Key generation method, data processing method, computing device and computer readable storage medium
By taking the approximate values of the target parameters and the modal value in the modal inverse process and performing approximate division, the problem of excessive computing resource consumption when cryptographic equipment generates keys is solved, and the effect of reducing processor burden and improving key generation efficiency is achieved.
Patent Information
- Application Number
- CN202510397414.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-01
AI Technical Summary
In the prior art, cryptographic devices consume more computing resources when generating keys, resulting in a heavy burden on the processor.
In the modulo inverse process, the approximate value of the target parameter and the modulo value are taken as the initial value and the approximate division is performed. The processor's built-in division instructions are used to directly perform division operations to avoid large-number division operations.
It reduces the computing resources required for key generation, reduces the computing burden of the processor, and improves the efficiency and performance of key generation.
Smart Images

Figure CN120034330A_ABST
Abstract
Description
Technical Field
[0001] The present specification relates to the field of computer application technology, specifically, to encryption technology under the field of computer application technology, and more specifically, to a key generation method, a data processing method, a computing device, and a computer-readable storage medium. Background Art
[0002] The key is the core element to ensure the security and effectiveness of the encryption algorithm. Various cryptographic devices are called one of the important components to protect the security of various computing devices.
[0003] In the related art, a cryptographic device consumes a lot of computing resources when generating a key, which places a heavy burden on the processor. Summary of the invention
[0004] The embodiments of this specification provide a key generation method, a data processing method, a computing device, and a computer-readable storage medium to achieve the purpose of reducing the computing resources required for key generation and reducing the burden on the processor.
[0005] To achieve the above technical objectives, the embodiments of this specification provide the following technical solutions: In a first aspect, an implementation of this specification provides a key generation method, applied to a processor, the key generation method comprising: In response to a key generation instruction carrying input data, executing a key generation process; The key generation process includes: Performing a modular inverse process based on the input data to obtain a modular inverse of a target parameter with respect to a modular value; the target parameter is obtained based on the input data; generating a target key based on a modular inverse of the target parameter with respect to the modular value; The modular inverse process includes: Determine whether the effective bit length of the target parameter is greater than a bit number threshold, and if so, take the approximate values of the target parameter and the modulus value as initial values of the dividend and the divisor for approximate calculation respectively; the number of bits of the approximate values of the target parameter and the modulus value is less than or equal to the bit number threshold, and the bit number threshold is the bit length of the signed integer division supported by the processor; In the calculation process of approximate division, the first division result and the second division result are obtained by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, the remainder is calculated according to the extended Euclidean method, and the dividend and the divisor are iterated.
[0006] In combination with the first aspect, in certain embodiments of the first aspect, taking the approximate values of the target parameter and the modulus value as initial values of the dividend and the divisor of the approximate calculation respectively includes: The target parameter and the modulus value are respectively right-shifted by target bits to obtain approximate values of the target parameter and the modulus value, wherein the target bit number is equal to the difference between the number of effective bits of the target parameter and the bit number threshold.
[0007] In combination with the first aspect, in certain implementations of the first aspect, obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor includes: Based on a first preset formula, calculating the first division result and the second division result; The first preset formula includes: ; wherein q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0>u1, v0<v1.
[0008] In combination with the first aspect, in certain implementations of the first aspect, after obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor, when the first division result and the second division result are different, the method further includes: Determine whether the third coefficient is 0, if not, iterate the divisor and dividend using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient according to the iteration relationship, and when the remainder is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modular value; If so, perform large number division and modular operation using the target parameter and the modular value, and when the remainder of the large number division and modular operation is zero, output the modular inverse of the target parameter with respect to the modular value, and when the remainder of the large number division and modular operation is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit number threshold; The large number division and modular operation include: using large number division to obtain a quotient and a remainder, and based on the quotient and remainder obtained by the large number division, using modular operation to iterate the fifth coefficient and the sixth coefficient, the fifth coefficient and the sixth coefficient are both coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
[0009] In combination with the first aspect, in certain implementations of the first aspect, before obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor, the method further includes: Determine whether the divisor of the approximate division is zero, and if not, enter the step of obtaining a first division result and a second division result by respectively enlarging the dividend and the divisor in the calculation process of the approximate division; If so, the step of determining whether the third coefficient is 0 is entered.
[0010] In combination with the first aspect, in some implementations of the first aspect, iterating the divisor and the dividend using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient according to the iterative relationship includes: Iterate the divisor and dividend using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient based on a second preset formula; The second preset formula includes: ; wherein r represents the remainder.
[0011] In combination with the first aspect, in some implementations of the first aspect, the process of generating the target parameter includes: The input data is masked by using a random mask to obtain the target parameter.
[0012] In combination with the first aspect, in some implementations of the first aspect, masking the input data using a random mask to obtain the target parameter includes: A modular multiplication of the random mask and the input data with respect to the modular value is calculated to obtain the target parameter.
[0013] In combination with the first aspect, in some implementations of the first aspect, when the effective bit length of the target parameter is less than the bit number threshold, the modular inverse process further includes: Dividing the target parameter by the modulus value to obtain a quotient of the division; obtaining a remainder of the division using the target parameter, the quotient of the division and the modulus value; Iterating a fifth coefficient and a sixth coefficient using a modular operation based on a quotient and a remainder obtained by the division, the fifth coefficient and the sixth coefficient being coefficients in the extended Euclidean method, and the fifth coefficient being used to calculate the modular inverse; Determine whether the remainder of the division is zero, and if so, output the modular inverse of the target parameter with respect to the modular value; If not, return to the step of obtaining the quotient of large number division by dividing the target parameter by the modulus value.
[0014] In a second aspect, an embodiment of the present specification provides a data processing method, applied to a processor, the data processing method comprising: In response to a security service request carrying target data, encrypting or decrypting the target data using a target key; The target key is generated based on any of the key generation methods described above.
[0015] In a third aspect, an embodiment of the present specification further provides a computing device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the key generation method or data processing method as described above when executing the computer program.
[0016] In a fourth aspect, an embodiment of the present specification further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the key generation method or data processing method as described above is implemented.
[0017] In a fifth aspect, an embodiment of the present specification provides a computer program product or a computer program, wherein the computer program product includes a computer program, and the computer program is stored in a computer-readable storage medium; the processor of the computer device reads the computer program from the computer-readable storage medium, and the processor implements the steps of the above-mentioned key generation method or data processing method when executing the computer program.
[0018] It can be seen from the above technical scheme that in the process of modular inversion, when the target parameter is greater than the bit threshold, the approximate values of the target parameter and the modulus value are taken as the initial values of the dividend and divisor of the approximate calculation, so that the dividend and divisor of the subsequent approximate calculation are within the bit length of the signed integer division supported by the processor, and the division operation can be directly performed using the division instruction built into the processor, without the need to implement complex algorithms based on software, which is conducive to reducing the computing resources consumed by the processor when performing approximate division, and is conducive to reducing the burden of the processor performing approximate division. In addition, in the calculation process of approximate division, the first division result and the second division result are obtained by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, the remainder is calculated according to the extended Euclidean method, and the dividend and the divisor are iterated. In this way, the possible quotient is found through approximate calculation, and when the two results of the approximate calculation are equal, further large number division operations can be avoided, which is conducive to reducing the computing resources consumed by the modular inversion process, and is conducive to improving the algorithm operation efficiency and reducing the operation burden of the processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0020] Figure 1 A schematic diagram of the architecture of a system on a chip provided for an implementation manner of this specification.
[0021] Figure 2 A schematic diagram of the architecture of another system on a chip provided for an implementation manner of this specification.
[0022] Figure 3 A flowchart of a key generation method provided in an embodiment of this specification.
[0023] Figure 4 A flowchart of another key generation method provided in an embodiment of this specification.
[0024] Figure 5 A flowchart of a data processing method provided in an embodiment of this specification.
[0025] Figure 6 A schematic diagram of the structure of a computing device provided for an embodiment of this specification. DETAILED DESCRIPTION
[0026] Unless otherwise defined, the technical terms or scientific terms used in the embodiments of this specification shall have the common meanings understood by persons with ordinary skills in the field to which this specification belongs. The words "first", "second" and similar words used in the embodiments of this specification do not indicate any order, quantity or importance, but are only used to avoid confusion of constituent elements.
[0027] Unless the context requires otherwise, throughout the specification, "plurality" means "at least two", and "including" is interpreted as an open, inclusive meaning, that is, "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples" are intended to indicate that a particular feature, structure, material or characteristic associated with the embodiment or example is included in at least one embodiment or example of the specification. The schematic representation of the above terms does not necessarily refer to the same embodiment or example.
[0028] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.
[0029] Overview In the process of generating a key, there may be a modular inverse operation. The modular inverse operation involves finding the multiplicative inverse of a number. Given two integers (a) and (modulus n), the goal of the modular inverse operation is to find an integer (x) (also known as the modular inverse of (a) with respect to (n)) that satisfies the following equation: [a \times x \equiv 1 \mod n], where times represents the multiplication operation, equiv represents congruence, and mod represents the remainder operation. In other words, the modular inverse operation seeks a number (x) such that the remainder of the product of (a) and (x) divided by (n) is 1.
[0030] For example, in the RSA algorithm, the RSA algorithm is based on the difficult problem of large number factorization, and its core lies in a pair of keys: the public key is used for encryption, and the private key is used for decryption.
[0031] In the process of generating the private key, the modular inverse operation plays a key role. Specifically, the key generation process may include: 1. Select two large prime numbers (p) and (q).
[0032] 2. Calculate the modulus (n = p \times q).
[0033] 3. Calculate the Euler's totient function (\phi(n) = (p - 1) \times (q - 1)).
[0034] 4. Select the public key exponent (e) such that (1 < e < \phi(n)) and (gcd(e, \phi(n)) = 1).
[0035] 5. Find the private key exponent (d) such that (e \times d \equiv 1 \mod \phi(n)). Here, (d) is the modular inverse of (e) with respect to (\phi(n)).
[0036] In addition to generating keys based on the RSA algorithm, modular inverse operations can also be widely used in other public key cryptographic systems. In the related art, in the process of generating keys based on modular inverse operations, it is necessary to solve the modular inverse by calculating the greatest common factor through Euclidean division, and the processor needs to consume a lot of computing resources when processing large number division, resulting in unsatisfactory performance of the key generation method and low overall efficiency.
[0037] In order to solve this problem, the inventor has found that in the modular inversion process, when the target parameter is greater than the bit threshold, the approximate values of the target parameter and the modular value are taken as the initial values of the dividend and divisor of the approximate calculation, so that the dividend and divisor of the subsequent approximate calculation are within the bit length of the signed integer division supported by the processor, and the division operation can be directly performed using the division instruction built into the processor, without the need to implement complex algorithms based on software, which is conducive to reducing the computing resources consumed by the processor when performing approximate division, and is conducive to reducing the burden of the processor performing approximate division. In addition, in the calculation process of approximate division, the first division result and the second division result are obtained by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, the remainder is calculated according to the extended Euclidean method, and the dividend and the divisor are iterated. In this way, the possible quotient is found through approximate calculation, and when the two results of the approximate calculation are equal, further large number division operations can be avoided, which is conducive to reducing the computing resources consumed by the modular inversion process, and is conducive to improving the algorithm operation efficiency and reducing the operation burden of the processor.
[0038] Furthermore, in order to further improve the execution efficiency of the method, in the process of solving the modular inverse based on the extended Euclidean method, when the third coefficient is not zero, the divisor and the dividend can be iterated using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient according to the iterative relationship, so as to achieve the purpose of utilizing the iterative relationship between the divisor and the dividend and extending the approximate calculation to subsequent division operations, so that the effective bit length of the data processed in the subsequent division operations is within the bit length of the signed integer division supported by the processor, and the number of occurrences of large number division (i.e., division in which the effective bit length of the divisor and the dividend exceeds the bit length of the signed integer division supported by the processor) is reduced, which is conducive to improving the execution efficiency of the method and reducing the resource consumption of the processor.
[0039] In addition, the inventors further discovered that in traditional key generation methods, the operation time of the modular inversion process is significantly different from the input data. Attackers can obtain relevant data in the key generation process through the operation time of the modular inversion process, resulting in obvious side channel weaknesses in the key generation method. In order to solve this problem, the inventors discovered that a random mask can be used to mask the input data, cutting off the relationship between the input data and the operation time, avoiding the situation where attackers crack the key through the operation time, which is conducive to enhancing the security of the method.
[0040] Based on the above concept, an embodiment of the present specification provides a key generation method. The key generation method provided in the embodiment of the present specification will be exemplarily described below in conjunction with the accompanying drawings.
[0041] Exemplary application scenarios refer to Figure 1 , Figure 1 A feasible usage scenario of the key generation method is shown. Figure 1 In the SoC, the SoC may include a Rich Execution Environment (REE) subsystem and a Trusted Execution Environment (TEE) subsystem. The REE subsystem and the TEE subsystem may be implemented based on the same processor core in the processor or on different processor cores. The REE subsystem and the TEE subsystem provide execution environments with different security levels. The REE subsystem may be used to run objects such as the system firmware, operating system (OS) and common applications (also known as client applications (CA)) of computing devices. The system firmware may be implemented as a Unified Extensible Firmware Interface (UEFI) for desktops, servers and other fields, or may be implemented as a boot loader (U-Boot) for embedded fields. In addition, the basic firmware, system firmware and operating system OS may communicate with an out-of-band control system.
[0042] The TEE subsystem provides an independent and highly secure operating environment that can be used to process sensitive information and perform critical security tasks, including but not limited to authentication, key management, and encryption operations. The TEE subsystem can be a secure operating system (TEE OS) that the TEE subsystem relies on. In some embodiments, a trusted application TA can also run in the TEE subsystem. The TEE subsystem may include a cryptographic module, and the keys in the cryptographic module may be managed and maintained by the TEE subsystem. When the keys in the cryptographic module need to be generated or updated, the TEE subsystem may generate keys based on the key generation method provided in the implementation mode of this specification.
[0043] In addition to Figure 1 In addition to the system-on-chip shown, in some embodiments, reference Figure 2 The system on chip may also include a secure element (SE) subsystem, and the SE subsystem may also include a cryptographic module, and the key in the cryptographic module may also be generated based on the key generation method provided in the implementation mode of this specification. The SE subsystem can be used to store important resources such as root keys, and the security of important resources stored in the SE subsystem can be ensured by means of permission verification, cryptographic technology, etc.
[0044] Since the key generation method provided in the implementation mode of this specification has low processor computing resource usage and short time consumption, it is helpful to ensure that the performance of the on-chip system can meet user needs. The above-mentioned REE subsystem, TEE subsystem and SE subsystem can be implemented based on the same processor core or on different processor cores. This specification does not limit this, and it depends on the actual situation.
[0045] Understandably, Figure 1 and Figure 2 It is only used to exemplify the possible application scenarios of the key generation method provided in the embodiments of this specification, and is not used to limit any application scenarios of the key generation method provided in the embodiments of this specification. In some embodiments, the key generation method can also be used for the generation and management of keys in trusted computing devices such as Trusted Platform Module (TPM) and Trusted Cryptography Module (TCM). This specification does not limit this and the specific situation will depend on the actual situation.
[0046] Exemplary Methods Taking the application in a processor as an example, the embodiment of this specification provides a key generation method, such as Figure 3 As shown, including: S301: In response to a key generation instruction carrying input data, executing a key generation process; The key generation process includes: S3011: Performing a modular inverse process based on the input data to obtain a modular inverse of a target parameter with respect to a modular value; the target parameter is obtained based on the input data; S3012: Generate a target key based on the modular inverse of the target parameter with respect to the modular value; The modular inverse process includes: Determine whether the effective bit length of the target parameter is greater than a bit number threshold, and if so, take the approximate values of the target parameter and the modulus value as initial values of the dividend and the divisor for approximate calculation respectively; the number of bits of the approximate values of the target parameter and the modulus value is less than or equal to the bit number threshold, and the bit number threshold is the bit length of the signed integer division supported by the processor; In the calculation process of approximate division, the first division result and the second division result are obtained by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, the remainder is calculated according to the extended Euclidean method, and the dividend and the divisor are iterated.
[0047] The processor can be a single-core processor or a multi-core processor. At present, a special circuit can be integrated inside the processor to perform the division operation, or the division operation can be accelerated by compiler optimization and other methods. These circuits are optimized to efficiently process data of a specific bit length (usually less than or equal to the bit length supported by the processor that conforms to integer division, that is, the number of digits threshold). Therefore, when the data involved in the division operation is less than or equal to the number of digits threshold, the division instruction built into the processor can be directly called to implement the division operation by hardware acceleration. For the division of large numbers (large numbers can refer to numbers exceeding the number of digits threshold), it is usually necessary to use a software-implemented algorithm to gradually approximate the result, which may involve multiple loop iteration processes, resulting in the need to consume a large amount of processor resources for the division of large numbers, resulting in low efficiency of the processor for the division operation, and a heavy computing burden on the processor.
[0048] In order to solve the problem that a large amount of computing resources are consumed by the processor to handle division operations in the modular inverse process, in this embodiment, the modular inverse process can be a modular inverse process implemented based on the extended Euclidean method. Compared with the traditional Euclidean method, in the modular inverse process of the key generation method, when the target parameter is greater than the bit number threshold, the approximate values of the target parameter and the modulus value are taken as the initial values of the dividend and divisor of the approximate calculation, respectively, so that the dividend and divisor of the subsequent approximate calculation are within the bit length of the signed integer division supported by the processor, and the division operation can be directly performed using the built-in division instruction of the processor without the need to implement complex algorithms based on software, which is beneficial to reducing the computing resources consumed by the processor when performing approximate division, and is beneficial to reducing the burden of the processor performing approximate division. In addition, in the calculation process of approximate division, the first division result and the second division result are obtained by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, the remainder is calculated following the extended Euclidean method, and the dividend and the divisor are iterated. In this way, the possible quotient is found through approximate calculation. When the two results of the approximate calculation are equal, further large number division operations can be avoided, which is beneficial to reducing the computing resources required for the modular inversion process and improving the algorithm operation efficiency, thereby reducing the computing resources required for the entire key generation process, improving the operation efficiency of the entire key generation process, and reducing the computing burden of the processor.
[0049] After obtaining the simulation of the target parameter about the modulus value, the corresponding target key can be generated according to different cryptographic algorithms. Taking the RSA algorithm as an example, assuming that after obtaining the target parameter n 0 About the modulus φ(n 0 ) modulo inverse d 0 Afterwards, we can use the modular inverse d 0 and the target parameter n 0 Get the private key (d 0 , n 0 ), based on the target parameter n 0 and the public key exponent e 0 Get the public key (e 0 , n 0 ), public key exponent e 0 It can be a pre-selected integer, such as the public key exponent e as described above. 0 Can satisfy (1 <e 0 <\phi(n 0 )) and (gcd(e 0 , \phi(n 0 )) = 1).
[0050] In one embodiment, a feasible method for taking approximate values of a target parameter and a modulus value is provided. Specifically, taking the approximate values of the target parameter and the modulus value as initial values of a dividend and a divisor for approximate calculation, respectively, includes: The target parameter and the modulus value are respectively right-shifted by target bits to obtain approximate values of the target parameter and the modulus value, wherein the target bit number is equal to the difference between the number of effective bits of the target parameter and the bit number threshold.
[0051] In this embodiment, the processor can efficiently implement the operation of taking approximate values of the target parameter and the modulus value through a right shift (bitwise right shift) operation. This is because the right shift operation can be equivalent to dividing a binary number by 2. Shifting a number right by one bit is equivalent to dividing the number by 2. This method is very effective in implementing fast division, and the right shift operation is directly supported in processors of most architectures, and has the characteristics of being simple and easy to implement. The processor usually makes corresponding optimizations for the bit shift operation, and the speed of executing the bit shift operation is often faster than executing other arithmetic operations, and the required computing resources are less. Therefore, in this embodiment, the approximate values of the target parameter and the modulus value can be taken by right shifting, and the number of bits of the target parameter and the modulus value can be quickly reduced to the bit threshold, and the entire operation process requires less computing resources of the processor, which is conducive to improving the execution efficiency of the method and reducing the computing burden of the execution method on the processor.
[0052] In one embodiment, a feasible approximate calculation method is provided. Specifically, obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor includes: Based on a first preset formula, calculating the first division result and the second division result; The first preset formula includes: ; wherein q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0>u1, v0<v1.
[0053] In this embodiment, the approximate calculation is performed by the first preset formula, so that the division operation can be performed on a smaller value instead of the original large number. Because a0, a1, u0, u1, v0 and v1 are all values that have been reduced by the shift operation, the calculation of q0 and q1 is much smaller than that of directly performing the division operation on the large number.
[0054] q0 and q1 are two approximate values obtained by increasing and decreasing the dividend a0, respectively. This approach is based on the fact that if a0 is close to a1 multiplied by a certain integer, then a0+u0 and a0+v0 will provide an estimate of a quotient that is larger and smaller, respectively. By calculating these two approximate values, the algorithm can quickly determine a value close to the true quotient. If q0 and q1 are equal, then they are likely to be the correct quotient, thus avoiding further division operations. Based on the above principles, directly performing large number division can be computationally very expensive. By using this approximate method, the algorithm reduces the number of times a full division is performed, thereby reducing the overall computational cost.
[0055] In one embodiment, a processing idea is proposed when the first division result and the second division result are different. Specifically, after obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor, when the first division result and the second division result are different, it also includes: Determine whether the third coefficient is 0, if not, iterate the divisor and dividend using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient according to the iteration relationship, and when the remainder is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modular value; If so, perform large number division and modular operation using the target parameter and the modular value, and when the remainder of the large number division and modular operation is zero, output the modular inverse of the target parameter with respect to the modular value, and when the remainder of the large number division and modular operation is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit number threshold; The large number division and modular operation include: using large number division to obtain a quotient and a remainder, and based on the quotient and remainder obtained by the large number division, using modular operation to iterate the fifth coefficient and the sixth coefficient, the fifth coefficient and the sixth coefficient are both coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
[0056] In this embodiment, the true quotient is gradually approached by iteration. In each iteration, the algorithm updates the estimated values of the dividend and the divisor. The algorithm uses the iterative relationship between the divisor and the dividend to extend the approximate calculation to the subsequent division operations, which means that in each iteration, the algorithm updates the current dividend and the divisor according to the result of the previous iteration, so that the subsequent division operations are also based on the calculation of the approximate value, reducing the overhead in the iterative calculation.
[0057] In order to avoid the problem that the algorithm cannot be performed due to the divisor being 0 in the approximate calculation, in one embodiment, before obtaining the first division result and the second division result by respectively expanding the dividend and the divisor, the method further includes: Determine whether the divisor of the approximate division is zero, and if not, enter the step of obtaining a first division result and a second division result by respectively enlarging the dividend and the divisor in the calculation process of the approximate division; If so, the step of determining whether the third coefficient is 0 is entered.
[0058] Optionally, in one embodiment, a feasible method for iterating the divisor and the dividend based on the iteration relationship is provided. Specifically, iterating the divisor and the dividend using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient according to the iteration relationship includes: Iterate the divisor and dividend using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient based on a second preset formula; The second preset formula includes: ; wherein r represents the remainder.
[0059] In this embodiment, by Calculate the new remainder, update the first to fourth coefficients through the iterative relationship, and update the divisor and dividend at the same time. In this way, it helps to gradually reduce the size of A and B while maintaining their relationship with the original values, extending the approximate calculation to subsequent division operations, thereby reducing the computing resources required by the processor to run the method.
[0060] As mentioned above, in order to cut off the relationship between input and operation time and avoid the risk of side channel attacks, in one embodiment of this specification, the process of generating the target parameters includes: The input data is masked by using a random mask to obtain the target parameter.
[0061] In some scenarios with high security requirements, the random mask may be generated by the processor by calling a true random number generator (Hardware Random Numeral Generator, HRNG). In other implementations, the random mask may also be generated by the processor by running a software algorithm. This specification does not limit this.
[0062] In this embodiment, the input data is masked by a random mask, which cuts off the fixed relationship between the input data and the operation time, avoids the situation where the attacker cracks the plaintext data through the operation time, and avoids the related side channel attack risks.
[0063] Specifically, in one embodiment, masking the input data using a random mask to obtain the target parameter includes: A modular multiplication of the random mask and the input data with respect to the modular value is calculated to obtain the target parameter.
[0064] Modular multiplication refers to taking the modulus (i.e., finding the remainder) of the result while calculating the multiplication result. The modular multiplication process may include: first calculating the product of the random mask and the input data, and then calculating the modulo result of the product and the modulus value. By adding a random mask, the size of the target parameter is not only related to the input data, but also to the random mask, so that the same input data may result in different time consumption of the entire operation process due to different random masks, avoiding the situation where attackers crack plaintext data such as input data through the time consumption of the operation process, and improving the security of the method.
[0065] In one embodiment, when the effective bit length of the target parameter is less than the bit number threshold, the modular inverse process further includes: Dividing the target parameter by the modulus value to obtain a quotient of the division; obtaining a remainder of the division using the target parameter, the quotient of the division and the modulus value; Iterating a fifth coefficient and a sixth coefficient using a modular operation based on a quotient and a remainder obtained by the division, the fifth coefficient and the sixth coefficient being coefficients in the extended Euclidean method, and the fifth coefficient being used to calculate the modular inverse; Determine whether the remainder of the division is zero, and if so, output the modular inverse of the target parameter with respect to the modular value; If not, return to the step of obtaining the quotient of large number division by dividing the target parameter by the modulus value.
[0066] In one embodiment, a feasible calculation process for outputting the modular inverse of the target parameter with respect to the modular value may include: t0 mod P, wherein t0 represents the fifth coefficient, i.e., the coefficient used to store intermediate results in the Euclidean algorithm, and P represents the modular value. When the remainder obtained during the iteration of the Euclidean algorithm is zero, the modular inverse of the target parameter with respect to the modular value can be output.
[0067] When the effective bit length of the target parameter is less than the bit number threshold, the modular inverse calculation can be directly performed based on the Euclidean method. At this time, the number of bits of the divisor and the dividend are both below the bit number threshold, and the processor can directly implement the division operation through the relevant division instructions, which is conducive to reducing the resource consumption of the processor and improving the execution efficiency of the method.
[0068] In a specific embodiment, a complete modular inverse calculation process is provided. Specifically, reference is made to Figure 4 , define the modular inverse process as RIDA, assume that W is the bit length of the signed integer division supported by the processor, P is a signed large integer, and B is a signed integer. Define A, R, T, t0, t1, q as signed large integers, a0, a1, q0, q1, h, u0, u1, v0, v1 and r as signed integers, where A is used to store the modulus P, R and T are used to store intermediate results (especially when updating t0 and t1), t0 and t1 are coefficients in the extended Euclidean method, t0 and t1 are respectively referred to as the fifth coefficient and the sixth coefficient in the above text, q is used to represent the quotient of division, a0 and a1 represent the approximate values of A and B in the calculation process, q0 and q1 are two possible quotients in the approximate calculation process (i.e., the first division result and the second division result), and h represents the difference between the effective bit length of A and W; u0, u1, v0 and v1 represent variables used in the extended Euclidean method, which can be used to store coefficients in the iterative process and help track and calculate intermediate values in the modular inverse process. r represents the remainder of the division.
[0069] Assume that the input data is X and the modulus value is P. When using RIDA to generate a key, the key generation method can be expressed as: 1. Obtain a random mask R (the random mask R can be a 256-bit random number), and calculate the modular multiplication of X and R with respect to P, which is B; 2. Calculate B = RIDA (P, B, W); 3. Calculate B = (B * R) mod P; 4. Output the modular inverse value of X.
[0070] refer to Figure 4 , the above process can be specifically expressed as: 1. Get a 256-bit random number R, and calculate the modular multiplication of X and R with respect to P, denoted as B. The purpose of this step is to cut off the connection between X and the operation time; 2. Let A = P, t0 = 0, t1 = 1; the purpose of this step is to initialize variables and prepare for subsequent calculations; 3. Check the effective bit length of A. If it is less than or equal to W, jump to 20; if it is greater than W, jump to 4; 4. Let h = A effective bit length - W, a0 = A right shifted by h bits, a1 = B right shifted by h bits. In this step, take the highest W bits of A effective bits and the effective bits of B at the same bit position as the initial values of the dividend and divisor for subsequent approximate calculations, which is equivalent to scaling A and B equally and discarding the data after the decimal point. Therefore, the deviation between a0, a1 and the actual scaled-down values of A and B is within 1. That is, by checking the bit length, ensure that the calculation is performed within the integer range supported by the processor to avoid the performance overhead of large number operations.
[0071] 5. Let u0 = 1, u1 = 0, v0 = 0, v1 = 1. The purpose of this step is to set the initial value of the iteration relationship between A and B. When choosing the approximate calculation, the deviation value of the divisor and the dividend is 1, then the deviation value in the iterative calculation process is exactly equal to u0, u1, v0, v1.
[0072] 6. Check (a1 + u1) and (a1 + v1). If either one is 0, jump to step 12. If both are not zero, go to step 7. The purpose of this step is to check whether the final divisor of the approximate calculation is 0.
[0073] 7. Calculate q0 = (a0 + u0) / (a1 + u1), q1 = (a0 + v0) / (a1 + v1). The purpose of this step is to increase the dividend or the divisor so that the calculated quotient is not less than the true value and the other is not greater than the true value compared with the quotient of large number division. This reduces the overhead of division operation by calculating an approximate value that is slightly larger and an approximate value that is slightly smaller.
[0074] 8. Check q0 and q1. If they are not equal, jump to step 12; if they are equal, go to step 9; 9. Calculate r = a0 − q0 ∗ a1, a0 = a1, a1 = r. The purpose of this step is to calculate the remainder and iterate a0 and a1. 10. Calculate r = u0 − q0 ∗ u1, u0 = u1, u1 = r, r = v0 − q0 ∗ v1, v0 = v1, v1 = r. During iteration, the iteration value of A is A, B, A - (A / B) * B, …, the iteration value of B is B, A – (A / B) * B, B -(B / (A - (A / B)*B))*(A - (A / B)*B), …. According to the iteration order of A and B, u0 represents the coefficient of A in the iteration formula of A, v0 represents the coefficient of B in the iteration formula of A, u1 represents the coefficient of A in the iteration formula of B, and v1 represents the coefficient of B in the iteration formula of B. Based on this, not only the initial values of u0, u1 and v0, v1 are determined, but also their iteration relationship is determined; 11. Return to step 6 for the next round of calculation; 12. Check v0. If it is not equal to 0, jump to step 17. If it is equal to 0, go to step 13. Because v0 and v1 are iterated under the coefficient -q0, in the case of loop iteration, a0 must be greater than or equal to a1, so the minimum quotient is 1. v0 will only be 0 at the initial value, that is, the division of signed integers supported by the processor cannot be used to replace the division of large numbers.
[0075] 13. Calculate the quotient of large number division q = A / B; 14. Calculate the remainder of large number division R = A – q ∗ B, and iterate the divisor and dividend A = B, B = R; 15. Modular inverse value iterative calculation R = (t0 – q ∗ t1) mod P, t0 = t1, t1 = R. Modular operation is used here to avoid the continuous increase of the number of digits of the value during the iteration process. The calculation of large numbers with larger digits requires more calculation.
[0076] 16. Check B. If it is 0, output the modulo inverse value (t0 * R) mod P. Otherwise, return to step 3. 17. According to the iteration relationship, calculate R = u0 ∗ A + v0 ∗ B, T = u1 ∗ A + v1 ∗ B, update A = R, B = T; 18. According to the iterative relationship, calculate R = u0 ∗ t0 + v0 ∗ t1, T = u1 ∗ t0 + v1 ∗ t1, and update t0 = R, t1 = T. In this step, the iterative relationship between the divisor and the dividend is used to extend the approximate calculation to the subsequent division operations, reducing the overhead in the iterative calculation. 19. Check B. If it is 0, output the modulo inverse value (t0 * R) mod P. Otherwise, return to step 3. 20. Calculate the division quotient q0 = A / B, where A and B are both within the range of the division bit supported by the processor; 21. Calculate the remainder of the division r = A – q0 ∗ B, and iterate the divisor and dividend A = B, B = r; 22. Modular inverse value iteration calculation R = (t0 – q0 ∗ t1) mod P, t0 = t1, t1 = R. Similarly, modular operation is used here to avoid the continuous increase of the number of digits of the value during the iteration process. The calculation of large numbers with larger digits also requires more calculations; 23. Check B. If it is 0, output the modular inverse value (t0 * R) mod P. Otherwise, return to step 20.
[0077] Accordingly, the embodiments of this specification also provide a data processing method, which is applied to a processor, such as Figure 5 As shown, the data processing method includes: S501: In response to a security service request carrying target data, encrypt or decrypt the target data using a target key; The target key is generated based on the key generation method described in any of the above implementations.
[0078] The security services include but are not limited to data encryption, data decryption, identity authentication, digital signature and verification, security measurement and other services.
[0079] Exemplary Devices In an exemplary embodiment of the present specification, a key generation device is further provided, which is applied to a processor, and the key generation device includes: A generation module, configured to execute a key generation process in response to a key generation instruction carrying input data; The key generation process includes: Performing a modular inverse process based on the input data to obtain a modular inverse of a target parameter with respect to a modular value; the target parameter is obtained based on the input data; generating a target key based on a modular inverse of the target parameter with respect to the modular value; The modular inverse process includes: Determine whether the effective bit length of the target parameter is greater than a bit number threshold, and if so, take the approximate values of the target parameter and the modulus value as initial values of the dividend and the divisor for approximate calculation respectively; the number of bits of the approximate values of the target parameter and the modulus value is less than or equal to the bit number threshold, and the bit number threshold is the bit length of the signed integer division supported by the processor; In the calculation process of approximate division, the first division result and the second division result are obtained by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, the remainder is calculated according to the extended Euclidean method, and the dividend and the divisor are iterated.
[0080] In some embodiments, the generation module takes the approximate values of the target parameter and the modulus value as the initial values of the dividend and divisor for the approximate calculation, respectively, and is specifically used to: right-shift the target parameter and the modulus value by a target number of bits, respectively, to obtain the approximate values of the target parameter and the modulus value, wherein the target number of bits is equal to the difference between the number of effective bits of the target parameter and the bit threshold.
[0081] In some implementations, obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor includes: Based on a first preset formula, calculating the first division result and the second division result; The first preset formula includes: ; wherein q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0>u1, v0<v1.
[0082] In some implementations, after obtaining the first division result and the second division result by respectively expanding the dividend and the divisor, when the first division result and the second division result are different, the generation module is further used to: determine whether the third coefficient is 0, if not, iterate the divisor and the dividend using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient according to the iteration relationship, and when the remainder is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modular value; If so, perform large number division and modular operation using the target parameter and the modular value, and when the remainder of the large number division and modular operation is zero, output the modular inverse of the target parameter with respect to the modular value, and when the remainder of the large number division and modular operation is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit number threshold; The large number division and modular operation include: using large number division to obtain a quotient and a remainder, and based on the quotient and remainder obtained by the large number division, using modular operation to iterate the fifth coefficient and the sixth coefficient, the fifth coefficient and the sixth coefficient are both coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
[0083] In some implementations, before the generation module obtains the first division result and the second division result by respectively enlarging the dividend and the divisor, it is further used to: determine whether the divisor of the approximate division is zero, and if not, enter the step of obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor in the calculation process of the approximate division; If so, the step of determining whether the third coefficient is 0 is entered.
[0084] In some implementations, the generating module iterates the divisor and the dividend using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient according to the iterative relationship, specifically for: Iterate the divisor and dividend using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient based on a second preset formula; The second preset formula includes: ; wherein r represents the remainder.
[0085] In some implementations, the key generation method further includes: The parameter generation module is used to mask the input data using a random mask to obtain the target parameter.
[0086] In some implementations, the parameter generation module masks the input data using a random mask to obtain the target parameter specifically for: A modular multiplication of the random mask and the input data with respect to the modular value is calculated to obtain the target parameter.
[0087] In some implementations, when the effective bit length of the target parameter is less than the bit number threshold, the modular inverse process further includes: Dividing the target parameter by the modulus value to obtain a quotient of the division; obtaining a remainder of the division using the target parameter, the quotient of the division and the modulus value; Iterating a fifth coefficient and a sixth coefficient using a modular operation based on a quotient and a remainder obtained by the division, the fifth coefficient and the sixth coefficient being coefficients in the extended Euclidean method, and the fifth coefficient being used to calculate the modular inverse; Determine whether the remainder of the division is zero, and if so, output the modular inverse of the target parameter with respect to the modular value; If not, return to the step of obtaining the quotient of large number division by dividing the target parameter by the modulus value.
[0088] Accordingly, in an exemplary embodiment of the present specification, a data processing device is further provided, which is applied to a processor, and the data processing device includes: A security processing module, configured to respond to a security service request carrying target data and perform encryption or decryption operations on the target data using a target key; The target key is generated based on the key generation method described in any of the above implementations.
[0089] For the specific definition of the key generation device and the data processing device, please refer to the definition of the key generation method or the data processing method above, which will not be repeated here. Each module in the above-mentioned key generation device and data processing device can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0090] Exemplary Computing Devices Another embodiment of the present application further provides a computing device, see Figure 6 As shown, an exemplary embodiment of the present specification also provides a computing device, including: a memory and a processor, the memory storing a computer program, and the processor executing the computer program when executing the computer program performs the steps of the key generation method or data processing method according to various embodiments of the present specification described in the above embodiments of the present specification.
[0091] The internal structure of the computing device can be as follows Figure 6As shown, the computing device includes a processor, a memory, a network interface and an input device connected through a system bus. Among them, the processor of the computing device is used to provide computing and control capabilities. The memory of the computing device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computing device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps of the key generation method or data processing method according to various embodiments of the present specification described in the above embodiments of the present specification are performed.
[0092] The processor may include a main processor and may also include a baseband chip, a modem, etc.
[0093] The memory stores a program for executing the technical solution of the present invention, and may also store an operating system and other key services. Specifically, the program may include a program code, and the program code includes computer operation instructions. More specifically, the memory may include a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), other types of dynamic storage devices that can store information and instructions, a disk storage, a flash, and the like.
[0094] The processor may be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the scheme of the present invention. It may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0095] The input device may include a device for receiving data and information input by a user, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer, or a gravity sensor.
[0096] Output devices may include means that allow information to be output to a user, such as display screens, printers, speakers, etc.
[0097] The communication interface may include using any transceiver or the like to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), etc.
[0098] The processor executes the program stored in the memory and calls other devices, which can be used to implement each step of any key generation method or data processing method provided in the above embodiments of the present application.
[0099] The computing device may also include a display component and a voice component. The display component may be a liquid crystal display or an electronic ink display. The input device of the computing device may be a touch layer covered on the display component, or a button, trackball or touchpad provided on the housing of the computing device, or an external keyboard, touchpad or mouse.
[0100] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the scheme of this specification, and does not constitute a limitation on the computing device to which the scheme of this specification is applied. The specific computing device may include more or fewer components than shown in the figure, or combine certain components, or have a different arrangement of components.
[0101] Exemplary computer program products and storage media In addition to the above-mentioned methods and devices, the key generation method or data processing method provided in the embodiments of this specification may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to execute the steps of the key generation method or data processing method according to various embodiments of this specification described in the above "Exemplary Method" section of this specification.
[0102] The computer program product may be written in any combination of one or more programming languages to write program code for performing the operations of the embodiments of the present specification, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0103] In addition, an embodiment of the present specification also provides a computer-readable storage medium on which a computer program is stored, and the computer program is executed by a processor to execute the steps of the key generation method or data processing method according to various embodiments of the present specification described in the above "Exemplary Method" section of the present specification.
[0104] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this specification may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0105] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0106] The above-mentioned embodiments only express several implementation methods of this specification, and the descriptions are relatively specific and detailed, but they cannot be understood as limiting the scope of the solutions provided by the embodiments of this specification. It should be pointed out that for ordinary technicians in this field, several modifications and improvements can be made without departing from the concept of this specification, which all belong to the protection scope of this specification. Therefore, the protection scope of the patent of this specification shall be based on the attached claims.
Claims
1. A key generation method, characterized in that: Applied to a processor, the key generation method includes: In response to a key generation instruction carrying input data, executing a key generation process; The key generation process includes: Performing a modular inverse process based on the input data to obtain a modular inverse of a target parameter with respect to a modular value; the target parameter is obtained based on the input data; generating a target key based on a modular inverse of the target parameter with respect to the modular value; The modular inverse process includes: Determine whether the effective bit length of the target parameter is greater than a bit number threshold, and if so, take the approximate values of the target parameter and the modulus value as initial values of the dividend and the divisor for approximate calculation respectively; the number of bits of the approximate values of the target parameter and the modulus value is less than or equal to the bit number threshold, and the bit number threshold is the bit length of the signed integer division supported by the processor; In the calculation process of approximate division, the first division result and the second division result are obtained by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, the remainder is calculated according to the extended Euclidean method, and the dividend and the divisor are iterated.
2. The method according to claim 1, characterized in that The taking the approximate values of the target parameter and the modulus value as initial values of the dividend and the divisor of the approximate calculation respectively comprises: The target parameter and the modulus value are respectively right-shifted by target bits to obtain approximate values of the target parameter and the modulus value, wherein the target bit number is equal to the difference between the number of effective bits of the target parameter and the bit number threshold.
3. The method according to claim 1, characterized in that The method of obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor comprises: Based on a first preset formula, calculating the first division result and the second division result; The first preset formula includes: ; wherein q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0>u1, v0<v1.
4. The method according to claim 3, characterized in that After obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor, when the first division result and the second division result are different, the method further includes: Determine whether the third coefficient is 0, if not, iterate the divisor and dividend using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient according to the iteration relationship, and when the remainder is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modular value; If so, perform large number division and modular operation using the target parameter and the modular value, and when the remainder of the large number division and modular operation is zero, output the modular inverse of the target parameter with respect to the modular value, and when the remainder of the large number division and modular operation is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit number threshold; The large number division and modular operation include: using large number division to obtain a quotient and a remainder, and based on the quotient and remainder obtained by the large number division, using modular operation to iterate the fifth coefficient and the sixth coefficient, the fifth coefficient and the sixth coefficient are both coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
5. The method according to claim 4, characterized in that Before obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor, the method further includes: Determine whether the divisor of the approximate division is zero, and if not, enter the step of obtaining a first division result and a second division result by respectively enlarging the dividend and the divisor in the calculation process of the approximate division; If so, the step of determining whether the third coefficient is 0 is entered.
6. The method according to claim 4, characterized in that The iterating the divisor and the dividend using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient according to the iterative relationship comprises: Iterate the divisor and dividend using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient based on a second preset formula; The second preset formula includes: ; wherein r represents the remainder.
7. The method according to any one of claims 1 to 6, characterized in that: The process of generating the target parameters includes: The input data is masked by using a random mask to obtain the target parameter.
8. The method according to claim 7, characterized in that The step of masking the input data using a random mask to obtain the target parameter comprises: A modular multiplication of the random mask and the input data with respect to the modular value is calculated to obtain the target parameter.
9. The method according to any one of claims 1 to 6, characterized in that: When the effective bit length of the target parameter is less than the bit number threshold, the modular inverse process further includes: Dividing the target parameter by the modulus value to obtain a quotient of the division; obtaining a remainder of the division using the target parameter, the quotient of the division and the modulus value; Iterating a fifth coefficient and a sixth coefficient using a modular operation based on a quotient and a remainder obtained by the division, the fifth coefficient and the sixth coefficient being coefficients in the extended Euclidean method, and the fifth coefficient being used to calculate the modular inverse; Determine whether the remainder of the division is zero, and if so, output the modular inverse of the target parameter with respect to the modular value; If not, return to the step of obtaining the quotient of large number division by dividing the target parameter by the modulus value.
10. A data processing method, characterized in that: Applied to a processor, the data processing method comprises: In response to a security service request carrying target data, encrypting or decrypting the target data using a target key; The target key is generated based on the key generation method described in any one of claims 1 to 7.
11. A computing device, characterized in that: It comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the key generation method according to any one of claims 1 to 9 or the data processing method according to claim 10 is implemented.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the key generation method according to any one of claims 1 to 9 or the data processing method according to claim 10 is implemented.
Citation Information
Patent Citations
Modular inverse operation unit
CN105988771A
Method of executing recursion operation, computer device, manufacturing and testing method
CN108021477A
Data processing method, medium, electronic device and program product
CN115357216A
Data encryption and decryption method and device, equipment and medium
CN116436709A
Data encryption method, device and system, electronic equipment and storage medium
CN117014208A