SHA-3 algorithm-based fixed-length message processing method, device, equipment and product
By adopting a fixed-length and short message processing method based on the SHA-3 algorithm in privacy calculation, the problem of low cryptographic calculation calculation efficiency in the prior art is solved, and efficient hashing calculation for batch fixed-length and short messages is realized.
Patent Information
- Application Number
- CN202411998357.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-05-13
AI Technical Summary
When the prior art performs hardware acceleration of performance-sensitive cryptographic operations in privacy computing, the computing efficiency is low and it is difficult to meet the hash computing requirements of batch fixed-length short messages.
The fixed-length and short message processing method based on the SHA-3 algorithm is adopted. By performing message filling processing on the original message, it detects whether the current working state of the pipeline structure meets the preset working state, and performs function loop processing on the to-process messages based on the pipeline structure when the conditions are met, thereby improving hash calculation efficiency.
By detecting and controlling the working state of the pipeline structure, multiple sets of pending messages can be processed simultaneously within the same clock cycle, improving the clock frequency and hash computing efficiency of the hardware design.
Smart Images

Figure CN119995835A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of information security technology, and in particular, relates to a fixed-length short message processing method, device, equipment and product based on the SHA-3 algorithm. Background Art
[0002] In recent years, privacy computing technologies represented by secure multi-party computing, federated learning, and trusted execution environment have been widely used in fields such as cloud computing because they can ensure the confidentiality, integrity, and availability of data when using data.
[0003] The construction of protocols and algorithms in privacy computing technology is usually based on cryptographic operations such as hash operations and modular operations, which will indirectly affect the overall computing efficiency of privacy computing. Therefore, how to perform hardware acceleration on these performance-sensitive cryptographic operations to improve computing efficiency is an urgent problem that needs to be solved. Summary of the invention
[0004] The embodiments of the present application provide a fixed-length short message processing method, apparatus, device and product based on the SHA-3 algorithm, which can perform hardware acceleration on cryptographic operations and effectively improve the efficiency of hash calculations.
[0005] In a first aspect, an embodiment of the present application provides a method for processing a fixed-length short message based on a SHA-3 algorithm, comprising:
[0006] Performing message padding processing on the original message to obtain a message to be processed, wherein the length of the original message is less than or equal to the first specified length;
[0007] Detecting whether a current working state of a pipeline structure established based on a third-generation secure hash SHA-3 algorithm satisfies a preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of an iterative loop, and the multiple round functions are used to simultaneously cyclically process a first predetermined number of messages to be processed within the same clock cycle;
[0008] If it is detected that the current working state of the pipeline structure meets the preset working state, the message to be processed is processed through a round function loop based on the pipeline structure to obtain a target message.
[0009] In some embodiments, the preset working state is used to indicate that there is a round function in the pipeline structure that is in an idle state, and detecting whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm satisfies the preset working state includes:
[0010] Detecting whether a sequence value in a current state sequence corresponding to the pipeline structure is a preset value, and obtaining a first detection result, wherein the sequence value of the current state sequence is used to indicate the working state of all current round functions in the pipeline structure;
[0011] Based on the first detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
[0012] In some embodiments, the preset working state is used to indicate that there is a pending message in the pipeline structure that is being processed by the round function cycle of the last clock cycle, and detecting whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state includes:
[0013] Detect whether the control signal corresponding to the pipeline structure is a preset value to obtain a second detection result, where the control signal is used to indicate whether there is a message to be processed in the pipeline structure that is being processed by the round function loop of the last clock cycle;
[0014] Based on the second detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
[0015] In some embodiments, a round function loop is performed on a message to be processed based on a pipeline structure to obtain a target message, including:
[0016] When the original message is detected to be a valid message, the message to be processed is processed by round function loop based on the pipeline structure to obtain the algorithm processing result and update the current working state of the pipeline structure;
[0017] A message with a specified number of digits is intercepted from the algorithm processing result as the target message, and the target message is output.
[0018] In some embodiments, a first register is provided between each round function, and a round function loop is performed on the message to be processed based on the pipeline structure to obtain a target message, including:
[0019] Inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain an intermediate processing result, wherein the result calculated by the current round function in each clock cycle is stored in a first register after the current round function, so that the next function in the next clock cycle is calculated by reading data from the first register;
[0020] The intermediate processing result is used as the message to be processed, and the step of inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain the intermediate processing result is returned to the step of obtaining the intermediate processing result until the round function cycle processing of the second predetermined number of time cycles is completed;
[0021] taking the intermediate processing result corresponding to the second predetermined number of time periods completed as the algorithm processing result;
[0022] A message with a specified number of bits is intercepted from the algorithm processing result and determined as a target message, and the target message is output.
[0023] In some embodiments, updating the current working state of the pipeline structure includes:
[0024] Update the sequence value of the current state sequence corresponding to the pipeline structure, and / or
[0025] When the message to be processed is processed in the round function loop of the last clock cycle, the control signal corresponding to the pipeline structure is set to a preset value.
[0026] In some embodiments, each round function is composed of a plurality of permutation functions, a second register is provided between at least two permutation functions, and the second register is used to store a result calculated by the permutation function before the second register.
[0027] In some embodiments, performing message filling processing on the original message to obtain a message to be processed includes:
[0028] Add the specified characters to the end of the original message to obtain a preliminary processed message;
[0029] The message padding rule corresponding to the SHA-3 algorithm is used to perform message padding processing on the preliminary processed message to obtain data to be processed whose message length is the second specified length.
[0030] In a second aspect, an embodiment of the present application provides a fixed-length short message processing device based on a SHA-3 algorithm, comprising:
[0031] A message filling module, used to perform message filling processing on the original message to obtain a message to be processed, wherein the length of the original message is less than or equal to the first specified length;
[0032] A detection module, used to detect whether a current working state of a pipeline structure established based on a third-generation secure hash SHA-3 algorithm satisfies a preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of an iterative loop, and the multiple round functions are used to simultaneously cyclically process a first predetermined number of messages to be processed within the same clock cycle;
[0033] The loop processing module is used to perform round function loop processing on the message to be processed based on the pipeline structure to obtain the target message if it is detected that the current working state of the pipeline structure meets the preset working state.
[0034] In a third aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any method of the first aspect when executing the computer program.
[0035] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method of any one of the first aspects is implemented.
[0036] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when executed on a terminal device, enables the terminal device to execute any one of the methods in the first aspect.
[0037] The embodiment of the present application provides a fixed-length short message processing method, device, equipment and product based on the SHA-3 algorithm, the method comprising: performing message padding processing on the original message to obtain a message to be processed, the length of the original message is less than or equal to the first specified length; detecting whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of the iterative loop, and the multiple round functions are used to simultaneously process the first predetermined number of messages to be processed in the same clock cycle; if it is detected that the current working state of the pipeline structure meets the preset working state, the round function loop processing is performed on the message to be processed based on the pipeline structure to obtain the target message. Using the above technical solution, by detecting whether the current working state of the pipeline structure established based on the SHA-3 algorithm meets the preset working state, the pipeline structure can effectively control the loop processing of the message to be processed. At the same time, the pipeline structure allows the first predetermined number of messages to be processed to be processed simultaneously in the same clock cycle, which improves the clock frequency and hash calculation efficiency of the hardware design. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0039] Figure 1 It is a flowchart of a fixed-length short message processing method based on the SHA-3 algorithm provided by the prior art;
[0040] Figure 2 It is a flowchart of a method for processing a fixed-length short message based on the SHA-3 algorithm provided in one embodiment of the present application;
[0041] Figure 3 It is a flowchart of another method for processing a fixed-length short message based on the SHA-3 algorithm provided in an embodiment of the present application;
[0042] Figure 4 It is a flowchart of a method for processing a fixed-length short message based on the SHA-3 algorithm provided in another embodiment of the present application;
[0043] Figure 5 It is a flowchart of another method for processing a fixed-length short message based on the SHA-3 algorithm provided in an embodiment of the present application;
[0044] Figure 6 It is a schematic diagram of the main signal assignment dependency in a control unit provided in an embodiment of the present application;
[0045] Figure 7 This is a message timing diagram of continuous message input provided by an embodiment of the present application;
[0046] Figure 8 This is another message timing diagram of continuous message input provided by an embodiment of the present application;
[0047] Fig. 9 This is a schematic diagram of a structure of a message to be processed provided by an embodiment of the present application;
[0048] Fig.10 It is a structural block diagram of a fixed-length short message processing device based on the SHA-3 algorithm provided in one embodiment of the present application;
[0049] Fig.11 It is a structural diagram of a terminal device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0050] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0051] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0052] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0053] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0054] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0055] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0056] The fixed-length short message processing method based on the SHA-3 algorithm provided in the embodiment of the present application can be applied to terminal devices such as mobile phones, tablet computers, wearable devices, vehicle-mounted devices, augmented reality (AR) / virtual reality (VR) devices, laptops, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), etc. The embodiment of the present application does not impose any restrictions on the specific type of terminal devices.
[0057] It can be considered that the privacy set intersection algorithm based on oblivious transmission uses a hash function to perform hash calculations on fixed-length short messages, but the hardware implementation of the existing hash function is not sufficient to meet the hash calculation of batch fixed-length short messages, which restricts the further promotion and use of privacy intersection and other technologies. Therefore, designing a hash function that can batch process multiple groups of fixed-length short messages can effectively meet the application scenarios where hash calculations are frequently used.
[0058] Among them, the hash function is a cryptographic primitive that can convert a message of any length into a value of fixed length. At present, the commonly used secure hash function in the world is SHA256. China has independently developed an alternative SM3 hash function. The commonality of the two hash functions is that they process 512 bits of input each time, and the 256 bits of calculated output can be used as the initialization vector of the next round of 512 bits of input or the final hash result.
[0059] SHA-3 algorithm is the third generation hash algorithm launched after SHA-2 algorithm. Compared with the first two hash algorithms, SHA-3 algorithm can complete hash calculation only through Boolean operation and circular shift operation, and it also has high security. SHA-3 algorithm consists of four hash functions (SHA3-224, SHA3-256, SHA3-384 and SHA3-512) and two scalable output functions (SHAKE-128 and SHAKE-256). When using it, the appropriate SHA-3 algorithm can be dynamically selected according to the input packet size, output length and security requirements in the actual application scenario.
[0060] Among them, the existing hardware acceleration schemes for SHA256 and SM3 algorithms require too many rounds of iterative compression, resulting in a large number of clock cycles when implemented in hardware, which affects the efficiency of hash calculations for batch messages. The number of iterative compression rounds in the SHA-3 algorithm is much lower than that of the SHA256 and SM3 algorithms. Therefore, the throughput upper limit of the SHA-3 algorithm calculation is theoretically higher than that of the SHA256 and SM3 algorithms.
[0061] Figure 1 It is a flowchart of a fixed-length short message processing method based on the SHA-3 algorithm provided by the prior art. Figure 1 As shown in the figure, the calculation process of the SHA-3 algorithm can be divided into two stages: absorption and squeezing. First, the original message can be padded to an integer multiple of r according to the padding rule, and then the padded message is split into n groups of message blocks P 0 , P 1 ,…,P n-1 Then, in the absorption phase, the iterative function f is used to hash each message block in turn, and in the squeeze phase, the iterative function f is continued to be used to process the message output in the absorption phase. Finally, the low-order bit data in the message output in the squeeze phase is combined with the low-order bit data in the message output in the absorption phase to obtain the output summary, that is, the final output message data.
[0062] Among them, the iterative function f represents the iterative function for processing fixed-length byte strings. It is the core module of the entire SHA-3 algorithm hardware acceleration implementation. It consists of 24 rounds of Keccak-f functions. Each round of Keccak-f function is composed of 5 rounds of permutation functions, namely θ, ρ, π, χ, ι; r represents the length of the message group, c represents the length of the redundant data, and r+c represents the length of the fixed-length byte string processed by the iterative function f.
[0063] However, the above-mentioned fixed-length short message processing method based on the SHA-3 algorithm is mainly used to process the original long message, and does not take into account the particularity of the fixed-length short message batch hash, resulting in a low computational throughput based on the existing hardware implementation. At the same time, the above-mentioned fixed-length short message processing method based on the SHA-3 algorithm does not provide a suitable hardware mechanism to control the input and output of batch fixed-length short messages.
[0064] In order to effectively meet the application scenarios where hash calculations are frequently used, Figure 2 FIG. 1 is a flow chart of a method for processing a fixed-length short message based on the SHA-3 algorithm provided in an embodiment of the present application. Figure 2 As shown, in this embodiment, the original message (i.e., a fixed-length short message) can first be filled with a message to obtain a message to be processed P 0 Since the original message is a short message of fixed length, only one round of iterative function f needs to be executed in the absorption phase of the SHA-3 algorithm, and only the low-order bits of the output value of the iterative function f need to be intercepted in the squeeze phase to serve as the hash value finally output by the algorithm.
[0065] Since the iterative function f needs to perform 24 rounds of Keccak-f iterative operations in total, if only one set of Keccak-f functions is designed during hardware design, only one fixed-length short message can be processed each time, which does not meet the goal of batch fixed-length short message hashing. Therefore, this embodiment can expand the original 24-round round function, and the round factor of the expanded round function is recorded as Unroll Factor (UF). UF needs to be divisible by 24, so UF can be 1, 2, 3, 4, 6, 8, 24. The larger the UF, the more rounds can be performed per clock cycle, and the fewer clock cycles are required to complete one f function. However, the way of expanding the round function not only increases the consumption of hardware area, but also increases the delay of the critical path.
[0066] Therefore, this embodiment further inserts registers between and within the expanded round functions to establish a multi-stage pipeline structure to shorten the critical path delay and improve the clock frequency of the hardware design. In addition, this embodiment also enables batches of fixed-length short messages to enter the pipeline structure through the control mechanism established by the control unit and the additional handshake mechanism, achieving the effect of processing multiple groups of fixed-length short messages in the same clock cycle, thereby improving the throughput of hash calculations and the utilization of hardware resources.
[0067] Figure 3 It is a flowchart of another fixed-length short message processing method based on the SHA-3 algorithm provided in an embodiment of the present application. As an example but not a limitation, the method can be applied to a terminal device.
[0068] S101. Perform message padding processing on an original message to obtain a message to be processed, wherein the length of the original message is less than or equal to a first specified length.
[0069] The original message can be a message that is originally input to the terminal device and needs to be processed. For example, the original message can be input to the terminal device in real time or at intervals of a time period, so that the terminal device can process the input original message based on the fixed-length short message processing method of the SHA-3 algorithm provided in this embodiment; the length of the original message can be less than or equal to the first specified length, that is, the original message can be understood as a fixed-length short message, and the first specified length can be configured based on an empirical value, such as 576 bits. The message to be processed is the message to be input to the SHA-3 algorithm for processing. The specific content of the original message and the message to be processed is not limited. For example, in this step, it is only necessary to perform message padding processing on the original message to obtain a message to be processed of a specified length. The specific padding processing rules can be configured according to different needs.
[0070] In some embodiments, performing message filling processing on the original message to obtain a message to be processed includes:
[0071] Add the specified characters to the end of the original message to obtain a preliminary processed message;
[0072] The message padding rule corresponding to the SHA-3 algorithm is used to perform message padding processing on the preliminary processed message to obtain data to be processed whose message length is the second specified length.
[0073] In a specific implementation manner, this embodiment can obtain a preliminary processing message by adding a specified character to the end of the original message, such as determining whether the specified character is 01 or 1111 based on the selected SHA-3 algorithm instance (i.e., selecting a hash function in SHA3-224 / 256 / 384 / 512 or SHAKE-128 / 256). After adding the specified character to the end of the original message, the preliminary processing message can be filled in according to the message filling rule to obtain the data to be processed with a message length of the second specified length. The message filling rule is a message filling method for the SHA-3 algorithm, such as a filling rule that can include pad10*1. The second specified length can be 1600 bits.
[0074] S102. Detect whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of the iterative loop, and the multiple round functions are used to simultaneously and cyclically process a first predetermined number of messages to be processed within the same clock cycle.
[0075] Among them, the pipeline structure can be constructed according to the SHA-3 algorithm by inserting registers between multiple round functions of the SHA-3 algorithm. The number of specific round functions in the pipeline structure can be a first predetermined number, and the specific content of the first predetermined number can be configured in advance by relevant personnel. Furthermore, multiple round functions in the pipeline structure can be used to simultaneously and cyclically process a first predetermined number of messages to be processed within the same clock cycle. For example, the pipeline structure can simultaneously batch load multiple messages to be processed for round function cyclic processing, and the maximum number of loaded messages to be processed is the first predetermined number.
[0076] The current working state may be the working state of the current pipeline structure, such as the working state of the round function in the pipeline structure, or the loop state of the pending message currently processed by the round function. For example, the SHA-3 algorithm is composed of 24 rounds of Keccak-f functions, and each Keccak-f function can be regarded as a round function. Then, a pending message needs to be processed by 24 rounds of round function loop processing to output the target message. Then, the current working state may include the round of round function loop processing that a pending message is undergoing. The preset working state can be used to measure whether a new pending message can be loaded at present, and the specific content can be configured according to actual needs.
[0077] In this step, the current working state of the pipeline structure can be detected, such as detecting whether the current working state meets the preset working state to measure whether the pending message of the previous step is loaded into the pipeline structure for processing. The detection method can be determined according to the actual situation. For example, it can be determined based on the relevant information about the pipeline structure stored in the control unit to determine whether the current working state of the pipeline structure meets the preset working state. It can also be directly detected by the detection unit to determine whether the current working state of the pipeline structure meets the preset working state. Alternatively, different detection methods can be used based on different preset working states. This embodiment does not limit this.
[0078] In some embodiments, the preset working state is used to indicate that there is a round function in the pipeline structure that is in an idle state, and detecting whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm satisfies the preset working state includes:
[0079] Detecting whether a sequence value in a current state sequence corresponding to the pipeline structure is a preset value, and obtaining a first detection result, wherein the sequence value of the current state sequence is used to indicate the working state of all current round functions in the pipeline structure;
[0080] Based on the first detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
[0081] In this embodiment, the preset working state can be used to indicate that there is a round function in the pipeline structure that is in an idle state; the current state sequence can be a sequence generated by the control unit, and the sequence value of the current state sequence can be used to indicate the working state of all current round functions in the pipeline structure, such as the sequence value can be represented by 0 or 1, 0 represents that the current round function is in an idle state, and 1 represents that the current round function is in a working state; the sequence length of the current state sequence can be a numerical value corresponding to the first predetermined number, and the sequence value of the current state sequence can correspond to the round function in the pipeline structure. For example, when the first predetermined number is 3, the current state sequence can be 000 in the initial state, and when there is a message to be processed input into the pipeline structure for round function loop processing, the current state sequence can be synchronously updated to 001; when there is a second message to be processed input into the pipeline structure for round function loop processing, the current state sequence can be synchronously updated to 011.
[0082] In a specific implementation, it is possible to detect whether the sequence value in the current state sequence corresponding to the pipeline structure is a preset value, such as detecting whether each sequence value in the current state sequence is a preset value, or only detecting whether the highest bit sequence value in the current state sequence is a preset value, and determining whether the current working state of the pipeline structure meets the preset working state based on the first detection result obtained. Exemplarily, when the preset value is 1, if it is detected that the highest bit sequence value in the current state sequence is not 1, it means that there is a round function in the pipeline structure in an idle state, then it can be determined that the current working state of the pipeline structure meets the preset working state; if it is detected that the highest bit sequence value in the current state sequence is 1, it means that there is no round function in the pipeline structure in an idle state, that is, all round functions in the pipeline structure are in a working state, then it can be determined that the current working state of the pipeline structure does not meet the preset working state.
[0083] In some embodiments, the preset working state is used to indicate that there is a pending message in the pipeline structure that is being processed by the round function cycle of the last clock cycle, and detecting whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state includes:
[0084] Detect whether the control signal corresponding to the pipeline structure is a preset value to obtain a second detection result, where the control signal is used to indicate whether there is a message to be processed in the pipeline structure that is being processed by the round function loop of the last clock cycle;
[0085] Based on the second detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
[0086] In this embodiment, the preset working status can be used to indicate that there is a pending message in the pipeline structure that is undergoing round function cycle processing in the last clock cycle, that is, the pending message will complete the round function cycle processing in the next clock cycle, and the pipeline structure will have an idle round function in the next clock cycle.
[0087] It should be noted that the control unit of the present embodiment can monitor the loop status of the pending messages in the pipeline structure in real time, and generate corresponding control signals according to the loop status of the pending messages. For example, when there are pending messages in the pipeline structure that are undergoing round function loop processing in the last clock cycle, the control signal can be configured to be 1, and when all pending messages in the pipeline structure have not undergone round function loop processing in the last clock cycle, the control signal can be configured to be 0. Subsequently, the present embodiment can measure whether the current working state of the pipeline structure meets the preset working state based on the control signal, that is, it can determine whether the control signal corresponding to the pipeline structure is a preset value, and determine whether the current working state of the pipeline structure meets the preset working state based on the second detection result. More specifically, if the control signal corresponding to the pipeline structure is detected to be a preset value (such as 1), it means that there is a message to be processed in the pipeline structure and is undergoing the round function cycle processing of the last clock cycle, then it can be determined that the current working state of the pipeline structure meets the preset working state; if the control signal corresponding to the pipeline structure is not a preset value, that is, the control signal is 0, it means that there is no message to be processed in the pipeline structure and is undergoing the round function cycle processing of the last clock cycle, then it can be determined that the current working state of the pipeline structure does not meet the preset working state.
[0088] S103: If it is detected that the current working state of the pipeline structure meets the preset working state, a round function loop is performed on the message to be processed based on the pipeline structure to obtain a target message.
[0089] Through the above steps, when it is determined that the current working state of the pipeline structure meets the preset working state, the round function loop processing can be performed on the message to be processed based on the pipeline structure. For example, the round function loop processing can be directly performed according to the configuration of the registers in the pipeline structure, or other signals can be used to continue to determine whether the round function loop processing can be performed on the message to be processed, so as to achieve accurate processing of the message to be processed. The specific processing process of the round function loop processing will not be further expanded here, as long as the target message of the message to be processed can be obtained.
[0090] The present embodiment provides a fixed-length short message processing method based on the SHA-3 algorithm, which performs message padding processing on the original message to obtain a message to be processed, wherein the length of the original message is less than or equal to the first specified length; detects whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of the iterative loop, and the multiple round functions are used to simultaneously process a first predetermined number of messages to be processed in a loop in the same clock cycle; if it is detected that the current working state of the pipeline structure meets the preset working state, the message to be processed is processed based on the pipeline structure. The round function loop processing is performed to obtain the target message. By using this method, by detecting whether the current working state of the pipeline structure established based on the SHA-3 algorithm meets the preset working state, the pipeline structure can effectively control the loop processing of the message to be processed by the pipeline structure. At the same time, the pipeline structure allows the first predetermined number of messages to be processed to be processed simultaneously in the same clock cycle, thereby improving the clock frequency and hash calculation efficiency of the hardware design.
[0091] Figure 4 This is a flowchart of a method for processing fixed-length short messages based on the SHA-3 algorithm provided by another embodiment of the present application. This embodiment further optimizes the target message by performing round function loop processing on the message to be processed based on the pipeline structure: when the original message is detected to be a valid message, the message to be processed is processed based on the pipeline structure to obtain the algorithm processing result and update the current working state of the pipeline structure; intercept the message of the specified number of bits from the algorithm processing result as the target message, and output the target message. Figure 4 As shown, the method includes:
[0092] S201. Perform message padding processing on an original message to obtain a message to be processed, wherein the length of the original message is less than or equal to a first specified length.
[0093] S202. Detect whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of the iterative loop, and the multiple round functions are used to simultaneously and cyclically process a first predetermined number of messages to be processed within the same clock cycle.
[0094] S203. If it is detected that the current working state of the pipeline structure meets the preset working state, then when it is detected that the original message is a valid message, the message to be processed is processed in a round function loop based on the pipeline structure to obtain the algorithm processing result, and the current working state of the pipeline structure is updated.
[0095] Among them, the SHA-3 algorithm can adopt a sponge structure, and the specific calculation process can be divided into two stages: absorption and extrusion. The algorithm processing result can be understood as the processing result output by the SHA-3 algorithm in the absorption stage, and the target data can be the final data output after further processing the algorithm processing result in the extrusion stage.
[0096] In a specific implementation, the loading of the original message can be controlled by a handshake mechanism. For example, on the one hand, the upstream module can provide a valid signal while sending the original message to indicate whether the original message is valid. On the other hand, the control unit can determine the ready signal indicating whether the hardware module is ready to receive the message through detection logic, and feed the ready signal back to the upstream module.
[0097] Correspondingly, if the control unit determines through the detection logic that the hardware module is ready to receive the message, that is, it detects that the current working state of the pipeline structure meets the preset working state, then it can further combine the valid signal provided by the upstream module to comprehensively judge whether the message to be processed can be processed based on the pipeline structure. For example, under the premise that the current working state of the pipeline structure meets the preset working state, it can be determined that the message to be processed can be processed based on the pipeline structure. The round function cycle is processed, so as to obtain the algorithm processing result. At the same time, the current working state of the pipeline structure can be synchronously updated; if the original message is detected as not a valid message under the premise that the current working state of the pipeline structure meets the preset working state, there is no need to process the message to be processed by the round function cycle, and the operation is terminated.
[0098] In some embodiments, a first register is provided between each round function, and a round function loop is performed on the message to be processed based on the pipeline structure to obtain an algorithm processing result, including:
[0099] Inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain an intermediate processing result, wherein the result calculated by the current round function in each clock cycle is stored in a first register after the current round function, so that the next function in the next clock cycle is calculated by reading data from the first register;
[0100] The intermediate processing result is used as the message to be processed, and the step of inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain the intermediate processing result is returned to the step of obtaining the intermediate processing result until the round function cycle processing of the second predetermined number of time cycles is completed;
[0101] The intermediate processing result corresponding to the second predetermined number of time periods is used as the algorithm processing result.
[0102] In a specific implementation, a first register may be provided between each round function, and each message to be processed needs to undergo 24 rounds of round function cycle processing. Then, the entire round function cycle processing process may be divided into a plurality of first predetermined number of clock cycles of round function cycle processing, and the round function cycle processing within each clock cycle may be completed by a round function. For example, when the first predetermined number is 3, the entire round function cycle processing process may be divided into 8 (i.e., the second predetermined number) of first predetermined number of clock cycles of cycle processing, wherein within the first predetermined number of clock cycles (e.g., within 3 clock cycles), the message to be processed may be input into the round function in the pipeline structure, and each clock cycle may be completed by The current round function is calculated, and the result of the current round function calculation is stored in the first register after the current round function, so that the next function in the next clock cycle can be calculated by reading data from the first register. After completing the round function processing of 3 clock cycles, the intermediate processing result can be obtained. Next, the round function processing operation of the above 3 clock cycles can be repeated until it is repeated 8 times to obtain the algorithm processing result, that is, the intermediate processing result can be used as the message to be processed, and return to the step of inputting the message to be processed into the round function in the pipeline structure within the first predetermined number of clock cycles to obtain the intermediate processing result, until the round function cycle processing of the second predetermined number of time cycles is completed.
[0103] In some embodiments, each round function is composed of a plurality of permutation functions, a second register is provided between at least two permutation functions, and the second register is used to store a result calculated by the permutation function before the second register.
[0104] In a specific implementation, in order to obtain a higher clock frequency, on the basis of setting the first register between round functions, a register can be further inserted into the round function, so that more messages to be processed can be processed simultaneously in the same clock cycle.
[0105] Specifically, in this embodiment, each round function can be composed of five permutation functions, namely θ, ρ, π, X and l. A second register can be set between at least two permutation functions. The second register can be used to store the result calculated by the permutation function before the second register. The specific configuration position and number of the second register are not limited and can be configured according to actual needs.
[0106] S204, intercepting a message of a specified number of digits from the algorithm processing result as a target message, and outputting the target message.
[0107] In a specific implementation, a message of a specified number of bits can be intercepted from the algorithm processing result as the target message during the squeezing stage. Exemplarily, the low-order bits in the algorithm processing result can be intercepted according to the selected SHA-3 algorithm instance, and the selected target message can be output. For example, when the SHA3-512 hash function is selected for message processing, only the first 512 low-order bits of the 1600-bit result obtained by the SHA3-512 algorithm processing can be intercepted as the target message.
[0108] The present embodiment provides a fixed-length short message processing method based on the SHA-3 algorithm. When it is detected that the current working state of the pipeline structure meets the preset working state and the original message is a valid message, the message to be processed is processed in a round function loop based on the pipeline structure, and the current working state of the pipeline structure is updated. This further ensures the effective processing of the message to be processed and provides an information basis for the subsequent accurate loading of new messages to be processed.
[0109] In some embodiments, updating the current working state of the pipeline structure includes:
[0110] Update the sequence value of the current state sequence corresponding to the pipeline structure, and / or
[0111] When the message to be processed is processed in the round function loop of the last clock cycle, the control signal corresponding to the pipeline structure is set to a preset value.
[0112] In a specific implementation, updating the current working state of the pipeline structure may include: updating the sequence value of the current state sequence in real time according to the situation of loading the pending message into the pipeline structure or outputting the pipeline structure, so as to more accurately control the loading of new messages. The sequence value of the current state sequence may be updated in a manner such as adjusting the bits one by one, such as updating the sequence value of the current state sequence from 011 to 111 when loading a new pending message into the pipeline structure; or updating the sequence value of the current state sequence from 111 to 110 when a pending message completes 24 rounds of round function cycle processing.
[0113] Alternatively, updating the current working state of the pipeline structure may also include: updating the sequence value of the current state sequence in real time according to the loop state of the currently processed pending message, so as to more accurately control the loading of new messages. For example, when a pending message in the pipeline structure undergoes round function loop processing in the last clock cycle, the control signal may be set to a preset value. Furthermore, in the next clock cycle, if another pending message in the pipeline structure also undergoes round function loop processing in the last clock cycle, the control signal may be kept unchanged at the preset value. Alternatively, in the next clock cycle, if all pending messages in the pipeline structure do not undergo round function loop processing in the last clock cycle, the control signal may be updated from the preset value to another value.
[0114] The following is an exemplary description of a fixed-length short message processing method based on the SHA-3 algorithm provided in an embodiment of the present application:
[0115] Figure 5 FIG. 1 is a flow chart of another method for processing a fixed-length short message based on the SHA-3 algorithm provided in an embodiment of the present application. Figure 5 As shown, the round functions Keccak-f can be separated by registers, and the number of pipeline stages (denoted as Pipeline Stages, PS) represents the maximum number of short messages of fixed length that can be processed simultaneously. Take the short message msg as 64 bits in length and the selected SHA-3 algorithm instance as SHA3-512 as an example to illustrate. First, the message filling module can fill the short message msg according to the filling rules according to the length of the short message and the selected SHA-3 algorithm instance. The 1600-bit message obtained after filling can be {1024′b0, 8′h80, 496′b0, 8′h06, msg}, from left to right, from high to low bits of data.
[0116] The control unit can be responsible for the iterative loop control of 24 rounds of Keccak-f functions and the control of loading new messages through the handshake mechanism. For example, this embodiment introduces a busy sequence to monitor the working status in the pipeline. The length of the busy sequence can be defined as PS bits, recorded as bit[PS-1:0]busy, and the busy sequence can be initialized to 0 before message processing.
[0117] The loading of messages can be controlled by the handshake mechanism. On the one hand, the upstream module can provide a valid signal to indicate whether the current message is valid. On the other hand, the control unit can provide a ready signal to indicate whether the hardware module is ready to receive the message. The ready signal generated by the control unit can be determined by the busy sequence and the done signal. For example, when Stage (PS-1) in the pipeline structure is idle, that is, the high bit busy[PS-1] of the busy sequence is 0, or when the message in Stage (PS-1) is in the last round of Keccak-f function calculation and the done signal is set to 1, the control unit can set the ready signal to 1 to indicate that the upstream module can receive new messages. Through the handshake mechanism, whether the short message is transmitted continuously or intermittently, the designed hardware module can receive new messages without affecting the calculation process of other messages in the pipeline structure.
[0118] Figure 6 Schematic diagram of the main signal assignment dependency in a control unit provided in an embodiment of the present application. Figure 6 As shown, when there is a message in the pipeline structure that is about to complete the iterative operation or the round function Stage (PS-1) in the pipeline structure is in an idle state, the upstream module is informed that it can receive new messages. The assignment formula of the control signal done is: And satisfy ready=~busy[PS-1]||done, and then determine the load signal according to the ready signal and the valid signal provided by the upstream module. If the upstream module indicates that the short message is valid and the hardware module allows the reception of the message to be processed, that is, the handshake is successful, then the load signal load can be set to 1, and the new short message is loaded in the next clock cycle, and the busy sequence is updated to {busy[PS-2:0], 1′b1}, indicating that the new message will enter Stage 0 in the pipeline in the next clock cycle; before the 24 rounds of iterative operations of the message to be processed are completed, the busy sequence can be cyclically updated to {busy[PS-2:0], busy[PS-1]} in each clock cycle to track the direction of the message to be processed in the pipeline structure; when the message to be processed reaches the last round of Keccak-f function operation, the done signal can be set to 1. If the upstream module does not provide a valid new message at this time, the busy sequence will be updated to {busy[PS-2:0], 1′b0} in the next clock cycle, indicating that Stage0 is out of working state. If the upstream module provides a valid new message at this time, the busy sequence will be updated to {busy[PS-2:0], 1′b1} in the next clock cycle, indicating that Stage0 is still in working state in the next clock cycle and is processing the new input message.
[0119] After the pending message has been processed through one round of pipeline structure calculation, it can be considered that a total of PS round function calculations have been completed. If the calculation of the pipeline is completed, the done signal can be set to 1 and the hash result of the short message can be output. Taking SHA3-512 as an example, the lower 512 bits of the 1600 bits output by the iterative function f can be selected as the final hash result, where the round signal indicates how many times the message to be processed has passed through the pipeline and is used as the index of the round constant storage table of the l function in the Keccak-f function.
[0120] Furthermore, this embodiment can dynamically adjust PS to a suitable value according to the hashing requirements of the actual scenario and the area of the hardware design.
[0121] Figure 7 is a message timing diagram of continuous message input provided by an embodiment of the present application, such as Figure 7 As shown in FIG. 1 , a timing diagram of the continuous input of fixed-length short messages when PS=3 is shown, wherein the pipeline structure includes three pipeline stages Stage0, Stage1, and Stage2. In the 0th clock cycle, message M0 can be input to pipeline stage 0. One Keccak-f function calculation requires one clock cycle. In the first clock cycle, message M1 can be input to pipeline stage 0, and message M0 can be input to pipeline stage 1. In the second clock cycle, message M2 can be input to pipeline stage 0, message M1 can be input to pipeline stage 1, and message M0 can be input to pipeline stage 2. By analogy, after 24 clock cycles, the hash results of three groups of fixed-length short messages can be output in three consecutive clock cycles. At the same time, when the short message is hashed, a new short message will be loaded into the pipeline, and the cycle will repeat.
[0122] Furthermore, in order to obtain a higher clock frequency, registers (such as Figure 5 The optional register between the θ function and the ρ function in the θ function enables more short messages to be processed in the same clock cycle.
[0123] Figure 8 is another message sequence diagram of continuous message input provided by an embodiment of the present application, such as Figure 8As shown in the figure, the timing diagram of the optional registers of the Keccak-f function is enabled on the basis of PS=3, so that one group of short messages is completed in 48 clock cycles, and the pipeline structure can process up to 6 groups of short messages in the same clock cycle, where Stage0 and Stage1 correspond to the first Keccak-f, Stage2 and Stage3 correspond to the second Keccak-f, and Stage4 and Stage5 correspond to the third Keccak-f. After 48 clock cycles, the hash results of 6 groups of fixed-length short messages can be output in 6 consecutive clock cycles. At the same time, when the short message is hashed, a new short message will be loaded into the pipeline, and the cycle will repeat.
[0124] Furthermore, according to the SHA-3 algorithm standard, the length of the bit string processed by the Keccak-f function (i.e., the message to be processed) is always 1600 bits. At the same time, in order to facilitate the definition of the specific operation of the permutation function, Fig. 9 is a schematic diagram of a structure of a message to be processed provided by an embodiment of the present application, such as Fig. 9 As shown, the message to be processed can be defined as a three-dimensional matrix of 5×5×64, and organized according to the arrangement shown in the figure. Let the input 1600-bit string (i.e., the message to be processed) be S, and the mapping relationship between the three-dimensional matrix A and S can be A[x][y][z]=x[64(x+5y)+z]. Among them, A[x][y][z] represents the value to be filled in the corresponding coordinates in the three-dimensional matrix, and S[n] represents the nth bit in the 1600-bit string, and satisfies 0≤x≤4, 0≤y≤4 and 0≤z≤63.
[0125] The specific implementation process of the five-round permutation function in the Keccak-f function of this embodiment is described below as an example:
[0126] (i) The θ function consists of XOR and circular shift operations.
[0127] First, the temporary variable B can be calculated based on the three-dimensional matrix A according to the following expression (1), where “*” represents all 64 bits on the z-axis. Represents the exclusive-or operation.
[0128] Next, the calculated temporary variable B can be used to calculate the temporary variable C according to the following expression (2), where ROT(data, num) represents the left circular shift function, data represents the 64-bit data to be shifted, num represents the shift length, and data' is denoted as the result of ROT(data, num). Then data' can be expressed as data'=(data<<num)|(data>>(64-num)).
[0129] Finally, the calculated C can be used to complete the permutation of the three-dimensional matrix A, thereby obtaining the result of the θ function, as shown in the following expression (3). The sizes of the temporary variables B and C obtained above are both 5×64 bits.
[0130]
[0131] (ii) The ρ function can be a left circular shift operation on the bits of the z-axis in the three-dimensional matrix D, as shown in the following expression (4), wherein the circular shift constant r(x, y) represents the shift length corresponding to the coordinate (x, y), and the corresponding value can be calculated in advance and stored as a constant during hardware implementation, as shown in the following Table 1. After the ρ function, the three-dimensional matrix D can be replaced by the three-dimensional matrix E.
[0132] E[x][y][z]=D[x][y][(zr(x,y)+64)mod 64]=ROT(D[x][y],r(x,y)) (4)
[0133] Table 1 Cyclic shift constant r(x, y)
[0134]
[0135]
[0136] (iii) The π function can be to spatially translate the 64 bits of the z-axis in the three-dimensional matrix E, that is, to change the original x-coordinate and y-coordinate. This process is shown in the following expression (5), which replaces the three-dimensional matrix E with the three-dimensional matrix F.
[0137] F[y][2x+3y][z]=E[x][y][z] (5)
[0138] (iv) The χ function consists of some simple Boolean operations. The three-dimensional matrix F can be replaced by the three-dimensional matrix G according to the following expression (6), where “^” represents the logical AND operation and “~” represents the logical NOT operation.
[0139]
[0140] (v) The l function can add a round constant RC to each round of iteration according to different iteration rounds to destroy the original symmetry of the three-dimensional array.
[0141] Normally, the round constant RC is 64 bits, but in actual use, only 0, 1, 3, 7, 15, 31, and 63 bits in RC will change between 0 and 1, and the remaining bits are all 0 and remain unchanged. When , only the 0, 1, 3, 7, 15, 31, and 63 bits of the original RC need to be stored, and the stored round constant RC is XORed with the bits corresponding to G[0][0] to obtain the result of the function. Table 2 below shows the 7-bit round constant RC that is actually stored, a total of 24 groups.
[0142] Table 2 The actual stored 7-bit wheel constant RC
[0143] RC[0] = 7'b000_0001 RC[1]=7'b001_1010 RC[2]=7'b101_1110 RC[3] = 7'b111_0000 RC[4]=7'b001_1111 RC[5] = 7b010_0001 RC[6]=7'b111_1001 RC[7]=7'b101_0101 RC[8]=7'b000_1110 RC[9]=7'b000_1100 RC
[10] = 7'b011_0101 RC
[11] =7'b010_0110 RC
[12] = 7'b011_1111 RC
[13] =7'b100_1111 RC
[14] =7'b101_1101 RC
[15] =7'b101_0011 RC
[16] =7'b101_0010 RC
[17] =7'b100_1000 RC
[18] =7'b001_0110 RC
[19] =7'b110_0110 RC
[20] =7'b111_1001 RC
[21] =7'b101_1000 RC
[22] =7'b010_0001 RC
[23] =7'b111_0100
[0144] From the above description, it can be found that the fixed-length short message processing method based on the SHA-3 algorithm provided in this embodiment removes unnecessary message filling modules for fixed-length short messages, and directly uses the pre-calculated filling fixed value to splice to the end of the short message to realize message filling processing. At the same time, a control mechanism is established to decide whether to load new messages for processing, and the transmission of messages between upstream and downstream modules is controlled by a handshake mechanism. In addition, by expanding the round function and inserting registers between and within the round function to build a pipeline, the core hardware module of the SHA-3 algorithm can process multiple groups of fixed-length short messages in the same clock cycle, thereby improving the throughput and efficiency of hash calculations.
[0145] Corresponding to the fixed-length short message processing method based on the SHA-3 algorithm in the above embodiment, Fig.10 This is a structural block diagram of a fixed-length short message processing device based on the SHA-3 algorithm provided in one embodiment of the present application. For the sake of convenience of explanation, only the parts related to the embodiment of the present application are shown.
[0146] Reference Fig.10 , the device comprises:
[0147] The message filling module 301 is used to perform message filling processing on the original message to obtain a message to be processed, wherein the length of the original message is less than or equal to the first specified length;
[0148] A detection module 302 is used to detect whether a current working state of a pipeline structure established based on a third-generation secure hash SHA-3 algorithm satisfies a preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of an iterative loop, and the multiple round functions are used to simultaneously cyclically process a first predetermined number of messages to be processed within the same clock cycle;
[0149] The loop processing module 303 is used to perform round function loop processing on the message to be processed based on the pipeline structure to obtain the target message if it is detected that the current working state of the pipeline structure meets the preset working state.
[0150] The present embodiment provides a fixed-length short message processing device based on the SHA-3 algorithm, which performs message filling processing on the original message through a message filling module to obtain a message to be processed, and the length of the original message is less than or equal to the first specified length; the detection module detects whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state, wherein the pipeline structure is constructed by inserting registers between multiple round functions of the iterative loop, and the multiple round functions are used to simultaneously process a first predetermined number of messages to be processed in the same clock cycle; if the loop processing module detects that the current working state of the pipeline structure meets the preset working state, the pipeline structure performs round function loop processing on the message to be processed to obtain the target message. By using the device, by detecting whether the current working state of the pipeline structure established based on the SHA-3 algorithm meets the preset working state, the pipeline structure can effectively control the loop processing of the message to be processed by the pipeline structure. At the same time, the pipeline structure allows the first predetermined number of messages to be processed to be processed simultaneously in the same clock cycle, thereby improving the clock frequency and hash calculation efficiency of the hardware design.
[0151] Optionally, the preset working state is used to indicate that there is a round function in the pipeline structure that is in an idle state, and the detection module is specifically used to:
[0152] Detecting whether a sequence value in a current state sequence corresponding to the pipeline structure is a preset value, and obtaining a first detection result, wherein the sequence value of the current state sequence is used to indicate the working state of all current round functions in the pipeline structure;
[0153] Based on the first detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
[0154] Optionally, the preset working state is used to indicate that there is a message to be processed in the pipeline structure and is being processed by the round function cycle of the last clock cycle. The detection module is specifically used to:
[0155] Detect whether the control signal corresponding to the pipeline structure is a preset value to obtain a second detection result, where the control signal is used to indicate whether there is a message to be processed in the pipeline structure that is being processed by the round function loop of the last clock cycle;
[0156] Based on the second detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
[0157] Optionally, the loop processing module includes:
[0158] A loop processing unit, for performing round function loop processing on the message to be processed based on the pipeline structure when the original message is detected to be a valid message, obtaining an algorithm processing result, and updating the current working state of the pipeline structure;
[0159] The interception unit is used to intercept a message of a specified number of digits from the algorithm processing result as a target message and output the target message.
[0160] Optionally, a first register is provided between each round function, and the loop processing unit is specifically used for:
[0161] Inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain an intermediate processing result, wherein the result calculated by the current round function in each clock cycle is stored in a first register after the current round function, so that the next function in the next clock cycle is calculated by reading data from the first register;
[0162] The intermediate processing result is used as the message to be processed, and the step of inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain the intermediate processing result is returned to the step of obtaining the intermediate processing result until the round function cycle processing of the second predetermined number of time cycles is completed;
[0163] The intermediate processing result corresponding to the second predetermined number of time periods is used as the algorithm processing result.
[0164] Optionally, the loop processing unit is specifically used for:
[0165] Update the sequence value of the current state sequence corresponding to the pipeline structure, and / or
[0166] When the message to be processed is processed in the round function loop of the last clock cycle, the control signal corresponding to the pipeline structure is set to a preset value.
[0167] Optionally, each round function is composed of multiple permutation functions, and a second register is provided between at least two permutation functions, and the second register is used to store a result calculated by the permutation function before the second register.
[0168] Optionally, the message filling module is specifically used for:
[0169] Add the specified characters to the end of the original message to obtain a preliminary processed message;
[0170] The message padding rule corresponding to the SHA-3 algorithm is used to perform message padding processing on the preliminary processed message to obtain data to be processed whose message length is the second specified length.
[0171] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0172] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0173] The present application also provides a terminal device, Fig.11 is a schematic diagram of the structure of a terminal device provided by an embodiment of the present application, such as Fig.11 As shown, the terminal device includes: at least one processor 401, a memory 402, an input device 403, an output device 404, and a computer program stored in the memory 402 and executable on at least one processor 401. When the processor 401 executes the computer program, the steps in any of the above-mentioned method embodiments are implemented.
[0174] The input device 403 may be used to receive input digital or character information and generate key signal input related to user settings and function control of the terminal device. The output device 404 includes display devices such as a display screen.
[0175] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by the processor 401, the steps in the above-mentioned method embodiments can be implemented.
[0176] An embodiment of the present application provides a computer program product. When the computer program product runs on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned method embodiments when executing the computer program product.
[0177] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor 401, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electric carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.
[0178] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0179] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0180] In the embodiments provided in the present application, it should be understood that the disclosed devices / terminal equipment and methods can be implemented in other ways. For example, the device / terminal equipment embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0181] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0182] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.
Claims
1. A method for processing fixed-length short messages based on the SHA-3 algorithm, characterized in that: include: Performing message padding processing on the original message to obtain a message to be processed, wherein the length of the original message is less than or equal to the first specified length; Detecting whether a current working state of a pipeline structure established based on a third-generation secure hash SHA-3 algorithm satisfies a preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of an iterative loop, and the multiple round functions are used to simultaneously and cyclically process a first predetermined number of messages to be processed within the same clock cycle; If it is detected that the current working state of the pipeline structure meets the preset working state, the message to be processed is processed in a round function cycle based on the pipeline structure to obtain a target message.
2. The fixed-length short message processing method based on the SHA-3 algorithm as claimed in claim 1, characterized in that: The preset working state is used to indicate that there is a round function in the pipeline structure that is in an idle state, and the detection of whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm satisfies the preset working state includes: Detecting whether a sequence value in a current state sequence corresponding to the pipeline structure is a preset value, and obtaining a first detection result, wherein the sequence value of the current state sequence is used to represent the working state of all current round functions in the pipeline structure; Based on the first detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
3. The fixed-length short message processing method based on the SHA-3 algorithm as claimed in claim 1, characterized in that: The preset working state is used to indicate that there is a message to be processed in the pipeline structure and is being processed by the round function cycle of the last clock cycle. The detection of whether the current working state of the pipeline structure established based on the third-generation secure hash SHA-3 algorithm meets the preset working state includes: Detecting whether a control signal corresponding to the pipeline structure is a preset value to obtain a second detection result, wherein the control signal is used to indicate whether there is a message to be processed in the pipeline structure and is being processed by a round function cycle in the last clock cycle; Based on the second detection result, it is determined whether the current working state of the pipeline structure meets the preset working state.
4. The fixed-length short message processing method based on the SHA-3 algorithm as claimed in claim 1, characterized in that: The performing round function loop processing on the message to be processed based on the pipeline structure to obtain the target message includes: In the case where it is detected that the original message is a valid message, the message to be processed is processed by round function loop based on the pipeline structure to obtain an algorithm processing result, and the current working state of the pipeline structure is updated; A message of a specified number of bits is intercepted from the algorithm processing result as a target message, and the target message is output.
5. The fixed-length short message processing method based on the SHA-3 algorithm as claimed in claim 4, characterized in that: A first register is provided between each of the round functions, and the round function loop processing is performed on the message to be processed based on the pipeline structure to obtain an algorithm processing result, including: Inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain an intermediate processing result, wherein the result calculated by the current round function in each clock cycle is stored in a first register after the current round function, so that the next function in the next clock cycle is calculated by reading data from the first register; The intermediate processing result is used as a message to be processed, and the step of inputting the message to be processed into the round function in the pipeline structure within a first predetermined number of clock cycles to obtain the intermediate processing result is returned to execute, until the round function cycle processing of a second predetermined number of time cycles is completed; The intermediate processing result corresponding to the second predetermined number of time periods is used as the algorithm processing result.
6. The method for processing fixed-length short messages based on the SHA-3 algorithm as claimed in claim 4, characterized in that: The updating of the current working state of the pipeline structure includes: Update the sequence value of the current state sequence corresponding to the pipeline structure, and / or When the message to be processed is processed by the round function loop in the last clock cycle, the control signal corresponding to the pipeline structure is set to a preset value.
7. The method for processing fixed-length short messages based on the SHA-3 algorithm according to any one of claims 1 to 6, characterized in that: Each of the round functions is composed of a plurality of permutation functions, and a second register is arranged between at least two of the permutation functions, and the second register is used to store a result calculated by the permutation function before the second register.
8. The method for processing fixed-length short messages based on the SHA-3 algorithm according to any one of claims 1 to 6, characterized in that: The process of performing message filling processing on the original message to obtain the message to be processed includes: Adding a specified character to the end of the original message to obtain a preliminary processed message; The message padding rule corresponding to the SHA-3 algorithm is used to perform message padding processing on the preliminary processed message to obtain data to be processed whose message length is the second specified length.
9. A fixed-length short message processing device based on SHA-3 algorithm, characterized in that: include: A message filling module, used to perform message filling processing on an original message to obtain a message to be processed, wherein the length of the original message is less than or equal to a first specified length; A detection module, used to detect whether a current working state of a pipeline structure established based on a third-generation secure hash SHA-3 algorithm satisfies a preset working state, wherein the pipeline structure is constructed based on inserting registers between multiple round functions of an iterative loop, and the multiple round functions are used to simultaneously cyclically process a first predetermined number of messages to be processed within the same clock cycle; The loop processing module is used to perform round function loop processing on the message to be processed based on the pipeline structure to obtain a target message if it is detected that the current working state of the pipeline structure meets the preset working state.
10. A terminal device comprising a processor, a memory, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the terminal device implements the method according to any one of claims 1 to 8.
11. A computer program product, characterized in that The invention comprises a computer program, which, when executed by a processor, enables the method according to any one of claims 1 to 8 to be performed.