Key Generation Method, Data Processing Method, Computing Device, and Computer-Readable Storage Medium
By using approximation and extended Euclidean method iteratively in the modulo inverse process and processing input data in combination with random masks, the problems of excessive computing resource consumption and insufficient security in the key generation method are solved, and efficient and secure key generation is achieved.
Patent Information
- Application Number
- CN202510397414.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-01
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-01
AI Technical Summary
In the prior art, the key generation method consumes a large amount of computing resources, resulting in excessive burden on the processor, and the modular inverse computing time can be used by the attacker to expose the data during the key generation process, which poses a security risk.
In the modulo inverse process, the approximate values of the target parameters and modulo values are taken as the initial divisor and divisor, and iterative calculation is used to use the extended Euclidean method to process the input data in combination with a random mask to avoid the fixed relationship between the calculation time and the input data, reduce computing resource consumption and enhance security.
Through approximate calculation and iterative methods, the computing resource consumption during key generation is reduced, the computing efficiency of the processor is improved, and the correlation between the computing time and the input data is cut off, enhancing the security of the method.
Smart Images

Figure CN120034330B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer application technologies. Specifically, it relates to encryption technologies in the field of computer application technologies. More specifically, it relates to a key generation method, a data processing method, a computing device, and a computer-readable storage medium. Background Art
[0002] A key is a core element for ensuring the security and effectiveness of encryption algorithms. Various cryptographic devices are one of the important components for protecting the security of various computing devices.
[0003] In related technologies, the cryptographic devices consume a relatively large amount of computing resources when generating keys, imposing a heavy burden on the processor. Summary of the Invention
[0004] Embodiments of this specification provide a key generation method, a data processing method, a computing device, and a computer-readable storage medium to achieve the purpose of reducing the computing resources required for key generation and reducing the burden on the processor.
[0005] To achieve the above technical objectives, the embodiments of this specification provide the following technical solutions:
[0006] In a first aspect, an embodiment of this specification provides a key generation method applied to a processor. The key generation method includes:
[0007] In response to a key generation instruction carrying input data, execute a key generation process;
[0008] The key generation process includes:
[0009] Execute a modular inverse process based on the input data to obtain the modular inverse of a target parameter with respect to a modulus value; the target parameter is obtained based on the input data;
[0010] Generate a target key based on the modular inverse of the target parameter with respect to the modulus value;
[0011] The modular inverse process includes:
[0012] Determine whether the effective bit length of the target parameter is greater than a bit threshold. If so, take the approximate values of the target parameter and the modulus value as the initial values of the dividend and divisor for approximate calculation respectively; the bit lengths of the approximate values of the target parameter and the modulus value are less than or equal to the bit threshold, and the bit threshold is the bit length of the signed integer division supported by the processor;
[0013] During the calculation of approximate division, by separately expanding the dividend and the divisor, a first division result and a second division result are obtained. When the first division result is the same as the second division result, the remainder is calculated following the extended Euclidean method, and the dividend and the divisor are iterated.
[0014] In combination with the first aspect, in some embodiments of the first aspect, the taking of approximate values of the target parameter and the modulus as the initial values of the dividend and the divisor for approximate calculation respectively includes:
[0015] The target parameter and the modulus are respectively right-shifted by a target number of bits to obtain approximate values of the target parameter and the modulus, and the target number of bits is equal to the difference between the effective number of bits of the target parameter and the bit threshold.
[0016] In combination with the first aspect, in some embodiments of the first aspect, the obtaining of the first division result and the second division result by separately expanding the dividend and the divisor includes:
[0017] Based on a first preset formula, the first division result and the second division result are calculated;
[0018] The first preset formula includes: ; where q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0 > u1, v0 < v1.
[0019] In combination with the first aspect, in some embodiments of the first aspect, after obtaining the first division result and the second division result by separately expanding the dividend and the divisor, when the first division result is not the same as the second division result, it further includes:
[0020] Judge whether the third coefficient is 0. If not, according to the iterative relationship, use the first coefficient, the second coefficient, the third coefficient and the fourth coefficient to iterate the divisor and the dividend. When the remainder is not zero, return to the step of judging whether the effective bit length of the target parameter is greater than the bit threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modulus.
[0021] If so, perform large number division and modular operation using the target parameter and the modulus. When the remainder of the large number division and modular operation is zero, output the modular inverse of the target parameter with respect to the modulus. When the remainder of the large number division and modular operation is not zero, return to the step of judging whether the effective bit length of the target parameter is greater than the bit threshold;
[0022] The large number division and modulo operation include: obtaining a quotient and a remainder by using large number division, and iterating a fifth coefficient and a sixth coefficient by using modulo operation based on the quotient and the remainder obtained by the large number division. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
[0023] In combination with the first aspect, in some embodiments of the first aspect, before obtaining the first division result and the second division result by separately expanding the dividend and the divisor, it further includes:
[0024] Determine whether the divisor of the approximate division is zero. If not, enter the step of obtaining the first division result and the second division result by separately expanding the dividend and the divisor in the calculation process of the approximate division;
[0025] If so, enter the step of determining whether the third coefficient is 0.
[0026] In combination with the first aspect, in some embodiments of the first aspect, the iterating the divisor and the dividend by using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient according to the iteration relationship includes:
[0027] Based on a second preset formula, iterate the divisor and the dividend by using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient;
[0028] The second preset formula includes:
[0029] ; where r represents the remainder.
[0030] In combination with the first aspect, in some embodiments of the first aspect, the generation process of the target parameter includes:
[0031] Mask the input data with a random mask to obtain the target parameter.
[0032] In combination with the first aspect, in some embodiments of the first aspect, the masking the input data with a random mask to obtain the target parameter includes:
[0033] Calculate the modular multiplication of the random mask and the input data with respect to the modulus value to obtain the target parameter.
[0034] In combination with the first aspect, in some embodiments of the first aspect, when the effective bit length of the target parameter is less than the bit number threshold, the modular inverse process further includes:
[0035] Divide the target parameter by the modulus value to obtain the quotient of the division;
[0036] Obtain the remainder of the division using the target parameter, the quotient of the division, and the modulus value;
[0037] Based on the quotient and remainder obtained from the division, iteratively calculate the fifth coefficient and the sixth coefficient using modular arithmetic. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse;
[0038] Determine whether the remainder of the division is zero. If so, output the modular inverse of the target parameter with respect to the modulus value;
[0039] If not, return to the step of obtaining the quotient of the long division by dividing the target parameter by the modulus value.
[0040] In a second aspect, an embodiment of this specification provides a data processing method applied to a processor. The data processing method includes:
[0041] In response to a security service request carrying target data, perform an encryption or decryption operation on the target data using a target key;
[0042] The target key is generated based on the key generation method described in any of the above.
[0043] In a third aspect, an embodiment of this specification further provides a computing device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the key generation method or the data processing method described above is implemented.
[0044] In a fourth aspect, an embodiment of this specification further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the key generation method or the data processing method described above is implemented.
[0045] In a fifth aspect, an embodiment of this specification provides a computer program product or a computer program. The computer program product includes a computer program stored in a computer-readable storage medium. The processor of the computer device reads the computer program from the computer-readable storage medium, and when the processor executes the computer program, the steps of the key generation method or the data processing method described above are implemented.
[0046] As can be seen from the above technical solution, in the key generation method provided in the embodiments of this specification during the modular inverse process, when the target parameter is greater than the bit threshold, the approximate values of the target parameter and the modulus value are respectively used as the initial values of the dividend and the divisor for approximate calculation, so that both the dividend and the divisor in the subsequent approximate calculation are within the bit length of the signed integer division supported by the processor, and the built-in division instruction of the processor can be directly used for division operations without implementing complex algorithms based on software, which is beneficial to reducing the computing resources consumed by the processor when performing approximate division and reducing the burden of the processor performing approximate division. In addition, during the calculation process of approximate division, by respectively expanding the dividend and the divisor, a first division result and a second division result are obtained. When the first division result and the second division result are the same, the remainder is calculated following the extended Euclidean method, and the dividend and the divisor are iterated. In this way, a possible quotient can be found through approximate calculation, and when the two results of the approximate calculation are equal, further large number division operations can be avoided, which is beneficial to reducing the computing resources consumed by the modular inverse process, improving the operation efficiency of the algorithm, and reducing the operation burden of the processor. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on the provided drawings without creative efforts.
[0048] Figure 1 It is a schematic diagram of the architecture of a system-on-chip provided by the embodiments of this specification.
[0049] Figure 2 It is a schematic diagram of the architecture of another system-on-chip provided by the embodiments of this specification.
[0050] Figure 3 It is a schematic flowchart of a key generation method provided by the embodiments of this specification.
[0051] Figure 4 It is a schematic flowchart of another key generation method provided by the embodiments of this specification.
[0052] Figure 5 It is a schematic flowchart of a data processing method provided by the embodiments of this specification.
[0053] Figure 6 It is a schematic diagram of the structure of a computing device provided by the embodiments of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] Unless otherwise defined, the technical terms or scientific terms used in the embodiments of this specification shall have the ordinary meanings understood by those of ordinary skill in the art to which this specification pertains. The "first", "second" and similar terms used in the embodiments of this specification do not denote any order, quantity or importance, but are merely set up to avoid confusion of components.
[0055] Unless otherwise required by the context, throughout this specification, "a plurality of" means "at least two", and "including" is interpreted as open and inclusive, that is, "including, but not limited to". In the description of the specification, the terms "one embodiment", "some embodiments", "exemplary embodiments", "examples", "specific examples" or "some examples", etc., are intended to indicate that the specific features, structures, materials or characteristics related to the embodiment or example are included in at least one embodiment or example of this specification. The schematic representations of the above terms do not necessarily refer to the same embodiment or example.
[0056] Next, the technical solutions in the embodiments of this specification will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.
[0057] Overview
[0058] During the process of generating a key, there may be a modular inverse operation. The modular inverse operation involves finding the multiplicative inverse of a number. Given two integers (a) and (modulus n), the goal of the modular inverse operation is to find an integer (x) (also known as the modular inverse of (a) with respect to (n)) that satisfies the following equation: [a \times x \equiv 1 \mod n], where "times" represents the multiplication operation, "equiv" represents congruence, and "mod" represents the remainder operation. In other words, the modular inverse operation seeks a number (x) such that the remainder of the product of (a) and (x) divided by (n) is 1.
[0059] For example, in the RSA algorithm, the RSA algorithm is based on the problem of factoring large numbers, and its core lies in a pair of keys: the public key is used for encryption, and the private key is used for decryption.
[0060] During the process of generating the private key, the modular inverse operation plays a key role. Specifically, the key generation process may include:
[0061] 1. Select two large prime numbers (p) and (q).
[0062] 2. Calculate the modulus (n = p \times q).
[0063] 3. Calculate the Euler's totient function ($\phi(n)=(p - 1)\times(q - 1)$).
[0064] 4. Select a public key exponent ($e$) such that ($1\lt e\lt\phi(n)$) and ($\gcd(e,\phi(n)) = 1$).
[0065] 5. Find the private key exponent ($d$) such that ($e\times d\equiv1\mod\phi(n)$). Here, ($d$) is the modular inverse of ($e$) with respect to ($\phi(n)$).
[0066] In addition to generating keys based on the RSA algorithm, modular inverse operations can also be widely applied in other public key cryptosystems. In related technologies, during the process of generating keys based on modular inverse operations, the greatest common divisor needs to be calculated by the Euclidean algorithm to solve the modular inverse, and the processor consumes a lot of computing resources when processing large number division, resulting in the performance of the key generation method not being ideal and the overall efficiency being low.
[0067] To solve this problem, the inventors have found through research that during the modular inverse process, when the target parameter is greater than the bit threshold, the approximate values of the target parameter and the modulus value can be taken as the initial values of the dividend and divisor for approximate calculation respectively, so that the dividend and divisor for subsequent approximate calculation are both within the bit length of the signed integer division supported by the processor, and the built-in division instruction of the processor can be directly used for division operations without implementing complex algorithms based on software, which is beneficial to reducing the computing resources consumed by the processor when performing approximate division and reducing the burden of the processor performing approximate division. In addition, during the calculation process of approximate division, by expanding the dividend and the divisor respectively, a first division result and a second division result are obtained. When the first division result and the second division result are the same, the remainder is calculated following the extended Euclidean method, and the dividend and the divisor are iterated. In this way, a possible quotient can be found through approximate calculation, and when the two results of approximate calculation are equal, further large number division operations can be avoided, which is beneficial to reducing the computing resources consumed by the modular inverse process, improving the algorithm operation efficiency, and reducing the operation burden of the processor.
[0068] Further, in order to further improve the execution efficiency of the method, during the process of solving the modular inverse based on the extended Euclidean method, when the third coefficient is not zero, according to the iterative relationship, the divisor and the dividend can be iterated using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient, so as to achieve the purpose of extending the approximate calculation to subsequent division operations by using the iterative relationship between the divisor and the dividend, making the effective bit lengths of the data processed in subsequent division operations all within the bit length of the signed integer division supported by the processor, reducing the number of occurrences of large number division (i.e., division where the effective bit lengths of the divisor and the dividend exceed the bit length of the signed integer division supported by the processor), which is beneficial to improving the execution efficiency of the method and reducing the resource consumption of the processor.
[0069] In addition, the inventors further found through research that in traditional key generation methods, the operation time of the modular inverse process varies significantly depending on the input data, and attackers can obtain relevant data during the key generation process through the operation duration of the modular inverse process, resulting in obvious side-channel vulnerabilities in the key generation method. To solve this problem, the inventors found through research that the input data can be masked with a random mask to cut off the relationship between the input data and the operation time, avoiding the situation where attackers crack the key through the operation time, which is beneficial to enhancing the security of the method.
[0070] Based on the above concept, the embodiments of this specification provide a key generation method. Next, the key generation method provided by the embodiments of this specification will be described exemplarily with reference to the accompanying drawings.
[0071] Exemplary application scenario
[0072] Reference Figure 1 , Figure 1 shows a feasible usage scenario of the key generation method. In Figure 1In the system-on-chip, the system-on-chip may include a Rich Execution Environment (REE) subsystem and a Trusted Execution Environment (TEE) subsystem. The REE subsystem and the TEE subsystem may be implemented based on the same processor core in the processor, or may be implemented based on different processor cores. The REE subsystem and the TEE subsystem provide execution environments with different security levels. The REE subsystem can be used to run system firmware of a computing device, an operating system (OS), and general applications (also referred to as client applications (CA)). The system firmware may be implemented as a Unified Extensible Firmware Interface (UEFI) for the desktop, server, and other fields, or may be implemented as a boot loader (U-Boot) for the embedded field. In addition, the base firmware, the system firmware, and the operating system OS can communicate with the out-of-band control system.
[0073] The TEE subsystem provides an independent and highly secure operating environment, which can be used to process sensitive information and execute critical security tasks. These security tasks include, but are not limited to, authentication, key management, and encryption operations. The TEE subsystem may rely on a trusted operating system (TEE OS). In some embodiments, trusted applications (TA) may also run in the TEE subsystem. The TEE subsystem may include a cryptographic module, and the keys in the cryptographic module can be managed and maintained by the TEE subsystem. When the keys in the cryptographic module need to be generated or updated, the TEE subsystem can generate keys based on the key generation method provided in the embodiments of this specification.
[0074] In addition to the system-on-chip as Figure 1 shown, in some embodiments, referring to Figure 2 , the system-on-chip may also include a Secure Element (SE) subsystem. The SE subsystem may also include a cryptographic module, and the keys in the cryptographic module can also be generated based on the key generation method provided in the embodiments of this specification. The SE subsystem can be used to store important resources such as root keys, and ensure the security of the important resources stored in the SE subsystem through means such as permission verification and cryptographic techniques.
[0075] Since the key generation method provided by the embodiments of this specification has low occupancy of the computing resources of the processor and short time consumption, it is beneficial to ensure that the performance of the system on chip can meet the user requirements. The above REE subsystem, TEE subsystem, and SE subsystem can be implemented based on the same processor core or different processor cores. This specification does not limit this, and it depends on the actual situation specifically.
[0076] It can be understood that Figure 1 and Figure 2 are only used to exemplarily represent the possible application scenarios of the key generation method provided by the embodiments of this specification, and are not used to limit any application scenarios of the key generation method provided by the embodiments of this specification. In some embodiments, the key generation method can also be used for key generation and management in trusted computing devices such as Trusted Platform Module (TPM) and Trusted Cryptography Module (TCM). This specification does not limit this, and it depends on the actual situation specifically.
[0077] Exemplary method
[0078] Taking the application to a processor as an example, the embodiments of this specification provide a key generation method, as Figure 3 shown, including:
[0079] S301: In response to a key generation instruction carrying input data, execute a key generation process;
[0080] The key generation process includes:
[0081] S3011: Based on the input data, execute a modular inverse process to obtain the modular inverse of the target parameter with respect to the modulus value; the target parameter is obtained based on the input data;
[0082] S3012: Based on the modular inverse of the target parameter with respect to the modulus value, generate a target key;
[0083] The modular inverse process includes:
[0084] Judge whether the effective bit length of the target parameter is greater than the bit threshold. If so, take the approximate values of the target parameter and the modulus value as the initial values of the dividend and divisor for approximate calculation respectively; the bit lengths of the approximate values of the target parameter and the modulus value are less than or equal to the bit threshold, and the bit threshold is the bit length of the signed integer division supported by the processor;
[0085] In the process of approximate division, by separately expanding the dividend and the divisor, a first division result and a second division result are obtained. When the first division result is the same as the second division result, the remainder is calculated following the extended Euclidean method, and the dividend and the divisor are iterated.
[0086] The processor can be a single-core processor or a multi-core processor. Currently, dedicated circuits can be integrated inside the processor to perform division operations, or the division operations can be accelerated through compiler optimization and other means. These circuits are optimized to efficiently process data of a specific bit length (usually less than or equal to the bit length of the signed integer division supported by the processor, i.e., the bit number threshold). Therefore, when the data participating in the division operation is less than or equal to the bit number threshold, the built-in division instruction of the processor can be directly called to implement the division operation through hardware acceleration. For large number (a large number can refer to a number exceeding the bit number threshold) division, usually, algorithms implemented by software need to be used to gradually approximate the result, which may involve multiple loop iteration processes, resulting in large number division consuming a large amount of processor resources, leading to low operation efficiency of the processor for division and heavy operation burden of the processor.
[0087] To solve the problem that the processor consumes a large amount of computing resources in processing division operations during the modular inverse process, in this embodiment, the modular inverse process can be a modular inverse process implemented based on the extended Euclidean method. Compared with the traditional Euclidean method, in the modular inverse process of the key generation method, when the target parameter is greater than the bit number threshold, the approximate values of the target parameter and the modulus value are respectively taken as the initial values of the dividend and the divisor for approximate calculation, so that both the dividend and the divisor in subsequent approximate calculations are within the bit length of the signed integer division supported by the processor, and the built-in division instruction of the processor can be directly used for division operations without implementing complex algorithms based on software, which is beneficial to reducing the computing resources consumed by the processor during the execution of approximate division and reducing the burden of the processor in executing approximate division. In addition, in the process of approximate division calculation, by separately expanding the dividend and the divisor, a first division result and a second division result are obtained. When the first division result is the same as the second division result, the remainder is calculated following the extended Euclidean method, and the dividend and the divisor are iterated. In this way, by approximate calculation, a possible quotient can be found, and when the two results of the approximate calculation are equal, further large number division operations can be avoided, which is beneficial to reducing the computing resources consumed by the modular inverse process, improving the operation efficiency of the algorithm, thus reducing the computing resources consumed by the entire key generation process, improving the operation efficiency of the entire key generation process, and reducing the operation burden of the processor.
[0088] After obtaining the simulation of the target parameter with respect to the modulus value, corresponding target keys can be generated according to different cryptographic algorithms. Taking the RSA algorithm as an example, assume that after obtaining the modular inverse d0 of the target parameter n0 with respect to the modulus value ϕ(n0), the private key (d0, n0) can be obtained based on the modular inverse d0 and the target parameter n0, and the public key (e0, n0) can be obtained based on the target parameter n0 and the public key exponent e0. The public key exponent e0 can be a pre-selected integer. As described above, the public key exponent e0 can satisfy (1 < e0 < ϕ(n0)) and (gcd(e0, ϕ(n0)) = 1).
[0089] In one embodiment, a feasible way to obtain approximate values of the target parameter and the modulus value is provided. Specifically, the obtaining of the approximate values of the target parameter and the modulus value as the initial values of the dividend and the divisor for approximate calculation respectively includes:
[0090] Right-shift the target parameter and the modulus value by a target number of bits respectively to obtain approximate values of the target parameter and the modulus value. The target number of bits is equal to the difference between the effective number of bits of the target parameter and the bit number threshold.
[0091] In this embodiment, the processor can efficiently implement the operation of obtaining approximate values of the target parameter and the modulus value through a right-shift (bitwise right shift) operation. This is because the right-shift operation is equivalent to performing a division-by-2 operation on a binary number. Shifting a number one bit to the right is equivalent to dividing the number by 2. This method is very effective in implementing fast division, and the right-shift operation is directly supported in the processors of most architectures, with the characteristics of being simple and easy to implement. Processors usually make corresponding optimizations for shift operations. The execution speed of shift operations is often faster than that of other arithmetic operations, and the required computing resources are less. Therefore, in this embodiment, by obtaining approximate values of the target parameter and the modulus value through right-shifting, the number of bits of the target parameter and the modulus value can be quickly reduced to the bit number threshold, and the computing resources of the processor required for the entire operation process are less, which is beneficial to improving the execution efficiency of the method and reducing the computing burden of the processor for executing the method.
[0092] In one embodiment, a feasible approximate calculation method is given. Specifically, the obtaining of the first division result and the second division result by respectively expanding the dividend and the divisor includes:
[0093] Calculate the first division result and the second division result based on a first preset formula;
[0094] The first preset formula includes: ; where, q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0 > u1, and v0 < v1.
[0095] In this embodiment, approximate calculation is performed through a first preset formula, so that division operations can be carried out on smaller numerical values instead of on the original large numbers. Since a0, a1, u0, u1, v0, and v1 are all numerical values reduced through shift operations, the calculation of q0 and q1 requires much less computational effort compared to directly performing division operations on large numbers.
[0096] q0 and q1 are two approximate values, which are obtained by increasing and decreasing the dividend a0 respectively. This method is based on the fact that if a0 is close to a1 multiplied by a certain integer, then a0 + u0 and a0 + v0 will respectively provide an overestimated and underestimated quotient estimate. By calculating these two approximate values, the algorithm can quickly determine a value close to the true quotient. If q0 and q1 are equal, then they are likely to be the correct quotient, thus avoiding further division operations. Based on the above principle, directly performing division on large numbers can be computationally very expensive. By using this approximate method, the algorithm reduces the number of times of performing full division, thereby reducing the overall computational cost.
[0097] In one embodiment, a processing idea when the first division result and the second division result are not the same is proposed. Specifically, after obtaining the first division result and the second division result by respectively expanding the dividend and the divisor, when the first division result and the second division result are not the same, it further includes:
[0098] Judge whether the third coefficient is 0. If not, according to the iterative relationship, use the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient to iterate the divisor and the dividend. When the remainder is not zero, return to the step of judging whether the effective bit length of the target parameter is greater than the bit number threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modulus value.
[0099] If it is, perform large number division and modular operation using the target parameter and the modulus value. When the remainder of the large number division and modular operation is zero, output the modular inverse of the target parameter with respect to the modulus value. When the remainder of the large number division and modular operation is not zero, return to the step of judging whether the effective bit length of the target parameter is greater than the bit number threshold.
[0100] The large number division and modulo operation include: obtaining a quotient and a remainder by using large number division, and iterating a fifth coefficient and a sixth coefficient by using modulo operation based on the quotient and the remainder obtained by the large number division. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
[0101] In this embodiment, the true quotient is gradually approximated by an iterative method. In each iteration, the algorithm updates the estimated values of the dividend and the divisor. The algorithm utilizes the iterative relationship between the divisor and the dividend to extend the approximate calculation to subsequent division operations, which means that in each iteration, the algorithm updates the current dividend and divisor according to the result of the previous iteration. This enables subsequent division operations to be based on approximate value calculations, reducing the overhead in iterative calculations.
[0102] To avoid the problem that the algorithm cannot proceed due to the divisor being 0 in approximate calculations, in one embodiment, before obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor, it further includes:
[0103] Judging whether the divisor of the approximate division is zero. If not, then enter the step of obtaining the first division result and the second division result by respectively enlarging the dividend and the divisor in the calculation process of the approximate division;
[0104] If so, then enter the step of judging whether the third coefficient is 0.
[0105] Optionally, in one embodiment, a feasible way of iterating the divisor and the dividend based on the iterative relationship is given. Specifically, the iteration of the divisor and the dividend by using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient according to the iterative relationship includes:
[0106] Iterating the divisor and the dividend by using the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient based on a second preset formula;
[0107] The second preset formula includes:
[0108] ; where r represents the remainder.
[0109] In this embodiment, by calculating a new remainder, updating the first coefficient to the fourth coefficient through the iterative relationship, and simultaneously updating the divisor and the dividend. In this way, it helps to gradually reduce the magnitudes of A and B while maintaining their relationship with the original values, extending the approximate calculation to subsequent division operations, thereby reducing the computing resources that the processor needs to call when running this method.
[0110] As described above, in order to cut off the relationship between the input and the operation time and avoid the risk of side-channel attacks, in one embodiment of this specification, the generation process of the target parameter includes:
[0111] Mask the input data with a random mask to obtain the target parameter.
[0112] In some scenarios with high security requirements, the random mask can be generated by the processor by calling a hardware random number generator (HRNG). In other embodiments, the random mask can also be generated by the processor by running a software algorithm. This specification does not make any limitations in this regard.
[0113] In this embodiment, by masking the input data with a random mask, the fixed relationship between the input data and the operation time is cut off, avoiding the situation where an attacker cracks the plaintext data through the operation time and avoiding the related side-channel attack risk.
[0114] Specifically, in one embodiment, the masking the input data with a random mask to obtain the target parameter includes:
[0115] Calculate the modular multiplication of the random mask and the input data with respect to the modulus value to obtain the target parameter.
[0116] Modular multiplication means that while calculating the multiplication result, the result is taken modulo (i.e., the remainder is obtained). The above modular multiplication process can include: first calculating the product of the random mask and the input data, and then calculating the modulo result of the product and the modulus value. By adding a random mask, the size of the target parameter is related not only to the input data but also to the random mask, so that the same input data may result in different operation times for the entire operation process due to different random masks, avoiding the situation where an attacker cracks the input data and other plaintext data through the operation time and improving the security of the method.
[0117] In one embodiment, when the effective bit length of the target parameter is less than the bit threshold, the modular inverse process further includes:
[0118] Divide the target parameter by the modulus value to obtain the quotient of the division;
[0119] Use the target parameter, the quotient of the division, and the modulus value to obtain the remainder of the division;
[0120] Based on the quotient and remainder obtained from the division, the fifth coefficient and the sixth coefficient are iterated using modular arithmetic. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
[0121] Determine whether the remainder of the division is zero. If so, output the modular inverse of the target parameter with respect to the modulus value.
[0122] If not, return to the step of obtaining the quotient of the long division by dividing the target parameter by the modulus value.
[0123] In one embodiment, the feasible calculation process for outputting the modular inverse of the target parameter with respect to the modulus value may include: t0 mod P, where t0 represents the fifth coefficient, that is, the coefficient used to store intermediate results in the Euclidean algorithm, and P represents the modulus value. When the remainder obtained during the iteration process of the Euclidean algorithm is zero, the modular inverse of the target parameter with respect to the modulus value can be output.
[0124] When the effective bit length of the target parameter is less than the bit number threshold, the modular inverse can be directly calculated based on the Euclidean method. At this time, the bit numbers of both the divisor and the dividend are below the bit number threshold, and the processor can directly implement the division operation through relevant division instructions, which is beneficial to reducing the resource consumption of the processor and improving the execution efficiency of the method.
[0125] In a specific embodiment, a feasible process for complete modular inverse calculation is provided. Specifically, refer to Figure 4 , define the modular inverse process as RIDA. Assume that W is the bit length of the signed integer division supported by the processor, P is a signed large integer, B is a signed integer, and define A, R, T, t0, t1, q as signed large integers, and a0, a1, q0, q1, h, u0, u1, v0, v1, and r as signed integers. Among them, A is used to store the modulus P, R and T are used to store intermediate results (especially when updating t0 and t1), t0 and t1 are coefficients in the extended Euclidean method, t0 and t1 are respectively referred to as the fifth coefficient and the sixth coefficient above, q is used to represent the quotient of the division, a0 and a1 represent the approximate values of A and B during the calculation process, q0 and q1 are respectively two possible quotients (i.e., the first division result and the second division result) during the approximate calculation process, h represents the difference between the effective bit length of A and W; u0, u1, v0, and v1 represent the variables used in the extended Euclidean method, and they can be used to store the coefficients during the iteration process to help track and calculate the intermediate values during the modular inverse process. r represents the remainder of the division.
[0126] Let the input data be X and the modulus value be P. When generating a key using RIDA, the key generation method can be expressed as:
[0127] 1. Obtain a random mask R (the random mask R can be a 256-bit random number), and calculate the modular multiplication of X and R with respect to P, which is B;
[0128] 2. Calculate B = RIDA(P, B, W);
[0129] 3. Calculate B = (B * R) mod P;
[0130] 4. Output the modular inverse value of X.
[0131] Reference Figure 4 , the above process can be specifically expressed as:
[0132] 1. Obtain a 256-bit random number R, and calculate the modular multiplication of X and R with respect to P, denoted as B. The purpose of this step is to cut off the connection between X and the operation time;
[0133] 2. Let A = P, t0 = 0, t1 = 1; the purpose of this step is to initialize variables and prepare for subsequent calculations;
[0134] 3. Detect the effective bit length of A. If it is less than or equal to W, jump to 20; if it is greater than W, jump to 4;
[0135] 4. Let h = the effective bit length of A - W, a0 = A shifted right by h bits, a1 = B shifted right by h bits. In this step, take the highest W bits of the effective bits of A, and take the effective bits at the same bit position of B as the initial values of the dividend and divisor for subsequent approximate calculations. It is equivalent to shrinking A and B proportionally and discarding the data after the decimal point. So the deviation between a0, a1 and the true shrinking values of A, B is within 1; that is, through the bit length check, ensure the calculation within the integer range supported by the processor and avoid the performance overhead of large number operations.
[0136] 5. Let u0 = 1, u1 = 0, v0 = 0, v1 = 1. The purpose of this step is to set the initial values of the iteration relationship between A and B. When choosing the deviation value between the divisor and the dividend for approximate calculation to be 1, the deviation value during the iterative calculation is exactly equal to u0, u1, v0, v1 numerically.
[0137] 6. Detect (a1 + u1) and (a1 + v1). If any one of them is 0, jump to step 12. If both are not zero, enter step 7. The purpose of this step is to detect whether the final divisor of the approximate calculation is 0.
[0138] 7. Calculate \(q0=(a0 + u0) / (a1 + u1)\) and \(q1=(a0 + v0) / (a1 + v1)\). The purpose of this step is to make the calculated quotient values, by increasing the dividend or the divisor, such that one is not less than the true value and the other is not greater than the true value compared to the quotient of the large number division. Through one overestimated approximation calculation and one underestimated approximation calculation, the overhead of the division operation is reduced.
[0139] 8. Detect \(q0\) and \(q1\). If they are not equal, jump to step 12; if they are equal, proceed to step 9.
[0140] 9. Calculate \(r = a0 - q0 * a1\), \(a0 = a1\), \(a1 = r\). The purpose of this step is to calculate the remainder and iterate \(a0\) and \(a1\).
[0141] 10. Calculate \(r = u0 - q0 * u1\), \(u0 = u1\), \(u1 = r\), \(r = v0 - q0 * v1\), \(v0 = v1\), \(v1 = r\). During iteration, the iterative values of \(A\) are \(A\), \(B\), \(A-(A / B)*B\), ……, and the iterative values of \(B\) are \(B\), \(A – (A / B)*B\), \(B-(B / (A - (A / B)*B))*(A - (A / B)*B)\), ……. According to the iterative order of \(A\) and \(B\), \(u0\) represents the coefficient of \(A\) in the iterative formula of \(A\), \(v0\) represents the coefficient of \(B\) in the iterative formula of \(A\), \(u1\) represents the coefficient of \(A\) in the iterative formula of \(B\), and \(v1\) represents the coefficient of \(B\) in the iterative formula of \(B\). Based on this, not only the initial values of \(u0\), \(u1\) and \(v0\), \(v1\) are determined, but also their iterative relationships are determined.
[0142] 11. Return to step 6 for the next round of calculation.
[0143] 12. Detect \(v0\). If it is not equal to 0, jump to step 17; if it is equal to 0, proceed to step 13. Since \(v0\) and \(v1\) are iterated under the coefficient \(-q0\), in the case of cyclic iteration, \(a0\) must be greater than or equal to \(a1\), so the minimum quotient is 1, and \(v0\) will only be 0 at the initial value, that is, when the division of signed integers supported by the processor cannot be used to replace the large number division.
[0144] 13. Calculate the quotient \(q = A / B\) of the large number division.
[0145] 14. Calculate the remainder \(R = A - q * B\) of the large number division and iterate the divisor and dividend \(A = B\), \(B = R\).
[0146] 15. Iteratively calculate the modular inverse value: R = (t0 – q * t1) mod P, where t0 = t1 and t1 = R. Here, modular arithmetic is used to avoid the continuous growth of the number of digits during the iteration process. Larger numbers with more digits require more computational effort for calculation.
[0147] 16. Detect B. If it is 0, output the modular inverse value (t0 * R) mod P; otherwise, return to step 3.
[0148] 17. According to the iterative relationship, calculate R = u0 * A + v0 * B and T = u1 * A + v1 * B, and update A = R and B = T.
[0149] 18. According to the iterative relationship, calculate R = u0 * t0 + v0 * t1 and T = u1 * t0 + v1 * t1, and update t0 = R and t1 = T. In this step, by using the iterative relationship between the divisor and the dividend, the approximate calculation is extended to subsequent division operations, reducing the overhead in iterative calculations.
[0150] 19. Detect B. If it is 0, output the modular inverse value (t0 * R) mod P; otherwise, return to step 3.
[0151] 20. Calculate the quotient q0 = A / B of the division. At this time, both A and B are within the range of division digits supported by the processor.
[0152] 21. Calculate the remainder r = A – q0 * B of the division, and iterate the divisor and the dividend: A = B and B = r.
[0153] 22. Iteratively calculate the modular inverse value: R = (t0 – q0 * t1) mod P, where t0 = t1 and t1 = R. Similarly, modular arithmetic is used here to avoid the continuous growth of the number of digits during the iteration process. Larger numbers with more digits require more computational effort for calculation.
[0154] 23. Detect B. If it is 0, output the modular inverse value (t0 * R) mod P; otherwise, return to step 20.
[0155] Correspondingly, the embodiment of the present specification also provides a data processing method, which is applied to a processor. As Figure 5 shown, the data processing method includes:
[0156] S501: In response to a security service request carrying target data, encrypt or decrypt the target data by using the target key;
[0157] The target key is generated based on the key generation method described in any of the above embodiments.
[0158] The security services include, but are not limited to, services such as data encryption, data decryption, authentication, digital signature and verification, and security measurement.
[0159] Exemplary device
[0160] In an exemplary embodiment of this specification, a key generation device is further provided, which is applied to a processor. The key generation device includes:
[0161] A generation module, configured to execute a key generation process in response to a key generation instruction carrying input data;
[0162] The key generation process includes:
[0163] Performing a modular inverse process based on the input data to obtain the modular inverse of the target parameter with respect to the modulus value; the target parameter is obtained based on the input data;
[0164] Generating a target key based on the modular inverse of the target parameter with respect to the modulus value;
[0165] The modular inverse process includes:
[0166] Judging whether the effective bit length of the target parameter is greater than the bit number threshold. If so, taking the approximate values of the target parameter and the modulus value as the initial values of the dividend and the divisor for approximate calculation respectively; the bit numbers of the approximate values of the target parameter and the modulus value are less than or equal to the bit number threshold, and the bit number threshold is the bit length of the signed integer division supported by the processor;
[0167] In the process of approximate division calculation, by expanding the dividend and the divisor respectively, a first division result and a second division result are obtained. When the first division result and the second division result are the same, calculate the remainder following the extended Euclidean method, and iterate the dividend and the divisor.
[0168] In some embodiments, the generation module taking the approximate values of the target parameter and the modulus value as the initial values of the dividend and the divisor for approximate calculation specifically is: shifting the target parameter and the modulus value to the right by a target number of bits respectively to obtain the approximate values of the target parameter and the modulus value, and the target number of bits is equal to the difference between the effective bit number of the target parameter and the bit number threshold.
[0169] In some embodiments, the obtaining the first division result and the second division result by expanding the dividend and the divisor respectively includes:
[0170] Calculating the first division result and the second division result based on a first preset formula;
[0171] The first preset formula includes: ; where q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0 > u1, and v0 < v1.
[0172] In some embodiments, after obtaining the first division result and the second division result by separately expanding the dividend and the divisor, when the first division result and the second division result are different, the generating module is further configured to: determine whether the third coefficient is 0. If not, according to the iterative relationship, use the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient to iterate the divisor and the dividend. When the remainder is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit number threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modulus value.
[0173] If so, perform a large number division and a modular operation using the target parameter and the modulus value. When the remainder of the large number division and the modular operation is zero, output the modular inverse of the target parameter with respect to the modulus value. When the remainder of the large number division and the modular operation is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit number threshold.
[0174] The large number division and the modular operation include: obtaining a quotient and a remainder by using the large number division, and based on the quotient and the remainder obtained by the large number division, iterating a fifth coefficient and a sixth coefficient by using the modular operation. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
[0175] In some embodiments, before obtaining the first division result and the second division result by separately expanding the dividend and the divisor, the generating module is further configured to: determine whether the divisor of the approximate division is zero. If not, enter the step of obtaining the first division result and the second division result by separately expanding the dividend and the divisor during the calculation process of the approximate division;
[0176] If so, enter the step of determining whether the third coefficient is 0.
[0177] In some embodiments, the generating module specifically uses the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient to iterate the divisor and the dividend according to the iterative relationship as follows:
[0178] Based on the second preset formula, use the first coefficient, the second coefficient, the third coefficient, and the fourth coefficient to iterate the divisor and the dividend;
[0179] The second preset formula includes:
[0180] ; where r represents the remainder.
[0181] In some embodiments, the key generation method further includes:
[0182] A parameter generation module, configured to mask the input data with a random mask to obtain the target parameter.
[0183] In some embodiments, the parameter generation module specifically uses a random mask to mask the input data to obtain the target parameter as follows:
[0184] Calculate the modular multiplication of the random mask and the input data with respect to the modulus value to obtain the target parameter.
[0185] In some embodiments, when the effective bit length of the target parameter is less than the bit number threshold, the modular inverse process further includes:
[0186] Dividing the target parameter by the modulus value to obtain the quotient of the division;
[0187] Using the target parameter, the quotient of the division, and the modulus value to obtain the remainder of the division;
[0188] Based on the quotient and remainder obtained from the division, iteratively use modular arithmetic for the fifth coefficient and the sixth coefficient. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse;
[0189] Determine whether the remainder of the division is zero. If so, output the modular inverse of the target parameter with respect to the modulus value;
[0190] If not, return to the step of dividing the target parameter by the modulus value to obtain the quotient of the long division.
[0191] Correspondingly, in an exemplary embodiment of the present specification, there is also provided a data processing device, which is applied to a processor. The data processing device includes:
[0192] A security processing module, configured to encrypt or decrypt the target data using a target key in response to a security service request carrying the target data;
[0193] The target key is generated based on the key generation method described in any of the above embodiments.
[0194] For specific limitations on the key generation device and the data processing device, reference may be made to the limitations on the key generation method or the data processing method in the foregoing text, which will not be elaborated herein. Each module in the foregoing key generation device and data processing device may be implemented in whole or in part by software, hardware, and their combination. Each of the foregoing modules may be embedded in the processor in the computer device in the form of hardware or independent of the processor, or may be stored in the memory in the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to each of the foregoing modules.
[0195] Exemplary computing device
[0196] Another embodiment of the present application further provides a computing device. Refer to Figure 6 As shown, an exemplary embodiment of this specification further provides a computing device, including: a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it executes the steps in the key generation method or the data processing method according to various embodiments of this specification described in the foregoing embodiments of this specification.
[0197] The internal structure of this computing device may be as Figure 6 As shown, this computing device includes a processor, a memory, a network interface, and an input device connected through a system bus. Among them, the processor of this computing device is used to provide computing and control capabilities. The memory of this computing device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of this computing device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it performs the steps in the key generation method or the data processing method according to various embodiments of this specification described in the foregoing embodiments of this specification.
[0198] The processor may include a main processor, and may also include a baseband chip, a modem, etc.
[0199] The memory stores a program for implementing the technical solution of the present invention, and may also store an operating system and other key services. Specifically, the program may include program code, and the program code includes computer operation instructions. More specifically, the memory may include a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), other types of dynamic storage devices that can store information and instructions, a disk memory, a flash, etc.
[0200] The processor can be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the solution of the present invention. It can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0201] The input device can include devices for receiving user input data and information, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer or a gravity sensor, etc.
[0202] The output device can include devices for allowing output of information to the user, such as a display screen, a printer, a speaker, etc.
[0203] The communication interface can include devices of any transceiver type for communicating with other devices or communication networks, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.
[0204] The processor executes the program stored in the memory and calls other devices, which can be used to implement each step of any one of the key generation methods or data processing methods provided in the above embodiments of the present application.
[0205] The computing device may further include a display component and a voice component. The display component may be a liquid crystal display screen or an electronic ink display screen. The input device of the computing device may be a touch layer covering the display component, or a button, a trackball or a touchpad provided on the housing of the computing device, or an external keyboard, a touchpad or a mouse, etc.
[0206] Those skilled in the art can understand that Figure 6 the structure shown in
[0207] Exemplary computer program products and storage media
[0208] In addition to the above methods and devices, the key generation method or data processing method provided by the embodiments of this specification may also be a computer program product, which includes computer program instructions. When the computer program instructions are run by a processor, the processor is caused to execute the steps of the key generation method or data processing method according to various embodiments of this specification described in the "Exemplary Method" section above of this specification.
[0209] The computer program product can be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of this specification. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The programming code can be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0210] In addition, the embodiments of this specification also provide a computer-readable storage medium, on which a computer program is stored. The computer program is executed by a processor to perform the steps of the key generation method or data processing method according to various embodiments of this specification described in the "Exemplary Method" section above of this specification.
[0211] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it may include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided by this specification may include non-volatile and / or volatile memories. Non-volatile memories may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0212] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0213] The above-described embodiments merely represent several implementation manners of this specification, and their descriptions are relatively specific and detailed. However, it should not be construed as a limitation on the scope of the solutions provided by the embodiments of this specification. It should be noted that for those of ordinary skill in the art, without departing from the concept of this specification, several modifications and improvements can still be made, and these all belong to the protection scope of this specification. Therefore, the protection scope of the patent of this specification shall be subject to the appended claims.
Claims
1. A key generation method, characterized in that, Applied to a processor, the key generation method includes: In response to a key generation instruction carrying input data, execute a key generation process; The key generation process includes: Execute a modular inverse process based on the input data to obtain the modular inverse of the target parameter with respect to the modulus value; the target parameter is obtained based on the input data; Generate a target key based on the modular inverse of the target parameter with respect to the modulus value; The modular inverse process includes: Determine whether the effective bit length of the target parameter is greater than a bit threshold. If so, take the approximate values of the target parameter and the modulus value as the initial values of the dividend and divisor for approximate calculation respectively; the bit lengths of the approximate values of the target parameter and the modulus value are less than or equal to the bit threshold, and the bit threshold is the bit length of the signed integer division supported by the processor; During the calculation process of approximate division, obtain a first division result and a second division result by respectively expanding the dividend and the divisor. When the first division result and the second division result are the same, calculate the remainder following the extended Euclidean method and iterate the dividend and the divisor; The obtaining of the first division result and the second division result by respectively expanding the dividend and the divisor includes: Obtain the first division result by expanding the dividend and obtain the second division result by expanding the divisor.
2. The method according to claim 1, wherein The taking of the approximate values of the target parameter and the modulus value as the initial values of the dividend and divisor for approximate calculation respectively includes: Right-shift the target parameter and the modulus value by a target number of bits to obtain the approximate values of the target parameter and the modulus value, where the target number of bits is equal to the difference between the effective number of bits of the target parameter and the bit threshold.
3. The method according to claim 1, wherein The obtaining of the first division result and the second division result by respectively expanding the dividend and the divisor includes: Calculate the first division result and the second division result based on a first preset formula; The first preset formula includes: ; where q0 represents the first division result, q1 represents the second division result, a0 represents the dividend, a1 represents the divisor, u0 represents the first coefficient, u1 represents the second coefficient, v0 represents the third coefficient, v1 represents the fourth coefficient, u0 > u1, and v0 < v1.
4. The method according to claim 3, characterized in that After obtaining the first division result and the second division result by respectively expanding the dividend and the divisor, when the first division result and the second division result are not the same, it further includes: Determine whether a third coefficient is 0. If not, iterate the divisor and the dividend using the first coefficient, second coefficient, third coefficient, and fourth coefficient according to the iteration relationship. When the remainder is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit threshold; when the remainder is zero, output the modular inverse of the target parameter with respect to the modulus value; If so, perform a large number division and modular operation using the target parameter and the modulus value. When the remainder of the large number division and modular operation is zero, output the modular inverse of the target parameter with respect to the modulus value; when the remainder of the large number division and modular operation is not zero, return to the step of determining whether the effective bit length of the target parameter is greater than the bit threshold; The large number division and modulo operation include: obtaining a quotient and a remainder by using large number division, and iterating a fifth coefficient and a sixth coefficient by using modulo operation based on the quotient and the remainder obtained by the large number division. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse.
5. The method according to claim 4, wherein Before obtaining the first division result and the second division result by separately expanding the dividend and the divisor, it further includes: judging whether the divisor of the approximate division is zero. If not, then enter the step of obtaining the first division result and the second division result by separately expanding the dividend and the divisor in the calculation process of the approximate division; If so, then enter the step of judging whether the third coefficient is 0.
6. The method according to claim 4, characterized in that, The iterating the divisor and the dividend by using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient according to the iteration relationship includes: iterating the divisor and the dividend by using the first coefficient, the second coefficient, the third coefficient and the fourth coefficient based on a second preset formula; The second preset formula includes: ; wherein, r represents the remainder.
7. The method according to any one of claims 1 to 6, characterized in that, The generation process of the target parameter includes: masking the input data by using a random mask to obtain the target parameter.
8. The method according to claim 7, characterized in that, The masking the input data by using a random mask to obtain the target parameter includes: calculating the modular multiplication of the random mask and the input data with respect to the modulus value to obtain the target parameter.
9. The method according to any one of claims 1 to 6, characterized in that, When the effective bit length of the target parameter is less than the bit threshold, the modular inverse process further includes: dividing the target parameter by the modulus value to obtain the quotient of the division; using the target parameter, the quotient of the division and the modulus value to obtain the remainder of the division; iterating the fifth coefficient and the sixth coefficient by using modulo operation based on the quotient and the remainder obtained by the division. Both the fifth coefficient and the sixth coefficient are coefficients in the extended Euclidean method, and the fifth coefficient is used to calculate the modular inverse; judging whether the remainder of the division is zero. If so, then output the modular inverse of the target parameter with respect to the modulus value; If not, then return to the step of dividing the target parameter by the modulus value to obtain the quotient of the large number division.
10. A data processing method, characterized in that, Applied to a processor, the data processing method includes: responding to a security service request carrying target data, and encrypting or decrypting the target data by using a target key; The target key is generated based on the key generation method according to any one of claims 1 to 7.
11. A computing device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the key generation method according to any one of claims 1 to 9 or the data processing method according to claim 10.
12. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements the key generation method according to any one of claims 1 to 9 or the data processing method according to claim 10.
Citation Information
Patent Citations
Modular inverse operation unit
CN105988771A
Data processing method, medium, electronic device and program product
CN115357216A
Data encryption method, device and system, electronic equipment and storage medium
CN117014208A