Random number generator, random number generation method, medium and product
Patent Information
- Application Number
- CN202510120692.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-01-24
Smart Images

Figure CN119995856A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a random number generator, a random number generation method, a medium and a product. Background Art
[0002] The post-processing system in the existing random number generator usually first performs a health check on the generated random numbers. After passing the health check, the SHA256 algorithm is used to adjust the random numbers to generate fixed-length true random numbers with higher quality. The true random numbers can then be encrypted and processed by the AES algorithm to generate more secure pseudo-random numbers. Two algorithm cores are used in the existing random number post-processing process, which increases the area and power consumption of the entire system. At the same time, the health check of the random numbers output by the entropy source cannot guarantee that the true random numbers output by the SHA-256 algorithm core and the pseudo-random numbers output by the AES algorithm core still meet the standard requirements, and the security is insufficient.
[0003] It can be seen that how to reduce the hardware circuit area of the random number generator, reduce power consumption and improve security is a problem that technical personnel in this field need to solve. Summary of the invention
[0004] The purpose of the embodiments of the present invention is to provide a random number generator, a random number generation method, a medium and a product, which can reduce the hardware circuit area of the random number generator, reduce power consumption and improve security, thereby improving the output performance of the random number generator. The specific scheme is as follows:
[0005] In a first aspect, the present invention provides a random number generator, comprising:
[0006] Entropy source, used to generate random numbers;
[0007] an algorithm core connected to an entropy source, the algorithm core comprising a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register, the integrity operation module being used to perform an integrity hash operation on a random number generated by the entropy source based on the random key to obtain a true random number, and the encryption operation module being used to perform an encryption operation on the true random number based on the random key to obtain a pseudo-random number;
[0008] A health detection module is connected to the output of the integrity operation module and the encryption operation module, and is used to perform health detection on the true random number and the pseudo-random number.
[0009] Optionally, the health detection module includes:
[0010] A true random number health detection module connected to the output of the integrity operation module, used for performing health detection on the true random number;
[0011] The pseudo-random number health detection module connected to the output of the encryption operation module is used to perform health detection on the pseudo-random number.
[0012] Optionally, the method further includes a first path selector connected to the entropy source, configured to:
[0013] In response to a key write enable signal being pulled high, writing the random number generated by the entropy source as a random key into the key register;
[0014] In response to the key write enable signal being pulled low, the random number generated by the entropy source is transmitted to the integrity operation module, so that the integrity operation module performs an integrity hash operation on the transmitted random number based on the random key to obtain a true random number.
[0015] Optionally, also include:
[0016] A first cache having a first connection path with the integrity operation module, and used for storing the true random number;
[0017] The second cache connected to the encryption operation module is used to store the pseudo-random number.
[0018] Optionally, a second path selector connected to the integrity operation module is further included, configured to:
[0019] In response to the pseudo-random number mode enable signal being pulled high, the true random number output by the integrity operation module is input into the encryption operation module, so that the encryption operation module performs encryption operation on the true random number based on the random key to obtain a pseudo-random number.
[0020] Optionally, it further includes a first control switch for controlling the first connection path, and a second control switch for controlling a second connection path between the output of the integrity operation module and the encryption operation module;
[0021] When the first control switch is closed, the first connection path is connected, the integrity operation module stores the true random number output by the integrity operation module into the first cache through the first connection path, and the true random number health detection module connected to the output of the integrity operation module performs health detection on the true random number output by the integrity operation module;
[0022] When the second control switch is closed, the second connection path is connected, and the true random number output by the integrity operation module is transmitted to the encryption operation module through the second connection path, so that the encryption operation module performs encryption operation on the true random number based on the random key to obtain a pseudo-random number, and stores the pseudo-random number in the second cache, and inputs the pseudo-random number health detection module connected to the output of the encryption operation module to perform health detection on the pseudo-random number;
[0023] When the health detection result corresponding to any of the true random numbers does not meet the health standard, the true random numbers in the first cache and the pseudo-random numbers in the second cache are cleared;
[0024] When the health check result corresponding to any of the pseudo-random numbers does not meet the health standard, the pseudo-random numbers in the second cache are cleared.
[0025] In a second aspect, the present invention discloses a random number generation method, comprising:
[0026] Generate a random number using an entropy source, and input the random number output by the entropy source into an algorithm core, wherein the algorithm core includes a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register;
[0027] Using the integrity operation module, based on the random key, the random number generated by the entropy source is subjected to integrity hash operation to obtain a true random number, and the health detection module is used to perform health detection on the true random number.
[0028] The encryption operation module is used to perform encryption operation on the true random number based on the random key to obtain a pseudo-random number, and the health detection module is used to perform health detection on the pseudo-random number.
[0029] In a third aspect, the present invention discloses a computer-readable storage medium having a computer program stored thereon, and the computer program implements the steps of the aforementioned random number generation method when executed by a processor.
[0030] In a fourth aspect, the present invention provides a computer program product, comprising a computer program / instruction, which implements the steps of the aforementioned disclosed random number generation method when executed by a processor.
[0031] In a fifth aspect, the present invention discloses an electronic device, comprising:
[0032] Memory for storing computer programs;
[0033] A processor is used to execute the computer program to implement the steps of the aforementioned random number generation method.
[0034] It can be seen from the above scheme that the present invention provides a random number generator, including: an entropy source for generating random numbers; an algorithm core connected to the entropy source, the algorithm core including a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register, the integrity operation module is used to perform an integrity hash operation on the random number generated by the entropy source based on the random key to obtain a true random number, and the encryption operation module is used to perform an encryption operation on the true random number based on the random key to obtain a pseudo-random number; a health detection module, connected to the outputs of the integrity operation module and the encryption operation module, and used to perform health detection on the true random number and the pseudo-random number.
[0035] It can be seen that the beneficial effect of the present invention is that the algorithm core connected to the entropy source includes an integrity operation module for performing integrity hash operation on the random number generated by the entropy source to obtain a true random number and an encryption operation module for performing encryption operation on the true random number. The integrity operation module and the encryption operation module share the random key stored in the key register in the algorithm core. In this way, through one algorithm core, the output of true random numbers and pseudo-random numbers can be achieved, the hardware circuit area is reduced, and the power consumption is reduced. In addition, through the health detection module connected to the output of the integrity operation module and the encryption operation module, the output true random numbers and pseudo-random numbers are subjected to health detection, which can ensure that both the true random numbers and the pseudo-random numbers meet the standards, improve security, and thus improve the output performance of the random number generator.
[0036] Correspondingly, the random number generation method, medium and product provided by the present invention also have the above-mentioned technical effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0038] Figure 1 A schematic diagram of an existing random number generator implementation method;
[0039] Figure 2 A schematic diagram of a random number generator provided by an embodiment of the present invention;
[0040] Figure 3 A schematic diagram of the hardware structure of a random number generator provided by an embodiment of the present invention;
[0041] Figure 4 A schematic diagram of another random number generator hardware structure provided by an embodiment of the present invention;
[0042] Figure 5 A flow chart of a random number generation method provided by an embodiment of the present invention;
[0043] Figure 6 A flow chart of another random number generation method provided by an embodiment of the present invention;
[0044] Figure 7 A structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0045] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0046] In the field of information security, especially in the field of cryptography, the quality and generation efficiency of random numbers are crucial. Random numbers are widely used in various scenarios, such as key generation, initialization vectors, timestamps, authentication challenge codes, key negotiation, and large prime number generation. Random numbers are generally generated by random number generators. Existing random number generators generally support the generation of true random numbers and pseudo-random numbers. Among them, true random numbers are generated by unpredictable sources such as physical processes or quantum phenomena, and are highly unpredictable and unrepeatable. Pseudo-random numbers are generated by algorithms, so they have certain repeatability and predictability. However, due to the complexity of the physical process, the generated true random numbers may contain noise and deviations, which affect their randomness and quality. It is necessary to perform appropriate post-processing on the true random numbers, thereby greatly improving the randomness of the data and obtaining high-quality true random numbers and pseudo-random numbers. Therefore, the post-processing system of true random numbers is the core part of the entire random number generator.
[0047] See also Figure 1 As shown, Figure 1The figure is a schematic diagram of an existing random number generator implementation method, in which the random number generator uses physical processes such as electronic noise, thermal noise, etc. in the entropy source to generate true random numbers. After the true random numbers are generated, the true random numbers enter the post-processing system. First, a health check is performed on the generated true random numbers to ensure that the true random numbers generated by the entropy source meet the international and domestic standards for true random numbers. After passing the health check, the SHA256 algorithm is used to adjust the true random numbers to reduce the deviation and noise in the random numbers, so that it can generate a fixed-length higher-quality true random number. At this time, the true random number can be output for use; then the true random number can also be encrypted by the AES algorithm and processed to generate a more secure pseudo-random number.
[0048] Although the prior art can generate true random numbers and pseudo-random numbers and improve the quality of random numbers to a certain extent, there are still several problems: after the existing true random number generator generates true random numbers, two algorithm cores are used in the post-processing process of the random numbers, which increases the area and power consumption of the entire system. The SHA-256 algorithm and the AES algorithm have slow operation speeds. Therefore, the use of these two algorithms reduces the generation rate of random numbers and reduces the output performance of the entire system. The health check and the SHA-256 algorithm core are serially operated. The health check needs to be completed before subsequent operations can be performed, resulting in a decrease in the operating speed of the entire system. At the same time, the health check of the random numbers output by the entropy source cannot fully guarantee that the true random numbers output by the SHA-256 algorithm core and the pseudo-random numbers output by the AES algorithm core still meet the standard requirements. Therefore, security still needs to be strengthened. To this end, the present invention provides a random number generator with smaller area and power consumption, higher performance and greater security, which can use one algorithm core to realize the true random number and pseudo-random number generation functions, and reduce the area and power consumption of the entire system. Use algorithms with higher performance and faster operation speed to improve the output performance of the entire system. Make the health check run in parallel with other modules, and use the health check to detect the true random numbers and pseudo-random numbers output by the system in real time, to ensure the quality of the random numbers generated by the entire system and improve the security of the entire system.
[0049] The terms "including" and "having" in the specification of the present invention and the above-mentioned drawings, as well as any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but may include steps or units that are not listed.
[0050] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0051] See also Figure 2As shown, the present invention provides a random number generator, comprising:
[0052] An entropy source 11, used to generate random numbers;
[0053] An algorithm core 12 connected to an entropy source, the algorithm core comprising a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register, the integrity operation module being used to perform an integrity hash operation on a random number generated by an entropy source based on the random key to obtain a true random number, and the encryption operation module being used to perform an encryption operation on the true random number based on the random key to obtain a pseudo-random number.
[0054] The health detection module 13 is connected to the output of the integrity operation module and the encryption operation module, and is used to perform health detection on the true random number and the pseudo-random number.
[0055] The entropy source generates random numbers using physical processes such as electronic noise, thermal noise, etc., and the random number generator includes a post-processing system for post-processing the random numbers generated by the entropy source. The algorithm core is an algorithm core for calculating the random numbers generated by the entropy source to obtain true random numbers and pseudo-random numbers, and may include a key register, an integrity calculation module, and an encryption calculation module. The algorithm core may be a Zu Chongzhi algorithm core.
[0056] The health detection module 13 may include:
[0057] A true random number health detection module connected to the output of the integrity operation module, used for performing health detection on the true random number;
[0058] The pseudo-random number health detection module connected to the output of the encryption operation module is used to perform health detection on the pseudo-random number.
[0059] In an optional implementation, the random number generator further includes a first path selector connected to the entropy source, configured to:
[0060] In response to a key write enable signal being pulled high, writing the random number generated by the entropy source as a random key into the key register;
[0061] In response to the key write enable signal being pulled low, the random number generated by the entropy source is transmitted to the integrity operation module, so that the integrity operation module performs an integrity hash operation on the transmitted random number based on the random key to obtain a true random number.
[0062] Among them, the key write enable signal is pulled high after completing an integrity hash operation or an integrity hash operation and encryption operation to update the random key in the key register, thereby further improving the security of random numbers and pseudo-random numbers.
[0063] In an optional implementation, the random number generator further includes:
[0064] A first cache having a first connection path with the integrity operation module, and used for storing the true random number;
[0065] A second cache connected to the encryption operation module is used to store the pseudo-random number. The pseudo-random number output by the encryption operation module is simultaneously output to the pseudo-random number health detection module and the second cache. Both the first cache and the second cache can be FIFO (i.e., first-in-first-out memory).
[0066] In an optional implementation, the random number generator further includes a second path selector connected to the integrity operation module, configured to:
[0067] In response to the pseudo-random number mode enable signal being pulled high, the true random number output by the integrity operation module is input into the encryption operation module, so that the encryption operation module performs encryption operation on the true random number based on the random key to obtain a pseudo-random number. The true random number output by the integrity operation module is simultaneously output to the true random number health check module, and is output to the encryption operation module through the second path selector.
[0068] In response to the pseudo-random number mode enable signal being pulled low, the true random number output by the integrity operation module is simultaneously input to the true random number health check module and the first cache.
[0069] In the case where the health detection result corresponding to any of the true random numbers does not meet the health standards, the true random numbers in the first cache are cleared; in the case where the health detection result corresponding to any of the pseudo-random numbers does not meet the health standards, the pseudo-random numbers in the second cache are cleared. The true random number health detection module can trigger an interrupt when the health detection result corresponding to any of the true random numbers does not meet the health standards, and notify the CPU so that the CPU executes the clearing operation of the first cache. The pseudo-random number health detection module can notify the CPU when the health detection result corresponding to any of the pseudo-random numbers does not meet the health standards, so that the CPU executes the clearing operation of the second cache.
[0070] In an optional embodiment, the random number generator further includes a first control switch for controlling the first connection path, and a second control switch for controlling a second connection path between the output of the integrity operation module and the encryption operation module;
[0071] When the first control switch is closed, the first connection path is connected, the integrity operation module stores the true random number output by the integrity operation module into the first cache through the first connection path, and the true random number health detection module connected to the output of the integrity operation module performs health detection on the true random number output by the integrity operation module;
[0072] When the second control switch is closed, the second connection path is connected, and the true random number output by the integrity operation module is transmitted to the encryption operation module through the second connection path, so that the encryption operation module performs encryption operation on the true random number based on the random key to obtain a pseudo-random number, and stores the pseudo-random number in the second cache, and inputs the pseudo-random number health detection module connected to the output of the encryption operation module to perform health detection on the pseudo-random number;
[0073] When the health detection result corresponding to any of the true random numbers does not meet the health standard, the true random numbers in the first cache and the pseudo-random numbers in the second cache are cleared;
[0074] When the health check result corresponding to any of the pseudo-random numbers does not meet the health standard, the pseudo-random numbers in the second cache are cleared.
[0075] It can be seen that the algorithm core connected to the entropy source in the embodiment of the present invention includes an integrity operation module for performing integrity hash operation on the random number generated by the entropy source to obtain a true random number, and an encryption operation module for performing encryption operation on the true random number. The integrity operation module and the encryption operation module share the random key stored in the key register in the algorithm core. In this way, through one algorithm core, the output of true random numbers and pseudo-random numbers can be achieved, the system hardware circuit area can be reduced, and the power consumption can be reduced. In addition, by performing health detection on the output true random numbers and pseudo-random numbers through the health detection module connected to the output of the integrity operation module and the encryption operation module, it can be ensured that both the true random numbers and the pseudo-random numbers meet the standards, thereby improving security and thus improving the output performance of the random number generator.
[0076] For example, see Figure 3 As shown, Figure 3 The schematic diagram of the hardware structure of a random number generator disclosed in an embodiment of the present invention includes an entropy source, a first path selector, a second path selector, a Zu Chongzhi algorithm core, a true random number health detection module, a pseudo-random number health detection module, a true random number output FIFO (i.e., a first cache), and a pseudo-random number output FIFO (a second cache).
[0077] For example, see Figure 4 As shown, Figure 4The schematic diagram of another random number generator hardware structure disclosed in an embodiment of the present invention includes an entropy source, a first path selector, a Zu Chongzhi algorithm core, a true random number health detection module, a pseudo-random number health detection module, a true random number output FIFO (i.e., a first cache), a pseudo-random number output FIFO (a second cache), and a control switch.
[0078] Among them, the entropy source is used to generate random numbers. Path selector: used to send random numbers to different modules according to the enable. The Zu Chongzhi algorithm core is divided into a key register module, an integrity operation module and an encryption operation module. The key register is used to store the key. The integrity operation module and the encryption operation module extract the same key from the key register, and can generate higher quality true random numbers and pseudo-random numbers in parallel. According to the enable, the integrity operation module can send the true random number to the output FIFO or the encryption operation module, and the encryption operation module can send the pseudo-random number to the output FIFO. Health detection module: used to perform health detection on the quality of random numbers in parallel during the data transmission process of true random numbers and pseudo-random numbers. If the random number does not meet the requirements of international and domestic standards, an alarm interrupt will be issued to prevent the system from outputting random numbers that do not meet the requirements. Output FIFO: divided into true random number output FIFO and pseudo-random number output FIFO. Used to store and output random numbers that meet the standards.
[0079] In an optional implementation, when the key write enable is pulled high, the Zu Chongzhi algorithm core stops working, and the first 128-bit random number input by the entropy source is first written into the key register part of the Zu Chongzhi algorithm core; after the 128-bit random number is written into the key register, the key write enable is pulled low; the random number begins to be input into the calculation part of the Zu Chongzhi algorithm core, and the random number needs to be input with a data length of not less than 32 bits to ensure the randomness of the output true random number. After each operation is completed, you can choose to pull the key write enable high again to update the key in the key register, thereby further improving the quality of the generated true random number. Furthermore, one integrity hash operation outputs a 32-bit true random number. Generally, the integrity hash operation of the Zu Chongzhi algorithm core needs to be run at least 32 times, that is, to output a 1024-bit true random number, so as to ensure the reliability of the health check results, which depends on the health check method used; ensure that the health check meets international and domestic standards for random number detection; if the health check finds that the true random number does not meet the requirements, an error alarm interrupt will be issued, the entire system will stop running, and the true random number and pseudo-random number output FIFO will be cleared; if the true random number output FIFO is full and the pseudo-random number mode is not enabled, an interrupt will be issued, the entire system will stop working, and wait for the data in the FIFO to be read out.
[0080] The encryption operation runs in parallel with the integrity hash operation and uses the same key; in general, the Zu Chongzhi algorithm core encryption operation needs to output at least 1024 bits of pseudo-random numbers to ensure the reliability of the health test results, which depends on the health test method used; ensure that the health test meets international and domestic standards for random number testing; if the health test finds that the pseudo-random number does not meet the requirements, an error alarm interrupt will be issued, the entire system will stop running, the pseudo-random number output FIFO will be cleared, and the true random number output FIFO will remain unchanged; if the pseudo-random number output FIFO is full and the pseudo-random number mode is enabled, an interrupt will be issued, the entire system will stop working, and wait for the data in the FIFO to be read out.
[0081] The embodiment of the present invention provides a random number generator with better performance, smaller area and lower power consumption, which can be implemented in resource-constrained systems. This is of great significance for computing devices that need to efficiently generate high-quality random numbers, such as mobile devices, embedded systems, etc. In the field of cryptography, the quality of random numbers directly affects the security of encryption algorithms. The high-quality random numbers generated by the embodiment of the present invention can also be used to generate encryption keys, and are also of great value for application scenarios that require high-quality random numbers, such as simulation experiments, random sampling, etc.
[0082] For further information, see Figure 5 As shown, an embodiment of the present invention discloses a random number generation method, including:
[0083] Step S11: Generate a random number using an entropy source, and input the random number output by the entropy source into an algorithm core, wherein the algorithm core includes a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register.
[0084] In this embodiment, the CPU can configure the number of bits of random numbers output by the entropy source each time, control the number of bits of random numbers output by the entropy source each time, such as 32 bits, and control the entropy source to generate random numbers so as to input the random numbers output by the entropy source into the algorithm core.
[0085] Step S12: Using the integrity operation module, perform an integrity hash operation on the random number generated by the entropy source based on the random key to obtain a true random number, and use the health detection module to perform a health detection on the true random number.
[0086] Step S13: Using the encryption operation module, perform an encryption operation on the true random number based on the random key to obtain a pseudo-random number, and use a health detection module to perform a health detection on the pseudo-random number.
[0087] Among them, the health detection module, connected to the output of the integrity operation module and the encryption operation module, may include a true random number health detection module connected to the output of the integrity operation module, used to perform health detection on the true random number, and a pseudo-random number health detection module connected to the output of the encryption operation module, used to perform health detection on the pseudo-random number.
[0088] For example, see Figure 6 As shown, Figure 6 Another random number generation method flow chart provided in an embodiment of the present invention may include the following steps:
[0089] Step S1: The entropy source generates random numbers, which are received by the post-processing system (i.e., the part of the random number generator that processes the random numbers generated by the entropy source, obtains true and false random numbers, and performs health checks), that is, the post-processing system receives random numbers from the entropy source;
[0090] Step S2: pull up the key write enable, and write the random number into the Zu Chongzhi algorithm key register first; when the key register is full, pull down the key write enable, and write the random number directly into the Zu Chongzhi algorithm core for integrity hashing operation. This step mainly includes the following steps:
[0091] Step 1: When the key write enable is pulled high, the Zu Chongzhi algorithm core stops working, and the first 128 bits of random numbers input by the entropy source are first written into the key register part of the Zu Chongzhi algorithm core;
[0092] Step 2: After the 128-bit random number is written into the key register, pull the key write enable low;
[0093] Step 3: The random number starts to be input into the calculation part of Zu Chongzhi's algorithm core, and the random number needs to be input with a data length of no less than 32 bits to ensure the randomness of the output true random number.
[0094] Step 4: After each operation (i.e., integrity hash operation) is completed, you can choose to execute step 1 again, and you can pull up the key write enable again to update the key in the key register, thereby further improving the quality of the generated true random number.
[0095] The purpose of this step is to use random numbers to configure the key used by the Zu Chongzhi algorithm and input the random numbers into the Zu Chongzhi algorithm core.
[0096] Step S3: The Zu Chongzhi algorithm core outputs a true random number obtained through integrity hashing operation; if the pseudo-random number mode is not enabled, the output true random number will undergo health detection and be stored in the true random number output FIFO at the same time, waiting to be used. This step mainly includes the following steps:
[0097] Step 1: A completeness hash operation outputs a 32-bit true random number. Generally, the Zu Chongzhi algorithm core completeness hash operation needs to be run at least 32 times, that is, output a 1024-bit true random number, so as to ensure the reliability of the health detection result, which depends on the health detection method used;
[0098] Step 2: Ensure that health testing complies with international and domestic standards for random number testing;
[0099] Step 3: If the health check finds that the true random number does not meet the requirements, an error alarm interrupt will be issued, the entire system will stop running, and the true random number and pseudo-random number output FIFO will be cleared. If the pseudo-random number mode is not enabled, only the true random number output FIFO can be cleared. If the pseudo-random number mode is enabled, the true random number and pseudo-random number output FIFO will be cleared when the true random number is also stored in the FIFO. For ease of operation, regardless of whether the pseudo-random mode is enabled, the clear instruction can correspond to the true random number and pseudo-random number output FIFO.
[0100] Step 4: If the true random number output FIFO is full and the pseudo-random number mode is not enabled, an interrupt will be issued and the entire system will stop working, waiting for the data in the FIFO to be read out.
[0101] The purpose of this step is to use the integrity hashing function of the Zu Chongzhi algorithm core to obtain higher quality true random numbers, perform health checks at the same time, and store true random numbers without enabling pseudo-random number mode.
[0102] Step S4 is to use Zu Chongzhi's algorithm to check the true random number for encryption if the pseudo-random number mode is enabled, and the output pseudo-random number will undergo health detection and be stored in the pseudo-random number output FIFO, waiting to be used. This step also includes the following steps:
[0103] Step 1: The encryption operation and integrity hash operation are run in parallel, using the same key;
[0104] Step 2: In general, the Zu Chongzhi algorithm core encryption operation needs to output at least 1024 bits of pseudo-random numbers to ensure the reliability of the health detection results, which depends on the health detection method used;
[0105] Step 3: Ensure that health testing complies with international and domestic standards for random number testing;
[0106] Step 4: If the health check finds that the true random number does not meet the requirements, an error alarm interrupt will be issued, the entire system will stop running, the pseudo-random number output FIFO will be cleared, and the true random number output FIFO will remain unchanged;
[0107] Step 5: If the pseudo-random number output FIFO is full and the pseudo-random number mode is enabled, an interrupt will be issued and the entire system will stop working, waiting for the data in the FIFO to be read out.
[0108] The purpose of this step is to perform encryption operations on the true random numbers generated by the Zu Chongzhi algorithm to obtain more secure pseudo-random numbers, and to perform health checks and storage on the pseudo-random numbers.
[0109] That is, the post-processing system receives random numbers from the entropy source; the key write enable is pulled high, and the random numbers are first written into the Zu Chongzhi algorithm key register; when the key register is full, the key write enable is pulled low, and the random numbers are directly written into the Zu Chongzhi algorithm core for integrity hashing operation; the Zu Chongzhi algorithm core outputs the true random number obtained after the integrity hashing operation; if the pseudo-random number mode is not enabled, the output true random number will undergo health detection and be stored in the true random number output FIFO at the same time, waiting to be used; if the pseudo-random number mode is enabled, the Zu Chongzhi algorithm core is used to perform encryption operation on the true random number, and the output pseudo-random number will undergo health detection and be stored in the pseudo-random number output FIFO at the same time, waiting to be used.
[0110] In this way, after receiving the random number generated by the entropy source, the random number is sent to the Zu Chongzhi algorithm core, and after the integrity hash operation, each operation generates a 32-bit long true random number with higher quality, and is output to FIFO storage while receiving health detection, thereby realizing the output of true random numbers; at the same time, if the pseudo-random number mode is enabled, the true random number can be output to the Zu Chongzhi algorithm core while receiving health detection to perform encryption operations in parallel with the integrity hash operation, thereby generating a more secure pseudo-random number, which is output to FIFO storage while receiving health detection, thereby realizing the technical solution of pseudo-random number output. The use of a Zu Chongzhi algorithm core in hardware to parallelly realize the output of true random numbers and pseudo-random numbers avoids the problem of excessively large system hardware circuit area, high power consumption, and low output performance caused by using two algorithm cores that are more complex than the Zu Chongzhi algorithm, thereby greatly improving the output performance of the random number generator, saving the area of the system, reducing power consumption, and realizing a faster random number generation rate. On the other hand, the health check is run in parallel with other modules, and the health check is used to detect the true random numbers and pseudo-random numbers output by the system in real time, ensuring that the true random numbers and pseudo-random numbers generated by the entire system meet the standards, ensuring the quality of the random numbers generated by the system, and improving the security of the entire system. By generating a sequence password to achieve encryption and integrity hash operations, it has good security, fast running speed and low complexity.
[0111] Furthermore, an embodiment of the present invention provides a random number generation device, comprising:
[0112] An entropy source module, used to generate random numbers and input the random numbers output by the entropy source into an algorithm core, wherein the algorithm core includes a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register;
[0113] An operation module, configured to use the integrity operation module to perform an integrity hash operation on the random number generated by the entropy source based on the random key to obtain a true random number; and use the encryption operation module to perform an encryption operation on the true random number based on the random key to obtain a pseudo-random number;
[0114] The detection module is used to perform a health detection on the true random number using a health detection module, and to perform a health detection on the pseudo-random number using a health detection module.
[0115] The storage module is used to store true random numbers and pseudo random numbers.
[0116] In an optional implementation, a random number generating device includes:
[0117] The entropy source module is mainly used to generate random numbers and send them to the post-processing system.
[0118] The operation module is mainly responsible for post-processing the random numbers using the Zu Chongzhi algorithm. On the one hand, it performs integrity hashing operations on the random numbers generated by the entropy source module to generate higher quality true random numbers; on the other hand, it performs encryption operations on the true random numbers generated by integrity hashing operations to generate more secure pseudo-random numbers.
[0119] The detection module is mainly used to perform health checks on the quality of random numbers in parallel in accordance with international and domestic standards during the data transmission process of true random numbers and pseudo-random numbers. If the random numbers do not meet the requirements of international and domestic standards, an alarm interrupt will be issued to prevent the system from outputting random numbers that do not meet the requirements.
[0120] The storage module is mainly used to store true random numbers and pseudo-random numbers.
[0121] Among them, the entropy source module is connected to the operation module, and is mainly responsible for generating random numbers and sending the random numbers to the operation module. The operation module is connected to the detection module and the storage module, and is mainly responsible for post-processing the random numbers using the Zu Chongzhi algorithm. Among them, on the one hand, the random numbers generated by the entropy source module are subjected to integrity hashing operations to generate true random numbers with higher quality; on the other hand, the true random numbers generated by the integrity hashing operations are encrypted to generate more secure pseudo-random numbers. The detection module is connected to the operation module, and is mainly used for parallel health detection of the quality of random numbers in accordance with international and domestic standards during the data transmission of true random numbers and pseudo-random numbers. If the random numbers do not meet the requirements of international and domestic standards, an alarm interrupt will be issued to prevent the system from outputting random numbers that do not meet the requirements. The storage module can be connected to the operation module and the entropy source module, and is mainly used to store true random numbers, pseudo-random numbers, and random numbers input by the entropy source.
[0122] In this way, a Zu Chongzhi algorithm core is used to generate higher quality true random numbers and pseudo-random numbers in parallel, so that health detection and data transmission can be run in parallel, and real-time health detection of true random numbers and pseudo-random numbers can be performed simultaneously.
[0123] Figure 7 A structural diagram of an electronic device provided by an embodiment of the present invention, such as Figure 7 As shown, the electronic device includes: a memory 70 for storing a computer program;
[0124] The processor 71 is used to implement the steps of the random number generation method in the above embodiment when executing a computer program.
[0125] The electronic device provided in this embodiment may include but is not limited to a smart phone, a tablet computer, a laptop or desktop computer, a server, etc.
[0126] Among them, the processor 71 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 71 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 71 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 71 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 71 may also include an artificial intelligence (AI) processor, which is used to process computing operations related to machine learning.
[0127] The memory 70 may include one or more computer-readable storage media, which may be non-transitory. The memory 70 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 70 is at least used to store the following computer program 701, wherein the computer program can implement the relevant steps of the random number generation method disclosed in any of the aforementioned embodiments after being loaded and executed by the processor 71. In addition, the resources stored in the memory 70 may also include an operating system 702 and data 703, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 702 may include Windows, Unix, Linux, etc. Data 703 may include, but is not limited to, configuration data, etc.
[0128] In some embodiments, the electronic device may further include a display screen 72 , an input / output interface 73 , a communication interface 74 , a power supply 75 , and a communication bus 76 .
[0129] Those skilled in the art will understand that Figure 7 The structure shown in the figure does not constitute a limitation on the electronic device, and may include more or fewer components than shown in the figure.
[0130] It is understandable that if the random number generation method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the current technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium to execute all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, magnetic disk or optical disk and other media that can store program codes.
[0131] Based on this, an embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the random number generation method described above are implemented.
[0132] A computer program product provided by an embodiment of the present invention is introduced below. The computer program product described below can be referenced to other embodiments described in this document.
[0133] A computer program product comprises a computer program / instruction, which implements the steps of the random number generation method disclosed above when executed by a processor.
[0134] The above is a detailed introduction to the random number generator, random number generation method, medium and product provided in the embodiments of the present invention. The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description.
[0135] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0136] The random number generator, random number generation method, medium and product provided by the present invention are introduced in detail above. Specific examples are used herein to illustrate the principle and implementation mode of the present invention. The description of the above embodiments is only used to help understand the method and core idea of the present invention. It should be pointed out that for ordinary technicians in this technical field, without departing from the principle of the present invention, the present invention can also be improved and modified, and these improvements and modifications also fall within the scope of protection of the claims of the present invention.
Claims
1. A random number generator, characterized in that: include: Entropy source, used to generate random numbers; an algorithm core connected to an entropy source, the algorithm core comprising a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register, the integrity operation module being used to perform an integrity hash operation on a random number generated by the entropy source based on the random key to obtain a true random number, and the encryption operation module being used to perform an encryption operation on the true random number based on the random key to obtain a pseudo-random number; A health detection module is connected to the output of the integrity operation module and the encryption operation module, and is used to perform health detection on the true random number and the pseudo-random number.
2. The random number generator according to claim 1, characterized in that The health detection module comprises: A true random number health detection module connected to the output of the integrity operation module, used for performing health detection on the true random number; The pseudo-random number health detection module connected to the output of the encryption operation module is used to perform health detection on the pseudo-random number.
3. The random number generator according to claim 1, characterized in that Also included is a first path selector connected to the entropy source, configured to: In response to a key write enable signal being pulled high, writing the random number generated by the entropy source as a random key into the key register; In response to the key write enable signal being pulled low, the random number generated by the entropy source is transmitted to the integrity operation module, so that the integrity operation module performs an integrity hash operation on the transmitted random number based on the random key to obtain a true random number.
4. The random number generator according to claim 1, characterized in that Also includes: A first cache having a first connection path with the integrity operation module is used to store the true random number.
5. The random number generator according to claim 4, characterized in that Also includes: The second cache connected to the encryption operation module is used to store the pseudo-random number.
6. The random number generator according to claim 5, characterized in that Also included is a second path selector connected to the integrity operation module, for: In response to the pseudo-random number mode enable signal being pulled high, the true random number output by the integrity operation module is input into the encryption operation module, so that the encryption operation module performs encryption operation on the true random number based on the random key to obtain a pseudo-random number.
7. The random number generator according to claim 5, characterized in that Also includes a first control switch for controlling the first connection path, and a second control switch for controlling a second connection path between the output of the integrity operation module and the encryption operation module; When the first control switch is closed, the first connection path is connected, the integrity operation module stores the true random number output by the integrity operation module into the first cache through the first connection path, and the true random number health detection module connected to the output of the integrity operation module performs health detection on the true random number output by the integrity operation module; When the second control switch is closed, the second connection path is connected, and the true random number output by the integrity operation module is transmitted to the encryption operation module through the second connection path, so that the encryption operation module performs encryption operation on the true random number based on the random key to obtain a pseudo-random number, and stores the pseudo-random number in the second cache, and inputs the pseudo-random number health detection module connected to the output of the encryption operation module to perform health detection on the pseudo-random number; When the health detection result corresponding to any of the true random numbers does not meet the health standard, the true random numbers in the first cache and the pseudo-random numbers in the second cache are cleared; When the health check result corresponding to any of the pseudo-random numbers does not meet the health standard, the pseudo-random numbers in the second cache are cleared.
8. A random number generation method, characterized in that: include: Generate a random number using an entropy source, and input the random number output by the entropy source into an algorithm core, wherein the algorithm core includes a key register for storing a random key, an integrity operation module connected to the key register, and an encryption operation module connected to the key register; Using the integrity operation module, based on the random key, perform an integrity hash operation on the random number generated by the entropy source to obtain a true random number, and using the health detection module to perform a health detection on the true random number; The encryption operation module is used to perform encryption operation on the true random number based on the random key to obtain a pseudo-random number, and the health detection module is used to perform health detection on the pseudo-random number.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the random number generation method according to claim 8 are implemented.
10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the random number generation method according to claim 8 are implemented.
Citation Information
Patent Citations
Method for encrypting and deciphering wireless local area network WAPI and CCMP
CN101753290A
Random number generating system and random number generating method
CN102609238A
Pseudo-random number generation method and device, electronic equipment and storage medium
CN117827146A
True random number generator, true random number generation method, product and medium
CN118245019A
Random number generator of information encryption system, random number generation method, equipment and medium
CN119109589A
Cited By
True random number generation system and method based on small rubidium clock
CN122132005A