Matrix transpose
By performing matrix transformation and logical combination operations on the processing device, matrix transposition and masking operations are implemented, the data protection problem of matrix transposition operations in the prior art is solved, and the resistance to attacks is improved.
Patent Information
- Application Number
- CN202411888145.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-12-16
- Filing Date
- 2024-12-20
- Publication Date
- 2025-06-27
AI Technical Summary
In the field of data processing and encryption, it is difficult for the prior art to effectively protect data in matrix transpose operations, especially in the face of brute force attacks, side channel attacks, or attacks using quantum computing technology.
By performing a matrix transformation operation on the processing device, it includes shifting the vector values of the first set of ordered vectors in the first direction to generate a second set of ordered vectors, and generating a working vector by logical combination, thereby generating a fourth set of ordered vectors to realize matrix transposition while applying a masking operation to protect data.
This method can perform matrix transposition operations without directly accessing the matrix data to be transposed, providing protection for encryption operations and enhancing resistance to attacks.
Smart Images

Figure CN120216849A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to electronic circuits and devices, and more particularly to implementing a matrix transpose method by an electronic circuit or device. Background Art
[0002] In the fields of data processing and encryption, it is common practice to use matrices and apply different operations to them.
[0003] A common operation applied to a matrix during computer processing is a transpose operation, during which the rows and columns of the matrix are swapped. Summary of the Invention
[0004] One embodiment protects data during a processing operation while applying matrix transpose to a matrix as part of the processing operation. For example, one embodiment may use one or more matrix transformations to protect an encryption operation against attacks such as brute force attacks or side channel attacks, e.g., attacks that use quantum computing techniques to discover the values of matrices used during cryptographic operations.
[0005] In one embodiment, a method includes: performing an encryption operation using a processing device and protecting the processing device during the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer and each row forms a corresponding vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the values of the vectors of the first set of ordered vectors in a first direction, where the pitch of the shift applied to the vectors of the first set of ordered vectors is based on the order number of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector.
[0006] In one embodiment, a device includes a memory and processing circuitry coupled to the memory. The processing circuitry performs an encryption operation in operation and protects the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer and each row forms a respective vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the values of the vectors of the first set of ordered vectors in a first direction, where the spacing of the shift applied to the vectors of the first set of ordered vectors is based on the sequential numbering of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector.
[0007] In one embodiment, a system includes a processor and encryption circuitry coupled to the processor. The encryption circuitry performs an encryption operation in operation and protects the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer and each row forms a respective vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the values of the vectors of the first set of ordered vectors in a first direction, where the spacing of the shift applied to the vectors of the first set of ordered vectors is based on the sequential numbering of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector.
[0008] In one embodiment, the content of a non-transitory computer-readable medium causes encryption circuitry to perform a method. The method includes: performing an encryption operation and protecting the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer and each row forms a respective vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the values of the vectors of the first set of ordered vectors in a first direction, where the spacing of the shift applied to the vectors of the first set of ordered vectors is based on the sequential numbering of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Exemplary features and advantages will be set forth in detail in the following non-limiting description of specific embodiments with reference to the drawings.
[0010] Figure 1 An embodiment of an electronic device adapted to implement Figure 4 and Figure 5 is shown very schematically and in the form of a block;
[0011] Figure 2 A matrix transpose operation is shown schematically;
[0012] Figure 3 A masking operation is shown very schematically and in the form of a block;
[0013] Figure 4 A block diagram illustrating a first implementation mode of a matrix transpose method according to an embodiment; and
[0014] Figure 5 A block diagram illustrating a second implementation mode of a matrix transpose method according to an embodiment. DETAILED DESCRIPTION
[0015] In the various figures, the same features have been designated by the same reference numerals. Specifically, structural and / or functional features common between the various embodiments may have the same reference numerals and may have the same structure, dimensions, and material properties.
[0016] For clarity, only those steps and elements that contribute to an understanding of the described embodiments are shown and described in detail.
[0017] Unless otherwise stated, when referring to two elements connected together, this means a direct connection without any intermediate element other than a conductor, and when referring to two elements coupled together, this means that the two elements may be connected, or they may be coupled via one or more other elements.
[0018] In the following description, when referring to absolute position determiners such as "front", "rear", "top", "bottom", "left", "right", etc., or relative position determiners such as "top", "bottom", "upper", "lower", etc., or orientation determiners such as "horizontal", "vertical", etc., unless otherwise stated, the orientation of the accompanying drawings is referred to.
[0019] Unless otherwise stated, the expressions "about", "approximately", "substantially", and "circa" mean plus or minus 10%, and in the embodiments plus or minus 5%.
[0020] The embodiments described below relate to the implementation of matrix transpose. A matrix transpose operation is an operation in which the rows and columns of an input matrix are reversed. The embodiments described below also relate to implementing a masking operation and thus enabling a secure responsibility for the transpose operation of the matrix to be transposed.
[0021] Figure 1 FIG. 1 is a block diagram schematically showing an example of an architecture of an electronic device or system 100 adapted to implement a matrix transpose method according to one or more embodiments disclosed herein.
[0022] According to one example, the electronic device 100 includes a processor 101 (CPU), which is adapted to implement different processing of data stored in the memory and / or supplied by other circuits of the device 100. According to one embodiment, the processor 101 is adapted to implement a matrix transpose method. According to one embodiment, the processor 101 includes registers and at least one arithmetic unit or circuit, and the at least one arithmetic unit or circuit performs mathematical operations according to data and / or vectors of data during operation.
[0023] According to one example, the electronic device 100 further includes different types of memories 102 (MEM), and the memories 102 include, for example, non-volatile memories, volatile memories 103, and / or read-only memories. In one embodiment, each memory 102 is adapted to store different types of data.
[0024] According to one example, the electronic device 100 further includes, for example, a security element or circuit 103 (SE), and the security element or circuit 103 manipulates sensitive and / or secret data during operation. The security element 103 may include its own processor(s), one or more of its own memories, etc. According to one embodiment, the security element 101 is adapted to implement a matrix transpose method.
[0025] According to one example, the electronic device 100 may further include an interface circuit 104 (IN / OUT), which is adapted to send and / or receive data originating from outside the device 100. The interface circuit 104 may also be adapted to implement data display, for example, a display screen.
[0026] According to one example, the electronic device 100 further includes different circuits 105 (FCT1) and 106 (FCT2) that perform different functions during operation. For example, the circuits 105 and 106 may include measurement circuits, data conversion circuits, etc. According to one embodiment, the circuits 105 and 106 may include circuits adapted to implement a matrix transpose method.
[0027] According to one example, the electronic device 100 further includes one or more data buses 107, and the one or more data buses 107 are adapted to transfer data between its different components.
[0028] According to one embodiment, each element of the electronic device 100 capable of implementing the matrix transpose method includes a register and at least one arithmetic unit or circuit, and the at least one arithmetic unit or circuit is capable of performing mathematical operations based on data and / or vectors of data.
[0029] According to one specific example, the electronic device 100 is adapted to implement a computer program, and specifically a computer program capable of implementing the matrix transpose method.
[0030] Figure 2 It shows the application of the transpose operation Trans to the matrix Matrix.
[0031] The matrix Matrix is a matrix including n rows and p columns, where n and p are integers greater than or equal to 1. The elements or coefficients of the matrix Matrix are labeled as m i,j , where i is an integer varying from 0 to p - 1, and j is an integer varying from 0 to n - 1. According to one embodiment, the integers n and p are the same. According to an example embodiment, the integer n is in the range from 1 to 20, for example equal to 4, 6 or 16, and the integer p is in the range from 1 to 40, for example equal to 32.
[0032] The transpose operation Trans enables the provision of a matrix Trans(Matrix) including p rows and n columns. The elements or coefficients of the matrix Trans(Matrix) are labeled as m' j,i , and are given by the following formula:
[0033] m j ’ ,i = m i,j (1)
[0034] In other words, the transpose operation Trans enables the exchange of the rows and columns of the matrix Matrix. In other words, the vector representing the elements of the row with index k of the matrix Matrix includes the same elements as the vector representing the elements of the column with index k of the matrix Trans(Matrix), where k is an integer varying between 1 and n or p.
[0035] Regarding Figure 4 and Figure 5 The method described illustrates the actual implementation of the transpose operation of the type of the transpose operation Trans.
[0036] Figure 3 The operation MASK of masking the data item Data by the masking data item Mask is shown very schematically and in the form of a block.
[0037] According to one embodiment, the data item Data is a binary data item representing a sensitive or secret data item, i.e., a data item having content that is not accessible to everyone and / or a data item whose access to the content is restricted to an entity or a group of entities.
[0038] According to one embodiment, the masking data item Mask or the mask Mask is a data item used to mask the content of the data item Data. It is common practice to use pseudo-random or randomly generated data as the mask Mask.
[0039] There are multiple types of masking operations. In one embodiment, the masking operation MASK described herein is a masking operation using the exclusive OR (XOR) logic function, which is labeled as the xor function hereinafter.
[0040] According to one embodiment, the application of the masking operation MASK enables the obtaining of the masked data item MASK(Data). The masked data item MASK(Data) is given by the following formula:
[0041] MASK(Data) = Data xor Mask (2)
[0042] The operation of unmasking the masked data item corresponds again to the application of the masking operation MASK. In fact:
[0043] MASK(MASK(Data)) = (Data xor Mask) xor Mask = Data (3)
[0044] Figure 5 Illustrates the implementation of a method for transposing a matrix with masked data. The masking operation is applied to the data matrix with respect to Figure 5 to be described in detail.
[0045] Figure 4 is a block diagram illustrating the actual implementation mode of method 400, which performs the operation of transposing a matrix of the type of transpose operation Trans described with respect to Figure 2 According to one embodiment, the method 400 can be implemented by the device 100 described with respect to Figure 1 and more specifically by a processor and / or one of the circuits forming the circuit of the device 100.
[0046] To illustrate the operation of method 400, consider the matrix Mat of size 4×4 given by the following:
[0047]
[0048] where the elements A to P are data items.
[0049] Method 400 is also applied to obtain the transpose of a rectangular matrix of size n*p of the type of the matrix Matrix described Figure 2 . For this purpose, the rectangular matrix needs to be partitioned into a plurality of square matrices and Method 400 is applied to each square matrix, or the rectangular matrix is completed with empty elements to obtain a square matrix. The ability of those skilled in the art is sufficient to make the necessary adaptations based on the explanations given below. The implementation of Method 400 is described in detail below by only considering a square matrix Matrix where the integers n and p are equal.
[0050] At the initial step 401(Mat), and as described above, considering the matrix Mat, the data of the matrix Mat is stored in registers in the form of four row vectors m[0], m[1], m[2] and m[3], and each row vector represents a row of the matrix Mat. In other words, the vectors m[0] to m[3] are given by:
[0051]
[0052] In the case of the matrix Matrix described Figure 2 , the vector m[i] is given by the following formula, where i varies from 0 to n-1:
[0053] m[i] = (m i,0 ,m i,1 ,…,m i,n-1 ) (6)
[0054] At step 402(RotR) after step 401, the vectors x[0], x[1], x[2] and x[3] are generated based on the vectors m0, m1, m2 and m3 and stored in registers. The vectors x[0] to x[3] are given by the following formula applied by an arithmetic unit or circuit:
[0055]
[0056] where ROTR represents a function for shifting the elements of a vector to the right, whose first parameter corresponds to the vector having the elements to be shifted, and whose second parameter corresponds to the shift spacing, that is, an integer added to the index of each element, modulo the number of elements included in the vector.
[0057] In the case of the matrix Matrix described Figure 2 , the vector x[i] is given by the following formula, where i varies from 0 to n-1:
[0058] x[i] = ROTR(m[i],i) (8)
[0059] At step 403 (Work Reg) after step 402, the working vector w is generated based on vectors x[0] to x[3] and stored in a register. The working vector w is given by the following equation applied by the arithmetic unit:
[0060] w = x[0] xor x[1] xor x[2] xor x[3] (9)
[0061] In the case of the matrix Matrix described with respect to Figure 2 the working vector w is given by the following equation:
[0062]
[0063] where represents the successive application of the logical exclusive OR function or xor function to multiple data items.
[0064] At step 404 (!Vect(i)) after step 403, vectors z[0,l], z[1,l], z[2,l] and z[3,l] are generated based on vectors x[0], x[1], x[2] and x[3] and stored in a register, where j is an integer varying between 0 and n - 1. Vectors z[0,l] to z[3,l] are given by the following equation applied by the arithmetic unit:
[0065]
[0066] where:
[0067] & represents the logical AND function;
[0068] ! represents the logical function enabling the obtaining of the complement of a binary word, in other words,! enables the swapping of elements representing binary 1 and binary 0 in a vector;
[0069] Vect 4 is a unit vector of size 4, whose first element is equal to 1 and whose remaining elements are all equal to 0;
[0070] and l is an integer varying from 0 to 3.
[0071] Specifically, a unit vector is a vector in which all elements except one element include a data item representing binary 0, and specifically, the function ROTR(Vect 4 , i + l) is used to generate a unit vector of size 4 and having an element including a data item representing binary 1 given by the result of taking the modulus of the sum of the integers i and l with 4.
[0072] According to one embodiment, at the first occurrence of step 404, the integer l is equal to zero. The condition for incrementing the integer l will be described hereinafter.
[0073] In the case of the matrix Matrix described with respect to Figure 2 the vector z[i, l] is given by the following formula, where i varies from 0 to n - 1:
[0074] z[i, l] = x[i] &!ROTR(Vect n , i + l) (12)
[0075] where Vect n is the unit vector including n elements.
[0076] At step 405 (XOR) after step 404, the vector y[l] is generated by using the following formula applied by the arithmetic unit and stored in the register:
[0077] y[l] = w xor z[0, l] xor z[1, l] xor z[2, l] xor z[3, l] (13)
[0078] In the case where l is equal to zero, y[0] is given by the following formula:
[0079] y[0] = w xor z[0, 0] xor z[1, 0] xor z[2, 0] xor z[3, 0] = (A, E, I, M) (14)
[0080] In the case of the matrix Matrix described with respect to Figure 2 the vector y[l] is given by the following formula:
[0081]
[0082] At step 406 (l < n - 1?) after step 405, if the value of the integer l used at step 405 is less than 3, (the output Y (yes) of step 406) the next step is step 407 (l++), otherwise (the output N (no) of step 406) the next step is step 408 (RotL).
[0083] In Figure 2 the case of the matrix Matrix, the value of the integer l is compared with n - 1.
[0084] At step 407 after step 406, the integer l is incremented by one unit, that is, incremented by 1.
[0085] At step 408, vectors v[0], v[1], v[2] and v[3] are generated according to vectors y[0], y[1], y[2] and y[3] and stored in registers. Vectors v[0] to v[3] are given by the following equations applied by the arithmetic unit:
[0086]
[0087] where ROTL represents a function for shifting the elements of a vector to the left, whose first parameter corresponds to the vector having the elements to be shifted, and whose second parameter corresponds to the shift step, that is, an integer is subtracted from the index of each element, modulo the number of elements included in the vector.
[0088] In the case of the matrix Matrix described with respect to Figure 2 vector v[i] is given by the following equation:
[0089] v[i] = ROTL(y[i], i) (17)
[0090] At step 409 (Trans(Matrix)) after step 408, all vectors v[0], v[1], v[2] and v[3] have been generated and enable the transpose Trans(Mat) of matrix Mat to be obtained. In fact, vectors v[0], v[1], v[2] and v[3] represent all the rows of the transpose Trans(Mat).
[0091] In Figure 2 the case of the matrix Matrix, vectors v[i] form the rows of the matrix Matrix.
[0092] The advantage of this implementation mode is that it enables the matrix transpose operation to be performed without accessing the data of the matrix to be transposed. In fact, using the working vector w enables the data to be masked during the implementation of method 400.
[0093] Figure 5 is a block diagram illustrating another practical implementation mode of method 500, which performs a matrix transpose operation of the type of transpose operation Trans described with respect to Figure 2 According to one embodiment, method 500 can be implemented by the device 100 described with respect to Figure 1 and more specifically, by a processor and / or one of the circuits forming the circuits of device 100.
[0094] Method 500 is similar to that described with respect to Figure 4The described method 400. In fact, method 500 enables a matrix transpose operation that provides the transpose of a masked matrix as output. To achieve this, the method includes all the steps of method 400 and includes the masking steps described in detail below.
[0095] To illustrate the operation of method 500, and for method 400, consider again the 4×4 matrix Mat given by:
[0096]
[0097] Method 500 is also applicable to obtaining the transpose of a rectangular matrix of size n*p of the type of matrix Matrix described Figure 2 below. To this end, the rectangular matrix needs to be divided into a plurality of square matrices and method 500 is applied to each square matrix, or the rectangular matrix is completed with empty elements to obtain a square matrix. The ability of those skilled in the art is sufficient to make the necessary adaptations based on the explanations given below. The implementation of method 500 is described in detail below by only considering a square matrix Matrix where the integers n and p are equal.
[0098] At the initial step 501(Mat), step 501 can be the same as step 401 of Figure 4 and the data of matrix Mat is stored in registers in the form of four row vectors m[0], m[1], m[2] and m[3], each row vector representing a row of matrix Mat. In other words, vectors m[0] to m[3] are given by:
[0099]
[0100] In the case of the matrix Matrix described Figure 2 below, vector m[i] is given by the following formula, where i varies from 0 to n-1:
[0101] m[i] = (m i,0 , m i,1 , …, m i,n-1 ) (20)
[0102] At step 502(RotR), step 502 can be the same as step 402 and after step 501, vectors x[0], x[1], x[2] and x[3] are generated based on vectors m0, m1, m2 and m3 and stored in registers. Vectors x[0] to x[3] are given by the following formula applied by an arithmetic unit or circuit:
[0103]
[0104] In the case of Figure 2In the case of the described matrix Matrix, the vector x[i] is given by the following formula, where i varies from 0 to n - 1:
[0105] x[i] = ROTR(m[i], i) (22)
[0106] At step 503 (working Reg), step 503 can be the same as step 403 and after step 502, the working vector w is generated based on vectors x[0] to x[3] and stored in a register. The working vector w is given by the following formula applied by an arithmetic unit or circuit:
[0107] w = x[0] xor x[1] xor x[2] xor x[3] (23)
[0108] In the case of the Figure 2 described matrix Matrix, the working vector w is given by the following formula:
[0109]
[0110] where represents the successive application of the logical exclusive - or function or xor function to multiple data items.
[0111] At step 504 (MASK! Vect(i)) after step 503, vectors z’[0, l], z’[1, l], z’[2, l] and z’[3, l] are generated based on vectors x[0], x[1], x[2] and x[3] and the mask r[l] and stored in a register, where l is an integer that varies from 0 to n - 1. Vectors z[0, l] to z[3, l] are given by the following formula applied by an arithmetic unit or circuit:
[0112]
[0113] According to one embodiment, the mask r[l] is a masking data item. According to one example, the mask r[l] is generated randomly or pseudo - randomly. The mask r[l] is used at step 504 to mask the vectors x[0], x[1], x[2] and x[3].
[0114] According to one embodiment, at the first occurrence of step 504, the integer l is equal to zero. The condition for incrementing the integer l will be described below.
[0115] In the case of the Figure 2 described matrix Matrix, the vector z’[i, l] is given by the following formula, where i varies from 0 to n - 1:
[0116] z’[i, l] = (x[i] xor r[l]) &! ROTR(Vectn , i + l) (26)
[0117] At step 505 (XOR) after step 504, the vector y’[l] is generated by using the following equation applied by an arithmetic unit or circuit and stored in a register:
[0118] y’[l] = w xor z’[0, l] xor z’[1, l] xor z’[2, l] xor z’[3, l] (27)
[0119] In the case where l is equal to zero, y’[0] is given by the following equation:
[0120] y’[0] = w xor z’[0, 0] xor z’[1, 0] xor z’[2, 0] xor z’[3, 0] = (A, E, I, M) (28)
[0121] In the case of Figure 2 the matrix Matrix described, the vector y’[l] is given by the following equation:
[0122]
[0123] At step 506 (l < n - 1?) after step 505, if the value of the integer l used at step 505 is less than -3, then (the output Y of step 506) the next step is step 507 (i++), otherwise (the output N of step 506) the next step is step 508 (RotL).
[0124] In Figure 2 the case of the matrix Matrix, the value of the integer l is compared with n - 1.
[0125] At step 507 after step 506, the integer l is incremented by one unit, that is, incremented by 1.
[0126] At step 508, the vectors v’[0], v’[1], v’[2] and v’[3] are generated based on the vectors y’[0], y’[1], y’[2] and y’[3]. The vectors v’[0] to v’[3] are given by the following equations:
[0127]
[0128] In the case of Figure 2 the matrix Matrix described, the vector v’[i] is given by the following equation:
[0129] v′[i] = ROTL(y′[i], i) (31)
[0130] At the final step 509 (Trans(Matrix)) after step 508, all vectors v’[0], v’[1], v’[2] and v’[3] have been generated and enable the transpose Trans(Mat) of matrix Mat to be obtained, and all rows of the transpose Trans(Mat) have been masked with different masks (mask r[l]). In fact, vectors v’[0], v’[1], v’[2] and v’[3] represent all rows of the transpose Trans(Mat).
[0131] In Figure 2 the case of matrix Matrix, vectors v’[i] form the rows of matrix Matrix.
[0132] The advantage of this implementation mode is that it enables the matrix transpose operation to be performed without accessing the data of the matrix to be transposed. In fact, the use of working vector w enables the data to be masked during the implementation of method 500.
[0133] Another advantage of this implementation mode is that it enables a masked matrix transpose to be provided.
[0134] One embodiment protects the data in a processing operation during the application of matrix transpose to a matrix as part of the processing operation. For example, one embodiment facilitates the use of one or more matrix transformations to protect encryption operations against attacks, such as protecting against brute force or side channel attacks, for example protecting against attacks using quantum computing techniques to discover the values of matrices used during encryption operations.
[0135] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these different embodiments and variations can be combined, and other variations will occur to those skilled in the art.
[0136] Finally, based on the functional indications given above, the actual implementation of the described embodiments and variations is within the capabilities of those skilled in the art.
[0137] In one embodiment, a method (400; 500) is for an electronic device to transpose a matrix (Mat) that includes n rows and n columns, each row of the matrix (Mat) forming a first vector m[i], where i is an integer that varies from 0 to n - 1, and the first vector is stored in a first register of the electronic device. The method includes the following successive steps:
[0138] (a) obtaining a second vector x[i] by shifting each first vector m[i] to the right by a spacing corresponding to the number of the row;
[0139] (b) By applying the following equation using the arithmetic unit of the electronic device, a second vector w stored in the second register of the electronic device is generated:
[0140] w = XOR0 n-1 (x[i]), (32)
[0141] where the function corresponds to the successive application of the logical exclusive OR function to a plurality of data items;
[0142] (c) By applying the following equation for each value of i using the arithmetic unit of the electronic device, a third vector z[i, l] stored in the third register of the electronic device is generated, where l is an integer varying from 0 to n - 1:
[0143] z[i, l] = x[i] &!ROTR(Vect n , i + l), (33)
[0144] where:
[0145] & represents the logical AND function;
[0146] ! represents the logical function capable of obtaining the complement of a binary data item;
[0147] ROTR(Vect n , i + l) represents a unit vector in which all elements are equal to 0 except that the element of rank i + l is equal to 1; and
[0148] (d) By applying the following equation using the arithmetic unit, a fourth vector v[l] stored in the fourth register of the electronic device is generated, and the fourth vector v[l] represents the rows of the transpose of matrix A:
[0149]
[0150] where:
[0151] ROTL represents the left shift function;
[0152] xor represents the logical exclusive OR function,
[0153] where steps (c) and (d) are repeated for all values of l.
[0154] In one embodiment, the electronic device is adapted to implement a method (400; 500) for transposing a matrix (Mat), the matrix (Mat) comprising n rows and p columns, each row of the matrix (Mat) forming a first vector m[i], where i is an integer varying from 0 to n - 1, the first vector being stored in the first register of the electronic device, the method comprising the following successive steps:
[0155] (a) Obtain a second vector x[i] by shifting each first vector m[i] to the right by a spacing corresponding to the number of the row;
[0156] (b) Generate a second vector w stored in a second register of the electronic device by applying the following equation using an arithmetic unit of the electronic device:
[0157]
[0158] where the function corresponds to the successive application of the logical exclusive OR function to a plurality of data items;
[0159] (c) Generate a third vector z[i, l] stored in a third register of the electronic device by applying the following equation for each value of i using an arithmetic unit of the electronic device, where l is an integer varying from 0 to n - 1:
[0160] z[i, l] = x[i] &!ROTR(Vect n , i + l), (36)
[0161] where:
[0162] & represents the logical AND function;
[0163] ! represents the logical function enabling the complement of a binary data item to be obtained;
[0164] ROTR(Vect n , i + l) represents a unit vector all of whose elements are equal to 0 except for the element of rank i + l which is equal to 1; and
[0165] (d) Generate a fourth vector v[l] stored in a fourth register of the electronic device by applying the following equation using the arithmetic unit, where the fourth vector v[l] represents the rows of the transpose of matrix A:
[0166] v[l] = ROTL(w xor XOR1 n (z[i, l])), (37)
[0167] where:
[0168] ROTL represents the left shift function;
[0169] xor represents the logical exclusive OR function,
[0170] where steps (c) and (d) are repeated for all values of l.
[0171] In one embodiment, the method includes a masking operation.
[0172] In one embodiment, the masking operation includes applying the xor function.
[0173] In one embodiment, the method includes step (e) of masking a second vector x[i] during step (c).
[0174] In one embodiment, at step (c), a masked third vector z’[i,l] is generated by applying the following equation for each value of i:
[0175] z[i,l] = (x[i] xor r[l]) &!Vect(i,l), (38)
[0176] where r[l] is a mask.
[0177] In one embodiment, the mask r[l] is randomly generated.
[0178] In one embodiment, the integers n and p are equal.
[0179] In one embodiment, the integer n is in the range from 1 to 20.
[0180] In one embodiment, a method includes: using a processing device to perform an encryption operation and protecting the processing device during the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer and each row forms a respective vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the values of the vectors of the first set of ordered vectors in a first direction, wherein the spacing of the shift applied to the vectors of the first set of ordered vectors is based on the sequential numbering of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector.
[0181] In one embodiment, the matrix is a sub - matrix of a larger matrix that is transposed as part of the execution of the encryption operation and the protection, the larger matrix having more than n rows, more than n columns, or more than n rows and more than n columns.
[0182] In one embodiment, the matrix is an augmented matrix of a second matrix that is transposed as part of the execution of the encryption operation and the protection, the second matrix having fewer than n rows, fewer than n columns, or fewer than n rows and fewer than n columns.
[0183] In one embodiment, generating the second set of ordered vectors includes shifting the values of the vectors of the first set of ordered vectors to the right.
[0184] In one embodiment, the working vector is generated by continuously applying an exclusive - or function to the vectors of the second set of ordered vectors.
[0185] In one embodiment, the third set of ordered vectors is generated as follows:
[0186] z[i, l] = x[i] &!ROTR(Vect n , i + l),
[0187] where: z[i, l] represents the value in the l-th position of the i-th vector of the third set of ordered vectors; & represents the logical AND function;! represents the logical NOT function; and ROTR(Vect n , i + l) represents a unit vector in which all elements are equal to 0 except that the element of rank i + l is equal to 1.
[0188] In one embodiment, the fourth set of ordered vectors is generated as follows:
[0189] v[l] = ROTL(w xor XOR1 n (z[i, l])),
[0190] where: v[l] represents the vector of the fourth set of ordered vectors; ROTL represents the left shift function; and xor represents the logical exclusive OR function.
[0191] In one embodiment, performing the matrix transformation operation includes performing a masking operation.
[0192] In one embodiment, the masking operation includes the application of an exclusive OR function.
[0193] In one embodiment, the masking operation includes masking the vectors of the second set of ordered vectors.
[0194] In one embodiment, the masking operation includes randomly generating a mask.
[0195] In one embodiment, n is an integer having a range from 1 to 20.
[0196] In one embodiment, a device includes a memory and processing circuitry coupled to the memory. The processing circuitry performs an encryption operation in operation and protects the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer, and each row forms a respective vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the values of the vectors of the first set of ordered vectors in a first direction, where the spacing of the shift applied to the vectors of the first set of ordered vectors is based on the sequential numbering of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector.
[0197] In one embodiment, the matrix is a sub-matrix of a larger matrix that is transposed as part of the execution of the encryption operation and the protection, the larger matrix having more than n rows, more than n columns, or more than n rows and more than n columns.
[0198] In one embodiment, the matrix is an augmented matrix of a second matrix that is transposed as part of the execution of the encryption operation and the protection, the second matrix having fewer than n rows, fewer than n columns, or fewer than n rows and fewer than n columns.
[0199] In one embodiment, the second set of ordered vectors is generated by shifting the values of the vectors of the first set of ordered vectors to the right.
[0200] In one embodiment, the working vector is generated by continuously applying an exclusive OR function to the vectors of the second set of ordered vectors.
[0201] In one embodiment, performing the matrix transformation operation includes performing a masking operation.
[0202] In one embodiment, a system includes a processor and encryption circuitry coupled to the processor. The encryption circuitry performs an encryption operation in operation and protects the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer, and each row forms a respective vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the values of the vectors of the first set of ordered vectors in a first direction, where the spacing of the shift applied to the vectors of the first set of ordered vectors is based on the sequential numbering of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector.
[0203] In one embodiment, an encryption circuit device generates a result of an encryption operation based on a fourth set of ordered vectors in operation; and a processor uses the result of the encryption operation to execute an application in operation.
[0204] In one embodiment, a second set of ordered vectors is generated by shifting vector values of a first set of ordered vectors to the right.
[0205] In one embodiment, performing a matrix transformation operation includes performing a masking operation.
[0206] In one embodiment, the content of a non-transitory computer-readable medium causes an encryption circuit device to perform a process. The process includes: performing an encryption operation and protecting the execution of the encryption operation. Performing the encryption operation and the protection includes: performing a matrix transformation operation on a matrix having n rows and n columns, where n is a positive integer and each row forms a respective vector of a first set of ordered vectors. Performing the matrix transformation operation includes: generating a second set of ordered vectors by shifting the vector values of the first set of ordered vectors in a first direction, wherein the spacing of the shift applied to the vectors of the first set of ordered vectors is based on the sequential numbering of the vectors of the first set of ordered vectors; generating a working vector by logically combining the vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and generating a fourth set of ordered vectors based on the third set of ordered vectors and the working vector. In one embodiment, the content includes instructions executable by the encryption circuit device.
[0207] Some embodiments may take the form of a computer program product or include a computer program product. For example, according to one embodiment, a computer-readable medium is provided, the computer-readable medium including a computer program that is adapted to execute one or more of the above-described methods or functions. The medium may be a physical storage medium, such as, for example, a read-only memory (ROM) chip, or a disk, such as a digital versatile disk (DVD-ROM), a compact disc (CD-ROM), a hard disk, a memory, a network, or a portable media article that will be read by an appropriate drive device or via an appropriate connection, including other relevant code encoded in one or more barcodes or stored on one or more such computer-readable media and readable by an appropriate reader device.
[0208] In addition, in some embodiments, some or all of the methods and / or functions may be implemented or provided in other ways, such as being implemented at least partially in firmware and / or hardware, which includes but is not limited to one or more application specific integrated circuits (ASICs), digital signal processors, discrete circuit devices, logic gates, standard integrated circuits, controllers (e.g., by executing appropriate instructions and including microcontrollers and / or embedded controllers), field programmable gate arrays (FPGAs), complex programmable logic devices (CPLDs), etc., as well as devices employing RFID technology and various combinations thereof.
[0209] The various embodiments described above may be combined to provide additional embodiments. Aspects of the embodiments may be modified as needed to incorporate concepts from various patents, applications, and publications to provide additional embodiments.
[0210] These and other changes may be made to the embodiments in light of the above detailed description. In general, in the following claims, the terms used should not be construed to limit the claims to the specific embodiments disclosed in the specification and claims, but should be construed to include all possible embodiments and the full scope of equivalents to such claims. Thus, the claims are not limited by the present disclosure.
Claims
1. A method comprising: using a processing device to perform cryptographic operations; as well as protecting the processing device during execution of the encryption operation, the performing of the encryption operation and the protecting comprising: performing a matrix transformation operation on a matrix, the matrix having n rows and n columns, wherein n is a positive integer, each row forming a corresponding vector of the first set of ordered vectors, the performing of the matrix transformation operation comprising: generating a second set of ordered vectors by shifting values of vectors of the first set of ordered vectors in a first direction, wherein a spacing of the shift applied to the vectors of the first set of ordered vectors is based on a sequential number of the vectors of the first set of ordered vectors; generating a working vector by logically combining vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and A fourth set of ordered vectors is generated based on the third set of ordered vectors and the working vectors.
2. The method of claim 1 , wherein the matrix is a submatrix of a larger matrix that is transposed as part of the execution of the encryption operation and the protection, the larger matrix having more than n rows, more than n columns, or more than n rows and more than n columns.
3. The method of claim 1 , wherein the matrix is an augmented matrix of a second matrix that is transposed as part of the execution of the encryption operation and the protecting, the second matrix having fewer than n rows, fewer than n columns, or fewer than n rows and fewer than n columns.
4. The method of claim 1 , wherein generating the second set of ordered vectors comprises: Shift the values of the vectors of the first set of ordered vectors right.
5. The method of claim 1, wherein the working vector is generated by successively applying an XOR function to vectors of the second set of ordered vectors.
6. The method of claim 5, comprising generating the third set of ordered vectors according to: z[i,l]=x[i]&!ROTR(Vect n ,i+l), in: z[i,l] represents the value in position l of the i-th vector of the third set of ordered vectors; & represents the logical and function; ! represents the logical NOT function; and ROTR(Vect n ,i+l) represents a unit vector whose elements are all equal to 0 except the element of rank i+l which is equal to 1.
7. The method of claim 6, comprising generating the fourth set of ordered vectors according to: v[l]=ROTL(w xor XOR1 n (z[i,l])), in: v[l] represents a vector of the fourth set of ordered vectors; ROTL stands for Shift Left Function; and xor represents the logical exclusive OR function.
8. The method of claim 1, wherein performing the matrix transformation operation comprises: Perform a masking operation.
9. The method of claim 8, wherein the masking operation comprises: Application of the XOR function.
10. The method of claim 8, wherein the masking operation comprises: A mask on the vector of the second set of ordered vectors.
11. The method of claim 10, wherein the masking operation comprises: Generates a mask randomly. 12 . The method according to claim 1 , wherein n is an integer ranging from 1 to 20.
13. A device comprising: Memory; as well as processing circuitry coupled to the memory, wherein the processing circuitry is operable to perform cryptographic operations and to protect the performance of the cryptographic operations, the performing of the cryptographic operations and the protecting comprising: performing a matrix transformation operation on a matrix, the matrix having n rows and n columns, where n is a positive integer, each row forming a respective vector of the first set of ordered vectors, the performing of the matrix transformation operation comprising: generating a second set of ordered vectors by shifting values of vectors of the first set of ordered vectors in a first direction, wherein a spacing of the shift applied to the vectors of the first set of ordered vectors is based on a sequential number of the vectors of the first set of ordered vectors; generating a working vector by logically combining vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and A fourth set of ordered vectors is generated based on the third set of ordered vectors and the working vectors.
14. The apparatus of claim 13, wherein the matrix is a submatrix of a larger matrix that is transposed as part of the performance of the encryption operation and the protection, the larger matrix having more than n rows, more than n columns, or more than n rows and more than n columns.
15. The apparatus of claim 13, wherein the matrix is an augmented matrix of a second matrix that is transposed as part of the performance of the encryption operation and the protecting, the second matrix having fewer than n rows, fewer than n columns, or fewer than n rows and fewer than n columns.
16. The apparatus of claim 13, wherein the second set of ordered vectors is generated by right-shifting values of vectors of the first set of ordered vectors.
17. The apparatus of claim 13, wherein the working vector is generated by successively applying an XOR function to vectors of the second set of ordered vectors.
18. The apparatus of claim 13, wherein performing the matrix transformation operation comprises: Perform a masking operation.
19. A system comprising: processor; as well as an encryption circuit device, the encryption circuit device being coupled to the processor, wherein the encryption circuit device is operable to perform an encryption operation and to protect the execution of the encryption operation, the execution of the encryption operation and the protection comprising: performing a matrix transformation operation on a matrix, the matrix having n rows and n columns, wherein n is a positive integer, each row forming a respective vector of a first set of ordered vectors, the execution of the matrix transformation operation comprising: generating a second set of ordered vectors by shifting values of vectors of the first set of ordered vectors in a first direction, wherein a spacing of the shift applied to the vectors of the first set of ordered vectors is based on a sequential number of the vectors of the first set of ordered vectors; generating a working vector by logically combining vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and A fourth set of ordered vectors is generated based on the third set of ordered vectors and the working vectors.
20. The system of claim 19, wherein: The cryptographic circuitry is operable to generate a result of the cryptographic operation based on the fourth set of ordered vectors; and The processor is operable to execute an application using the result of the cryptographic operation.
21. The system of claim 19, wherein the second set of ordered vectors is generated by right-shifting values of vectors of the first set of ordered vectors.
22. The system of claim 19, wherein performing the matrix transformation operation comprises: Perform a masking operation.
23. A non-transitory computer readable medium having content, the content causing an encryption circuit device to perform a method, the method comprising: Perform cryptographic operations; as well as protecting the execution of the encryption operation, the executing the encryption operation and the protecting comprising: performing a matrix transformation operation on a matrix, the matrix having n rows and n columns, wherein n is a positive integer, each row forming a corresponding vector of the first set of ordered vectors, the performing the matrix transformation operation comprising: generating a second set of ordered vectors by shifting values of vectors of the first set of ordered vectors in a first direction, wherein a spacing of the shift applied to the vectors of the first set of ordered vectors is based on a sequential number of the vectors of the first set of ordered vectors; generating a working vector by logically combining vectors of the second set of ordered vectors; generating a third set of ordered vectors based on the second set of ordered vectors; and A fourth set of ordered vectors is generated based on the third set of ordered vectors and the working vectors.
24. The non-transitory computer-readable medium of claim 23, wherein the content comprises instructions executable by the cryptographic circuitry.