Lattice-based cryptographic algorithm-oriented anti-side-channel-attack NTT circuit and calculator thereof
By designing an anti-side channel attack NTT circuit for grid-based cryptographic algorithms, parallel computing is implemented using multiple butterfly computing units, and computing performance is improved through randomization processing, the problem of insufficient computing performance and parallel efficiency in the prior art is solved, and more efficient NTT calculation is achieved.
Patent Information
- Application Number
- CN202510350210.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-05-24
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-17
AI Technical Summary
When designing general fast number theory transformation (NTT) circuits, the prior art fails to fully utilize more complex computing units such as basis 8 and basis 16 to achieve higher computing performance and parallel efficiency, especially when performing polynomial multiplication on polynomial rings in grid-based cryptographic algorithms, the calculation overhead is relatively high.
An anti-side channel attack NTT circuit for grid-based cryptographic algorithm is designed, and components such as register sets, control modules, memory and calculation modules are used to realize parallel operation of 2k data per round through 2k-1 butterfly computing units, and randomized the selection of butterfly computing units is used to improve computing performance and parallel efficiency.
It realizes the calculation performance and parallel efficiency of the NTT circuit while ensuring universality, and reduces the amount of memory required for the "ping-pong" iterative structure, and is suitable for NTT/INTT transformation based on MLWE/RLWE grid password.
Smart Images

Figure CN120165869A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of information security and cryptographic hardware circuits, and particularly relates to an NTT circuit resistant to side-channel attacks for lattice-based cryptographic algorithms and a calculator thereof. Background Art
[0002] With the rapid development of science and technology, the influence of Internet information technology in various fields is increasing, and ensuring the security of information systems has become increasingly important. Public-key cryptographic algorithms are the basic components of information security. In recent years, with the development of quantum algorithms and quantum computers, the security of traditional public-key cryptographic systems based on difficult problems such as large integer factorization and discrete logarithm has been threatened, while the lattice-based public-key cryptographic system can resist attacks from quantum computers to a certain extent. In July 2022, among the selected lists of post-quantum cryptographic standard algorithms announced by the National Institute of Standards and Technology (NIST) in the United States, the key encapsulation algorithms Kyber, Ntru, and Saber, and the digital signature algorithm Dilithium are all lattice-based cryptographic algorithms. During the operation of these algorithms, a large number of polynomial multiplications on polynomial rings are required, occupying a large computational overhead.
[0003] Fast Number Theoretic Transform (NTT) is the most commonly used method to accelerate polynomial multiplication, and can achieve the multiplication operation of two polynomials in O(N log N) time. Denote G[x] as a polynomial, and a=(a0,…,a N-1 ) as its coefficient vector. When , it is transformed into the point-value vector through the NTT algorithm, where represents the Nth primitive root of unity in the prime field Z q , also known as the rotation factor, and the calculation formula is i∈{0,1,…,N - 1}, A i is the i-th term of A; when , where is the 2Nth primitive root of unity in Z q , and the calculation process is Regardless of the situation, the coefficient vector a will be continuously recursively transformed through the divide-and-conquer algorithm to obtain the point-value vector A, and in each round of operation, the vector elements and the rotation factors need to be put into the Butterfly Unit (BFU) to complete the calculation.
[0004] The input lengths for NTT conversion in the Kyber and Dilithium algorithms are 128 and 256 respectively. After extending the number of polynomial terms and the modulus, the Saber and Ntru algorithms can also achieve an input length of N = 2. n At present, when designing a general NTT circuit, the performance and power consumption are generally balanced through a double butterfly unit (2BFU) structure or by using calculation units based on 3 or 4, and more complex calculation units such as those based on 8 or 16 are not used to achieve higher calculation performance and parallel efficiency. Summary of the Invention
[0005] The object of the present invention is to provide an NTT circuit resistant to side-channel attacks and its calculator for lattice-based cryptographic algorithms in view of the deficiencies of the existing technology.
[0006] To achieve the above object, in the first aspect, the present invention provides a calculator for an NTT circuit resistant to side-channel attacks for lattice-based cryptographic algorithms, including:
[0007] Register groups RegL and RegR, each including 2 k registers. Each register group is used to receive and store a vector of length K = 2 k where k is a natural number greater than 0. The input end of each register is connected to the output end of a write control multiplexer, and the output end of each register is connected to the input end of a read control multiplexer.
[0008] A control module, which is respectively connected to the write control multiplexer and the read control multiplexer, and is used to send a control signal lable to the write control multiplexer and the read control multiplexer. The control signal lable controls the operation of the write control multiplexer and the read control multiplexer to realize the data writing and reading control of the register groups RegL and RegR. When one register group is controlled as the input register group, the other register group is the output register group, and the control signal lable is inverted after each round of calculation.
[0009] A memory M_W, which is used to store rotation factors.
[0010] A calculation module, which is respectively connected to the memory and the control module to obtain the rotation factor ω stored in the memory M_W. The calculation module includes 2 k-1 butterfly units, supports parallel operation of 2 k data per round. The calculation module is also used to receive a rotation factor γ sent externally, where γ is an element in the prime field Z q . The control module is also used to receive an externally generated random sequence Random through a random number interface.
[0011] The first permutation module PU1 and the second permutation module PU2, where the first permutation module PU1 is respectively connected to the control module, the output ends of the write control multiplexer gate and the read control multiplexer gate, and the input end of the calculation module. The first permutation module PU1 is used to adjust the positions of the inputs of 2 k-1 butterfly units according to the control signal is_idwt sent by the control module, so as to read data from the registers at the corresponding positions of the register bank RegL or the register bank RegR, and send the read data to the calculation module for calculation. During the sending process, the selection of the butterfly units is randomized by using the random sequence Random, so that each group of data randomly selects butterfly units. The calculation module generates an operation result according to the read data, the rotation factor ω, and the rotation factor γ. The second permutation module PU2 is respectively connected to the output end of the calculation module, the input ends of the write control multiplexer gate and the read control multiplexer gate. The second permutation module PU2 is used to adjust the output positions of 2 k-1 butterfly units according to the control signal is_idwt sent by the control module, so as to send the calculation result of this round to the registers at the corresponding positions of the register bank RegR or the register bank RegL, and implement the decimation algorithm for different inputs and outputs. During the sending to RegR or RegL, the inverse process of the randomized selection with the random sequence Random is used, so that the order of the data in RegR and RegL is independent of the randomized selection process.
[0012] Further, the butterfly calculation unit includes 2 multipliers, 1 adder, 1 subtractor, and 2 modulo multiplication 1 / 2 units. The first input ends of the 2 multipliers are respectively connected to the memory M_W to read the rotation factors stored in the memory, and their second input ends are respectively connected to the output ends of the first multiplexer gate and the second multiplexer gate. The first input ends of the first multiplexer gate and the second multiplexer gate are respectively connected to the first permutation module PU1 to receive two polynomial coefficients at specific positions in the K = 2 k length vector from the register bank RegL or the register bank RegR. The second input ends of the first multiplexer gate and the second multiplexer gate are respectively connected to the output ends of the adder and the subtractor. The output ends of the 2 multipliers are respectively connected to the first input ends of the third multiplexer gate and the fourth multiplexer gate, and the input ends of the 2 modulo multiplication 1 / 2 units are respectively connected. The input ends of the third multiplexer gate and the fourth multiplexer gate are connected to the first permutation module PU1 to receive the K = 2 kTwo polynomial coefficients at specific positions in the length vector. The output ends of the third multiplexer gate and the fourth multiplexer gate are both connected to the input ends of the adder and the subtractor. The output end of the adder and the output end of one of the modulo multiplication by 1 / 2 units are respectively connected to the two input ends of the fifth multiplexer gate. The output end of the subtractor and the output end of the other modulo multiplication by 1 / 2 unit are respectively connected to the two input ends of the sixth multiplexer gate. The output ends of the fifth multiplexer gate and the sixth multiplexer gate are connected to the input end of the second permutation module PU2 to send the calculation result to the second permutation module PU2. The first multiplexer gate, the second multiplexer gate, the third multiplexer gate, the fourth multiplexer gate, the fifth multiplexer gate, and the sixth multiplexer gate are respectively connected to the control module, so that the butterfly unit performs different operations according to the control signal sel sent by the control module. The control signal sel is determined by the control signal is_idwt and satisfies the relation sel = is_idwt.
[0013] Furthermore, the operation types of the butterfly unit include:
[0014] ① E = ω′1 * e + ω′2 * f mod q, F = ω′1 * e - ω′2 * f mod q;
[0015] ② E = e + ω′2 * f mod q, F = e - ω′2 * f mod q;
[0016] ③ E = (e + f) * ω′1 / 2 mod q, F = (e - f) * ω′2 / 2 mod q;
[0017] ④ E = (e + f) / 2 mod q, F = (e - f) * ω′2 / 2 mod q;
[0018] Among them, E and F are the output results of the butterfly calculation unit respectively. ω′1 and ω′2 are both rotation factors provided by the memory M_W. e and f are respectively polynomial coefficients in the vector of length K = 2 stored in the register bank. mod represents the modulo operation, and q is the modulus. When the control signal sel = 0, the butterfly calculation unit performs operations of type ① or ②. When the control signal sel = 1, the butterfly unit performs operations of type ③ or ④. k Furthermore, the control module is also used to generate a control signal unit_model. The control signal unit_model determines the current calculation mode of the calculation module. The calculation mode includes a 2-way parallel radix-2 NTT operation and a radix-2 NTT operation.
[0019] Furthermore, when the polynomial is in the ring Z k-1 way parallel radix-2 NTT operation and radix-2 k NTT operation.
[0020] Furthermore, when the polynomial is in the ring Zq [x] / (x N - 1), the control signal is_idwt = 0. The computing module performs both the NTT operation and the inverse NTT operation using the time-domain decimation algorithm with input in reverse order and output in normal order. When the polynomial is an element in the ring Z q [x] / (x N + 1) and the number-theoretic transform is performed, the control signal is_idwt = 0. The computing module performs the time-domain decimation algorithm with input in reverse order and output in normal order. When the polynomial is an element in the ring Z q [x] / (x N + 1) and the inverse number-theoretic transform is performed, the control signal is_idwt = 1. The computing module performs the frequency-domain decimation algorithm with input in reverse order and output in normal order.
[0021] In a second aspect, the present invention provides an NTT circuit for lattice-based cryptographic algorithms against side-channel attacks, including the above-mentioned NTT calculator for lattice-based cryptographic algorithms against side-channel attacks.
[0022] Beneficial effects: The NTT circuit provided by the present invention can be applied to the NTT / INTT transforms in most scenarios with different parameter settings based on MLWE / RLWE lattice cryptography, and can select an appropriate k value according to the actual situation. By increasing the k value, the parallel efficiency of the circuit can be improved, and a general NTT circuit for anti-side-channel attacks can be realized. While ensuring generality, higher computing performance and optimization of the number of memories in the "ping-pong" iterative structure are achieved. The "ping-pong" iterative structure requires 2N RAM space for N-point NTT / INTT operations, and this solution only requires N RAM space and 2 register Reg spaces k+1 , having broad application prospects. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 is a schematic diagram of the radix-2 k NTT calculator of the present invention;
[0024] Figure 2 is a schematic diagram of the structure of the butterfly unit in an embodiment of the present invention;
[0025] Figure 3 is a schematic diagram of the data flow during the calculation process of the radix-8 calculator formed when the control signal is_idwt = 0;
[0026] Figure 4 is a schematic diagram of the data flow during the calculation process of the radix-8 calculator formed when the control signal is_idwt = 1;
[0027] Figure 5 is a schematic block diagram of the NTT circuit for lattice-based cryptographic algorithms against side-channel attacks in an embodiment of the present invention. Detailed implementation manners
[0028] The present invention will be further illustrated below in conjunction with the accompanying drawings and specific embodiments. These embodiments are implemented on the premise of the technical solution of the present invention. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention.
[0029] As Figures 1 to 4 shown, an NTT calculator for resisting side-channel attacks for lattice-based cryptographic algorithms provided by an embodiment of the present invention includes a register bank, a control module, a memory, a calculation module, a first permutation module PU1, a second permutation module PU2, etc.
[0030] The register bank is divided into two groups, namely a register bank RegL and a register bank RegR. The register bank RegL and the register bank RegR each include 2 k registers. Each register bank is used to receive a vector a=(a0, a1,..., a k ) of length K = 2 K-1 sent externally and store it. k is a natural number greater than 0, and a0 to a K-1 are all polynomial coefficients. The input end of each register is connected to the output end of a write control multiplexer gate, and the output end of each register is connected to the input end of a read control multiplexer gate.
[0031] The control module is respectively connected to the write control multiplexer gate and the read control multiplexer gate, and is used to send a control signal lable to the write control multiplexer gate and the read control multiplexer gate. The control signal lable controls the write control multiplexer gate and the read control multiplexer gate to work, so as to realize the data writing and reading control of the register bank RegL and the register bank RegR. When controlling one of the register banks as the input register bank, the other register bank is the output register bank, and the control signal lable is inverted after each round of calculation. Specifically, when the value of the control signal lable is 0, the register bank RegL is the input register bank, and the vector a=(a0, a1,..., a k ) of length K = 2 K-1 stored in it is read as the input of the calculation module; the register bank RegR is used as the output register bank, and the 2 k outputs calculated by the calculation module are written into the register bank RegR. When the value of the control signal lable is 1, the register bank RegR is the input register bank, and the vector a=(a0, a1,..., a k ) of length K = 2 K-1 stored in it is read as the input of the calculation module; the register bank RegL is used as the output register bank, and the 2 k outputs calculated by the calculation module are written into the register bank RegL.
[0032] The memory M_W is used to store the rotation factors ω. Specifically, there are K / 2 - 1 rotation factors ω, which are respectively or where t is an integer greater than 0, is a t-th primitive root of unity in a certain prime field Z q , q is a certain prime number, here t = K, that is or and satisfies and and obtained from RAM_W. Stored during the calculator initialization phase, the values and order of the rotation factors during the initialization process are determined by the control signal is_intt in the circuit. If is_intt = 0, then M_W stores the former, otherwise it stores the latter.
[0033] The calculation module is connected to the memory M_W to obtain the rotation factor ω stored in the memory M_W. The calculation module includes 2 k-1 butterfly units, supporting parallel operations of 2 k data per round. The calculation module is also used to receive the rotation factor γ sent externally. γ is an element in the prime field Z q . The control module is also used to receive the random sequence Random generated externally through the random number interface to randomize the calculation of data on the specified butterfly units to implement the "shuffle" strategy.
[0034] The first permutation module PU1 and the second permutation module PU2. The first permutation module PU1 is respectively connected to the output ends of the control module, the write control multiplexer gate and the read control multiplexer gate, and the input end of the calculation module. The first permutation module PU1 is used to adjust the positions of the inputs of 2 k-1 butterfly units according to the control signal is_idwt sent by the control module, so as to read data from the registers at the corresponding positions of the register bank RegL or the register bank RegR, and send the read data to the calculation module for calculation. During the sending process, the selection of the butterfly units is randomized using the random sequence Random, so that each group of data randomly selects a butterfly unit. The calculation module will generate an operation result according to the read data, the rotation factor ω, and the rotation factor γ. The second permutation module PU2 is respectively connected to the output end of the calculation module, the input ends of the write control multiplexer gate and the read control multiplexer gate. The second permutation module PU2 is used to adjust the positions of the inputs of 2 k-1The output position of a butterfly unit is used to send the calculation result of this round to the register at the corresponding position of the register bank RegR or the register bank RegL, so as to implement the decimation algorithm for different inputs and outputs. During the sending to RegR or RegL, the inverse process of random selection using the random sequence Random is utilized, so that the order of the data in RegR and RegL is independent of the random selection process.
[0035] For details, see Figure 1 , Figure 1 As shown, the radix-8 calculator formed when k = 3. The register bank RegL includes 8 registers RegL[Z], and the register bank RegR respectively includes 8 registers RegR[Z], where Z takes integer values from 0 to 7. Correspondingly, a write control multiplexer is respectively connected to the front side of each register RegL[Z] and each register RegR[Z]. The rear sides of the 8 registers RegL[Z] and the 8 registers RegR[Z] are respectively connected to 8 read multiplexers. 4 butterfly calculation units (BF0, BF1, BF2, BF3) are required to complete 3-layer NTT / INTT operations.
[0036] See Figure 2 In the embodiment of the present invention, the butterfly calculation unit includes 2 multipliers 1, 1 adder 2, 1 subtractor 3, and 2 modular multiplication 1 / 2 units 4. The first input ends of the 2 multipliers 1 are respectively connected to the memory M_W to read the rotation factors stored in the memory M_W. And its second input ends are respectively connected to the output ends of the first multiplexer 5 and the second multiplexer 6. The first input ends of the first multiplexer 5 and the second multiplexer 6 are respectively connected to the first permutation module PU1 to receive two polynomial coefficients at specific positions in the K = 2 k length vector from the register bank RegL or the register bank RegR. The second input ends of the first multiplexer 5 and the second multiplexer 6 are respectively connected to the output ends of the adder 2 and the subtractor 3. The output ends of the 2 multipliers 1 are respectively connected to the first input ends of the third multiplexer 7 and the fourth multiplexer 8, and the input ends of the 2 modular multiplication 1 / 2 units 4 are respectively connected. The input ends of the third multiplexer 7 and the fourth multiplexer 8 are connected to the first permutation module PU1 to receive the K = 2 kTwo polynomial coefficients at specific positions in the length vector, and the output ends of the third multiplexing gate 7 and the fourth multiplexing gate 8 are respectively connected to the input ends of the adder and the subtractor. The output end of the adder and the output end of one of the modulo multiplication by 1 / 2 units 4 are respectively connected to the input ends of the fifth multiplexing gate 9, and the output end of the subtractor and the output end of the other modulo multiplication by 1 / 2 unit are respectively connected to the input ends of the sixth multiplexing gate 10. The output ends of the fifth multiplexing gate 9 and the sixth multiplexing gate 10 are connected to the input end of the second permutation module PU2 to send the calculation result to the second permutation module PU2. The above-mentioned first multiplexing gate, second multiplexing gate, third multiplexing gate, fourth multiplexing gate, fifth multiplexing gate, and sixth multiplexing gate are respectively connected to the control module, so that the butterfly unit performs different operations according to the control signal sel sent by the control module. The control signal sel is determined by the control signal is_idwt and satisfies the relationship sel = is_idwt. In addition, the above-mentioned modulo multiplication by 1 / 2 unit 4 can be implemented by a shifter, an adder, and a MUX to improve the calculation efficiency. The modulo multiplication operation in the circuit uses the reconfigurable Barrett reduction algorithm to improve the calculation efficiency and support different moduli.
[0037] Specifically, the operation types of the above butterfly unit include:
[0038] ①E = ω′1 * e + ω′2 * f mod q, F = ω′1 * e - ω′2 * f mod q;
[0039] ②E = e + ω′2 * f mod q, F = e - ω′2 * f mod q;
[0040] ③E = (e + f) * ω′1 / 2 mod q, F = (e - f) * ω′2 / 2 mod q;
[0041] ④E = (e + f) / 2 mod q, F = (e - f) * ω′2 / 2 mod q;
[0042] Among them, E and F are the output results of the butterfly calculation unit respectively, ω′1 and ω′2 are both rotation factors provided by the memory M_W, and e and f are respectively the polynomial coefficients stored in the register group, that is, e, f ∈ a c , c = 0, 1,..., N - 1, mod is the modulo operation, and q is the modulus; when the control signal sel = 0, the butterfly calculation unit performs the operations of type ① or ②, and when the control signal sel = 1, the butterfly unit performs the operations of type ③ or ④. The operations of the above type ① and ② and the operations of type ③ and ④ can be distinguished by whether the rotation factor ω′1 in the input is equal to 1. The operations of the above type ① and ② are applied to the polynomial as the ring Z q [x] / (x NNTT / INTT operations when the elements are in the form as in (0-1), and NTT (which can also be called DWT) operations when the polynomial is an element in the ring Z q [x] / (x N +1). The operations of the above types ③ and ④ are applied to the case where the polynomial is an element in the ring Z q [x] / (x N +1) for INTT (which can also be called IDWT) operations.
[0043] When the polynomial is an element in the ring Z q [x] / (x N -1), the control signal is_idwt = 0, and the calculation module executes both NTT and INTT operations using the time-domain decimation algorithm with input in reverse order and output in normal order. When the polynomial is an element in the ring Z q [x] / (x N +1) and number-theoretic transform is performed, the control signal is_idwt = 0, and the calculation module executes the time-domain decimation algorithm with input in reverse order and output in normal order. When the polynomial is an element in the ring Z q [x] / (x N +1) and inverse number-theoretic transform is performed, the control signal is_idwt = 1, and the calculation module executes the frequency-domain decimation algorithm with input in reverse order and output in normal order.
[0044] To support the radix-2 n NTT / INTT operations for vectors of any length N = 2 k ^m, the radix-2 k NTT calculator needs to be backward compatible. It is determined by the control signal unit_model whether to use the 2 k-1 -way parallel radix-2 NTT operation or the radix-2 k NTT operation. Let n = n1*k + n2, where n1 and n2 are integers and n2 < k. When n2 = 0, the radix-2 k NTT arithmetic unit always uses the radix-2 k NTT operation mode. When n2 ≠ 0, the calculator first performs n2 rounds of radix-2 operations and then n1 rounds of radix-2 k operations, or first performs n1 rounds of radix-2 k operations and then n2 rounds of radix-2 operations.
[0045] If the value of the control signal unit_model is 0, then there are K / 2 butterfly units in parallel for the radix-2 operation steps, and its calculation process is the same as that of the radix-2 NTT algorithm, which will not be elaborated here.
[0046] If the value of the control signal unit_model is 1, the value of is_idwt is 0, and the value of is_intt is 0, initialize the control signal label to 0. At this time, M_W stores Perform k rounds of calculations. Receive the rotation factor γ from the outside d (The calculator reads from the corresponding position of RAM_W, and the position is determined by the circuit control unit), for any Let u′ and v′ be the data at positions j′ and in the input register bank respectively. If it is the first round, then calculate Otherwise, in the s d -th round (s d ∈[2, k + 1)) calculate A 2*j′ = u′ + ω d * v′, A 2*j′+1 = u′ - ω d * v′, and write them into the positions 2j′ and 2*j′ + 1 in the output register bank respectively. The above γ d j′ represents the j′-th power of the rotation factor γ d , where ω d is selected by the control module and the memory, satisfying: where bitreverse(t′) is the bit-reversed value of the integer t′. Each round of these steps of calculation is completed in parallel by butterfly units and randomized according to the random sequence Random as to which butterfly unit the data is calculated on. The value of the control signal sel is 0. After k rounds of calculation, the result stored in the output register bank is bit-reversed.
[0047] If the value of the control signal unit_model is 1, the value of is_idwt is 0, and the value of is_intt is 1, initialize the control signal label to 0. At this time, M_W stores Perform k rounds of calculations. Receive the rotation factor γ from the outside l (The calculator reads from the corresponding position of RAM_W, and the position is determined by the circuit control unit), for any Let u″′ and v″′ be the data at positions j l and in the input register bank respectively. If it is the first round, then calculate Otherwise, in the s l -th round (s l ∈[2, k + 1)) calculate and write them into the positions 2*j l and 2*jl +1, the above represents the rotation factor γ l to the power of j l where ω l is selected by the control module and the memory, satisfying: where bitreverse(t′) is the bit-reversed value of the integer t′. Each round above step calculation is completed in parallel by
[0048] butterfly units and randomized according to the random sequence Random for which butterfly unit the data is calculated on. The value of the control signal sel is 0. After k rounds of calculation, the result stored in the output register bank is bit-reversed. If the value of the control signal unit_model is 1, the value of is_idwt is 1, the value of is_intt is 1, the value of the control signal sel is 1, the initialization control signal label is 0, and at this time the memory M_W stores g (the calculator reads from the corresponding position of the RAM_W, and the position is determined by the circuit control unit), for any let u″ and v″ be the data at positions 2*y and 2*y + 1 in the input register bank respectively. If it is the last round, then calculate A y =(u″ + v″)*γ g y / 2, otherwise, in the s g round (s g ∈[2,k + 1)) calculate A y =(u″ + v″) / 2, and write it to positions y and in the output register bank respectively. Here, ω g is also selected by the control module and the memory specifically. Each round of K / 2 step calculations above is completed in parallel by K / 2 butterfly units and randomized according to the random sequence Random for which butterfly unit the data is calculated on.
[0049] Figure 3 is the schematic diagram of the data flow in the calculation process of the radix-8 calculator when k = 3 and the control signal is_idwt = 0. Figure 4 is the schematic diagram of the data flow in the calculation process of the radix-8 calculator when k = 3 and the control signal is_idwt = 1. For the readability of the data flow diagram, Figure 3 , Figure 4 the influence of Random is omitted.
[0050] See Figure 5 , based on the above embodiments, those skilled in the art can easily understand that the present invention also provides an NTT circuit for lattice-based cryptography algorithms against side-channel attacks, including the above-mentioned NTT calculator for lattice-based cryptography algorithms against side-channel attacks. In addition, it also includes a control unit, a polynomial coefficient memory RAM_NTT, a rotation factor storage module RAM_W, etc. The NTT calculator receives unit_model, is_idwt control signals, as well as polynomial coefficient data, a random sequence Random, and rotation factor data and performs base-2 k or base-2 NTT / INTT operations. The control unit determines the control signal is_idwt of the calculator according to the control signals mod_poly and is_intt, and determines the unit_model signal during the calculation process. The polynomial coefficient memories RAM_NTT and RAM_W store the N = 2 n terms of data and rotation factor data to be subjected to NTT / INTT operations respectively.
[0051] Using Figure 5 the circuit shown in n to perform base-2 k NTT / INTT operations on N = 2 n terms of data requires a special design of the bit-reversal algorithm. Specifically, let N = 2 k be the length of the input polynomial coefficient vector of the circuit, K = 2 k be the input length of the base-2 i″ computing module. Let n = n1*k + n2, where n1 and n2 are integers and n2 < k. For any b' ∈ [0, N - 1], for any i' ∈ [0, n - 1], let b'[i'] be the i'-th bit of its binary representation (if the binary representation length of b' is less than n bits, it is padded with 0s). According to the different values of the control signal is_idwt, the bit-reversal algorithm in the circuit will also be different: when the control signal is_idwt = 0, let b1 = b'[0:n - n2 - 1], b2 = b'[n - n2:n - 1], the binary representation of the output a'0 is an empty string. For any i'' ∈ [0, n1), let L i″ = n - n2 - (i'' + 1)k, R i″+1 = n - n2 - i''k - 1, calculate a' i″ = a' i″ ||b1[L i″ :R || is the concatenation symbol, and a″ is the output of this bit-reversal algorithm. When the control signal is_idwt = 1, let b1 = b′[n2:n - 1], b2 = b′[0:n2 - 1], the binary representation of the output a′0 is an empty string. For any i″ ∈ [0, n1), let L i″ = n - n2 - (i″ + 1)k, R i″ = n - n2 - i″k - 1, calculate a′ i″+1 = a′ i″ || b1[L i″ :R i″ . After that, the normal bit-reversal process needs to be performed on b2, and the final output Let bitreverse(x, t, is_idwt) represent the aforementioned specially designed bit-reversal algorithm, where t represents the integer for which bit-reversal is required. bitreverse(t) is the normal bit-reversal algorithm.
[0052] The NTT calculator needs to receive 2 k polynomial coefficients from RAM_NTT in the circuit and the rotation factors from RAM_W within one calculation cycle, and select the calculation mode according to the control signal given by the control module in the circuit, output a vector of length 2 k and store it back in the polynomial coefficient memory RAM_NTT. When the value of the control signal mod_poly is 0, the storage module RAM_W stores 2N rotation factors When the value of the control signal mod_poly is 1, the storage module RAM_W stores N rotation factors
[0053] To meet the bandwidth requirements for 2 k data within one cycle, the polynomial coefficient memory RAM_NTT contains 2 k banks and an address generator. These banks are implemented by dual-port BlockRAM in the FPGA device, with a storage capacity of N * 64 / 2 k , and can store at most N / 2 k 64-bit long data. Within one clock cycle, one bank can only support reading one data and writing one data. This requires that the 2 k data provided to the calculator in each cycle are distributed in different banks. To avoid access conflicts, the bank number in the bank and the New_Addr position in the bank numbered Bank_Addr are generated by the Bank_Addr and New_Addr components in the address generator. Let addr be the original address generated by the control unit, and the algorithm in the address generator is as follows: New_Addr = addr >> k, idx ∈ {0, 1, …, n / k - 1}.
[0054] The circuit determines the form of the modular polynomial and whether it is an NTT inverse operation by the control signals mod_poly and is_intt respectively. When mod_poly = 0, the modular polynomial is x N + 1. When mod_poly = 1, the modular polynomial is x N - 1. is_intt = 0 indicates that the current operation is an NTT transform, and is_intt = 1 indicates that the current operation is an INTT transform. The value of the control signal is_idwt is determined by the above two signals. When mod_poly = 0 and is_intt = 1, the value of is_idwt is 1, and in other cases it is 0. The input length N = 2 n and the radix K = 2 k satisfy n = n1 * k + n2. The following introduces the calculation process of the NTT circuit in different modes:
[0055] When mod_poly = 0 and is_intt = 0, the circuit performs an NTT transform with the modular polynomial x N + 1. Denote f = (f0, …, f N-1 ) as the coefficient vector of the polynomial. In this mode, the coefficient vector needs to be processed by bit-reversal first. Denote F = (F0, …, F N-1 ) as the circuit input vector. Then for any i ∈ [0, N), F i = f bitreverse(K,i,is_idwt=0) . The circuit first performs n2 rounds of radix-2 operations, and then performs n1 rounds of radix-2 k operations: For any s1 ∈ [1, n2], denote m1 = 2 s1 . For any j1 ∈ [0, m1 / 2), read the rotation factor from the storage module RAM_W For any Denote the K-length vector A = (A0, …, A K-1 ) as the input vector of the calculator. For any The address generator reads the polynomial coefficient with the original address of from the polynomial coefficient memory RAM_NTT and assigns it to A 2*h1 and A 2*h1+1 . The calculator executes the operation, and its input is: (A, K, γ1, unit_model = 0, is_idwt = 0), and stores the output back into the polynomial coefficient memory RAM_NTT at the corresponding position. For any s2 ∈ [1, n1], denote For any Read the rotation factor from the storage module RAM_W For any Let the K-length vector A = (A0, …, A K-1 ) be the input vector of the calculator. For any h2 ∈ [0, K), the address generator reads the polynomial coefficients with the original address from RAM_NTT and assigns them to A i2 . The calculator performs an arithmetic operation with its inputs: (A, K, γ2, unit_model = 1, is_idwt = 0), and stores the output back into the polynomial coefficient memory RAM_NTT at the corresponding location. Finally, the NTT transformation result of the polynomial is stored in the polynomial coefficient memory RAM_NTT.
[0056] When mod_poly = 0 and is_intt = 1, the circuit performs an INTT transformation with the modulo polynomial x N + 1. Let f = (f0, …, f N-1 ) be the coefficient vector of the polynomial. The circuit first performs n1 rounds of radix-2 k operations, and then performs n2 rounds of radix-2 operations: For any s3 ∈ [1, n1], let For any Read the rotation factor from the storage module RAM_W For any Let the K-length vector A = (A0, …, A K-1 ) be the input vector of the calculator. For any h3 ∈ [0, K), the address generator reads the polynomial coefficients with the original address from the polynomial coefficient memory RAM_NTT and assigns them to A i3 . The calculator performs an arithmetic operation with its inputs: (A, K, γ3, unit_model = 1, is_idwt = 1), and stores the output back into the polynomial coefficient memory RAM_NTT at the corresponding location. For any s4 ∈ [1, n2], let For any Read the rotation factor from the storage module RAM_W For any Let the K-length vector A = (A0, …, A K-1 ) be the input vector of the calculator. For any The address generator reads the polynomial coefficients with the original address from the polynomial coefficient memory RAM_NTT and assigns them to A 2*h4 and A 2*h4+1, the calculator performs an arithmetic operation with inputs (A, K, γ4, unit_model = 0, is_idwt = 1), and stores the output back into the polynomial coefficient memory RAM_NTT at the corresponding location. After the bit-reversal operation on the stored result f in the polynomial coefficient memory RAM_NTT, it is the INTT transformation result of the original input.
[0057] When mod_poly = 1 and is_intt = 0, the circuit performs the NTT transformation with the modulo polynomial x N -1. The calculation process in this mode is similar to that when mod_poly = 0 and is_intt = 0: In this mode, the coefficient vector is first processed by bit-reversal. Let F = (F0, …, F N-1 ) be the circuit input vector. Then, for any i ∈ [0, N), F i = f bitreverse(K,i,is_idwt=0) . The circuit first performs n2 rounds of radix-2 operations and then n1 rounds of radix-2 k operations: For any s5 ∈ [1, n2], let m5 = 2 s5 . For any Read the twiddle factor from the storage module RAM_W For any Let the K-length vector A = (A0, …, A K-1 ) be the input vector of the calculator. For any The address generator reads the polynomial coefficient with the original address from the polynomial coefficient memory RAM_NTT and assigns it to A 2*h5 and A 2*h5+1 . The calculator performs an arithmetic operation with inputs (A, K, γ5, unit_model = 0, is_idwt = 0), and stores the output back into the polynomial coefficient memory RAM_NTT at the corresponding location. For any s6 ∈ [1, n1], let For any Read the twiddle factor from the storage module RAM_W For any Let the K-length vector A = (A0, …, A K-1 ) be the input vector of the calculator. For any h6 ∈ [0, K), the address generator reads the polynomial coefficient with the original address from the polynomial coefficient memory RAM_NTT and assigns it to A i6 . The calculator performs an arithmetic operation with inputs (A, K, γ6, unit_model = 1, is_idwt = 0), and stores the output back into the polynomial coefficient memory RAM_NTT at the corresponding location. The NTT transformation result of the polynomial is stored in the polynomial coefficient memory RAM_NTT finally.
[0058] When mod_poly = 1 and is_intt = 1, the circuit performs an INTT transform with a modulo polynomial of x N - 1. The calculation process in this mode is basically the same as the NTT transform with a modulo polynomial of x N - 1. The difference is that in each round of the calculation process, the twiddle factor passed to the calculator needs to be replaced with the multiplicative inverse of the original twiddle factor in the prime field Z q . In addition, the twiddle factors stored in the memory will change according to the control signal is_intt. Finally, the coefficient vector stored in the polynomial coefficient memory RAM_NTT is modulo N -1 After the operation, it is the result of the NTT transform of the polynomial.
[0059] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art of this technology, the other parts not specifically described belong to the prior art or common general knowledge. Without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A calculator for a lattice cryptographic algorithm resistant to side channel attacks on NTT circuits, characterized in that: include: Register group RegL and register group RegR, each including 2 k registers, each register group is used to receive K=2 externally sent k The vector of length is stored, k is a natural number greater than 0, the input end of each register is connected to the output end of a write control multiplexing gate, and the output end of each register is connected to the input end of the read control multiplexing gate; A control module, connected to the write control multiplexing gate and the read control multiplexing gate respectively, for sending a control signal lable to the write control multiplexing gate and the read control multiplexing gate, wherein the control signal lable controls the write control multiplexing gate and the read control multiplexing gate to work, thereby realizing data writing and reading control of the register group RegL and the register group RegR. When one of the register groups is controlled as an input register group, the other register group is controlled as an output register group. The control signal lable is inverted after each round of calculation; A memory M_W, used to store rotation factors; A calculation module is connected to the memory and the control module respectively to obtain the rotation factor ω stored in the memory M_W. The calculation module includes 2 k-1 Butterfly units, supporting 2 per round k The computing module is also used to receive the rotation factor γ sent from the outside, where γ is the prime domain Z q An element in , the control module is further used to receive a random sequence Random generated externally through a random number interface; The first replacement module PU1 and the second replacement module PU2, the first replacement module PU1 is connected to the control module, the output end of the write control multiplexing gate and the read control multiplexing gate, and the input end of the calculation module respectively, and the first replacement module PU1 is used to adjust 2 according to the control signal is_idwt sent by the control module k-1 The input position of each butterfly unit is determined to read data from the register at the corresponding position of the register group RegL or the register group RegR, and the read data is sent to the calculation module for calculation. During the sending process, the selection of the butterfly unit is randomized by using the random sequence Random, so that each group of data randomly selects a butterfly unit. The calculation module generates a calculation result according to the read data, the rotation factor ω, and the rotation factor γ. The second replacement module PU2 is respectively connected to the output end of the calculation module, the input end of the write control multiplexing gate, and the input end of the read control multiplexing gate. The second replacement module PU2 is used to adjust 2 according to the control signal is_idwt sent by the control module. k-1 The output position of a butterfly unit is used to send the calculation result of this round to the register of the corresponding position of the register group RegR or the register group RegL to implement the extraction algorithm of different inputs and outputs. During the sending to RegR or RegL, the inverse process of random selection with the random sequence Random is used to make the order of data in RegR and RegL independent of the random selection process.
2. The calculator of the NTT circuit resistant to side channel attacks for the lattice cryptographic algorithm according to claim 1, characterized in that: The butterfly computing unit includes two multipliers, one adder, one subtractor, and two modular multiplication 1 / 2 units, the first input ends of the two multipliers are respectively connected to the memory M_W to read the rotation factors stored in the memory, and the second input ends are respectively connected to the output ends of the first multiplexing gate and the second multiplexing gate, the first input ends of the first multiplexing gate and the second multiplexing gate are respectively connected to the first replacement module PU1 to receive K=2 from the register group RegL or the register group RegR k The second input ends of the first multiplexing gate and the second multiplexing gate are connected to the output ends of the adder and the subtractor respectively, the output ends of the two multipliers are connected to the first input ends of the third multiplexing gate and the fourth multiplexing gate, and the input ends of the two modular multiplication 1 / 2 units respectively, and the input ends of the third multiplexing gate and the fourth multiplexing gate are connected to the first replacement module PU1 to receive K=2 from the register group RegL or the register group RegR k two polynomial coefficients at specific positions in the length vector, the output ends of the third multiplexing gate and the fourth multiplexing gate are both connected to the input ends of the adder and the subtractor, the output end of the adder and the output end of one of the modular multiplication 1 / 2 units are respectively connected to the two input ends of the fifth multiplexing gate, the output end of the subtractor and the output end of another modular multiplication 1 / 2 unit are respectively connected to the two input ends of the sixth multiplexing gate, the output ends of the fifth multiplexing gate and the sixth multiplexing gate are connected to the input end of the second replacement module PU2 to send the calculation result to the second replacement module PU2, the first multiplexing gate, the second multiplexing gate, the third multiplexing gate, the fourth multiplexing gate, the fifth multiplexing gate and the sixth multiplexing gate are respectively connected to the control module so that the butterfly unit performs different operations according to the control signal sel sent by the control module, the control signal sel is determined by the control signal is_idwt, and satisfies the relationship sel=is_idwt.
3. The calculator of the NTT circuit resistant to side channel attack for the lattice cryptographic algorithm according to claim 2, characterized in that: The operation types of the butterfly unit include: ①E=ω′1*e+ω′2*f mod q, F=ω′1*e-ω′2*f mod q; ②E=e+ω′2*f mod q, F=e-ω′2*f mod q; ③E=(e+f)*ω′1 / 2mod q, F=(ef)*ω′2 / 2mod q; ④E=(e+f) / 2mod q, F=(ef)*ω′2 / 2mod q; Among them, E and F are the output results of the butterfly computing unit, ω′1 and ω′2 are the rotation factors provided by the memory M_W, and e and f are K=2 stored in the register group respectively. k The polynomial coefficients in the vector of length, mod represents the modulo operation, and q is the modulus; when the control signal sel=0, the butterfly computing unit performs type ① or ② operations, and when the control signal sel=1, the butterfly unit performs type ③ or ④ operations.
4. The calculator of the NTT circuit resistant to side channel attack for the lattice cryptographic algorithm according to claim 3 is characterized in that: The control module is also used to generate a control signal unit_model, and the control signal unit_model determines the current calculation mode of the calculation module. The calculation mode includes 2 k-1 Parallel radix-2 NTT operations and radix-2 k NTT operation.
5. The calculator of the NTT circuit resistant to side channel attack for the lattice cryptographic algorithm according to claim 4, characterized in that: When the polynomial is a ring Z q [x] / (x N -1), the control signal is_idwt=0, the calculation module performs NTT operation and NTT inverse operation, both of which are time domain extraction algorithms with reverse input order and sequential output order. q [x] / (x N +1) and perform number theory transformation, the control signal is_idwt=0, the computing module executes the time domain extraction algorithm of input reverse order and output order, when the polynomial is a ring Z q [x] / (x N +1) and performs inverse number theoretic transformation, the control signal is_idwt=1, and the calculation module executes a frequency domain extraction algorithm with input reverse order and output order.
6. The NTT circuit for lattice cryptographic algorithm against side channel attacks is characterized by: A side-channel attack-resistant NTT calculator for a lattice cryptographic algorithm comprising any one of claims 1 to 5.