Software and hardware collaborative anti-quantum public key cryptographic algorithm implementation method
Through the method of software and hardware collaboration, a hierarchical cryptographic algorithm engine architecture and hardware integrated circuit are used to solve the problems of low security and poor practicality in existing post-quantum cryptographic algorithm applications, and efficient and flexible post-quantum algorithm operations are achieved.
Patent Information
- Application Number
- CN202510340412.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-17
AI Technical Summary
The actual application of existing post-quantum cryptographic algorithms has problems of low security and poor practicality, and the existing technology is difficult to flexibly expand new post-quantum algorithms.
Using a software and hardware collaboration method, the cryptographic algorithm logic resources are compiled through a micro-instruction code compiler, and combined with the hierarchical cryptographic algorithm engine architecture, the basic computing layer is implemented using hardware integrated circuits, supporting the operations of a variety of post-quantum algorithms.
It realizes the advantages of high hardware performance when consuming less hardware resources, and also gives full play to the flexibility of software implementation, supports diversified post-quantum algorithms, and improves security and practicality.
Smart Images

Figure CN120165868A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more particularly to a method for implementing a software and hardware collaborative quantum-resistant public key cryptography algorithm. Background Art
[0002] With the continuous development of quantum technology, the computing power of quantum computers has been continuously enhanced. In the field of encryption technology, conventional public key cryptography algorithms can be broken by large enough and stable quantum computers, making these public key cryptography algorithms no longer meet the encryption requirements under the new situation. Post-Quantum Cryptography (PQC) algorithms, also known as quantum-resistant cryptography algorithms, refer to cryptography algorithms that can resist attacks from quantum computers in the era of quantum computing. In related technologies, most researchers conduct research based on the algorithm theory of post-quantum cryptography, lacking research on the specific implementation of post-quantum cryptography operation hardware circuits, resulting in problems such as low security and poor practicability in the actual application of post-quantum cryptography algorithms.
[0003] Publication No. CN 117792628A discloses a post-quantum cryptography operation chip. The post-quantum operation unit includes multiple post-quantum operation components, and each post-quantum operation component is used for the cryptographic operation process of a post-quantum algorithm. The post-quantum operation components mainly implement various post-quantum cryptography algorithms based on hardware IP. When it is necessary to expand for a new post-quantum algorithm, the hardware IP of the new post-quantum algorithm needs to be added to the post-quantum operation unit. This method supports relatively fixed algorithms and has problems such as high resource consumption and poor flexibility. Summary of the Invention
[0004] Therefore, in order to better solve the above technical problems, the present invention is proposed. An embodiment of the present invention provides a method for implementing a software and hardware collaborative quantum-resistant public key cryptography algorithm. The technical solution is as follows:
[0005] In a first aspect, an embodiment of the present invention provides a method for implementing a software and hardware collaborative quantum-resistant public key cryptography algorithm, which is used in a cryptographic chip. The method includes:
[0006] Obtain the first cryptographic algorithm logic resource compiled by a micro-instruction code compiler, and save the first cryptographic algorithm logic resource to a first memory unit;
[0007] Obtain the first target information from a data interface, where the first target information includes cryptographic key information, and when the first target information meets the threshold condition, obtain a second cryptographic algorithm and a first rule according to the first target information, and send the first target information, the second cryptographic algorithm, and the first rule to a cryptographic algorithm engine;
[0008] Obtain the first operation result from the cryptographic algorithm engine, save the first operation result in the first cache unit, and return the first operation result through the data interface.
[0009] In the above method for implementing a software-hardware collaborative quantum-resistant public key cryptographic algorithm, the micro-instruction code compiler further includes: micro-control instructions, which are used to schedule the hardware resources required to implement the logical functions of the first cryptographic algorithm, the execution order of the sub-operation logic units, and pipeline and parallel control, etc.
[0010] In the above method for implementing a software-hardware collaborative quantum-resistant public key cryptographic algorithm, the step of determining that the first target information meets the threshold condition includes: determining the data volume of the first target information, where when the data volume of the first target information is less than the first threshold, the first target information does not meet the threshold condition, and generating the first feedback information; determining the second cryptographic algorithm of the first target information, obtaining the set of quantum-resistant cryptographic algorithms of the cryptographic chip, where when the set of quantum-resistant cryptographic algorithms of the cryptographic chip does not include the second cryptographic algorithm, the first target information does not meet the threshold condition, and generating the second feedback information.
[0011] In the above method for implementing a software-hardware collaborative quantum-resistant public key cryptographic algorithm, the step of determining the second cryptographic algorithm of the first target information includes: the basic COS sub-layer performs data parsing on the first target information based on the pre-stored data parsing rules to obtain the second cryptographic algorithm of the first target information and the first rule, where the basic COS sub-layer is the core software sub-layer of the cryptographic chip, and the first rule includes key pair generation, signature generation, signature verification, data encryption, and data decryption.
[0012] In the above-mentioned method for implementing a software-hardware collaborative quantum-resistant public key cryptography algorithm, the cryptographic algorithm engine includes: a first operation layer for implementing core underlying operations, where the underlying operations include modulo addition, modulo subtraction, modulo multiplication, modular inverse, butterfly operations, and random sampling, etc., and the first operation layer is implemented by a hardware integrated circuit; a second operation layer for implementing various operations at the intermediate level of the quantum-resistant public key cryptography algorithm, where the operations of the second operation layer include NTT operations, polynomial addition, polynomial multiplication, polynomial modular inverse, polynomial generation, vector operations, matrix operations, and Gaussian sampling, etc., and the various operations of the second operation layer are implemented through various second operation operators, and the second operation operators are implemented by a hardware integrated circuit; a third operation layer for implementing the NIST third-round post-quantum algorithms, where the NIST third-round post-quantum algorithms include Kyber quantum-resistant algorithm, McEliece quantum-resistant algorithm, Saber quantum-resistant algorithm, Dilithium quantum-resistant algorithm, Falcon quantum-resistant algorithm, Sphincs quantum-resistant algorithm, Rainbow quantum-resistant algorithm, and the third operation layer realizes the various post-quantum algorithms by controlling the operations of the second operation layer through microinstructions.
[0013] In the above-mentioned method for implementing a software-hardware collaborative quantum-resistant public key cryptography algorithm, the first operation layer includes: a first arithmetic operation unit, where the first arithmetic operation unit is an arithmetic operation array AEA, and the arithmetic operation array AEA is an n×n AE array, where AE is an operator of the first operation layer, and AE can independently implement the underlying operations; a first data generation unit for pseudo-random number generation and random distribution sampling; a first data storage unit for the AE array and the first data generation unit to read and store data.
[0014] In the above-mentioned method for implementing a software-hardware collaborative quantum-resistant public key cryptography algorithm, the first data generation unit includes: a pseudo-random number generator based on the HASH algorithm for generating pseudo-random numbers; a sampling circuit for random distribution sampling.
[0015] In the above-mentioned method for implementing a software-hardware collaborative quantum-resistant public key cryptography algorithm, the second operation operator is implemented by scheduling the arithmetic operation array AEA operation of the first operation layer.
[0016] In a second aspect, an embodiment of the present invention provides a software-hardware collaborative quantum-resistant public key cryptography algorithm operation chip, where the cryptographic operation chip includes:
[0017] A micro-instruction code compiler for compiling a first cryptographic algorithm logic function implemented using micro-control instructions to form a first cryptographic algorithm logic resource, and the first cryptographic algorithm logic resource is a piece of machine code that can be executed by the cryptographic algorithm engine;
[0018] A first memory unit for storing first cryptographic algorithm logic resources;
[0019] A data acquisition unit for communicating with an application layer interface, including receiving first target information sent by the application layer interface;
[0020] A data processing unit for parsing the first target information to obtain a second cryptographic algorithm and a first rule of the first target information;
[0021] A cryptographic algorithm implementation unit for implementing post-quantum cryptographic algorithms;
[0022] A feedback unit for receiving first and second feedback information and providing feedback;
[0023] An instruction parsing unit for analyzing instructions sent by a main controller or an instruction stream memory and allocating the instructions to corresponding modules for execution;
[0024] A functional operation unit for implementing functional operations of PQC algorithms, including an NTT operation circuit;
[0025] An arithmetic operation array for implementing basic operations of PQC algorithms, where the AEA includes an n x n AE operation operator, and the AE operation operator can independently implement underlying operations such as modular addition and modular subtraction;
[0026] A data generation unit for generating pseudo-random numbers and performing random distribution sampling;
[0027] A data storage unit for the AE array and the data generation unit to read and store data;
[0028] A first cache unit for storing the operation results of the cryptographic algorithm engine.
[0029] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above-mentioned software and hardware collaborative post-quantum public key cryptographic algorithm implementation method is implemented.
[0030] Compared with the prior art, the beneficial effects of the present invention are at least as follows:
[0031] After analyzing the post-quantum algorithms selected in the third round of NIST (National Institute of Standards and Technology), the basic mathematical problems of the present invention include lattice-based cryptography, multivariate and other schemes, all of which have common basic operations. On the basis of the basic operations, core operation operators of various different schemes are formed. Therefore, the functions of the quantum-resistant cryptographic algorithm are divided, and a hierarchical cryptographic algorithm engine architecture is adopted. The basic operation layer consists of AE operators to form an AEA computing array. Each AE operator can independently complete various underlying operation functions including modular addition, modular subtraction, modular multiplication, butterfly operation, random sampling, etc. The AE operator is implemented by a hardware integrated circuit to give full play to the high operation performance of hardware implementation. The AE is designed in an array form to achieve parallel operation and further improve the operation performance. AE can be interconnected to form operations that support different upper-level core operation layers. For example, multiple AEs can form an NTT (Number Theoretic Transforms) operation operator, and multiple AEs can form an nx32bit modular operation, so as to effectively utilize the on-chip logic resources and achieve an effective balance between resources and performance. Then, through software scheduling, it supports quantum-resistant public key algorithm protocols including lattice bases and other mathematical problems, realizes the functions of the quantum-resistant algorithm protocol layer, and further supports NIST third-round post-quantum algorithms such as Kyber, McEliece, Saber, and Rainbow. Through the above solutions, the high performance of hardware implementation can be fully utilized with less consumption of hardware resources, and at the same time, the high flexibility of software implementation can be exerted, which can flexibly support the implementation of other post-quantum algorithms in the future, thereby meeting the diverse needs of algorithms. Description of the Drawings
[0032] By describing the embodiments of the present application in more detail with reference to the accompanying drawings, the above and other objects, features, and advantages of the present application will become more apparent. The accompanying drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. They are used together with the embodiments of the present application to explain the present application and do not constitute a limitation to the present application. In the accompanying drawings, the same reference numerals generally represent the same components or steps.
[0033] Figure 1 The flowchart of the method for implementing a software-hardware collaborative quantum-resistant public key cryptographic algorithm according to an embodiment of the present application is illustrated;
[0034] Figure 2 The architecture diagram of a cryptographic algorithm chip according to an embodiment of the present application is illustrated;
[0035] Figure 3 The hierarchical architecture diagram of a cryptographic algorithm engine according to an embodiment of the present application is illustrated;
[0036] Figure 4 The figure shows a flowchart of a method for implementing a software-hardware collaborative quantum-resistant public key cryptography algorithm according to another embodiment of the present application;
[0037] Figure 5 The figure shows a structural diagram of the first operation layer of a cryptographic algorithm engine according to an embodiment of the present application;
[0038] Figure 6 The figure shows a schematic block diagram of an AE operator according to an embodiment of the present application;
[0039] Figure 7 The figure shows a structural framework diagram of a cryptographic algorithm chip provided according to an embodiment of the present application; Detailed implementation manners
[0040] Next, exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only a part of the embodiments of the present application, rather than all the embodiments of the present application, and the present application is not limited by the exemplary embodiments described herein.
[0041] Figure 1 The figure shows a flowchart of a method for implementing a software-hardware collaborative quantum-resistant public key cryptography algorithm provided according to an embodiment of the present application.
[0042] As Figure 1 shown, the method for implementing a software-hardware collaborative quantum-resistant public key cryptography algorithm according to an embodiment of the present application may include step S100, step S200, and step S300.
[0043] In step S100, obtain the first cryptographic algorithm logic resource compiled by a micro-instruction code compiler, and save the first cryptographic algorithm logic resource to a first memory unit.
[0044] Specifically, an algorithm engineer reads the algorithm description and implements the algorithm logic function using micro-control instructions. Then, after being compiled by the micro-instruction code compiler, these algorithm logic functions form the logic resources of the cryptographic algorithm. These logic resources are actually a piece of machine code that can be executed by the cryptographic algorithm engine. Then, the cryptographic algorithm logic resources will be stored in the first memory unit of the cryptographic chip. The first memory unit may be a static random access memory (SRAM). The data stored in the static random access memory can be read out in a non-destructive manner. The first memory unit may be a dedicated storage area for the cryptographic algorithm of the cryptographic algorithm engine and can be used to store the implementation of the algorithm protocol of the quantum-resistant cryptographic algorithm.
[0045] Further, step S100 further includes micro-control instructions for scheduling the hardware resources required to implement the first cryptographic algorithm logic function, the execution order of the sub-operation logic units, and pipeline and parallel control, etc.
[0046] Specifically, the micro-control instructions are a set of hardware control instruction sets for controlling the internal logic resource connection, operation, and logic control of the cryptographic chip.
[0047] In step S200, obtain the first target information from the data interface, where the first target information includes cryptographic key information, and when the first target information meets the threshold condition, obtain the second cryptographic algorithm and the first rule according to the first target information, and send the first target information, the second cryptographic algorithm, and the first rule to the cryptographic algorithm engine.
[0048] Next, it will be combined with Figures 2 to 6 to specifically illustrate the detailed process of judging whether the first target information meets the threshold condition and obtaining the second cryptographic algorithm and the first rule according to the first target information.
[0049] Figure 2 The figure illustrates the architecture diagram of the cryptographic algorithm chip according to an embodiment of the present application. As Figure 2 shown, the cryptographic algorithm chip architecture may include module firmware, module hardware, and a development verification system, etc. The development verification system can be used to provide complete tools and interface systems for the secondary development of the cryptographic chip, mainly including micro-control instructions and micro-instruction code compilers, etc., that is, the micro-control instructions and micro-instruction code compilers described in step S100. The module firmware may include a basic COS sub-layer and a secondary development support sub-layer. The secondary development support sub-layer can be used to provide a basic software interface layer for developers. Through this interface layer, the hardware complexity is maximally shielded and the development process is simplified, mainly including interface such as cryptographic algorithm call access interfaces and communication access interfaces. Figure 4 The figure illustrates the flowchart of the software and hardware collaborative quantum-resistant public key cryptographic algorithm implementation method according to another embodiment of the present application. As Figure 4 shown, the basic COS sub-layer may include a data interface 401, a data processing unit 402, a feedback unit 403, etc. The basic COS sub-layer is the core software sub-layer of the cryptographic chip. The data interface 401 can be a communication interface used when the basic COS sub-layer interacts with the application layer data interface. The data interface 401 can preliminarily convert the data received from the application layer data interface to obtain data suitable for processing by the cryptographic chip, that is, the first target data. The first target information includes cryptographic key information, plaintext and ciphertext information.
[0050] Further, step S200 further includes determining whether the first target information meets the threshold condition. According to an embodiment of the present application, the step of determining that the first target information meets the threshold condition includes: S210 determining the data volume of the first target information, where when the data volume of the first target information is less than the first threshold, the first target information does not meet the threshold condition, and generating first feedback information; S220 determining the second cryptographic algorithm of the first target information, and obtaining the set of quantum-resistant cryptographic algorithms of the cryptographic chip, where when the set of quantum-resistant cryptographic algorithms of the cryptographic chip does not include the second cryptographic algorithm, the first target information does not meet the threshold condition, and generating second feedback information.
[0051] According to an embodiment of the present application, in step S210, the first threshold may be a threshold set according to the data volume. For example, the first threshold may be a single character. When the first target data is an empty string, it does not meet the threshold condition, and first feedback information is generated. The feedback unit 403 can be used to receive the first feedback information at this time and return the feedback information to the application layer data interface through the data interface 401.
[0052] Then in step S220, the second cryptographic algorithm of the first target information is determined, and then it is determined whether the first target information meets the second threshold condition.
[0053] Specifically, the second cryptographic algorithm of the first target information can be obtained by the data processing unit 402 of the basic COS sublayer based on the pre-stored data parsing rules to parse the first target information. At the same time, the first rule of the first target information can be obtained. The first rule may include key pair generation, signature generation, signature verification, data encryption, and data decryption. Optionally, the data parsing rules may be stored in the first memory unit 405 or other storage units, and the parsing rules may change accordingly according to the changes in the quantum-resistant algorithms. Then the data processing unit 402 obtains the set of quantum-resistant cryptographic algorithms of the cryptographic chip. If the set of quantum-resistant cryptographic algorithms does not include the second cryptographic algorithm of the first target information, it can be determined that the first target information does not meet the threshold condition, and second feedback information is generated. The feedback unit 403 can be used to receive the second feedback information at this time and return the feedback information to the application layer data interface through the data interface 401; if the set of quantum-resistant cryptographic algorithms includes the second cryptographic algorithm of the first target information, it can be determined that the first target information meets the threshold condition, and at this time, the first target information, the second cryptographic algorithm, and the first rule are sent to the cryptographic algorithm engine for operation and execution.
[0054] After analyzing the post - quantum algorithms selected in the third round of NIST (National Institute of Standards and Technology), its basic mathematical problems include lattice - based cryptography, multivariate and other schemes, all of which have common basic operations. On the basis of these basic operations, the core operation operators of various different schemes are formed. Therefore, the functions of the quantum - resistant cryptographic algorithms are divided, and a hierarchical cryptographic algorithm engine architecture is adopted to implement the operations of the cryptographic algorithms.
[0055] Figure 3 The figure shows the hierarchical architecture diagram of the cryptographic algorithm engine according to an embodiment of the present application.
[0056] As Figure 3 and 4 shown, the cryptographic algorithm engine according to an embodiment of the present application may include a first operation layer 406, a second operation layer 407, and a third operation layer 408.
[0057] As Figure 3 and Figure 4 shown, the first operation layer 406 is used to implement the core underlying operations, where the underlying operations include: modular addition, modular subtraction, modular multiplication, modular inversion, butterfly operation, and random sampling, etc. The first operation layer is implemented by a hardware integrated circuit.
[0058] Specifically, the first operation layer 406 consists of AE operators to form an AEA computing array. Each AE operator can independently complete various underlying operation functions including modular addition, modular subtraction, modular multiplication, butterfly operation, random sampling, etc. The AE operator is implemented by a hardware integrated circuit to take advantage of the high computing performance of hardware implementation. The AE is designed in an array form, which can achieve parallel operations and further improve the computing performance. The first operation layer 406 may include the structure as Figure 5 shown.
[0059] Figure 5 The figure shows the structure diagram of the first operation layer of the cryptographic algorithm engine according to an embodiment of the present application.
[0060] As Figure 5 shown, the first operation layer 406 may include a first arithmetic operation unit 501, a first data generation unit 502, and a first data storage unit 503.
[0061] Specifically, the first arithmetic operation unit 501 is composed of an AEA computing array formed by AE operators. Each AE operator can independently complete various underlying operation functions including modular addition, modular subtraction, modular multiplication, butterfly operation, random sampling, etc., and is implemented by a hardware integrated circuit. For example, the AEA computing array can be composed of 4x4 AE operators, and different AEs can operate in parallel or in a pipelined manner. At this time, the computing array AEA can simultaneously implement 16-way parallel modular operations or butterfly operations. The first data storage unit 503 can be used for the AE array and the first data generation unit 502 to read and store data. Optionally, the first data storage unit 503 can have a large-capacity RAM memory and a working data register group, and the connection relationship between the working register group and the data stream of the AEA can be configured. The first data generation unit 502 can be used for pseudo-random number generation and random distribution sampling.
[0062] Furthermore, the first data generation unit 502 can include a pseudo-random number generator 5021 and a sampling circuit 5022.
[0063] Specifically, the pseudo-random number generator 5021 can be a pseudo-random number generator based on the HASH algorithm, which is used for generating pseudo-random numbers and can also support various other hashing algorithms required by the PQC algorithm for outputting pseudo-random sequences. The sampling circuit 5022 can have various random sampling functions, such as uniform sampling, binomial distribution sampling, rejection sampling, etc.
[0064] Furthermore, the AE operator is implemented by a hardware integrated circuit and supports various underlying basic operation functions. For example, the function of the AE operator can be implemented using the block diagram as Figure 6 shown.
[0065] Figure 6 The figure shows a schematic block diagram of an AE operator according to an embodiment of the present application.
[0066] As Figure 6As shown, a basic AE can be designed as a processing unit with five inputs and two outputs. In the figure, MA is a reconfigurable addition unit that supports arithmetic operations such as addition, subtraction, modular addition, modular subtraction, and exclusive OR. MM is a reconfigurable multiplication module that supports binary field multiplication and integer multiplication. The squares are registers. The AE unit has five input signals, A, B, w, m, and q, and two output signals, S1 and S2. For example, taking the butterfly operation as an example, A and B are the operands of the operation, w is the rotation factor, m is the modulus parameter of the Montgomery modular multiplier, and q is the modulus. Among them, m and q come from the modulus and modulus parameter registers, and A, B, and w come from the working register bank. The two output signals are the two outputs of the butterfly operation. There is also a function configuration register CFGR inside each AE unit. The configuration code of this AE is stored in CFGR. The configuration circuit CFDC parses the configuration code into the configuration signals CF_signals of each MA and MM. Both MA and MM determine their own functions according to the configuration signals, and the output results S1 and S2 are also selected according to the configuration code. Finally, the overall circuit can complete different basic arithmetic functions, and the configuration register CFGR can be configured by configuration instructions. In addition, each MA and MM has a clock gating function. When the AE function selected by the configuration code requires a certain MA or MM, the clock of the input register of this MA or MM is gated off to achieve the purpose of reducing power consumption. The AE operation code and its corresponding arithmetic relationship are shown in Table 1.
[0067] Table 1 AE Arithmetic Function Table
[0068]
[0069]
[0070] MA is the modular addition operation unit in AE. Although it is named modular addition operation, it can still support multiple configuration arithmetic functions, including modular addition, modular subtraction, bit addition, bit subtraction, etc. MM is the modular multiplication operation unit in AE. Similar to MA, it also has multiple configurable functions. The function tables of the MA and MM arithmetic units are shown in Tables 2 and 3.
[0071] Table 2 MA Arithmetic Unit Function Table
[0072] Serial number Opcode MA function Supported data length 1 {0000} MOD-ADD 8 - 32bit 2 {0001} MOD-SUB 8 - 32bit 3 {0010} ADD 8 - 32bit 4 {0011} SUB 8 - 32bit 5 {0100} AND 8 - 32bit 6 {0101} OR 8 - 32bit 7 {0110} XOR 8 - 32bit 8 {0111} PASS-A 8 - 32bit 9 {1000} PASS-B 8 - 32bit 10 other No function, output 0 8 - 32bit
[0073] Table 3 MM Arithmetic Unit Function Table
[0074] Serial number Opcode MM function Supported data length 1 {0} MUL 8 - 32bit 2 {1} GF2M_MUL 8 - 32bit
[0075] Return to reference Figure 3 and Figure 4, the second operation layer 407 is used to implement various operations at the intermediate level of the quantum-resistant public key cryptography algorithm. The operations of the second operation layer include: NTT operation, polynomial addition, polynomial multiplication, polynomial modular inverse, polynomial generation, vector operation, matrix operation, and Gaussian sampling, etc. The various operations of the second operation layer are implemented through various second operation operators, and the second operation operators are implemented by hardware integrated circuits.
[0076] Specifically, among the lattice-based post-quantum cryptographic operations, the most time-consuming and computationally intensive is the NTT operation, which constitutes polynomial and vector calculations, and vector calculations constitute matrix operations. Its public and private key generation, signature, signature verification, and public key encryption and decryption operations all require operations centered around NTT. The NTT operation is equivalent to the point operation in ECC and the modular exponentiation operation in RSA. The second operation layer 407 can be implemented by various second operation operators implemented by hardware integrated circuits. For example, the second operation operators include NTT operation operator (NTT), polynomial modular multiplication operation operator (POM), vector and matrix operation operator (MAO), etc. The parameters of its operations can be flexibly configured to support different algorithms and different security levels.
[0077] Furthermore, the second operation operator is implemented by scheduling the arithmetic operation array AEA of the first operation layer for operation.
[0078] Specifically, taking the NTT operation operator as an example, it can be implemented by a single AE array element or by an AEA array formed by multiple AEs. A single AE array element occupies less resources but requires more running rounds and can support multiple concurrent NTT operations at the same time. The AEA array of multiple AE array elements occupies relatively more resources, but the number of running rounds is reduced, so the running speed is high. The embodiments of the present application adopt the AEA array formed by multiple AE array elements to implement the function of the second operation operator. Of course, it can also be implemented by a single AE array element from the perspective of less resource occupancy and support for more concurrent NTT operations.
[0079] In reference Figure 3 and Figure 4 , the third operation layer 408 is used to implement the NIST third-round post-quantum algorithm. The NIST third-round post-quantum algorithm includes: Kyber quantum-resistant algorithm, McEliece quantum-resistant algorithm, Saber quantum-resistant algorithm, Dilithium quantum-resistant algorithm, Falcon quantum-resistant algorithm, Sphincs quantum-resistant algorithm, Rainbow quantum-resistant algorithm. The third operation layer realizes the various post-quantum algorithms by microinstructions controlling the operations of the second operation layer.
[0080] Specifically, the third operation layer 408 is an algorithm protocol layer for quantum-resistant algorithms, responsible for the specific implementation of various NIST post-quantum algorithms in the third round. Based on the operation support of the second operation layer 407, it can realize various functional operation operators of the second operation layer 407 through microinstructions, and finally form a quantum-resistant algorithm layer that supports quantum-resistant algorithms including Kyber, McEliece, Saber, Dilithium, Falcon, Sphincs, Rainbow, etc. At the same time, based on the hierarchical cryptographic algorithm engine architecture, other quantum-resistant algorithms can be flexibly and conveniently implemented in the later stage, thus meeting the requirements of algorithm diversity.
[0081] Return reference Figure 1 , in step S300, obtain the first operation result from the cryptographic algorithm engine, save the first operation result in the first cache unit, and return the first operation result through the data interface.
[0082] Specifically, the cryptographic algorithm engine can start operation execution according to the first target information, the second cryptographic algorithm, and the first rule. For example, find the corresponding quantum-resistant algorithm according to the second cryptographic algorithm, and determine the specific requirement of the operation as one of encryption, decryption, public-private key generation, data signature, and signature verification according to the first rule. Then start a series of operations on the first target information, and finally obtain the operation result. The operation result is cached in the first cache unit 404 such as Figure 4 . Finally, the processor reads the operation result from the first cache unit 404 according to the received operation end signal and returns it to the application layer data interface through the data interface 401.
[0083] Figure 7 The figure shows the structural framework diagram of a cryptographic algorithm chip provided by an embodiment of the present application.
[0084] As Figure 7 shown, a software and hardware collaborative quantum-resistant public key cryptographic algorithm operation chip according to an embodiment of the present application includes:
[0085] A microinstruction code compiler 701 for compiling the first cryptographic algorithm logic function implemented by microcontrol instructions to form the first cryptographic algorithm logic resource, where the first cryptographic algorithm logic resource is a piece of machine code that can be executed by the cryptographic algorithm engine;
[0086] A first memory unit 702 for storing the first cryptographic algorithm logic resource;
[0087] A data acquisition unit 703 for communicating with the application layer interface, including receiving the first target information sent by the application layer interface;
[0088] A data processing unit 704 for parsing the first target information to obtain the second cryptographic algorithm and the first rule of the first target information;
[0089] A feedback unit 705 for receiving the first and second feedback information and providing feedback;
[0090] A cryptographic algorithm implementation unit 706 for implementing post-quantum cryptographic algorithms;
[0091] An instruction parsing unit 707 for analyzing instructions sent by the main control or the instruction stream memory and allocating the instructions to corresponding modules for execution;
[0092] A functional operation unit 708 for implementing the functional operations of the PQC algorithm, including an NTT operation circuit;
[0093] An arithmetic operation array AEA 709 for implementing the basic operations of the PQC algorithm, where the AEA includes an n×n AE operation operator, and the AE operation operator can independently implement underlying operations such as modular addition and modular subtraction;
[0094] A data generation unit 710 for generating pseudo-random numbers and performing random distribution sampling;
[0095] A data storage unit 711 for the AEA array and the data generation unit to read and store data;
[0096] A first cache unit 712 for saving the operation results of the cryptographic algorithm engine.
[0097] In one example, in the cryptographic algorithm operation chip, the data acquisition unit 703 can be used to: preliminarily convert the data received from the application layer data interface to obtain data suitable for processing by the cryptographic chip, that is, the first target data; in response to the feedback information of the feedback unit 705, return the feedback information to the application layer data interface; and in response to the operation end signal of the cryptographic operation engine, return the operation result to the application layer data interface.
[0098] In one example, in the cryptographic algorithm operation chip, the data parsing of the first target information by the data processing unit 704 may include: determining whether the first target information meets the threshold condition; and in response to the first target information not meeting the threshold condition, generating corresponding feedback information.
[0099] Those skilled in the art can understand that other details of a software and hardware collaborative post-quantum public key cryptographic algorithm operation chip according to an embodiment of the present application are the same as the corresponding details described in a software and hardware collaborative post-quantum public key cryptographic algorithm implementation method according to an embodiment of the present application, and will not be repeated here to avoid redundancy.
[0100] An embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned method for implementing a software and hardware collaborative quantum-resistant public key cryptography algorithm is realized.
[0101] The basic principles of the present application have been described above in conjunction with specific embodiments. It should be understood that the above-disclosed specific details are only for the purposes of illustration and easy understanding, rather than limitations, and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for implementing a software-hardware collaborative quantum-resistant public key cryptographic algorithm, which is applied to a cryptographic chip, characterized in that: The method comprises: Acquire a first cryptographic algorithm logic resource compiled by a microinstruction code compiler, and save the first cryptographic algorithm logic resource to a first memory unit; Acquire first target information from a data interface, wherein the first target information includes cryptographic key information, and obtain a second cryptographic algorithm and a first rule according to the first target information when the first target information satisfies a threshold condition, and send the first target information, the second cryptographic algorithm and the first rule to a cryptographic algorithm engine; A first operation result is obtained from a cryptographic algorithm engine, the first operation result is stored in a first cache unit, and the first operation result is returned through a data interface.
2. A method for implementing a software-hardware collaborative quantum-resistant public key cryptographic algorithm as claimed in claim 1, characterized in that: The microinstruction code compiler further comprises: Micro-control instructions, wherein the micro-control instructions are used to schedule the hardware resources required to implement the first cryptographic algorithm logic function, the execution order of the sub-operation logic units, and pipeline and parallel control.
3. The method according to claim 1, characterized in that The step of determining that the first target information meets the threshold condition includes: Determining the data volume of the first target information, wherein when the data volume of the first target information is less than a first threshold, the first target information does not meet the threshold condition, and first feedback information is generated; Determine a second cryptographic algorithm for the first target information, and obtain a quantum-resistant cryptographic algorithm set of the cryptographic chip, wherein when the quantum-resistant cryptographic algorithm set of the cryptographic chip does not include the second cryptographic algorithm, the first target information does not meet the threshold condition, and second feedback information is generated.
4. The method according to claim 3, characterized in that The step of determining the second cryptographic algorithm for the first target information comprises: The basic COS sublayer performs data parsing on the first target information based on pre-stored data parsing rules to obtain the second cryptographic algorithm and the first rule of the first target information, wherein the basic COS sublayer is the core software sublayer of the cryptographic chip, and the first rule includes key pair generation, signature generation, signature verification, data encryption and data decryption.
5. The method according to claim 1, characterized in that The cryptographic algorithm engine comprises: The first operation layer is used to implement the core underlying operations, the underlying operations include: modular addition, modular subtraction, modular multiplication, modular inversion, butterfly operation and random sampling, etc. The first operation layer is implemented by hardware integrated circuits; The second operation layer is used to implement various operations at the intermediate level of the quantum-resistant public key cryptographic algorithm. The operations of the second operation layer include: NTT operation, polynomial addition, polynomial multiplication, polynomial modular inversion, polynomial generation, vector operation, matrix operation and Gaussian sampling, etc. The various operations of the second operation layer are implemented by various second operation operators, and the second operation operators are implemented by hardware integrated circuits; The third computing layer is used to implement the NIST third round of post-quantum algorithms, which include: Kyber anti-quantum algorithm, McEliece anti-quantum algorithm, Saber anti-quantum algorithm, Dilithium anti-quantum algorithm, Falcon anti-quantum algorithm, Sphincs anti-quantum algorithm, and Rainbow anti-quantum algorithm. The third computing layer controls the operations of the second computing layer through microinstructions to implement the various post-quantum algorithms.
6. The method according to claim 5, characterized in that The first computing layer comprises: A first arithmetic operation unit, wherein the first arithmetic operation unit is an arithmetic operation array AEA, and the arithmetic operation array AEA is an nxn AE array, wherein the AE is an operator of the first operation layer, and the AE can independently implement the bottom layer operation; A first data generation unit, used for pseudo-random number generation and random distribution sampling; The first data storage unit is used for the AE array and the first data generation unit to read and store data.
7. The method according to claim 6, characterized in that The first data generating unit includes: Pseudo-random number generator based on HASH algorithm, used to generate pseudo-random numbers; A sampling circuit is used for randomly distributed sampling.
8. The method according to claims 5-6, characterized in that The second operation operator is implemented by scheduling the arithmetic operation array AEA operation of the first operation layer.
9. A software-hardware collaborative quantum-resistant public key cryptographic algorithm computing chip, characterized in that: The chip comprises: A microinstruction code compiler, used for compiling a first cryptographic algorithm logic function implemented by a microcontroller instruction to form a first cryptographic algorithm logic resource, wherein the first cryptographic algorithm logic resource is a machine code that can be executed by a cryptographic algorithm engine; A first memory unit, used to store a first cryptographic algorithm logic resource; A data acquisition unit, configured to communicate with the application layer interface, including receiving first target information sent by the application layer interface; A data processing unit, used for performing data analysis on the first target information to obtain a second cryptographic algorithm and a first rule for the first target information; Cryptographic algorithm implementation unit, used for the implementation of quantum-resistant cryptographic algorithms; A feedback unit, configured to receive the first and second feedback information and provide feedback; The instruction parsing unit is used to analyze the instructions sent by the master control or instruction stream memory and assign the instructions to the corresponding Module execution; A functional operation unit, used to implement the functional operation of the PQC algorithm, including an NTT operation circuit; Arithmetic operation array, used to implement the basic operations of the PQC algorithm, where AEA contains nxn AE operation operators. The AE operation operator can independently implement low-level operations including modular addition and modular subtraction; A data generation unit, used for generating pseudo-random numbers and randomly distributed sampling; A data storage unit, used for the AE array and the data generation unit to read and store data; The first cache unit is used to store the calculation results of the cryptographic algorithm engine.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Post quantum cryptographic operation chip
CN117792628A
Cited By
Post-quantum cryptography algorithm security implementation method and system for resisting side channel attack
CN121814297A
A secure implementation method and system for post-quantum cryptography algorithms resistant to side-channel attacks
CN121814297B