity verification, identity authentication, and key generation.
[0010] The present invention processes binary numbers to generate binary random numbers, and all operations involved are binary operations.
[0011] The technical solution adopted by the present invention is as follows:
[0012] 1. A secure pseudo-random number generator for high throughput of FPGA:
[0013] The secure pseudo-random number generator is based on the hardware of FPGA and includes:
[0014] An initial seed input module for inputting the original seed from the outside and preprocessing it into the initial seed for storage;
[0015] A round constant generation module for pre-generating the round constants required for 12 rounds of the permutation function module and sending them to the permutation function module;
[0016] A permutation function module, which contains an optimized permutation function F' including round constants, is used to read the initial seed from the initial seed input module and store it, and then perform 12 rounds of permutation operations on the initial seed using the built-in optimized permutation function F' to obtain the final random number output;
[0017] A reseeding mechanism module, which is used to periodically refresh the original seed to ensure randomness and security during long-term operation.
[0018] The initial seed input module includes:
[0019] A register or FIFO, which is used to store the original seed;
[0020] A bit selection module, which reads the original seed stored in the register or FIFO and selects a part of the numbers from it;
[0021] A padding and initial XOR module, which is used to perform XOR operation on a part of the numbers selected by the bit selection module and a number composed of consecutive multiple 0s with the same number of bits, and splice the number composed of consecutive multiple 0s to form the initial seed.
[0022] The bit selection module includes:
[0023] A first counter, which is used to dynamically select bits in the original seed;
[0024] A multiplexer (MUX), which is used to select the binary values of a specified part of bits according to the dynamic selection of the first counter as a part of the numbers;
[0025] The padding and initial XOR module includes an XOR circuit and a splicing logic circuit. The XOR circuit is used to perform XOR operation on a part of the numbers and a number composed of consecutive multiple 0s with the same number of bits, and the splicing logic circuit is used to splice the number after XOR operation by the XOR circuit and the number composed of consecutive multiple 0s.
[0026] The round constant generation module includes:
[0027] A second counter, which is used to select the first-round round constant from the initial seed; the second counter and the first counter can be shared.
[0028] A non-linear feedback shift register NLSFR, which is used to generate the round constants of the subsequent 11 rounds according to the first-round round constant to realize the dynamic generation of the subsequent round constants, and has built-in left shift operation and XOR operation.
[0029] The permutation function module includes a register for storage and a logic circuit for performing operations such as XOR, AND, and NOT. The logic circuit forms an optimized permutation function F' through hardware topology design;
[0030] The reseeding mechanism module uses a timer / counter to track a time threshold or generate a quantity threshold to control the update.
[0031] II. A method for generating secure pseudo-random numbers with high throughput for FPGA, the method comprising:
[0032] (1) Seed input stage:
[0033] The original seed is stored in a register or FIFO, and after preprocessing by a bit selection module and a padding and initial XOR module, an initial seed is obtained as input data. The number of bits of the original seed and the initial seed is the same and both are binary numbers.
[0034] The original seed is from an external input or a true random number generator (TRNG) and is used to initialize the state of the pseudo-random number generator.
[0035] (2) Round constant generation stage:
[0036] The role of the round constant is to enhance the randomness, security and anti-attack ability of the random number generator by introducing dynamic, non-linear and unique changes, and to ensure the independence and complexity between each round of operations.
[0037] According to the initial seed, a counter combined with a non-linear feedback shift register (NLSFR) is used to pre-generate dynamic round constants for the permutation function execution stage through shift and XOR operations.
[0038] During the generation process, the dynamically generated round constants are pre-stored to reduce the computational requirements during runtime.
[0039] (3) Permutation function execution stage:
[0040] A register is set to store the input initial seed, and an optimized permutation function F' implemented by a logic circuit and containing round constants is used to process the initial seed. The optimized permutation function F' includes 12 rounds of permutation operations. After each execution of 12 rounds of permutation operations, the final random number is output as the secure pseudo-random number result.
[0041] (4) Reseeding mechanism stage:
[0042] By setting a time threshold or generating a quantity threshold, the original seed is periodically refreshed by a timer / counter according to the time threshold or the quantity threshold, that is, return to step (1) and then repeat steps (1) to (3) for loop processing, and continuously update and output the final random number.
[0043] The specific steps of step (1) are as follows: First, a counter of the bit selection module is used to select a certain number of consecutive bits from the original seeds stored in the register or FIFO on both the low - order side and the high - order side to form a preliminary binary number. Then, the padding and initial XOR module is used to perform an XOR operation on the preliminary binary number and a binary number composed of consecutive 0s with the same number of bits as the preliminary binary number. Then, consecutive 0s are concatenated at the end to form a binary number with the same number of bits as the original seeds as the initial seed, which is used for subsequent input to the optimized permutation function F'.
[0044] The specific steps of step (2) are as follows:
[0045] (21) First, a counter is used to select a preset number of bits of binary number from the initial seed as the round constant rc1 for the first round of the optimized permutation function F'.
[0046] (22) Then, the round constant rc of the nth round n uses the non - linear feedback shift register NLSFR to dynamically generate the round constant rc of the next round n+1 , expressed as:
[0047] rc n+1 [K - 1:0] = {rc n [K - 2:0], rc n [A] ^ rc n [B] ^ rc n [C] ^ rc n [D]}
[0048] Among them, ^ represents the XOR operation, {} represents binary number concatenation, rc n [62:0] represents the round constant rc n from bit 0 to bit 62 starting from the lowest bit, that is, from the lowest bit to the second - highest bit from the bottom, that is, from the right - most bit to the second - left - most bit; K represents the total number of bits of each round constant, A, B, C, D represent four preset fixed - number bits, rc n [A], rc n [B], rc n [C], rc n [D] respectively represent the values of the round constant rc n at the fixed - number bits A, B, C, D. A, B, C, D are all less than K and are used for the XOR operation of the round constant;
[0049] (23) Finally, the above process (22) is looped to sequentially generate the round constants corresponding to each round of the optimized permutation function F'.
[0050] During the above-mentioned processing of generating round constants, the fixed-bit numbers A, B, C, and D remain unchanged.
[0051] The generation of round constants in the present invention using a non-linear feedback shift register involves two basic operations: left shift or right shift and exclusive OR operation.
[0052] The optimized permutation function F' includes the operations of a 12-round permutation function.
[0053] In each round of permutation operation of the optimized permutation function F', the round constant in the Iota step corresponds to the round constant obtained in step (2), that is, the round constant in the Iota step of the i-th round of permutation operation of the optimized permutation function F' corresponds to the i-th round of round constant obtained in step (2). The initial seed is input into the optimized permutation function F', and the final random number is obtained after 12 consecutive rounds of permutation operations.
[0054] Each round of permutation operation of the optimized permutation function F' includes five steps that are sequentially performed within a logic circuit. The five steps are Theta step, Rho step, Pi step, Chi step, and Iota step;
[0055] First, perform the Theta step. By calculating the even parity of each column of the input binary data and performing an exclusive OR operation with each state bit value, the diffusion of global information is achieved;
[0056] Next, perform the Rho step. According to a predefined offset, each state bit value is circularly shifted to increase the confusion of the state;
[0057] Then, perform the Pi step. The bit state values on the same plane are rearranged to scatter local information globally;
[0058] Next, perform the Chi step. The bits on the same line are processed through a non-linear Boolean transformation to enhance the non-linear complexity of the state;
[0059] Finally, perform the Iota step. The round constant is XORed with specific bits an even number of times to introduce randomness and the uniqueness of the round.
[0060] The above five steps cooperate with each other to ensure the full confusion and diffusion of the state, providing high security for subsequent rounds.
[0061] Each round of permutation operation includes the above five steps and is executed 12 times, that is, the five steps are repeated 12 times. Through the combination of linear and non-linear operations in the round permutation function, the input data is fully confused to ensure high randomness and security of the output.
[0062] The value of each bit of the initial seed serves as a state bit value, and the state bit values of each bit of the initial seed are distributed in a three-dimensional arrangement of multiple cubes along the x, y, and z axes to form three-dimensional arrangement structure data.
[0063] The three-dimensional arrangement structure data is divided into three types of slices: horizontal slice plane, vertical slice slice, and longitudinal slice sheet, and three types of strips: horizontal strip row, vertical strip column, and longitudinal strip lane. Each type of slice is composed of the state bit values corresponding to all the cubes on one layer in the same plane, and each type of strip is composed of the state bit values corresponding to a column of cubes on the same straight line.
[0064] The horizontal slice plane is composed of the state bit values corresponding to all the cubes located on the xz plane, the vertical slice slice is composed of the state bit values corresponding to all the cubes located on the xy plane, and the longitudinal slice sheet is composed of the state bit values corresponding to all the cubes located on the yz plane; the horizontal strip row is composed of the state bit values corresponding to all the cubes located on the x-axis, the vertical strip column is composed of the state bit values corresponding to all the cubes located on the y-axis, and the longitudinal strip lane is composed of the state bit values corresponding to all the cubes located on the z-axis.
[0065] The final random number is obtained after 12 consecutive rounds of permutation operations on the three-dimensional arrangement structure data.
[0066] In each round of permutation operation, it is processed according to the following process:
[0067] In the Theta step, each state bit value in the three-dimensional arrangement data structure is processed and assigned a replacement according to the following formula:
[0068] s'[x][y][z]=s[x][y][z]^∑ y'' s[x-1][y''][z]^∑ y'' s[x+1][y''][z-1]
[0069] y''=y+△y
[0070] Among them, s'[x][y][z] represents the state bit value of the coordinate (x, y, z) in the three-dimensional arrangement structure data after being processed by the Theta step, s[x][y][z] represents the state bit value of the coordinate (x, y, z) in the three-dimensional arrangement structure data before being processed by the Theta step; y'' represents the y coordinate of the state bit value s[x][y][z] currently being calculated and the state bit values of two adjacent vertical strips column in its three-dimensional arrangement; ^ represents the exclusive OR operation, and △y represents the adjacent y coordinate step value;
[0071] The essence of the Theta step operation is to perform an exclusive OR operation on all state bit values s[x][y][z] with the parity check values of two adjacent vertical columns column, and obtain new state bit values.
[0072] The Rho step processes and assigns replacements to each state bit value in the three-dimensional arrangement data structure processed by the Theta step according to the following formula:
[0073] s''[x][y][z]=s'[x][y][z-(t+1)(t+2) / 2]
[0074] where t represents an intermediate variable used to calculate the bit value offset; s''[x][y][z] represents the state bit value at coordinates (x, y, z) in the three-dimensional arrangement structure data processed by the Rho step;
[0075] The Rho step operation translates all state bit values s'[x][y][z] by (t+1)(t+2) / 2 units in the z-axis direction. The Rho step operation fixes the x-axis and y-axis and can be regarded as a circular shift inside 25 vertical lanes.
[0076] The Pi step processes and assigns replacements to each state bit value on the same vertical slice slice in the three-dimensional arrangement data structure processed by the Rho step according to the following formula:
[0077] p'[x][y]=p[x'][y']
[0078]
[0079] where p'[x][y] represents the state bit value at coordinates (x, y) on the vertical slice slice in the xy plane of the three-dimensional arrangement structure data processed by the Pi step, p[x][y] represents the state bit value at coordinates (x, y) on the vertical slice slice in the xy plane of the three-dimensional arrangement structure data before the Pi step, and x', y' represent the new horizontal and vertical position coordinates of the state bit value in the state matrix;
[0080] The operation of the Pi step fixes the z-axis and is regarded as a bit permutation on 25 vertical slices slice, and the permutation limit is given by the following conditions.
[0081] The Chi step processes and assigns replacements to each state bit value on the same horizontal row row in the three-dimensional arrangement data structure processed by the Pi step according to the following formula:
[0082] q'[x]= q[x]^((q[x+1]^1)&q[x+2])
[0083] Among them, q'[x] represents the state bit value of coordinate x on the horizontal bar row located on the same x-axis in the three-dimensional arrangement structure data after Chi step processing, q[x] represents the state bit value of coordinate x on the horizontal bar row located on the same x-axis in the three-dimensional arrangement structure data before Chi step processing, ^ represents the exclusive OR operation, and & represents the AND operation.
[0084] The operation of the Chi step fixes the y-axis and z-axis, regarded as bit operations on all horizontal bar rows, including exclusive OR, AND, and NOT operations.
[0085] The Iota step processes and assigns replacements to each state bit value of the vertical bar lane located at the center of the three-dimensional arrangement data structure after the Chi step according to the following formula:
[0086] I'[0][0][z]=I[0][0][z]^RC i
[0087] Among them, i represents the number of rounds of the permutation operation, RC i represents the round constant of the current i-th round. Among them, I'[0][0][z] represents the state bit value of coordinate z on the vertical bar lane located at the center of the three-dimensional arrangement structure data after the Iota step processing, and z is an even number. I[0][0][z] represents the state bit value of coordinate z on the vertical bar lane located at the center of the three-dimensional arrangement structure data before the Iota step processing, and the value range of z is from 0 to 62.
[0088] The optimized permutation function F' of the present invention is a cryptographic hash function based on the Keccak algorithm, adopting a unique sponge structure, and completing the generation of the message digest in two stages: absorption and extrusion.
[0089] First, in the absorption stage, the input message is divided into blocks, each block is XORed with the first r bits of the current state, and then the state is updated through the permutation function; in the extrusion stage, the output digest is extracted from the first r bits of the state, and when it is insufficient, the state is continuously updated through the permutation function. The state characteristics consist of an absorption rate part r and a capacity part c. The absorption rate part r is responsible for processing the input and output, and the capacity part c provides security guarantees. In addition, the multi-round non-linear operation of the permutation function among them ensures a strong ability to resist collision and pre-image attacks, has higher flexibility and security compared with traditional processing, and is applicable to a variety of application scenarios, including cryptography and data integrity verification.
[0090] Each run of the existing permutation function F in the prior art contains 24 rounds of operations, resulting in a low throughput and being difficult to meet high-performance requirements.
[0091] Moreover, there are two main problems in the operation of the existing permutation function F: First, the round constant (data with a length of 64 bits) is generated during operation, resulting in a relatively high consumption of computing resources; second, the round constant is fixed and the same every time the F function is executed, which may make the behavior of the algorithm easier to be analyzed and predicted by attackers, thus reducing security.
[0092] To solve these problems, as Figure 3 shown, the present invention proposes an optimization scheme with coordinated improvements in multiple aspects:
[0093] On the one hand, the solution of the present invention optimizes the permutation function to F', and the number of running rounds is reduced from 24 rounds to 12 rounds. On the basis of ensuring security, it can significantly improve the throughput of the algorithm by reducing the computational complexity, making it more suitable for scenarios with high performance requirements.
[0094] On the other hand, the present invention adopts the processing mechanism of the non-linear feedback shift register NLSFR in the process of generating round constants. Based on the initial seed of random numbers, the round constants for the permutation function are pre-generated.
[0095] In this way, the generation of round constants can be completed before operation, thereby reducing the consumption of computing resources during operation. At the same time, simple shift and exclusive OR operations are used to generate dynamically changing round constants, ensuring that the round constants for each round are different. This processing method not only improves the efficiency of round constant generation, but also enhances the unpredictability and anti-attack ability of the algorithm, achieving a good balance between security and performance.
[0096] Furthermore, in order to solve the problem of waste of storage resources caused by only 7 bits participating in the exclusive OR operation in the round constant processing of the existing permutation function F and the problem of insufficient randomness of the output data due to the lack of use of S boxes and less non-linear changes, the present invention also improves the lota step of the round constant processing. It not only combines the pre-generated round constants for only 12 rounds, but also selects 32 bits from the round constants to perform exclusive OR operations with 32 bits of the data local number each time, increasing the unpredictability and computational complexity. Moreover, this improvement greatly improves the utilization efficiency of round constant storage resources, enhances the security of the algorithm and the randomness of the output results, and solves the above problems of resource waste and randomness.
[0097] In specific implementation, the present invention can also adopt a pipeline acceleration method to optimize the execution of the optimized permutation function F' to improve the throughput of the pseudo-random number generator (PRNG). Since the optimized permutation function F' has a total of 12 rounds of operations, by dividing it into a multi-stage pipeline design, multiple round constant operations can be executed in one clock cycle, and 2-level, 3-level, 4-level, 6-level or 12-level acceleration can be achieved according to requirements, which can further significantly improve the throughput, reduce the latency, and at the same time maintain the integrity and security of the processing.
[0098] Therefore, the solution of the present invention adopts multiple optimization technical means, significantly improving the performance and security of the pseudo-random number generator (PRNG). The specific beneficial effects include:
[0099] 1) By making a large number of modifications to the hash function, a new optimized permutation function F' of the 12-round permutation function is designed for the pseudo-random number generator (PRNG). Through linear and non-linear operations, the 1600-bit input seed is fully scrambled to ensure the high randomness and security of the output data. While improving the throughput, the output randomness is guaranteed, achieving a balance between security and performance.
[0100] 2) Establish a round constant generator based on a non-linear feedback shift register: Use a non-linear feedback shift register (NLSFR) to pre-generate round constants, and use simple shift and exclusive OR operations with specific data positions to reduce the computational complexity of round constant generation. At the same time, ensure that the round constants for each round are different, thereby improving the randomness and unpredictability of the output, while reducing the consumption of hardware resources.
[0101] 3) Optimized round constant generation and storage: Increase non-linear changes. Each time, select 32 bits from the round constants for exclusive OR operation with the original data, further enhancing the complexity and unpredictability of the output, further improving the randomness and anti-attack ability of the output data, while improving the utilization rate of round constant storage resources.
[0102] 4) Time threshold mechanism: Periodically perform reseeding operations to refresh the seed, ensuring the persistence and security of output randomness during long-term operation.
[0103] 5) Multi-level pipeline acceleration: By introducing pipeline technology, the throughput of the PRNG is improved. According to the 12-round design of the optimized permutation function F', the 12-round permutation function is efficiently parallelized, supporting 2-level, 3-level, 4-level, 6-level, and 12-level pipeline acceleration, enabling multiple round constants to be executed within one clock cycle, significantly improving the overall performance of the system. It only takes 4 clock cycles to complete the generation of 1600-bit random numbers, significantly enhancing the throughput.
[0104] 6) High throughput: During the operation of the 12-round F' function, by optimizing the calculation process and hardware resource allocation, while reducing the computational consumption, efficient and highly random pseudo-random number generation is achieved. After testing in a 200MHz FPGA environment, a throughput of 80Gbps is achieved, meeting the high-performance requirements.
[0105] In summary, these technical means achieve a balance between security and performance, significantly improving the efficiency, unpredictability, and hardware resource utilization rate of random number generation. Brief Description of the Drawings
[0106] Figure 1 This is the basic flowchart processed by the method and system of the present invention;
[0107] Figure 2 This is the flowchart of the i-th round of f permutation function;
[0108] Figure 3 This is the round constant generator and the improved effect diagram of the round constant;
[0109] Figure 4 This is the performance comparison diagram of pipelines with different levels;
[0110] Figure 5 This is the overall design diagram of the PRNG scheme;
[0111] Figure 6 This is the schematic diagram of the geometric representation of the state characteristics of the round permutation function in the scheme;
[0112] Figure 7 This is the classification schematic diagram of the specific arrangement of the state characteristics of the round permutation function in the scheme. Detailed implementation manners
[0113] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.
[0114] The overall design process of the scheme of the present invention is as Figure 5 shown. First, for the input 1600-bit seed, a 12-round permutation function is designed. In each round, the input data is fully scrambled through a series of linear and non-linear operations, so that the output data has high randomness. Secondly, a round constant generator based on NLSFR (non-linear feedback shift register) is designed. By performing exclusive OR operations with data at specific positions, the unpredictability of the output is further enhanced, and the hardware resources are significantly saved. In addition, the Iota function for processing round constants is optimized, and non-linear changes are added to further improve the data randomness and anti-attack ability. To ensure randomness during long-term operation, a time threshold mechanism is also designed to reseed the PRNG regularly to refresh the seed data and ensure the randomness and security of the output results.
[0115] The specific implemented secure pseudo-random number generator is based on the hardware of FPGA, and includes an initial seed input module, a round constant generation module, a permutation function module, and a reseeding mechanism module: there is a corresponding relationship between the hardware composition based on FPGA and each step in the method.
[0116] The initial seed input module is used to input the original 1600-bit seed x[1599:0] from the outside and preprocess it into the initial seed for storage.
[0117] The initial seed input module includes:
[0118] A register or FIFO for storing 1600-bit original seeds.
[0119] A bit selection module that reads the 1600-bit original seeds stored in the register or FIFO and selects a part of 576 bits as input. The bit selection module realizes dynamic selection through an 11-bit counter.
[0120] The above-mentioned bit selection module includes:
[0121] An 11-bit first counter for dynamically selecting bits in the original seeds;
[0122] A multiplexer (MUX) for selecting the binary values of a specified part of bits according to the dynamic selection of the first counter as a part of numbers.
[0123] The initial seed input module also includes a padding and initial XOR module for performing an XOR operation on the 576-bit data of a part of the numbers selected by the bit selection module and the number composed of 576 consecutive 0s of the same number of bits, and concatenating the number composed of 1024 consecutive 0s to form a 1600-bit initial seed.
[0124] The padding and initial XOR module includes an XOR circuit and a concatenation logic circuit. The XOR circuit is used to perform an XOR operation on the 576-bit part of the numbers and the number composed of 576 consecutive 0s of the same number of bits, and the concatenation logic circuit is used to concatenate the 576-bit number after the XOR operation by the XOR circuit and the number composed of 1024 consecutive 0s.
[0125] A round constant generation module for pre-generating 64-bit round constants required for 12 rounds of the permutation function module and sending them to the permutation function module;
[0126] The round constant generation module includes:
[0127] An 11-bit second counter for selecting the 64-bit round constant of the first round from the initial seeds. In a specific implementation, the second counter can be multiplexed with the 11-bit first counter in the first step, that is, the same counter is used.
[0128] A non-linear feedback shift register NLSFR for generating the round constants of the subsequent 11 rounds according to the 64-bit round constant of the first round to realize the dynamic generation of subsequent round constants, with built-in left shift operation and XOR operation. The logic of the XOR operation: used to implement rc n+1 [K - 1:0] = {rc n [K - 2:0], rc n [A] ^ rcn [B] ^ rc n [C] ^ rc n [D]} operation.
[0129] A permutation function module, which contains an optimized permutation function F' including the round constants generated by the round constant generation module, is used to read and store the initial seed in the initial seed input module, and then perform a 12-round permutation operation on the initial seed using the built-in optimized permutation function F' to obtain the final random number output;
[0130] The permutation function module includes a register for storing 1600 bits and a logic circuit for performing operations such as exclusive OR, AND, and NOT. The logic circuit forms the optimized permutation function F' through hardware topology design.
[0131] A reseeding mechanism module is used to periodically refresh the original seed to ensure randomness and security during long-term operation. The reseeding mechanism module uses a timer / counter to track the time threshold or generate a quantity threshold to control the update.
[0132] The following is a description of the implementation process of the solution of the present invention, as Figure 1 shown, including the sequential connection of each step and the detailed sub-step logic description:
[0133] (1) Seed input stage:
[0134] The process of generating a random number starts from a 1600-bit initial seed. The 1600-bit original seed generated by an external input or a true random number generator TRNG is stored in a register or FIFO. After preprocessing by a bit selection module and a padding and initial exclusive OR module, the initial seed is obtained as input data. The number of bits of the original seed and the initial seed is the same / bit and both are binary numbers.
[0135] In step (1), a counter of the bit selection module is first used in combination with a multiplexer (MUX) to respectively select a continuous number of bits / bit from the several bits / bit of the original seed stored in the register or FIFO on the low bit side and the high bit side to form a preliminary binary number. Then, the padding and initial exclusive OR module is used to perform an exclusive OR operation (performing an exclusive OR operation on each bit) on a binary number composed of continuous 0s with the same number of bits / bit as the preliminary binary number and the preliminary binary number, and then append continuous bits / bit of 0s at the end to make the number of bits the same as the number of bits of the original seed, forming a binary number with the same number of bits as the original seed as the initial seed for subsequent input to the optimized permutation function F'.
[0136] (2) Round constant generation stage:
[0137] According to a random initial seed, a counter is used in combination with a Non-Linear Feedback Shift Register (NLSFR) to pre-generate dynamic round constants for the execution phase of the permutation function through shift and exclusive-OR operations, specifically generating multiple round constants through shift and exclusive-OR operations.
[0138] (21) First, the round constant for optimizing the first round of the permutation function F' is selected from the initial seed by a counter for a preset number of bits of binary numbers as the round constant rc1 for optimizing the first round of the permutation function F'.
[0139] (22) Then, the round constant rc of the nth round n uses the Non-Linear Feedback Shift Register (NLSFR) to dynamically generate the round constant rc of the next round n+1 , expressed as:
[0140] rc n+1 [K-1:0] = {rc n [K-2:0], rc n [A] ^ rc n [B] ^ rc n [C] ^ rc n [D]}
[0141] where, ^ represents the exclusive-OR operation, {} represents binary number concatenation, rc n [62:0] represents the round constant rc n from the 0th bit to the 62nd bit starting from the least significant bit, that is, from the least significant bit to the second highest bit from the bottom, that is, from the rightmost bit to the second leftmost bit; K represents the total number of bits of each round constant, A, B, C, D represent four preset fixed numbers of bits, rc n [A], rc n [B], rc n [C], rc n [D] respectively represent the values of the round constant rc n at the fixed positions A, B, C, D. A, B, C, D are all less than K and are used for the exclusive-OR operation of the round constant;
[0142] (23) Finally, the above process (22) is looped to sequentially generate the round constants corresponding to each round in all optimized permutation functions F'.
[0143] Specifically in implementation, the fixed numbers of bits A, B, C, D during the generation process of the above round constants remain unchanged.
[0144] (3) Execution phase of the permutation function:
[0145] Set a register to store the input initial seed, and process the initial seed with an optimized permutation function F' implemented by a logic circuit and containing the round constants obtained in the round constant generation stage. The optimized permutation function F' includes 12 rounds of permutation operations, which is significantly reduced from the traditional 24 rounds to 12 rounds. After every 12 rounds of permutation operations are executed, a final random number with a length of 1600 bit is output as the secure pseudo-random number result.
[0146] As Figure 2 shown, each round of permutation operation of the optimized permutation function F' includes five steps sequentially carried out within the logic circuit. The five steps are the Theta step, Rho step, Pi step, Chi step, and Iota step. Each round of permutation operation includes the following steps:
[0147] Theta step (θ): Diffuse the input information to ensure the correlation of global data.
[0148] Rho step (ρ): Perform a cyclic shift on the bits to increase the confusion of the data.
[0149] Pi step (π): Rearrange the bits to further enhance the confusion effect.
[0150] Chi step (χ): Perform a non-linear Boolean transformation to enhance randomness.
[0151] Iota step (ι): Introduce the dynamically generated round constants, exclusive OR them with specific bits in the state to increase uniqueness and unpredictability. The round constants generated in the round constant generation stage are used in this step.
[0152] In specific implementation, the secure pseudo-random number generator and method are used to generate several random numbers per second. Since a total of 12 rounds of permutation functions need to be executed, and each round is independent of each other and contains five sub-steps, the solution uses a pipeline method by decomposing and parallelizing these 12 rounds of operations, so that multiple rounds of operations can be carried out simultaneously within the same clock cycle.
[0153] That is, the previous random number to be generated is carried out in the first computing module of the logic circuit, and the next random number to be generated is carried out in the second computing module of the logic circuit; after the second computing module finishes operating on the next random number to be generated, it enters the first computing module, and the second computing module continues to process the next random number to be generated after the next random number to be generated.
[0154] (4) Reseeding mechanism stage:
[0155] By setting a time threshold or a generated quantity threshold, when the time reaches the time threshold or the generated random number reaches the generated quantity threshold, the timer / counter periodically updates the original seed relied on by the pseudo-random number generator, which is generated by an external input or a true random number generator (TRNG), according to the time threshold or the generated quantity threshold, so as to ensure the security and unpredictability of the generated random number. That is, return to step (1) and then repeat steps (1) to (3) for loop processing, continuously update and output the final random number, and ensure the randomness, persistence, and security of the output final random number during long-term operation.
[0156] The solution of the present invention has been tested and verified through specific implementation, and the quality of the obtained final random number is very good. Compared with the random numbers obtained by other cumbersome methods, it has a comparable or higher random number quality.
[0157] Embodiments of the present invention are as follows:
[0158] The main calculation process of the pseudo-random number generator (PRNG) of the present invention is as Figure 1 shown, Figure 1 In the figure, r is called the bitrate and c is called the capacity, both of which are specified parameters, r + c = 1600. In the present invention, r is selected as 576 and c is selected as 1024. c (capacity) determines the security of the algorithm. The larger c is, the stronger the collision resistance and anti-attack ability are. The security level of the SHA-3 algorithm is approximately c / 2.
[0159] In the first step, an initial seed needs to be obtained by processing a 1600-bit original seed input from the outside.
[0160] A 1600-bit original seed is input from the outside and stored in a register or FIFO, denoted as x[1599:0]. 1599 and 0 represent the highest bit and the lowest bit respectively, which are the leftmost bit and the rightmost bit of the binary number respectively. [1599:0] represents the continuous bits from the lowest bit to the highest bit. Since r is selected as 576 in the present invention, 576 bits need to be selected from 1600 bits as the input in this embodiment.
[0161] (11) First, an 11-bit first counter is used in combination with a multiplexer (MUX) to select 576 bits from the 1600-bit seed. The specific method is as follows: Initially, the value of the counter is 11’b 001 1111 1111, where 11’b is the hardware description source and 001 1111 1111 is the count value, which is 511. At this time, {x[511:0], x[1599:1536]} totaling 576 bits are selected as the input, that is, 576 bits are selected in the direction of the lower bit from the current value of the counter. If it is less than 576 bits, it is complemented from the highest bit in a loop to form a total of 576 bits of input.
[0162] In the above processing, the value of the counter is incremented by 1 every clock cycle. When the value of the counter is 11’b110 0011 1111, 110 0011 1111 is 1599. At this time, the value of the counter already corresponds to the highest bit of the 1600-bit original seed. If it continues to increase, it will cause an overflow. Therefore, in the next clock cycle, the value of the counter is reset to 11’b000 0000 0000, which corresponds to the lowest bit of the 1600-bit original seed.
[0163] (12)Use the exclusive-OR circuit in the padding and initial XOR module to perform an exclusive-OR operation on the selected 576-bit input and 576-bit 0, and then use the concatenation logic circuit in the padding and initial XOR module to concatenate 1024-bit 0 (corresponding to c being 1024) at the back to form a total of 1600-bit input data, which is input to the optimized permutation function F'.
[0164] The second step is to generate round constants.
[0165] The traditional SHA-3 algorithm usually performs 24 rounds of permutation functions. Each round requires a 64-bit round constant. Therefore, a total of 24 64-bit round constants are required. These 24 round constants are directly specified by the algorithm and remain unchanged, so there are potential risks in security and randomness.
[0166] In this embodiment, the round constants are pre-generated based on the seeds of random numbers. The designed permutation function of the present invention has 12 rounds, so a total of 12 round constants are required.
[0167] First, the first round constant is also selected from the 1600-bit seed through the 11-bit same counter in the first step. The specific method is that the initial value of the counter is 11’b001 1111 1111, which is 511. At this time, x[575:512] with a total of 64 bits is selected as the round constant of the first round, that is, 64 bits are selected in the high-bit direction starting from the current value of the counter plus 1. If it is less than 64 bits, it is filled from the lowest bit in a loop to form a total of 64-bit round constant of the first round, denoted as rc1[63:0]. The round constant rc2 of the second round is generated from the round constant rc1 of the first round, and the round constant rc3 of the third round is generated from the round constant rc2 of the second round, and so on.
[0168] The specific generation method is as Figure 3As shown, taking the generation of rc2 from rc1 as an example, a non - linear feedback shift register (NLSFR) is used to generate dynamic round constants, which specifically includes two operations - shifting (left shift) and exclusive - OR. That is, rc2[63:0] = {rc1[62:0], rc1
[63] ^ rc1
[60] ^ rc1
[52] ^ rc1
[45] }, where ^ represents the exclusive - OR operation and , represents binary number concatenation.
[0169] What needs to be particularly noted is that the generation of round constants in the present invention using a non - linear feedback shift register involves two basic operations. The design of using a left shift and selecting rc1
[63] , rc1
[60] , rc1
[52] , rc1
[45] for exclusive - OR operation is just a special case. However, in actual implementation, other operations with the same calculation but different shift directions or different bit selections for exclusive - OR should also be regarded as the same method for generating round constants.
[0170] The third step is the process of obtaining a 1600 - bit random number output by performing 12 - round permutation function operations on the 1600 - bit input data obtained in the first step. The input and output of each round of permutation operation are both 1600 bits. The output of the first - round permutation function is used as the input of the second - round permutation function, the output of the second - round permutation function is used as the input of the third - round permutation function, and so on. The number of input and output of each round of permutation operation is called the state number, and each bit is called the state bit value. For example, the input number of the first - round permutation operation is S0, the input number of the second - round permutation operation is S1, and so on.
[0171] The value of each bit of the initial input data is used as a state bit value and also as a cube. The state bit values of each bit of the initial input data are distributed in a three - dimensional arrangement of multiple cubes along the mutually orthogonal x, y, and z axes to form a three - dimensional arrangement structure data. That is, the cubes are closely arranged along the x, y, and z axes, and each cube represents bit / bit data.
[0172] Specifically, first distribute on the xy plane where the x and y axes are located, and then expand along the z - axis direction. When distributing on each xy plane, first distribute along the x - axis line where the x axis is located, and then expand along the y - axis direction. When distributing on each x - axis line, first distribute along the positive x - axis direction at the center of the x - axis line, and then distribute along the negative x - axis direction. The sequence numbers of the x - axis and y - axis are both symmetrically distributed with 0 at the center position on both sides, and the sequence numbers of the z - axis are sorted in sequence along the z - axis direction.
[0173] According to a specific arrangement and division method, the three-dimensional arrangement structure data is divided into three types of slices: horizontal slice (plane), vertical slice (slice), and longitudinal slice (sheet), and three types of strips: horizontal strip (row), vertical strip (column), and longitudinal strip (lane). Each type of slice is composed of the state bit values corresponding to all the cubes on the same plane, and each type of strip is composed of the state bit values corresponding to a column of cubes on the same straight line.
[0174] The horizontal slice (plane) is composed of the state bit values corresponding to all the cubes located on the xz plane, the vertical slice (slice) is composed of the state bit values corresponding to all the cubes located on the xy plane, and the longitudinal slice (sheet) is composed of the state bit values corresponding to all the cubes located on the yz plane; the horizontal strip (row) is composed of the state bit values corresponding to all the cubes located on the x-axis, the vertical strip (column) is composed of the state bit values corresponding to all the cubes located on the y-axis, and the longitudinal strip (lane) is composed of the state bit values corresponding to all the cubes located on the z-axis.
[0175] In a specific implementation, its 1600-bit three-dimensional geometric representation is as Figure 6 shown, where each cube represents 1 bit of data. According to a specific arrangement method, its specific slices and strips are as Figure 7 shown.
[0176] After 12 consecutive rounds of permutation operations on the three-dimensional arrangement structure data, the final random number is obtained.
[0177] In a specific implementation, each round of permutation function includes five operations, namely Theta step (θ), Rho step (ρ), Pi step (π), Chi step (χ), and Iota step (ι). The five operations are carried out in sequence, that is, the output of the Theta step (θ) is used as the input of the Rho step (ρ), the output of the Rho step (ρ) is used as the input of the Pi step (π), and so on.
[0178] In each round of permutation function:
[0179] (31) The Theta step processes each state bit value in the three-dimensional arrangement data structure according to the following formula and assigns a value to replace its own value:
[0180] The Theta step processes each state bit value in the three-dimensional arrangement data structure according to the following formula and assigns a value to replace it:
[0181] s'[x][y][z]=s[x][y][z]^∑ y'' s[x - 1][y''][z] ^∑ y'' s[x + 1][y''][z - 1]
[0182] y'' = y + Δy
[0183] Where s'[x][y][z] represents the status bit value of the coordinate (x, y, z) in the three-dimensional arrangement structure data after Theta step processing, and s[x][y][z] represents the status bit value of the coordinate (x, y, z) in the three-dimensional arrangement structure data before Theta step processing; y'' represents the y coordinate of the status bit value s[x][y][z] calculated currently and the status bit values of two adjacent vertical bars column in its three-dimensional arrangement; ^ represents the exclusive OR operation, and Δy represents the preset adjacent y coordinate step value;
[0184] In specific implementation, if the case of x - 1 < 0 or x + 1 > 4 occurs, the actual situation can be to calculate (x - 1) mod 5, where mod represents the modulo operation. For example, when x - 1 is -1, (x - 1) mod 5 = 4. The purpose of taking the modulo of the calculated coordinate is to always keep it within the range of 0 - 4 and always be meaningful.
[0185] (32) The Rho step processes each status bit value in the three-dimensional arrangement data structure after Theta step processing according to the following formula and assigns a value to replace its own value:
[0186] ρ: s''[x][y][z] = s'[x][y][z - (t + 1)(t + 2) / 2]
[0187] Where t represents the intermediate variable used to calculate the bit value offset; s''[x][y][z] represents the status bit value of the coordinate (x, y, z) in the three-dimensional arrangement structure data after Rho step processing;
[0188] Where the intermediate variable t satisfies:
[0189] 0 ≤ t ≤ 24 and in GF(5) 2×2
[0190] or
[0191] if x = y = 0, t = -1
[0192] Where GF(5) 2×2 represents a 2×2 matrix space over the finite field GF(5), where all elements and operations are defined over the finite field GF(5), and in means belonging to;
[0193] The Pi step processes the state bit values of each position on the same vertical slice in the three-dimensional arrangement data structure after the Rho step according to the following formula and assigns the processed value to replace its own value:
[0194] π: p'[x][y]=p[x'][y']
[0195]
[0196] Among them, p'[x][y] represents the state bit value of the coordinate (x, y) on the vertical slice in the three-dimensional arrangement structure data after the Pi step, p[x][y] represents the state bit value of the coordinate (x, y) on the vertical slice in the three-dimensional arrangement structure data before the Pi step, and x', y' represent the new horizontal and vertical position coordinates of the state bit value in the state matrix, that is, the target position after the state bit value is remapped from the original position (x, y).
[0197] The Chi step processes the state bit values of each position on the same horizontal row in the three-dimensional arrangement data structure after the Pi step according to the following formula and assigns the processed value to replace its own value:
[0198] χ: q'[x]= q[x]^((q[x+1]^1)&q[x+2])
[0199] Among them, q'[x] represents the state bit value of the coordinate x on the horizontal row in the three-dimensional arrangement structure data after the Chi step, and q[x] represents the state bit value of the coordinate x on the horizontal row in the three-dimensional arrangement structure data before the Chi step.
[0200] The Iota step processes the state bit values of each position on the innermost vertical lane in the three-dimensional arrangement data structure after the Chi step according to the following formula and assigns the processed value to replace its own value:
[0201] ι: I'[0][0][z]=I[0][0][z]^RC i
[0202] Among them, i represents the number of rounds of the permutation operation, and RC i represents the round constant of the current i-th round. Among them, I'[0][0][z] represents the state bit value of the coordinate z on the innermost vertical lane in the three-dimensional arrangement structure data after the Iota step, and z is an even number. I[0][0][z] represents the state bit value of the coordinate z on the innermost vertical lane in the three-dimensional arrangement structure data before the Iota step.
[0203] The Iota step operation is performed on a vertical bar lane basis. In the prior art, when z is 0, 1, 3, 7, 15, 31, 63 in the algorithm, s[0][0][z] and RC i [z] perform an exclusive OR operation. The round constant has 64 bits, but actually only 7 bits perform the exclusive OR operation with the original data. This may limit the state change due to only 7-bit round constant exclusive OR, reducing the entropy and unpredictability of the random number, and affecting the quality and security of the pseudo-random number.
[0204] In the present invention, the ι operation of the Iota step is set to perform an exclusive OR operation with the round constant RC when z is an even number. i That is, the value of the even bit z of I[0][0][z] and the value of the corresponding even bit z in the round constant RC i perform an exclusive OR operation. In this way, 32 bits in the round constant are selected each time to perform an exclusive OR operation with 32 bits of I[0][0][z] respectively, reusing the round key, while increasing the unpredictability and complexity, and increasing the randomness of the operation.
[0205] The above description is the five permutation operations included in a round permutation function. By performing 12 rounds of permutation operations, a 1600-bit random number is output.
[0206] In the specific implementation process, in order to optimize the performance of the pseudo-random number generator modified based on SHA-3, a multi-stage pipeline design is adopted. Since this design includes a 12-round permutation function, by introducing pipeline processing, multiple rounds of operations can be executed within one clock cycle, effectively improving the throughput.
[0207] To evaluate the performance of different pipeline stages, comparative experiments of non-pipeline, 2-stage, 3-stage, 4-stage, and 6-stage pipelines were carried out, and the test results are as Figure 4 shown. The experiment is based on the Verilog language, implemented on Vivado 2024.2 for the AMD Virtex-7 FPGA (VC709 Connectivity Kit), and the throughput, LUT resource occupancy, and LUT / throughput ratio are compared.
[0208] From Figure 4 it can be seen that under the 3-stage pipeline design, the 12-round permutation function can be efficiently executed in parallel, and the generation of a 1600-bit pseudo-random number only requires 4 clock cycles, significantly improving the generation rate of the random number. At the same time, a good balance is achieved between throughput and resource consumption. Therefore, the present invention selects the 3-stage pipeline as the final implementation scheme to achieve a better balance between performance and resource utilization.
[0209] It can be seen that this optimization scheme can significantly improve throughput, reduce latency, while maintaining the integrity and security of the F' function, meeting the requirements of high-performance application scenarios.
[0210] Table 1
[0211] Design Board Process Clock frequency Throughput On-chip resources (slices) Throughput / frequency [1] ZYNQ 28nm 138.3MHz 15.37Mbps 46573 0.11bit / circle [2] XC2VP30 90nm 373MHz 46.63Gbps 12556 125bit / circle [3] ZYNQ 28nm 156.813MHz 19.60Gbps 10867 124.9bit / circle The present invention Virtex 7 28nm 200MHz 80Gbps 15341 400bit / circle
[0212] Through the testing of specific embodiments, in the FPGA operating environment, based on a clock frequency of 200 MHz, a throughput of up to 80 Gbps was achieved. As shown in Table 1, the comparison results with other research works indicate that the throughput of the present invention is significantly higher than other design schemes, and the hardware resource overhead is relatively low, with a total of 15,341 slices used.
[0213] The [1][2][3] in Table 1 are respectively sourced from:
[0214] [1] Yu F, Li L, He B, et al. Pseudorandom number generator based on a5D hyperchaotic four-wing memristive system and its FPGA implementation[J].The European Physical Journal Special Topics, 2021, 230(7): 1763-1772.
[0215] [2] Iyer N, Anandmohan P V, Poornaiah D V, et al. Efficient hardwarearchitectures for AES on FPGA[C] / / International Conference on ComputationalIntelligence and Information Technology. Berlin, Heidelberg: Springer BerlinHeidelberg, 2011: 249-257.
[0216] [3] Gafsi M, Abbassi N, Amdouni R, et al. Hardware implementation ofa strong pseudo-random numbers generator with an application to imageencryption[C] / / 2022 IEEE 9th International Conference on Sciences ofElectronics, Technologies of Information and Telecommunications (SETIT).IEEE, 2022: 510-515.
[0217] As can be seen from this implementation, while ensuring randomness and security, the present invention significantly improves hardware efficiency and meets the requirements of high-performance random number generation.
[0218] The above specific implementation manners are used to explain and illustrate the present invention, rather than to limit the present invention. Any modifications and changes made to the present invention within the spirit and scope of the claims of the present invention fall within the protection scope of the present invention. The above are only the preferred implementation manners of the present invention. Therefore, all equivalent changes or modifications made according to the structures, features and principles described in the scope of the patent application of the present invention are included in the scope of the patent application of the present invention.
Claims
1. A secure pseudo-random number generator for high throughput in FPGA, characterized in that: The secure pseudo-random number generator is based on FPGA hardware and includes: An initial seed input module is used to input the original seed from the outside and pre-process it into an initial seed storage; A round constant generation module, used to pre-generate the round constants required by the permutation function module 12 rounds, and send them to the permutation function module; The round constant generation module comprises: a second counter for selecting a first round constant from an initial seed; A nonlinear feedback shift register, used to generate the round constants of the next 11 rounds according to the round constants of the first round, with built-in left shift operation and XOR operation; The permutation function module has an optimized permutation function F' containing a round constant, which is used to read the initial seed in the initial seed input module and store it, and then use the built-in optimized permutation function F' to perform 12 rounds of permutation operations on the initial seed to obtain the final random number output; The optimized permutation function F' is a cryptographic hash function based on the Keccak algorithm, which uses a unique sponge structure to complete the generation of the message digest in two stages: absorption and extrusion: First, in the absorption phase, the input message is divided into blocks, each block is XORed with the first r bits of the current state, and then the state is updated through the permutation function; in the extrusion phase, the output summary is extracted from the first r bits of the state, and the state is updated through the permutation function if it is insufficient; the state feature consists of the absorption rate part r and the capacity part c. The absorption rate part r is responsible for processing input and output, and the capacity part c provides security. The reseed mechanism module is used to periodically refresh the original seed to ensure randomness and security during long-term operation.
2. The secure pseudo-random number generator for FPGA high throughput according to claim 1, characterized in that: The initial seed input module includes: A register or FIFO to store the original seed; A bit selection module that reads the original seed stored in the register or FIFO and selects a portion of it; A filling and initial XOR module is used to perform XOR operation on a part of the number selected by the bit selection module and a number composed of multiple consecutive 0s with the same number of bits, and to concatenate the number composed of multiple consecutive 0s to form an initial seed.
3. The secure pseudo-random number generator for FPGA high throughput according to claim 2, characterized in that: The bit selection module comprises: a first counter for dynamically selecting bits in the original seed; a multiplexer for selecting a binary value of a specified portion of bits according to the first counter; The filling and initial XOR module includes an XOR circuit and a splicing logic circuit. The XOR circuit is used to perform an XOR operation on a part of a number with a number consisting of multiple consecutive 0s of the same number of bits. The splicing logic circuit is used to splice the number after the XOR operation of the XOR circuit with a number consisting of multiple consecutive 0s.
4. The secure pseudo-random number generator for FPGA high throughput according to claim 1, characterized in that: The substitution function module includes a logic circuit for storing registers and for performing XOR, AND, NOT operations; the reseeding mechanism module uses a timer / counter to track a time threshold or a generation quantity threshold to control the update.
5. A method for generating secure pseudo-random numbers for high throughput in FPGA, characterized in that: The method is based on the secure pseudo-random number generator for FPGA high throughput according to any one of claims 1 to 4, and the method comprises: (1) Seed input stage: The original seed is stored in a register or FIFO, and after preprocessing by a bit selection module and a filling and initial XOR module, an initial seed is obtained as input data. The number of bits / bits of the original seed and the initial seed are the same and both are binary numbers; (2) Round constant generation stage: According to the initial seed, a nonlinear feedback shift register NLSFR is used to pre-generate round constants for the permutation function execution phase; (3) Permutation function execution phase: A register is set to store an input initial seed, and an optimized permutation function F' implemented by a logic circuit and containing a round constant is used to process the initial seed. The optimized permutation function F' includes 12 rounds of permutation operations. After each 12 rounds of permutation operations are performed, a final random number is output as a result; (4) Replanting mechanism stage: By setting a time threshold or a generation quantity threshold, the original seed is refreshed periodically through a timer / counter according to the time threshold or the generation quantity threshold, and the process returns to step (1) and then repeats steps (1) to (3) for a loop process, thereby continuously updating the output of the final random number.
6. The method for generating secure pseudo-random numbers for FPGA with high throughput according to claim 5, characterized in that: The step (1) is specifically as follows: first, a counter of a bit selection module is used to select a number of consecutive bits on the low-order side and the high-order side from the original seed stored in the register or FIFO to form a preliminary binary number, and then a filling and initial XOR module is used to perform an XOR operation on a binary number consisting of consecutive 0s with the same number of bits as the preliminary binary number, and then the consecutive 0s are concatenated at the end to form a binary number with the same number of bits as the original seed as the initial seed, which is then input into the optimized permutation function F'.
7. The method for generating secure pseudo-random numbers for FPGA with high throughput according to claim 5, characterized in that: The step (2) is specifically as follows: (21) First, a counter is used to select a preset binary number of several digits from the initial seed as the round constant rc1 for optimizing the first round of the permutation function F'; (22) Then the round constant rc of the nth round is n Use the nonlinear feedback shift register NLSFR to dynamically generate the next round of round constants rc n+1 , expressed as: rc n+1 [K-1:0] = {rc n [K-2:0], rc n [A]^rc n [B]^rc n [C]^rc n [D]} Among them, ^ represents the XOR operation, rc n [K-2:0] represents the wheel constant rc n From the lowest bit 0 to the K-2th bit; K represents the total number of bits of each round constant, A, B, C, D represent four pre-set fixed bits, rc n [A], rc n [B] rc n [C] , rc n [D] represents the wheel constant rc n The values at fixed positions A, B, C, D; (23) Finally, the above process (22) is repeated to generate the round constants corresponding to each round in all the optimized permutation functions F'.
8. The method for generating secure pseudo-random numbers for FPGA with high throughput according to claim 5, characterized in that: The round constant in the i-th round permutation operation of the optimized permutation function F' corresponds to the i-th round constant obtained in step (2).
9. The method for generating secure pseudo-random numbers for FPGA with high throughput according to claim 5, characterized in that: Each round of permutation operation of the optimized permutation function F' includes five steps performed sequentially in the logic circuit, the five steps are respectively a Theta step, a Rho step, a Pi step, a Chi step and an Iota step; First, the Theta step is performed to calculate the even parity of each column of the input binary data and perform an XOR operation on each bit; Then, the Rho step is performed to perform a cyclic shift on each bit according to a predefined offset; Then the Pi step is performed to rearrange the bits on the same face; Next, the Chi step is performed to process the bits on the same line through nonlinear Boolean transformation; Finally, the Iota step is performed to perform an even XOR operation on the round constant and the specific bit.
10. The method for generating secure pseudo-random numbers for FPGA with high throughput according to claim 9, characterized in that: The value of each bit of the initial seed is used as a state bit value, and the state bit values of each bit of the initial seed are distributed in a three-dimensional arrangement of multiple cubes along the three axes of x, y, and z to form three-dimensional arrangement structure data; the three-dimensional arrangement structure data is divided into three types of slices, namely, horizontal slices plane, vertical slices slice, and longitudinal slices sheet, and three types of strips, namely, horizontal strips row, vertical strips column, and vertical strips lane, each slice is composed of state bit values corresponding to all cubes in a layer on the same plane, and each strip is composed of state bit values corresponding to a column of cubes on the same straight line; the final random number is obtained after 12 rounds of permutation operations are performed continuously and sequentially on the three-dimensional arrangement structure data.
11. The method for generating secure pseudo-random numbers for FPGA with high throughput according to claim 10, characterized in that: In each round of permutation operation: The Theta step processes and replaces each state bit value in the three-dimensional arrangement data structure according to the following formula: s'[x][y][z]=s[x][y][z] ^∑ y'' s[x-1][y''][z] ^∑ y'' s[x+1][y''][z-1] y''=y+△y Wherein, s'[x][y][z] represents the state bit value of the coordinates (x, y, z) in the three-dimensional arrangement structure data after the Theta step, and s[x][y][z] represents the state bit value of the coordinates (x, y, z) in the three-dimensional arrangement structure data before the Theta step; y'' represents the y coordinate of the state bit values of the two adjacent columns of the vertical bar column under the current calculated state bit value s[x][y][z] and its three-dimensional arrangement; ^ represents an exclusive-or operation, and △y represents the step value of the adjacent y coordinates; The Rho step processes and replaces each state bit value in the three-dimensional arrangement data structure processed by the Theta step according to the following formula: s''[x][y][z]=s'[x][y][z-(t+1)(t+2) / 2] Wherein, t represents an intermediate variable used to calculate the bit value offset; s''[x][y][z] represents the state bit value of the coordinates (x, y, z) in the three-dimensional arrangement structure data after the Rho step; The Pi step is to process and replace each state bit value located on the same vertical slice in the three-dimensional arrangement data structure processed by the Rho step according to the following formula: p'[x][y]=p[x'][y'] Wherein, p'[x][y] represents the state bit value of the coordinates (x, y) on the vertical slice slice located on the same xy plane in the three-dimensional arrangement structure data after the Pi step processing, p[x'][y'] represents the state bit value of the coordinates (x', y') on the vertical slice slice located on the same xy plane in the three-dimensional arrangement structure data before the Pi step processing, and x', y' represent the new horizontal and vertical position coordinates of the state bit value in the state matrix; The Chi step is to process and replace the state bit value of each bit located in the same horizontal row in the three-dimensional arrangement data structure processed by the Pi step according to the following formula: q'[x]= q[x]^((q[x+1]^1)&q[x+2]) Wherein, q'[x] represents the state bit value of the coordinate x on the horizontal bar row located on the same x-axis line in the three-dimensional arrangement structure data after the Chi step processing, q[x] represents the state bit value of the coordinate x on the horizontal bar row located on the same x-axis line in the three-dimensional arrangement structure data before the Chi step processing, ^ represents an exclusive-or operation, and & represents an AND operation; The Iota step is to process and replace the state bit value of each vertical lane located at the center of the three-dimensional arrangement data structure processed by the Chi step according to the following formula: I'[0][0][z]=I[0][0][z]^RC i Among them, i represents the number of rounds of permutation operation, RC i Represents the round constant of the current i-th round, where I'[0][0][z] represents the state bit value of the coordinate z on the centermost vertical lane in the three-dimensional arrangement structure data after the Iota step, and z is an even number, and I[0][0][z] represents the state bit value of the coordinate z on the centermost vertical lane in the three-dimensional arrangement structure data before the Iota step.
Citation Information
Patent Citations
Method for generating key with fixed bit width on cryptographic chip
CN107124267A
FPGA Design of Pseudorandom Number Generator Based on Fractional Chaos and Zuchongzhi Algorithm
CN109508175A