Homomorphic encryption hardware accelerator based on FPGA and data processing method thereof
By designing a homomorphic encryption hardware accelerator based on FPGA, using number theory transformation and analog conversion technology, the calculation efficiency problem caused by polynomial operations in homomorphic encryption is solved, and more efficient encryption and decryption calculation is achieved.
Patent Information
- Application Number
- CN202510109214.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-01-23
AI Technical Summary
The homomorphic encryption calculation involves polynomial operations, resulting in large consumption of encryption and decryption time, and the increase in bit length and dimension of ciphertext data, which makes the calculation efficiency low.
A homomorphic encryption hardware accelerator based on FPGA is designed, including a data transmission module, a control module, a homomorphic encryption module, a homomorphic decryption module, a number theory transformation module and a small-variable large analog-to-digital conversion module. Through the number theory transformation and analog conversion technology, the computational complexity of polynomial multiplication is reduced, and parallel and pipeline processing solutions are adopted to improve the calculation efficiency.
The complexity of polynomial multiplication calculation in homomorphic encryption is reduced, the polynomial multiplication order reduction process is abolished, the difficulty of polynomial coefficient reduction is reduced, the efficiency of polynomial calculation is improved, and the throughput of the accelerator is improved through analog conversion technology.
Smart Images

Figure CN120030610A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of integrated circuit encryption, and in particular to a homomorphic encryption hardware accelerator based on FPGA and a data processing method thereof. Background Art
[0002] In the Internet era, data processing and management are the core business of enterprise development. Before the birth of cloud computing, enterprises needed to establish data centers for data processing and storage, which would undoubtedly greatly increase operating costs for enterprises. The emergence of cloud computing services provides a new type of solution for these enterprises. From the perspective of the provision of cloud computing services, security issues are the primary issue restricting the development of cloud computing. Once users choose to use cloud computing services, it means that the data is out of the management of the users themselves, and there is a risk of privacy data leakage. Traditional encryption forms can ensure the security of data storage and data transmission during the cloud computing process. However, when the cloud computing party needs to process and calculate the data, the data still needs to be decrypted. In this way, private data will still be exposed to the cloud computing party.
[0003] The characteristics of homomorphic encryption perfectly meet the needs of cloud computing privacy data protection. Homomorphic encryption means that after the plaintext is encrypted, the results of addition and multiplication operations in the ciphertext domain are consistent with the results of the same operations in the plaintext domain after decryption. In September 2009, Gentry proposed the first fully homomorphic encryption scheme that supports arbitrary additions and arbitrary multiplications. It has complete homomorphic support characteristics and supports homomorphic calculations of arbitrary additions and arbitrary multiplications. Since 2009, the field of cryptography has begun a research boom in fully homomorphic encryption schemes, and three generations of construction schemes have appeared in full homomorphic encryption schemes.
[0004] However, the homomorphic encryption calculation process involves polynomial operations, which greatly increases the time consumed by encryption and decryption in the software implementation process. At the same time, homomorphic encryption increases the bit length and dimension of the ciphertext data, and the calculation efficiency is too low when processing large amounts of data. Therefore, proposing an efficient and feasible homomorphic encryption scheme is a research hotspot in the field of homomorphic encryption research, and it has also become the only way for homomorphic encryption to move towards practical application. Summary of the invention
[0005] The purpose of the present invention is to provide a homomorphic encryption hardware accelerator based on FPGA and a data processing method thereof, which can improve the computational efficiency of homomorphic encryption and decryption.
[0006] The present invention is achieved through the following technical solutions:
[0007] In a first aspect, an embodiment of the present invention provides an FPGA-based homomorphic encryption hardware accelerator, comprising an FPGA end, wherein the FPGA end comprises a data transmission module, a control module, a homomorphic encryption module, a homomorphic decryption module, a number theory transformation module, and a small-to-large analog-to-digital conversion module;
[0008] The data transmission module is used to realize data transmission between the FPGA end and the host computer;
[0009] The control module is used to control the flow of data between various modules according to encryption or decryption operations;
[0010] The number theory transformation module is used to perform number theory transformation or inverse number theory transformation on the input data to obtain transformed data or inverse number theory transformed data;
[0011] The homomorphic encryption module is used to encrypt the transformed data to obtain ciphertext data;
[0012] The homomorphic decryption module is used to decrypt the transformed data to obtain plaintext data;
[0013] The small-to-large modulus conversion module is used to convert multiple channels of ciphertext data or plaintext data of small-bit-width moduli into one channel of data of large-bit-width modulus;
[0014] The control module controls the data input into the number theory transformation module for number theory transformation, transmits the data after number theory transformation to the homomorphic encryption module or the homomorphic decryption module for encryption or decryption, transmits the encrypted ciphertext data or the decrypted plaintext data to the number theory transformation module for inverse number theory transformation, transmits the data after inverse number theory transformation to the small-to-large analog-to-digital conversion module for conversion processing, and transmits the converted data to the data transmission module.
[0015] In a second aspect, another embodiment of the present invention provides a data processing method of a homomorphic encryption hardware accelerator based on FPGA, which is applicable to the homomorphic encryption hardware accelerator based on FPGA described in the above embodiment, including:
[0016] Receive the public key and plaintext data required for encryption or the private key and ciphertext data required for decryption sent by the host computer;
[0017] Convert the received data into signed binary data;
[0018] Performing a number-theoretic transformation on the signed binary data to obtain number-theoretic transformed data;
[0019] According to functional requirements, encrypting or decrypting the data after the number theory transformation to obtain ciphertext data or plaintext data;
[0020] Performing inverse number theory transformation on the ciphertext data or the plaintext data to obtain data after inverse number theory transformation;
[0021] The data after the inverse number theory transformation is converted into data with a large bit width modulus by performing a small bit width modulus conversion, and the converted data is transmitted to the host computer.
[0022] In a third aspect, another embodiment of the present invention provides an FPGA that can implement homomorphic encryption hardware acceleration, including a processor and a memory, the memory is used to store a computer program, the computer program includes program instructions, and the processor is configured to call the program instructions to execute the method described in the above embodiment.
[0023] In a fourth aspect, another embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor executes the method described in the above embodiment.
[0024] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0025] The embodiment of the present invention provides a FPGA-based homomorphic encryption hardware accelerator and a data processing method thereof. On the one hand, the complexity of finite field polynomial multiplication calculation in homomorphic encryption is reduced, the process of polynomial multiplication order reduction is cancelled, the difficulty of polynomial coefficient reduction is reduced, and the circuit can be integrated into a higher frequency structure, thereby improving the efficiency of polynomial calculation. On the other hand, through the analog conversion technology, the large number modulus is converted into multiple groups of small number modulus, and a parallel and pipeline processing scheme is designed to improve the throughput of the entire accelerator. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative work. In the drawings:
[0027] Figure 1 A structural block diagram of a homomorphic encryption hardware accelerator based on FPGA provided for the first embodiment of the present invention;
[0028] Figure 2 is a structural block diagram of a data transmission module in a first embodiment of the present invention;
[0029] Figure 3 is a structural block diagram of a homomorphic encryption module in the first embodiment of the present invention;
[0030] Figure 4 It is the structural block diagram of the homomorphic decryption module in the first embodiment of the present invention;
[0031] Figure 5 It is the structural block diagram of the number theory transformation module in the first embodiment of the present invention;
[0032] Figure 6 It is the structural block diagram of the small-to-large modulus conversion module in the first embodiment of the present invention;
[0033] Figure 7 It is the structural block diagram of the Montgomery reduction unit in the first embodiment of the present invention;
[0034] Figure 8 It is the flowchart of the data processing method of the FPGA-based homomorphic encryption hardware accelerator in the second embodiment of the present invention. Specific implementation manners
[0035] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below in conjunction with the embodiments and the drawings. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and do not limit the present invention.
[0036] Embodiment 1
[0037] As Figure 1 shown, the embodiment of the present invention is designed in a software and hardware combination manner based on the BGV homomorphic encryption scheme. The first embodiment of the present invention provides a FPGA-based homomorphic encryption hardware accelerator, including: a host computer and an FPGA side. In this embodiment, the host computer is a PC side, and the PC side is used to assist in verifying the calculation results of the FPGA side. Functions such as key generation, homomorphic calculation, plaintext calculation, and result comparison are implemented using python. The FPGA side is the core part of the entire accelerator and is used to implement homomorphic encryption and homomorphic decryption to achieve the acceleration purpose. The communication between the PC side and the FPGA side is completed using a serial port.
[0038] The FPGA side includes a data transmission module, a control module, a homomorphic encryption module, a homomorphic decryption module, a number theory transformation module and a small-to-large analog-to-digital conversion module. Among them, the data transmission module is used to realize the data transmission between the FPGA end and the host computer; the control module is used to control the flow of data between various modules according to the encryption or decryption operation; the number theory transformation module is used to perform number theory transformation or inverse number theory transformation on the input data to obtain transformed data or inverse number theory transformation data; the homomorphic encryption module is used to encrypt the transformed data to obtain ciphertext data; the homomorphic decryption module is used to decrypt the transformed data to obtain plaintext data; the small-to-large analog-to-digital conversion module is used to convert the ciphertext data or plaintext data of multiple small-bit-width moduli into data of one large-bit-width modulus; the control module controls the data input into the number theory transformation module for number theory transformation, transmits the number theory transformation data to the homomorphic encryption module or the homomorphic decryption module for encryption or decryption, transmits the encrypted ciphertext data or the decrypted plaintext data to the number theory transformation module for inverse number theory transformation, transmits the inverse number theory transformation data to the small-to-large analog-to-digital conversion module for conversion processing, and transmits the converted data to the data transmission module.
[0039] like Figure 2 As shown, the data transmission module includes a UART data transmission unit, a string to binary unit, a large to small analog to digital conversion unit and a first data storage unit.
[0040] The UART data transmission unit uses the UART protocol to complete the communication between the upper computer and the lower computer. A frame of data in the sending or receiving process consists of 3 parts, 1 start bit, 8 data bits and 1 stop bit. The baud rate is 115200. The 32 frames of data transmitted by the PC are spliced into 256-bit ASCII code data, and the 256-bit ASCII code data is transmitted to the string binary unit.
[0041] The string-to-binary unit removes the high 4 bits of every 8 bits of the received 256-bit ASCII code data to obtain a 128-bit BCD code with a value range of 0 to 9, and then converts the 128-bit BCD code into a 128-bit signed binary code through iterative operations. Each iterative operation multiplies 4 bits of data by 10 and accumulates them.
[0042] The large-to-small analog-to-digital conversion unit performs a modulo operation based on the remainder system on the 128-bit signed binary data and converts the 128-bit data into a modulo 0 ,q 1 ,q 2 ,q 3The parallel architecture is used to calculate four channels of data at the same time, and each channel of data is processed in a serial structure from low to high, processing 17 bits of data each time and then accumulating them, and performing 8 operations to obtain the final result.
[0043] The first data storage unit consists of 4 single-port RAM0-RAM3 with a bit width of 17 and a bit depth of 256, and 1 single-port RAM4 with a bit width of 256 and a bit depth of 256. RAM0-RAM3 is used to store the final results obtained by the 4 paths. RAM4 is used to store the plaintext or ciphertext data to be sent to the PC.
[0044] The control module controls the flow of data according to the function. When an encryption operation is to be performed, first, the control module will control the data to undergo a number theory transformation first, and secondly, transmit the data after the number theory transformation to the homomorphic encryption module for encryption, and then transmit the encrypted ciphertext data to the number theory transformation module for inverse number theory transformation, and then transmit the data after the inverse number theory transformation to the small-to-large analog-to-digital conversion module to merge the 4-way data into 1, and finally transmit the data to the data transmission module. Similarly, when a decryption operation is to be performed, first, the control module will control the data to undergo a number theory transformation first, and secondly, transmit the data after the number theory transformation to the homomorphic decryption module for decryption, and then transmit the decrypted plaintext data to the number theory transformation module for inverse number theory transformation, and then transmit the data after the inverse number theory transformation to the small-to-large analog-to-digital conversion module to merge the 4-way data into 1, and finally transmit the merged data to the data transmission module.
[0045] like Figure 3 As shown, the homomorphic encryption module includes an encryption control unit, an encryption calculation unit and a second data storage unit.
[0046] The encryption control unit is responsible for storing the six data that have undergone number theory transformation and are required for encryption calculation in the second data storage module in sequence. When all the encrypted data are stored once, the six parameters are read out and transmitted to the encryption calculation module at the same time, and then the encrypted ciphertext data is transmitted to the second data storage module for storage.
[0047] The encryption calculation unit is responsible for encrypting the data after number theory transformation into ciphertext. For the three random numbers required in the encryption algorithm, Python generates random numbers that meet the requirements and then stores them in ROM. In order to improve the throughput, the encryption calculation module adopts a pipeline structure to perform multiplication and addition operations in sequence.
[0048] The second data storage unit includes eight groups of single-port RAMs, among which six groups of RAMs are used to store the parameters required for homomorphic encryption, and the remaining two groups of RAMs are used to store the ciphertext data obtained by encryption. Each group of RAMs contains 4 single-port RAMs with a bit width of 17 bits and a depth of 256.
[0049] Similar to the homomorphic encryption module, the homomorphic decryption module includes a decryption control unit, a decryption calculation unit, and a third data storage unit, as Figure 4 shown.
[0050] The decryption control unit sequentially stores the three data required for decryption calculation into the third data storage unit. After all the data for one decryption are stored, it reads out the 3 parameters and transfers them to the decryption calculation unit, and then transfers the plaintext data obtained by decryption to the third data storage unit for storage.
[0051] The decryption calculation unit is responsible for decrypting the data after number-theoretic transform into plaintext data. It also adopts a pipeline structure and performs multiplication and addition operations sequentially. The third data storage unit includes four groups of single-port RAMs, among which three groups of RAMs are used to store the parameters required for homomorphic decryption, and the remaining one group of RAMs is used to store the plaintext data obtained by decryption. Each group of RAMs contains 4 single-port RAMs with a bit width of 17 bits and a depth of 256.
[0052] As Figure 5 shown, the number-theoretic transform module includes a butterfly operation unit, a control unit, a preprocessing module, a postprocessing unit, and a fourth data storage unit.
[0053] The butterfly operation unit is the core unit of the number-theoretic transform module. The butterfly operation includes addition, subtraction, and multiplication, and these operations are all performed in a finite field. First, it reads data from RAM1 for butterfly operation, and then stores the calculation result into RAM2. After all the operations at this layer are completed, it reads data from RAM2 for butterfly operation and stores the calculation result into RAM1, and so on for ping-pong operation. The butterfly operation is performed in the frequency extraction manner. The process is that the first 128 data are added to the last 128 data to obtain the even terms, and the first 128 data minus the last 128 data and then multiplied by the rotation factor to obtain the odd terms. After the calculation, a modulo operation is required.
[0054] The fourth data storage unit consists of 4 dual-port RAMs with a bit width of 17 bits and a depth of 256. Among them, RAM0 and RAM1 are used to store the preprocessing calculation result and the postprocessing calculation result, and RAM2 and RAM3 are used to store the intermediate results during the NTT (number-theoretic transform) process.
[0055] The control unit is used to control the entire module to perform ping-pong operation. First, data is read from RAM2 for NTT operation, and then the calculation result is stored in RAM3. When the NTT operation of this layer is completed, data is read from RAM3 for NTT operation, and the calculation result is stored in RAM2. This operation is alternated until the entire NTT operation is completed.
[0056] The preprocessing and postprocessing units are used to complete the preprocessing and postprocessing of polynomial parameters. The polynomial needs to be preprocessed before the NTT operation, that is, the scaling factor is multiplied by the polynomial coefficients. After the INTT (inverse number theory transformation) operation, the postprocessing is performed, that is, the inverse scaling factor is multiplied by the result polynomial coefficients. After applying the negative envelope convolution theorem, there is no need to expand the polynomial coefficients by multiples, and the process of taking the modulus of the result polynomial order is reduced.
[0057] like Figure 6 The analog-to-digital conversion module is designed by parallel processing and pipeline structure, which includes multiplication unit, Montgomery simple unit, and analog addition unit. Figure 7 As shown, the unit uses simple shift and multiplication operations to complete the modulo operation, avoiding the time-consuming division operation in the modulo process. In the embodiment of the present invention, all modular multiplication operations use the Montgomery approximation with a pipeline structure to complete the modulo operation.
[0058] The BGV homomorphic encryption and decryption algorithm is based on polynomials. An encryption operation requires two polynomial multiplications and three polynomial additions, and a decryption operation requires one polynomial multiplication and one polynomial addition. Polynomial operations are one of the most critical and time-consuming operations in the encryption and decryption process. Number theory transformations are used to optimize polynomial operations to reduce the computational complexity of polynomial operations.
[0059] The design method of number theory transformation is: use frequency extraction to perform butterfly operation. Butterfly operation includes modular addition, modular subtraction, and modular multiplication. The process is to add the first 128 data to the last 128 data to get the even terms, subtract the first 128 data from the last 128 data and then multiply by the rotation factor to get the odd terms. These operations are all performed on a finite field, and modular operations are required after the calculation.
[0060] Modular multiplication includes two parts: integer multiplication and modulo operation. First, integer multiplication is performed. The two inputs are the rotation factor and the result of the modular subtraction operation. Then the product is modulo operated to obtain the final result with the same bit width as the input. In order to obtain odd and even terms at the same time, the result of the modular addition is processed by register tapping during the calculation of modular multiplication. The performance bottleneck of modular multiplication is the modulo operation. The definition of modulo operation is the remainder obtained by dividing a number by the modulus. In order to achieve efficient modulo operation, the Montgomery modular reduction algorithm is used as the basic algorithm for hardware design. The algorithm uses simple shift and multiplication operations to complete the modulo calculation, avoiding the time-consuming division calculation in the modulo process, which is very suitable for hardware implementation.
[0061] The butterfly operation is the core unit of number theory transformation and is used for iterative operations of number theory transformation. First, data is read from RAM1 for butterfly operation, and then the calculation result is stored in RAM2. When all the operations in this layer are completed, data is read from RAM2 for butterfly operation, and the calculation result is stored in RAM1, and a ping-pong operation is performed in this way.
[0062] Homomorphic encryption polynomial multiplication is different from general polynomial multiplication. Homomorphic encryption polynomial multiplication is performed on the polynomial ring R q =Z q [x] / (x n +1). The result of the polynomial multiplication needs to be modulo x n +1 reduction. Applying the negative envelope convolution theory in polynomial multiplication can effectively optimize this problem. It only needs to be pre-processed before the number theory transformation, that is, the point multiplication of the scaling factor and the polynomial coefficient; after the inverse number theory transformation, post-processing is required, that is, the point multiplication of the scaling factor and the result polynomial coefficient, which reduces the modulus x of the final result polynomial. n +1 for the action.
[0063] The specific methods of homomorphic encryption and homomorphic decryption are as follows: The BGV encryption algorithm uses a public key (pk 0 ,pk 1 ) encrypts the plaintext m, and obtains the ciphertext c = (c 0 ,c 1 ).
[0064] The specific algorithm of homomorphic encryption is as follows:
[0065] Select an n-dimensional vector e from a discrete Gaussian distribution 0 ,e 1 , select n-dimensional vector r from the uniform distribution of {-1,0,1} to calculate the ciphertext c 0 、c 1 , the calculation formula is as follows:
[0066] c 0 =pk0 *r+2e 0 +m,
[0067] c 1 =pk 1 *r+2e 1 .
[0068] The BGV decryption algorithm uses the private key sk to decrypt the ciphertext c and obtain the plaintext m. The specific calculation formula is as follows:
[0069] m=(c 0 +c 1 *sk)mod2.
[0070] Among them, mod2 means performing modulo 2 operations. For the three random numbers required in the encryption algorithm, Python generates random numbers that meet the requirements and then stores them in ROM. The public key and plaintext required in the encryption process and the private key and ciphertext required in the decryption process are all generated by the host computer and stored in RAM through the data transmission module. All calculations of homomorphic encryption and homomorphic decryption are polynomial calculations, and polynomial calculations are processed by number theory changes before addition or multiplication operations.
[0071] In order to reduce the difficulty of modulo operation, in the design of the data transmission module, a remainder system is used to convert the large-bit-width modulo Q data into modulo q 0 ,q 1 ,q 2 ,q 3 After the calculation is completed, the ciphertext or plaintext data of the four small-bit-width moduli need to be converted into one large-bit-width modulus data. The design method of analog-to-digital conversion is: the remainder basis q can be converted into i The coefficients under are converted to polynomial coefficients under module Q. The calculation formula is as follows:
[0072]
[0073] Among them, t i Q i Module q i The inverse element in the sense of t is calculated in advance by Python. i and Q i , defined in the FPGA as a parameter, a i It is the ciphertext or plaintext data of four-way small bit width modulus, and modQ represents the modulo Q operation. The circuit design is carried out in the form of pipeline and parallel processing to improve the operation efficiency of the module.
[0074] The present invention proposes a homomorphic encryption hardware accelerator based on FPGA. By analyzing the main time-consuming points in the process of homomorphic encryption and decryption, it can be known that a large number of operations of homomorphic encryption and decryption are performed on polynomial rings. Polynomial multiplication is one of the most critical and time-consuming operations in the encryption and decryption process. When processing large-scale data, its operation time will increase significantly. The number theory transformation and negative package convolution theorem are used to reduce the computational complexity of polynomial multiplication. The Montgomery reduction algorithm is used to convert the modulo operation into multiplication and shift operations to improve the computational efficiency of polynomial operations. At the same time, the bit width of the polynomial coefficients will also affect the efficiency of the modulo operation. The remainder system and the Chinese remainder theorem are used to convert the high-bitwidth modulo operation into a low-bitwidth modulo operation. The parallel processing method is used to improve the parallelism and reduce the time required for the operation of encryption and decryption.
[0075] The FPGA-based homomorphic encryption hardware accelerator proposed in the present invention, on the one hand, reduces the complexity of finite field polynomial multiplication calculation in homomorphic encryption, cancels the process of polynomial multiplication order reduction, reduces the difficulty of polynomial coefficient reduction, can integrate the circuit into a higher frequency structure, and improves the efficiency of polynomial calculation. On the other hand, through the model conversion technology, the large number model is converted into multiple groups of small number models, and a parallel and pipeline processing scheme is designed to improve the throughput of the entire accelerator.
[0076] Example 2
[0077] like Figure 8 As shown, the present invention proposes a data processing method of a homomorphic encryption hardware accelerator based on FPGA, which is applicable to the homomorphic encryption hardware accelerator based on FPGA described in the above embodiment, and the method includes the following steps:
[0078] The host computer generates the public key and plaintext data required for encryption or the private key and ciphertext data required for decryption, and transmits the data to the FPGA end;
[0079] The FPGA receives the public key and plaintext data required for encryption or the private key and ciphertext data required for decryption sent by the host computer;
[0080] Convert the received data into signed binary data;
[0081] Performing a number-theoretic transformation on the signed binary data to obtain data after the number-theoretic transformation, specifically, converting the polynomial coefficient representation of the binary data into point value data;
[0082] According to the functional requirements, the point value data is encrypted or decrypted to obtain ciphertext data or plaintext data;
[0083] Performing inverse number theory transformation on the ciphertext data or the plaintext data to obtain inverse number theory transformed data, wherein the inverse number theory transformed data is represented by polynomial coefficients;
[0084] The data after the inverse number theory transformation is converted into data with a small bit width modulus into data with a large bit width modulus by using the Chinese remainder theorem, and the converted data is transmitted to the host computer;
[0085] The host computer performs data comparison to check whether the data is correct.
[0086] Among them, the specific method of encrypting the data after number theory transformation to obtain ciphertext data includes:
[0087] The data required for encryption calculation is stored in the second data storage unit in sequence. When all the encrypted data is stored once, the stored data is read out and transmitted to the encryption calculation unit to obtain ciphertext data, and the ciphertext data is transmitted to the second data storage unit for storage; the second data storage unit includes eight groups of single-port RAMs, of which six groups of RAMs are used to store the parameters required for homomorphic encryption, and the remaining two groups of RAMs are used to store the encrypted ciphertext data, and each group of RAMs includes 4 single-port RAMs with a bit width of 17 and a bit depth of 256;
[0088] The data read from the second data storage unit is encrypted to obtain ciphertext data.
[0089] Among them, the specific method of decrypting the data after number theory transformation to obtain the plaintext data includes:
[0090] The data required for the decryption calculation is stored in the third data storage unit in sequence. When all the data for decryption is stored once, the stored data is read out and transmitted to the decryption calculation unit to obtain plaintext data, and the plaintext data is transmitted to the third data storage unit for storage; the third data storage unit includes four groups of single-port RAMs, wherein three groups of RAMs are used to store the parameters required for homomorphic decryption, and the remaining group of RAMs is used to store the plaintext data obtained by decryption, and each group of RAMs includes 4 single-port RAMs with a bit width of 17 and a bit depth of 256;
[0091] The data read from the third data storage unit is decrypted to obtain plaintext data.
[0092] The data processing method of a homomorphic encryption hardware accelerator based on FPGA proposed in the embodiment of the present invention, on the one hand, reduces the complexity of finite field polynomial multiplication calculation in homomorphic encryption, cancels the process of polynomial multiplication order reduction, reduces the difficulty of polynomial coefficient reduction, and can integrate the circuit into a higher frequency structure, thereby improving the efficiency of polynomial calculation. On the other hand, through the modular conversion technology, the large number modularity is converted into multiple groups of small number modularity, and a parallel and pipeline processing scheme is designed to improve the throughput of the entire accelerator.
[0093] Example 3
[0094] Another embodiment of the present invention provides an FPGA that can implement homomorphic encryption hardware acceleration, including a processor and a memory, the memory is used to store a computer program, the computer program includes program instructions, and the processor is configured to call the program instructions to execute the aforementioned data processing method of the FPGA-based homomorphic encryption hardware accelerator.
[0095] It should be understood that in the embodiments of the present invention, the processor referred to may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0096] The memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A portion of the memory may also include a non-volatile random access memory. For example, the memory may also store information about the device type.
[0097] In a specific implementation, the processor described in the embodiment of the present invention may execute the implementation described in the method embodiment provided in the embodiment of the present invention, and may also execute the implementation described in the system embodiment of the present invention, which will not be described in detail here.
[0098] Example 4
[0099] In another embodiment of the present invention, an embodiment of a computer-readable storage medium is also provided, wherein the computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor executes the aforementioned data processing method of the FPGA-based homomorphic encryption hardware accelerator.
[0100] The computer-readable storage medium may be an internal storage unit of the terminal described in the foregoing embodiment, such as a hard disk or memory of the terminal. The computer-readable storage medium may also be an external storage device of the device, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the terminal. Further, the computer-readable storage medium may also include both an internal storage unit of the terminal and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the terminal. The computer-readable storage medium may also be used to temporarily store data that has been output or is to be output. A person of ordinary skill in the art may realize that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0101] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the terminals and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here.
[0102] In the several embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or it can be an electrical, mechanical or other form of connection.
[0103] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A homomorphic encryption hardware accelerator based on FPGA, characterized in that: It includes an FPGA end, and the FPGA end includes a data transmission module, a control module, a homomorphic encryption module, a homomorphic decryption module, a number theory transformation module, and a small-to-large analog-to-digital conversion module; The data transmission module is used to realize data transmission between the FPGA end and the host computer; The control module is used to control the flow of data between various modules according to encryption or decryption operations; The number theory transformation module is used to perform number theory transformation or inverse number theory transformation on the input data to obtain transformed data or inverse number theory transformed data; The homomorphic encryption module is used to encrypt the transformed data to obtain ciphertext data; The homomorphic decryption module is used to decrypt the transformed data to obtain plaintext data; The small-to-large modulus conversion module is used to convert multiple channels of ciphertext data or plaintext data of small-bit-width moduli into one channel of data of large-bit-width modulus; The control module controls the data input into the number theory transformation module for number theory transformation, transmits the data after number theory transformation to the homomorphic encryption module or the homomorphic decryption module for encryption or decryption, transmits the encrypted ciphertext data or the decrypted plaintext data to the number theory transformation module for inverse number theory transformation, transmits the data after inverse number theory transformation to the small-to-large analog-to-digital conversion module for conversion processing, and transmits the converted data to the data transmission module.
2. The FPGA-based homomorphic encryption hardware accelerator according to claim 1, characterized in that: The data transmission module includes a UART data transmission unit, a character string to binary unit, a large to small analog to digital conversion unit and a first data storage unit; The UART data transmission unit comprises one frame of data in the process of sending or receiving: one start bit, eight data bits and one stop bit, and splices 32 frames of data transmitted by the host computer into 256 bits of ASCII code data, and transmits the 256 bits of ASCII code data to the string binary unit; The string binary unit is used to remove the upper 4 bits of every 8 bits of the received 256-bit ASCII code data to obtain a 128-bit BCD code with a value range of 0 to 9, and then convert the 128-bit BCD code into a 128-bit signed binary code through an iterative operation, and each iterative operation multiplies 4 bits of data by 10 and accumulates them; The large-to-small analog-to-digital conversion unit performs a modulo operation based on a remainder system on the 128-bit signed binary data to convert the 128-bit data into a modulo q 0 ,q 1 ,q 2 ,q 3 The four-channel 17-bit data is calculated by parallel architecture at the same time. Each channel of data is processed in the form of a serial structure from low to high, and 17 bits of data are processed each time and then accumulated. The final result is obtained by performing 8 operations. The first data storage unit includes 4 groups of single-port RAMs, of which 3 groups are 4 single ports with a bit width of 17 and a bit depth of 256 for storing final results, and 1 group is 1 single port with a bit width of 256 and a bit depth of 256 for storing plaintext or ciphertext data to be sent to the host computer.
3. The FPGA-based homomorphic encryption hardware accelerator according to claim 2, characterized in that: The large-to-small analog-to-digital conversion module includes a Montgomery approximation simple element, and the Montgomery approximation simple element uses shift and multiplication operations to complete the modulo operation.
4. The FPGA-based homomorphic encryption hardware accelerator according to claim 1, characterized in that: The homomorphic encryption module includes an encryption control unit, an encryption calculation unit and a second data storage unit; The encryption control unit is used to store the data required for encryption calculation in the second data storage unit in sequence, and when all the encrypted data is stored, the stored data is read out and transmitted to the encryption calculation unit to obtain ciphertext data, and the ciphertext data is transmitted to the second data storage unit; The encryption calculation unit is used to encrypt the data read from the second data storage unit to obtain ciphertext data; The second data storage unit includes eight groups of single-port RAMs, of which six groups of RAMs are used to store parameters required for homomorphic encryption, and the remaining two groups of RAMs are used to store encrypted ciphertext data. Each group of RAM contains 4 single-port RAMs with a bit width of 17 and a bit depth of 256.
5. The FPGA-based homomorphic encryption hardware accelerator according to claim 1, characterized in that: The homomorphic decryption module includes a decryption control unit, a decryption calculation unit and a third data storage unit; The decryption control unit is used to store the data required for the decryption calculation in the third data storage unit in sequence, and when all the data are stored after being decrypted once, the stored data is read out and transmitted to the decryption calculation unit to obtain plaintext data, and the plaintext data is transmitted to the third data storage unit; The decryption calculation unit is used to decrypt the data read from the third data storage unit to obtain plaintext data; The third data storage unit includes four groups of single-port RAMs, wherein three groups of RAMs are used to store parameters required for homomorphic decryption, and the remaining group of RAMs is used to store plaintext data obtained by decryption, and each group of RAMs includes 4 single-port RAMs with a bit width of 17 and a bit depth of 256.
6. The FPGA-based homomorphic encryption hardware accelerator according to claim 1, characterized in that: The number theory transformation module includes a butterfly operation unit, a control unit, a pre-processing and post-processing unit and a fourth data storage unit; The butterfly operation unit performs butterfly operation in a frequency extraction manner. The butterfly operation includes modular addition, modular subtraction and modular multiplication. Specifically, the first 128 data are added to the last 128 data to obtain an even number, and the first 128 data are subtracted from the last 128 data and then multiplied by the rotation factor to obtain an odd number. The butterfly operation is performed on a finite field, and a modular operation is performed after the calculation is completed. The control unit is used to read data from RAM2 to perform NTT operation to obtain a first calculation result, and store the first calculation result in RAM3. When the NTT operation of this layer is completed, read data from RAM3 to perform NTT operation to obtain a second calculation result, and store the second calculation result in RAM2, and operate alternately until the entire NTT operation is completed; The preprocessing and postprocessing unit is used to complete the preprocessing and postprocessing of the polynomial parameters to obtain the preprocessing calculation results and the postprocessing calculation results; The fourth data storage unit includes four groups of dual-port RAMs, wherein RAM0 and RAM1 are used to store pre-processing calculation results and post-processing calculation results, RAM2 and RAM3 are used to store intermediate results in the NTT transformation process, and each group of RAM contains 4 dual-port RAMs with a bit width of 17 and a bit depth of 256.
7. A data processing method based on a homomorphic encryption hardware accelerator of FPGA, characterized in that: The FPGA-based homomorphic encryption hardware accelerator applicable to any one of claims 1 to 6 comprises: Receive the public key and plaintext data required for encryption or the private key and ciphertext data required for decryption sent by the host computer; Convert the received data into signed binary data; Performing a number-theoretic transformation on the signed binary data to obtain number-theoretic transformed data; According to functional requirements, encrypting or decrypting the data after the number theory transformation to obtain ciphertext data or plaintext data; Performing inverse number theory transformation on the ciphertext data or the plaintext data to obtain data after inverse number theory transformation; The data after the inverse number theory transformation is converted into data with a large bit width modulus by performing a small bit width modulus conversion, and the converted data is transmitted to the host computer.
8. The data processing method of the homomorphic encryption hardware accelerator based on FPGA as claimed in claim 7, characterized in that: The specific method of encrypting the data after the number theory transformation to obtain the ciphertext data includes: The data required for encryption calculation is stored in the second data storage unit in sequence. When all the encrypted data is stored once, the stored data is read out and transmitted to the encryption calculation unit to obtain ciphertext data, and the ciphertext data is transmitted to the second data storage unit for storage; the second data storage unit includes eight groups of single-port RAMs, of which six groups of RAMs are used to store the parameters required for homomorphic encryption, and the remaining two groups of RAMs are used to store the encrypted ciphertext data, and each group of RAMs includes 4 single-port RAMs with a bit width of 17 and a bit depth of 256; Encrypting the data read from the second data storage unit to obtain ciphertext data; The specific method of decrypting the data after the number theory transformation to obtain the plaintext data includes: The data required for the decryption calculation is stored in the third data storage unit in sequence. When all the data for decryption is stored once, the stored data is read out and transmitted to the decryption calculation unit to obtain plaintext data, and the plaintext data is transmitted to the third data storage unit for storage; the third data storage unit includes four groups of single-port RAMs, wherein three groups of RAMs are used to store the parameters required for homomorphic decryption, and the remaining group of RAMs is used to store the plaintext data obtained by decryption, and each group of RAMs includes 4 single-port RAMs with a bit width of 17 and a bit depth of 256; The data read from the third data storage unit is decrypted to obtain plaintext data.
9. An FPGA capable of implementing homomorphic encryption hardware acceleration, characterized in that: It comprises a processor and a memory, the memory is used to store a computer program, the computer program comprises program instructions, and is characterized in that the processor is configured to call the program instructions to execute the method according to any one of claims 7 to 8.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 7 to 8.
Citation Information
Patent Citations
Serial parameter configurable fast number-theory transformation hardware accelerator applied to lattice cipher
CN113342310A
Homomorphic operation accelerator and homomorphic operation execution device comprising same
CN114422102A
Hardware implementation method and hardware implementation device of Montgomery algorithm
CN115904310A
Data homomorphic encryption method, system, device, equipment, medium and product
CN118118155A
Vehicle detection system of based on radar sensor and method thereof
KR102807882B1
Cited By
Polynomial multiplication accelerator
CN120762625A