Anti-quantum public key cryptographic operation method and device based on reconfigurable technology

By adopting reconstructible technology in the post-quantum public key cryptography computing chip, flexible post-quantum cryptography algorithm is realized, solving the problems of high resource consumption and poor flexibility in the existing technology, and achieving efficient and flexible quantum public key cryptography anti-quantum public key cryptography operation.

CN120217412APending Publication Date: 2025-06-27HENAN MIZHUO INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510299451.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing post-quantum public key cryptographic computing chips consume a lot of resources, have poor flexibility, and are not easy to expand other post-quantum algorithms, which cannot meet the encryption needs under the new situation.

Method used

Using quantum public key cryptography resistant to reconstructible technology, various post-quantum cryptography algorithms are flexibly implemented through reconstructible technology, reducing resource consumption, improving flexibility and computing performance, and easily expanding other post-quantum cryptography algorithms.

Benefits of technology

It achieves the effect of less resource consumption, high flexibility, high computing performance, and easy expansion of other post-quantum cryptographic algorithms, meeting the encryption needs under the new situation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217412A_ABST
    Figure CN120217412A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-quantum public key cryptographic operation method and device based on a reconfigurable technology, and belongs to the technical field of electronic circuits and quantum encryption. The anti-quantum public key cryptographic operation device based on the reconfigurable technology comprises a first processing module used for determining a first cryptographic algorithm and a first rule associated with first target information according to the acquired first target information; the second processing module is used for performing a series of operations according to the first target information, a first cryptographic algorithm and a first rule sent by the first processing module to obtain a first operation result; the algorithm development and verification module is used for providing a reconfigurable operation module resource interface to complete development and verification of a cryptographic algorithm and compiling the cryptographic algorithm into a machine code; and the storage module is used for storing data and files including the compiled cryptographic algorithm, the first target information, the first cryptographic algorithm, the first rule, data in operation and operation result data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention discloses an anti - quantum public - key cryptography operation method and device based on reconfigurable technology, belonging to the technical fields of electronic circuits and quantum encryption technology. Background Art

[0002] With the continuous enhancement of the computing power of quantum computers, conventional public - key cryptography algorithms can be broken by large enough and stable quantum computers, making these traditional public - key cryptography algorithms no longer meet the encryption requirements under the new situation.

[0003] Post - Quantum Cryptography (PQC) algorithms, also known as anti - quantum cryptography algorithms, refer to cryptography algorithms that can resist attacks from quantum computers in the era of quantum computing. In related technologies, most researchers conduct research based on specific algorithm theories and lack research on specific applications, resulting in problems such as low security and poor practicability in the practical application of post - quantum cryptography algorithms. Currently, the publicly available post - quantum cryptography operation chips are also implemented based on integrated circuits. Each post - quantum operation component is used for the cryptography operation process of a post - quantum algorithm. When it is necessary to expand for a new post - quantum algorithm, the hardware integrated circuit of the new post - quantum algorithm needs to be added to the cryptography chip. This method supports relatively fixed algorithms and has problems such as high resource consumption, poor flexibility, and difficulty in expanding other post - quantum algorithms. Summary of the Invention

[0004] In order to solve the above - mentioned technical problems, the present invention is proposed. Embodiments of the present invention provide an anti - quantum public - key cryptography operation method and device based on reconfigurable technology, which can flexibly implement various post - quantum cryptography algorithms by using reconfigurable technology, and have the advantages of less resource consumption, high flexibility, high operation performance, and easy expansion of other post - quantum cryptography algorithms.

[0005] According to one aspect of the present application, there is provided an anti - quantum public - key cryptography operation device based on reconfigurable technology, including: a first processing module, configured to determine a first cryptography algorithm and a first rule associated with the acquired first target information; a second processing module, configured to perform a series of operations on the first target information, the first cryptography algorithm, and the first rule sent by the first processing module to obtain a first operation result; an algorithm development and verification module, configured to provide a reconfigurable operation module resource interface to complete the development and verification of the cryptography algorithm and compile it into machine code; a storage module, configured to store data and files, including the compiled cryptography algorithm, the first target information, the first cryptography algorithm, the first rule, the data during the operation, and the operation result data.

[0006] In the above anti-quantum public key cryptographic operation device based on reconfigurable technology, the first processing module includes: a communication unit for communicating with other units or external interfaces, including obtaining the first target information from an external application layer cryptographic service interface; a data processing unit for processing the first target information to obtain the first cryptographic algorithm and the first rule associated with the first target information and for determining whether the first target information meets a threshold condition, wherein the data processing unit performs data parsing on the first target information based on a preset data parsing rule to obtain the first cryptographic algorithm and the first rule.

[0007] In the above anti-quantum public key cryptographic operation device based on reconfigurable technology, the step in which the data processing unit determines whether the first target information meets a threshold condition includes: determining whether the data volume of the first target information is less than a first threshold, and when the data volume of the first target information is less than the first threshold, generating first feedback information; obtaining a set of cryptographic algorithms, and when the set of cryptographic algorithms does not include the first cryptographic algorithm of the first target information, determining that the first target information does not meet the threshold condition and generating second feedback information; wherein the set of cryptographic algorithms is the set of all cryptographic algorithms implemented by the cryptographic operation device.

[0008] In the above anti-quantum public key cryptographic operation device based on reconfigurable technology, the first processing module further includes: a feedback unit for receiving the first feedback information and the second feedback information and triggering the communication unit to send the first feedback information and the second feedback information to an external application layer cryptographic service interface; a sending unit for sending the first target information, the first cryptographic algorithm, and the first rule to a second processing module when the first target information meets the threshold condition.

[0009] In the above anti-quantum public key cryptography operation device based on reconfigurable technology, the second processing module includes: a cryptographic algorithm implementation unit for specifically implementing various cryptographic algorithms, including various post-quantum cryptographic algorithms, classical ECC, and various symmetric hash cryptographic algorithms, which, in response to the first cryptographic algorithm and the first rule, performs operations on the first target information using the corresponding cryptographic algorithm; an instruction parsing unit for analyzing the operation instructions or configuration instructions sent by the main control or the instruction stream memory and allocating the instructions to the corresponding units for execution; a reconfigurable functional operation unit for commanding each functional operation operator to perform operations according to the operation instructions of the instruction parsing unit and triggering the configuration instructions sent by the main control, where the functional operation operators include: NTT (NTT operation), POM (polynomial modular multiplication operation), POI (polynomial modular inverse operation), MAO (vector and matrix operation); a reconfigurable AEA array for modifying operation parameters and reconfiguring according to the operation instructions and configuration instructions of the instruction parsing unit to complete various operation functions, thereby supporting the operations of the functional operation operators; a reconfigurable data generation unit for reconstructing according to the operation instructions of the instruction parsing unit to complete the generation of pseudo-random numbers and various sampling functions; a reconfigurable data storage unit for the reconfigurable AEA array and the data generation unit to read and store data, supporting DMA transmission, and having a flexibly configurable working register group (WRG).

[0010] In the above anti-quantum public key cryptography operation device based on reconfigurable technology, the reconfigurable AEA array is an n×n AE array, the AE is configured as an operator for reconfigurable basic operations, and the AE can be reconfigured to implement various basic operation functions including modular addition, modular multiplication, etc.

[0011] According to another aspect of the present application, there is provided an anti-quantum public key cryptography operation method based on reconfigurable technology, including: obtaining a target information; obtaining a first cryptographic algorithm and a first rule according to the target information and determining whether the target information meets a threshold condition, where the first cryptographic algorithm and the first rule are information associated with the target information, and the first rule includes key pair generation, signature generation, signature verification, data encryption, and data decryption; performing operations according to the target information, the first cryptographic algorithm, and the first rule to obtain a first operation result; and returning the first operation result.

[0012] In the above anti-quantum public key cryptography operation method based on reconfigurable technology, the step of determining whether the target information meets the threshold condition includes: determining whether the data volume of the target information is less than a first threshold, and when the data volume of the target information is less than the first threshold, generating first feedback information; obtaining a set of cryptographic algorithms, and when the first cryptographic algorithm associated with the target information is not included in the set of cryptographic algorithms, determining that the target information does not meet the threshold condition and generating second feedback information.

[0013] In the above anti-quantum public key cryptography operation method based on reconfigurable technology, the step of obtaining the first operation result includes: matching a corresponding cryptographic algorithm according to the first cryptographic algorithm, triggering the matched cryptographic algorithm to start operating on the target information and issuing an operation instruction according to the first rule; according to the operation instruction, the reconfigurable functional operation unit is reconfigured to complete the corresponding operation and trigger the main control to send a configuration instruction and the reconfigurable data generation unit is reconfigured to complete the corresponding operation; according to the configuration instruction, the reconfigurable data storage unit configures the connection relationship between the WRG and the reconfigurable AEA array; according to the operation instruction and the configuration instruction, the reconfigurable AEA array modifies the operation parameters and is reconfigured to complete various basic operation functions.

[0014] According to another aspect of the present application, there is provided a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above anti-quantum public key cryptography operation method based on reconfigurable technology is implemented.

[0015] Compared with the prior art, the beneficial effects of the present invention are at least as follows:

[0016] After analyzing 8 algorithms solicited in the third round of the NIST (National Institute of Standards and Technology) post-quantum algorithm selection, the present invention found that the basic mathematical problems thereof all have common basic operations, and based on the basic operations, core operations of various different schemes are formed.

[0017] From the perspectives of resource utilization and algorithm performance, if multiple physical NTTs (Number Theoretic Transforms) and modular arithmetic and other hardware logic units are implemented, the algorithm operation performance can be effectively improved. However, due to the fixed algorithm, the resource consumption is relatively large, and it is not easy to expand to other post-quantum cryptography algorithms. Since there are many branches of PQC algorithms and various security levels, and in addition, the research on PQC algorithms is still in continuous development, it is very important to flexibly implement PQC algorithms. Therefore, a reconfigurable method is used to design them. The reconfigurable computing of the post-quantum public key cryptography algorithm chip can be divided into time-sensitive computing and space resource-sensitive computing methods. Time resource-sensitive computing requires quick completion of computing. Therefore, more logic resources are adopted, and the computing is completed within the shortest clock cycle by means of parallelism, pipelining, expanding the computing vector length, etc. The space resource-sensitive computing method generally uses a small amount of hardware logic resources and completes the computing by consuming more time.

[0018] The present invention adopts a technical route of time-space fusion, uses the operator AE of reconfigurable basic operations as the resource unit of the most basic reconfigurable operations. Each AE can be independently configured to complete multiple basic operation functions, and multiple AEs form a reconfigurable AEA computing array to achieve the compatibility of time-sensitive and space-sensitive computing. Through the above solution, with less hardware resource consumption, the reconfigurable resources of the algorithm can be flexibly configured according to the different performances and the number requirements of different algorithms, achieving flexible and maximized utilization of "resources - performance", and can flexibly support the implementation of other post-quantum algorithms in the later stage, thereby meeting the requirements of algorithm diversification. Brief Description of the Drawings

[0019] By describing the embodiments of the present application in more detail in conjunction with the drawings, the above and other objects, features and advantages of the present application will become more obvious. The drawings are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation to the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0020] Figure 1 The figure shows a schematic diagram of a post-quantum public key cryptography operation device based on reconfigurable technology according to an embodiment of the present application;

[0021] Figure 2 The figure shows a schematic diagram of a post-quantum public key cryptography operation device based on reconfigurable technology according to another embodiment of the present application;

[0022] Figure 3 The figure shows a schematic diagram of a post-quantum public key cryptography operation device based on reconfigurable technology according to another embodiment of the present application;

[0023] Figure 4 The figure shows a schematic diagram of a reconfigurable functional arithmetic unit provided according to an embodiment of the present application;

[0024] Figure 5 The figure shows a schematic diagram of a reconfigurable AEA array provided according to an embodiment of the present application;

[0025] Figure 6 The figure shows a schematic diagram of an operator AE for reconfigurable basic arithmetic provided according to an embodiment of the present application;

[0026] Figure 7 The figure shows a schematic diagram of an implementation of a functional arithmetic operator NTT based on a reconfigurable AEA array according to an embodiment of the present application;

[0027] Figure 8 The figure shows a flowchart of a method for quantum-resistant public key cryptography operations based on reconfigurable technology provided according to an embodiment of the present application;

[0028] Figure 9 The figure shows a flowchart of steps for determining whether target information meets a threshold condition according to an embodiment of the present application;

[0029] Figure 10 The figure shows a flowchart of steps for obtaining a first operation result according to an embodiment of the present application. Detailed implementation manners

[0030] Next, exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only a part of the embodiments of the present application, rather than all of the embodiments of the present application, and the present application is not limited by the exemplary embodiments described herein.

[0031] Please refer to Figure 1 , which shows a schematic diagram of a quantum-resistant public key cryptography operation device based on reconfigurable technology provided according to an embodiment of the present application. The quantum-resistant public key cryptography operation device based on reconfigurable technology includes:

[0032] A first processing module 100, configured to determine a first cryptographic algorithm and a first rule associated with the first target information according to the acquired first target information;

[0033] The first processing module 100 is configured to acquire the first target information, and parse the target information based on a pre-stored data parsing rule, so as to acquire the cryptographic algorithm and operation rule required by the target information, and the operation rule is one of public-private key generation, encryption, decryption, signature generation, and signature verification;

[0034] The second processing module 200 is configured to perform a series of operations on the basis of the first target information, the first cryptographic algorithm, and the first rule sent by the first processing module 100 to obtain a first operation result;

[0035] The second processing module 200 searches for the corresponding cryptographic algorithm in the implemented cryptographic algorithms according to the cryptographic algorithm required for the target information. The corresponding cryptographic algorithm enables the relevant reconfigurable arithmetic units according to the operation rules required for the target information to start a series of operations on the target information, and finally outputs the operation result, where the operation result is one of the public-private key, the encrypted ciphertext, the decrypted plaintext, the signed data, and the signature verification result;

[0036] The algorithm development and verification module 300 is configured to provide a reconfigurable arithmetic module resource interface to complete the development and verification of the cryptographic algorithm, and compile it into machine code;

[0037] Based on the reconfigurable computing ability of the second processing module 200, the algorithm development and verification module 300 exposes all the hardware resource interfaces of the cryptographic operation device, shields the complex register-level operations of the underlying hardware, facilitates users to quickly perform secondary development, and at the same time provides a set of microcode reconfigurable instruction sets and their supporting IDE environments for users to develop and verify other cryptographic algorithms. The finally compiled binary file is stored in the device and can be executed by the device; thus, other post-quantum cryptographic algorithms can be quickly and flexibly implemented without redesigning the device and adding additional hardware integrated circuits;

[0038] The storage module 400 is configured to store data and files, including the compiled cryptographic algorithm, the first target information, the first cryptographic algorithm, the first rule, the data during the operation, and the operation result data;

[0039] The storage module 400 may include a RAM memory and a FLASH memory. The storage capacity of the RAM (Random-Access Memory) memory can reach 1MB, and it supports byte / half-word / word data read and write access; the storage capacity of the FLASH memory can reach 16MB, and it supports read operations, erase operations, and write operations; the storage module 400 can partition the storage area to meet the storage requirements. For example, the FLASH memory may include a cryptographic algorithm storage area for storing the compiled cryptographic algorithm, and the RAM memory may be used to store the target information, the cryptographic algorithm required for the target information, the operation rules, the data during the operation, and the operation result data.

[0040] Please refer to Figure 2 , which shows a schematic diagram of a quantum-resistant public key cryptographic operation device based on reconfigurable technology according to another embodiment of the present application. The quantum-resistant public key cryptographic operation device based on reconfigurable technology includes as shown in the referenceFigure 1 All components of the anti-quantum public key cryptographic operation device based on reconfigurable technology provided by an embodiment of the present application shown, that is, the first processing module 100, the second processing module 200, the algorithm development and verification module 300, and the storage module 400.

[0041] Among them, the first processing module 100 further includes:

[0042] A communication unit 110, configured to communicate with other units or external interfaces, including obtaining the first target information from an external application layer cryptographic service interface;

[0043] The application layer cryptographic service interface is an external application interface and does not belong to the components of the device of the present invention. The communication unit 110 may include a communication access interface, and use this communication access interface to communicate with the external application layer interface, including obtaining target information from the external application layer cryptographic service interface; the communication unit 110 may also communicate with the algorithm development and verification module 300, and is used to pass in data during the verification in the algorithm development stage;

[0044] A data processing unit 120, configured to process the first target information to obtain the first cryptographic algorithm and the first rule associated with the first target information, and determine whether the first target information meets a threshold condition, where the data processing unit performs data parsing on the first target information based on a pre-set data parsing rule to obtain the first cryptographic algorithm and the first rule;

[0045] The data processing unit 120 reads the pre-set data parsing rule from the FLASH memory in the storage module 400, and uses this parsing rule to parse the target information. The parsing result is the cryptographic algorithm and operation rule required by the target information. The operation rule is one of public-private key generation, encryption, decryption, signature generation, and signature verification; the data parsing rule is set synchronously when the cryptographic algorithm is implemented and can be modified according to the change of the algorithm; then the data processing unit 120 can determine whether the first target information meets the threshold condition. If the judgment result is that the threshold condition is not met, feedback information is generated, and subsequent operations are no longer triggered at this time.

[0046] Optionally, the step of the data processing unit 120 determining whether the first target information meets the threshold condition includes:

[0047] Determine whether the data volume of the first target information is less than a first threshold. When the data volume of the first target information is less than the first threshold, generate a first feedback information;

[0048] The first threshold may be related to the character length. For example, when the target information is an empty string, it is considered that the target information does not meet the threshold condition, and feedback information indicating that the target information is non-compliant is generated. The first threshold may also be related to the type of information carried by the target information. When the parsing result of the target information does not include a cryptographic algorithm or operation rule, it can be considered that the target information does not meet the threshold condition, and feedback information indicating that the target information is incomplete is generated;

[0049] Obtain a set of cryptographic algorithms. When the set of cryptographic algorithms does not include the first cryptographic algorithm of the first target information, it is determined that the first target information does not meet the threshold condition, and second feedback information is generated; wherein the set of cryptographic algorithms is the set of all cryptographic algorithms implemented by the cryptographic operation device;

[0050] The set of cryptographic algorithms can be obtained by the data processing unit 120 from the storage module 400. The first cryptographic algorithm is the cryptographic algorithm required for the target information. When the first cryptographic algorithm is not included in the set of cryptographic algorithms, the device of the present invention temporarily cannot perform the required processing on the target information, and feedback information indicating that there is no matching cryptographic algorithm and temporarily cannot be processed is generated.

[0051] Optionally, the first processing module 100 further includes:

[0052] The feedback unit 130 is configured to receive, when the data processing unit 120 determines that the target information does not meet the threshold condition, the feedback information indicating that the target information is non-compliant, the target information is incomplete, and there is no matching cryptographic algorithm and temporarily cannot be processed generated by the data processing unit 120, and then trigger the communication unit 110 to send the corresponding feedback information to the external application layer cryptographic service interface. The user of the external application layer cryptographic service interface can perform corresponding operations according to different feedback information. For example, when the feedback information indicates that there is no matching cryptographic algorithm and temporarily cannot be processed, the user of the external application layer cryptographic service interface can use the algorithm development verification module 300 to perform rapid development verification on the cryptographic algorithm to meet the requirements of algorithm diversity;

[0053] The sending unit 140 is configured to send the target information, the cryptographic algorithm required for the target information, and the operation rule required for the target information to the second processing module 200 when the target information meets the threshold condition.

[0054] Please refer to Figure 3 , which shows a schematic diagram of a quantum-resistant public key cryptographic operation device based on reconfigurable technology according to another embodiment of the present application. The quantum-resistant public key cryptographic operation device based on reconfigurable technology includes, as shown in reference Figure 2All components of the anti-quantum public key cryptography operation device based on reconfigurable technology provided by another embodiment of the present application are shown, namely, the first processing module 100, the second processing module 200, the algorithm development and verification module 300, and the storage module 400. The first processing module 100 further includes: a communication unit 110, a data processing unit 120, a feedback unit 130, and a sending unit 140.

[0055] Optionally, the second processing module 200 further includes:

[0056] A cryptographic algorithm implementation unit 210, used for the specific implementation of cryptographic algorithms. Utilizing the reconfigurable computing function of the device of the present invention, various post-quantum cryptographic algorithms can be flexibly implemented through microinstructions. The post-quantum cryptographic algorithms may include Kyber, McEliece, Saber, Dilithium, Falcon, Sphincs, Rainbow, which are not limited herein; at the same time, classical ECC and various symmetric hash cryptographic algorithms can be implemented, such as SM2, ECC, SHA-1 / 2 / 3, AES, etc., to further improve the usage efficiency of the circuit. The cryptographic algorithms implemented through microinstructions are converted into instruction streams and stored in the instruction stream memory. The instruction stream memory can be the FLASH memory in the storage module 400; in response to the cryptographic algorithms and operation rules required by the target information, the target information is operated using the corresponding cryptographic algorithm;

[0057] An instruction parsing unit 220, used for analyzing the instructions sent by the main control or the instruction stream memory, and allocating the instructions to the corresponding units for execution. The instructions include operation instructions and configuration instructions; the instruction stream memory issues operation instructions, and the main control sends corresponding configuration instructions according to the operation instructions. The operation instructions or configuration instructions are executed by other unit modules;

[0058] A reconfigurable function operation unit 230, used for commanding each function operation operator to operate according to the operation instructions of the instruction parsing unit 220, and triggering the main control to send configuration instructions. Among them, the function operation operators include: NTT (NTT operation), POM (polynomial modular multiplication operation), POI (polynomial modular inverse operation), MAO (vector and matrix operation);

[0059] Please refer to Figure 4 , which shows a schematic diagram of a reconfigurable function operation unit provided according to an embodiment of the present application;

[0060] The fundamental mathematical problems of post-quantum cryptography algorithms include lattice-based cryptography, multivariate, coding, etc. Among the lattice-based post-quantum cryptographic operations, the most time-consuming and computationally intensive is the NTT operation, which constitutes polynomial and vector operations, and vector operations constitute matrix operations. The generation of public and private keys, signature / verification, and public key encryption / decryption operations all require operations centered around NTT. The NTT operation is equivalent to the point operation in ECC and the modular exponentiation operation in RSA. Therefore, the reconfigurable functional operation unit 230 is designed as shown in Figure 4 including various functional operation operators such as NTT2301 (NTT operation), POM2302 (polynomial modular multiplication operation), POI2303 (polynomial modular inverse operation), MAO2304 (vector and matrix operation), MMM2305 (large number modular multiplication operation), etc. In response to the operation instructions of the instruction parsing unit 220, it commands each functional operation operator to perform sequential or combined operations, thereby completing the operation requirements of the core of the cryptographic algorithm. Each functional operation operator can configure operation parameters according to the encryption level requirements of the target information. Among them, polynomial operations support multiple polynomial lengths such as 256 / 512 / 1024 / 2048 / 4096, vector operations support multiple dimensions such as 2 / 3 / 4 / 5 / 6 / 7 / 8, and matrix operations support multiple dimensions such as 2×2 to 8×8;

[0061] Return reference Figure 3 , the reconfigurable AEA array 240, is used to modify operation parameters and reconstruct according to the operation instructions and configuration instructions of the instruction parsing unit 220 to complete various operation functions, thereby supporting the operations of the functional operation operators;

[0062] Please refer to Figure 5 , which shows a schematic diagram of the reconfigurable AEA array provided according to an embodiment of the present application;

[0063] As shown in Figure 5 , the reconfigurable AEA array 240 can be a 4x4 AE array; the AE is configured as an operator for reconfigurable basic operations, which is implemented by an integrated circuit to take advantage of high operation performance, and at the same time can achieve various basic operation functions including modular addition and modular multiplication through configuration and reconstruction; the reconfigurable AEA array 240 responds to the operation instructions and configuration instructions of the instruction parsing unit 220, modifies operation parameters and reconstructs to complete various basic operation functions, thereby supporting the operations of the functional operation operators. In theory, by scheduling one AE, the operation requirements of the relevant functional operation operators can be completed. Taking the lattice cryptography algorithm as an example, the lattice cryptography algorithm is mainly composed of polynomial operations, and the algorithm has strong parallelism. Therefore, we can design multiple AEs to form an array for parallel operation to improve the algorithm performance. In particular, it is very necessary to use the reconfigurable AEA array 240 to speed up the NTT operation;

[0064] Please refer to Figure 6, which shows a schematic diagram of the operator AE for reconfigurable basic operations provided according to an embodiment of the present application;

[0065] As Figure 6 shown, AE can be designed as a processing unit with five inputs and two outputs, consisting of multiple basic MAs (reconfigurable addition units), MMs (reconfigurable multiplication units), registers, and routing paths. AE has two supporting dual-port RAMs for operations; MA supports addition, subtraction, modular addition, modular subtraction, exclusive OR, and PASS functions, MM supports binary field multiplication and integer multiplication, and the squares are registers; AE has five input signals, A, B, w, m, and q, and two output signals S1 and S2. Taking the butterfly operation as an example, A and B are operation operands, w is the rotation factor, m is the modulus parameter of the Montgomery modular multiplier, q is the modulus, where m and q come from the modulus and modulus parameter registers, A, B, and w come from the working register group, and the two output signals are the two outputs of the butterfly operation; there is also a function configuration register CFGR inside each AE unit, and the configuration code of this AE is stored in CFGR. The configuration circuit CFDC parses the configuration code into the configuration signals CF_signals of each MA and MM. Both MA and MM determine their own functions according to the configuration signals, and the output results S1 and S2 are also selected according to the configuration code. Finally, the overall circuit can complete different basic operation functions, and the configuration register CFGR can be configured by configuration instructions; the operation code of AE and its corresponding operation relationship can be shown in Table 1; the operation code of MA and its corresponding operation relationship can be shown in Table 2; the operation code of MM and its corresponding operation relationship can be shown in Table 3;

[0066] Table 1 AE operation function table

[0067]

[0068] Table 2 MA operation function table

[0069] Serial number Opcode MA function Supported data length 1 {0000} MOD-ADD 8 - 32bit 2 {0001} MOD-SUB 8 - 32bit 3 {0010} ADD 8 - 32bit 4 {0011} SUB 8 - 32bit 5 {0100} AND 8 - 32bit 6 {0101} OR 8 - 32bit 7 {0110} XOR 8 - 32bit 8 {0111} PASS-A 8 - 32bit 9 {1000} PASS-B 8 - 32bit 10 other No function, output 0 8 - 32bit

[0070] Table 3 MM operation function table

[0071]

[0072] Next, the implementation method of the functional operation operator NTT based on the reconfigurable AEA array 240 according to the embodiment of the present application will be described with reference to Figure 7 ;

[0073] As Figure 7 shown, designed with 4 AEs and 8 dual-port RAMs, taking the 256-point NTT operation as an example, the execution order when it completes the NTT operation is:

[0074] STEP1: The state machine controls RAM_A0, RAM_A1, RAM_A2, and RAM_A3 to output the coefficients of addresses 0, 32, 64, 96, 4n / 8, 5n / 8, 192, and 224 to AE. The state machine controls RAM_C to output the current 4 W values to AE. AE completes the operation through three-stage pipelining and writes the results to addresses 0, 1, 64, 65, 4n / 8, 4n / 8 + 1, 192, and 193 of RAM_B0;

[0075] STEP2: Reverse the input and output order of RAMA and RAMB, and repeat the operation in 1 to complete the operation of 8 address data in the second column;

[0076] STEP3: Repeat steps 1 and 2. Each time, complete the operation of 8 address data and repeat 16 times to complete the operation of 256 addresses in one round;

[0077] STEP4: Repeat step 3 for 8 rounds. At this time, the entire NTT operation is completed;

[0078] Return reference Figure 3 , the reconfigurable data generation unit 250 is used to complete the generation of pseudo-random numbers and various sampling functions according to the reconstruction of the operation instructions of the instruction parsing unit 220;

[0079] The reconfigurable data generation unit 250 includes a Kecak structure circuit and a sampling circuit. The Kecak circuit can implement the SHA3 series of algorithms, support SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE-128, and SHAKE-256 algorithms, and can generate pseudo-random numbers at the same time. The sampling circuit includes a uniform sampler, a binomial distribution sampler, and a rejection sampler. The pseudo-random numbers output from the kecak circuit are sampled by the sampling circuit, supporting the generation of random matrices, random vectors, random polynomials, etc.;

[0080] Taking the Kebyer algorithm as an example, when generating a random matrix, use the SHAKE-128 algorithm to output pseudo-random numbers, use the rejection sampler, the Kecak unit outputs 1088-bit random numbers, with 12 bits as a coefficient, and 4 × 12 bits are sampled simultaneously. When the coefficient value is greater than q, it is discarded, and when the coefficient value is less than q, it is stored as a polynomial coefficient and written into the memory. When generating a random short vector, use the SHAKE-256 algorithm to output pseudo-random numbers, the kecak outputs 1344-bit random numbers, use the binomial distribution sampler, output one coefficient every 4 bits, divide the 4-bit random numbers into two parts, each part with 2 bits, calculate the Hamming weight (the number of 1s) of each part, then subtract the two Hamming weights, and the result obtained is modulo q. The final result is stored as a polynomial coefficient and written into the memory;

[0081] The reconfigurable data storage unit 260 is used for the reconfigurable AEA array 240 and the reconfigurable data generation unit 250 to read and store data, supports DMA (Data Memory Access) transmission, and has a flexible and configurable working register group (WRG), and can configure the connection relationship between the WRG and the reconfigurable AEA array 240 according to the configuration instruction.

[0082] Please refer to Figure 8 , which shows a method flowchart of a quantum-resistant public key cryptography operation method based on reconfigurable technology provided by an embodiment of the present application. The quantum-resistant public key cryptography operation method based on reconfigurable technology may include step S100, step S200, step S300, and step S400.

[0083] In step S100, a target information is obtained.

[0084] The target information is the information that needs to be processed by a cryptographic algorithm. The target information can be obtained from the external application layer cryptographic service interface through the communication unit 110 of a device such as Figure 2 .

[0085] In step S200, a first cryptographic algorithm and a first rule are obtained according to the target information, and it is determined whether the target information meets the threshold condition, where the first cryptographic algorithm and the first rule are information associated with the target information, and the first rule includes key pair generation, signature generation, signature verification, data encryption, and data decryption.

[0086] The target information carries the required cryptographic algorithm and operation rule information. The cryptographic algorithm can be one of the quantum-resistant public key cryptographic algorithms or one of the traditional encryption algorithms, and the operation rule can be one of public-private key generation, signature generation, signature verification, data encryption, and data decryption. At the same time, the target information also carries the required encryption level information.

[0087] In one example, it can be obtained by processing the target information through the data processing unit 120 of a device such as Figure 2 . The data processing unit 120 reads the pre-set data parsing rule from the storage module 400, uses the parsing rule to parse the target information, and the parsing result is the cryptographic algorithm and operation rule required by the target information, and also includes the encryption level information required by the target information; then the data processing unit 120 can determine whether the target information meets the threshold condition according to the threshold condition.

[0088] In one example, it can be determined whether the target information meets the threshold condition through the process shown in Figure 9 .

[0089] Figure 9 The flowchart shows the steps of determining whether the target information meets the threshold condition according to an embodiment of the present application.

[0090] As Figure 9 shown, in step S221, it is determined whether the data volume of the target information is less than the first threshold. When the data volume of the target information is less than the first threshold, first feedback information is generated.

[0091] For example, the first threshold may be related to the character length. When the target information is an empty string, it is considered that the target information does not meet the threshold condition, and feedback information indicating that the target information is non-compliant is generated; the first threshold may also be related to the types of information carried by the target information. When the parsing result of the target information does not include a cryptographic algorithm or an operation rule, it can be considered that the target information does not meet the threshold condition, and feedback information indicating that the target information is incomplete is generated.

[0092] Then, in step S222, a set of cryptographic algorithms is obtained. When the set of cryptographic algorithms does not include the first cryptographic algorithm associated with the target information, it is determined that the target information does not meet the threshold condition, and second feedback information is generated.

[0093] The set of cryptographic algorithms is the set of all cryptographic algorithms implemented by the device of the present invention. The first cryptographic algorithm is the cryptographic algorithm required for the target information. When the first cryptographic algorithm is not included in the set of cryptographic algorithms, the device of the present invention cannot perform the required processing on the target information for the time being, and feedback information indicating that there is no matching cryptographic algorithm and it cannot be processed temporarily is generated.

[0094] Returning to reference Figure 8 , in step S300, a first operation result is obtained by performing an operation according to the target information, the first cryptographic algorithm, and the first rule.

[0095] In one example, the first operation result can be obtained through the process as Figure 10 shown.

[0096] Figure 10 The flowchart shows the steps of obtaining the first operation result according to an embodiment of the present application.

[0097] As Figure 10 shown, in step S310, the corresponding cryptographic algorithm is matched according to the first cryptographic algorithm, and the matched cryptographic algorithm is triggered according to the first rule to start operating on the target information and issue an operation instruction.

[0098] Match the corresponding cryptographic algorithm according to the cryptographic algorithm required by the target information in the implemented set of cryptographic algorithms, and start the matched cryptographic algorithm based on the operation rules and encryption level required by the target information to perform operation processing on the target information, and send operation instructions by the instruction stream memory.

[0099] Next, in step S320, according to the operation instructions, the reconfigurable functional operation unit is reconfigured to complete the corresponding operation and trigger the main control to send configuration instructions, and the reconfigurable data generation unit is reconfigured to complete the corresponding operation.

[0100] The operation instructions are responsible for analysis by the instruction parsing unit and assigned to the corresponding processing units for execution. According to the operation instructions, the reconfigurable functional operation unit performs operations using different functional operation operators, and the reconfigurable functional operation unit can configure operations of different lengths according to the encryption level requirements. The operations of the reconfigurable functional operation unit require the operation support of the reconfigurable AEA array. According to the operation requirements, the reconfigurable functional operation unit triggers the main control to send configuration instructions to reconfigure the reconfigurable AEA array to complete the corresponding operation function; according to the operation instructions, the reconfigurable data generation unit reconfigures the sampling circuit to complete different sampling functions.

[0101] In step S330, according to the configuration instructions, the reconfigurable data storage unit configures the connection relationship between the WRG and the reconfigurable AEA array; according to the operation instructions and configuration instructions, the reconfigurable AEA array modifies the operation parameters and is reconfigured to complete various basic operation functions.

[0102] The configuration instructions are also responsible for analysis by the instruction parsing unit and assigned to the corresponding processing units for execution. According to the operation instructions and configuration instructions, the reconfigurable AEA array modifies the operation parameters and is reconfigured to complete various basic operation functions; according to the configuration instructions, the reconfigurable data storage unit performs corresponding configuration on the working register group (WRG) and the connection relationship between the WRG and the AE to cooperate with the AE to complete the corresponding operation.

[0103] Return reference Figure 8 , in step S400, return the first operation result.

[0104] Based on the coordinated operations of the reconfigurable AEA array, the reconfigurable data storage unit, the reconfigurable functional operation unit, and the reconfigurable data generation unit, finally generate the operation result of the target information, and trigger the main control to return the operation result to the external application layer cryptographic service interface through the communication unit.

[0105] In addition, an embodiment of the present application may also be a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned anti-quantum public key cryptographic operation method based on reconfigurable technology is implemented.

[0106] The basic principles of the present application have been described in conjunction with specific embodiments. It should be understood that the above-disclosed specific details are only for illustrative and facilitating understanding purposes, rather than limitations, and are not used to limit the protection scope of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A quantum-resistant public key cryptographic computing device based on reconfigurable technology, characterized in that: The device comprises: A first processing module, configured to determine a first cryptographic algorithm and a first rule associated with the first target information according to the acquired first target information; A second processing module, configured to perform a series of operations according to the first target information, the first cryptographic algorithm and the first rule sent by the first processing module to obtain a first operation result; Algorithm development and verification module, used to provide a reconfigurable operation module resource interface to complete the development and verification of cryptographic algorithms and compile them into machine code; The storage module is used to store data and files, including the compiled cryptographic algorithm, the first target information, the first cryptographic algorithm, the first rule, the data in operation and the operation result data.

2. The quantum-resistant public key cryptographic computing device based on reconfigurable technology as claimed in claim 1, characterized in that: The first processing module comprises: A communication unit, used to communicate with other units or external interfaces, including obtaining the first target information from an external application layer cryptographic service interface; A data processing unit is used to process the first target information to obtain the first cryptographic algorithm and the first rule associated with the first target information and to determine whether the first target information satisfies a threshold condition, wherein the data processing unit performs data analysis on the first target information based on a preset data analysis rule to obtain the first cryptographic algorithm and the first rule.

3. The quantum-resistant public key cryptographic computing device based on reconfigurable technology as claimed in claim 2, characterized in that: The step of the data processing unit determining whether the first target information meets a threshold condition comprises: determining whether the data volume of the first target information is less than a first threshold, and generating first feedback information when the data volume of the first target information is less than the first threshold; A cryptographic algorithm set is obtained. When the cryptographic algorithm set does not contain the first cryptographic algorithm of the first target information, it is determined that the first target information does not meet the threshold condition, and second feedback information is generated; wherein the cryptographic algorithm set is a set of all cryptographic algorithms implemented by the cryptographic operation device.

4. The quantum-resistant public key cryptographic computing device based on reconfigurable technology as claimed in claim 3, characterized in that: The first processing module also includes: a feedback unit, configured to receive the first feedback information and the second feedback information, and trigger the communication unit to send the first feedback information and the second feedback information to an external application layer cryptographic service interface; A sending unit is used to send the first target information, the first cryptographic algorithm, and the first rule to the second processing module when the first target information meets a threshold condition.

5. The quantum-resistant public key cryptographic computing device based on reconfigurable technology as claimed in claim 1, characterized in that: The second processing module comprises: A cryptographic algorithm implementation unit, used for the specific implementation of multiple cryptographic algorithms, including multiple post-quantum cryptographic algorithms, classical ECC, and multiple symmetric hash cryptographic algorithms, and in response to the first cryptographic algorithm and the first rule, using the corresponding cryptographic algorithm to operate on the first target information; An instruction parsing unit is used to analyze the operation instructions or configuration instructions sent by the master control or instruction stream memory, and assign the instructions to the corresponding units for execution; A reconfigurable functional operation unit, used to command various functional operation operators to operate according to the operation instructions of the instruction parsing unit, and trigger the main control to send configuration instructions, wherein the functional operation operators include: NTT (NTT operation), POM (polynomial modular multiplication operation), POI (polynomial modular inverse operation), MAO (vector and matrix operation); A reconfigurable AEA array, used to modify operation parameters and reconfigure according to the operation instructions and configuration instructions of the instruction parsing unit to complete various operation functions, thereby supporting the operation of the functional operation operator; A reconfigurable data generation unit, used to complete the generation of pseudo-random numbers and various sampling functions according to the reconfiguration of the operation instructions of the instruction parsing unit; The reconfigurable data storage unit is used for the reconfigurable AEA array and the data generation unit to read and store data, supports DMA transmission, and has a flexibly configurable working register group (WRG).

6. The quantum-resistant public key cryptographic computing device based on reconfigurable technology as claimed in claim 5, characterized in that: The reconfigurable AEA array is an nxn AE array, and the AE is configured as an operator of reconfigurable basic operations. The AE can be reconfigured to implement various basic operation functions including modular addition, modular multiplication, etc.

7. A quantum-resistant public key cryptographic operation method based on reconfigurable technology, characterized in that: The method comprises: Obtaining target information; Obtaining a first cryptographic algorithm and a first rule according to the target information and determining whether the target information meets a threshold condition, wherein the first cryptographic algorithm and the first rule are information associated with the target information, and the first rule includes key pair generation, signature generation, signature verification, data encryption, and data decryption; Performing a calculation according to the target information, the first cryptographic algorithm and the first rule to obtain a first calculation result; Returns the first operation result.

8. The quantum-resistant public key cryptographic operation method based on reconfigurable technology as claimed in claim 7, characterized in that: The step of determining whether the target information meets the threshold condition comprises: Determining whether the data volume of the target information is less than a first threshold, and generating first feedback information when the data volume of the target information is less than the first threshold; A cryptographic algorithm set is obtained, and when the cryptographic algorithm set does not include the first cryptographic algorithm associated with the target information, it is determined that the target information does not meet a threshold condition, and second feedback information is generated.

9. The quantum-resistant public key cryptographic operation method based on reconfigurable technology according to claim 7, characterized in that: The step of obtaining the first operation result comprises: Matching a corresponding cryptographic algorithm according to the first cryptographic algorithm, triggering the matched cryptographic algorithm to start computing the target information and issuing a computing instruction according to the first rule; According to the operation instruction, the reconfigurable functional operation unit is reconfigured to complete the corresponding operation and trigger the main control to send the configuration instruction and the reconfigurable data generation unit is reconfigured to complete the corresponding operation; According to the configuration instructions, the reconfigurable data storage unit configures the connection relationship between WRG and the reconfigurable AEA array; according to the operation instructions and configuration instructions, the reconfigurable AEA array modifies the operation parameters and reconfigures to complete various basic operation functions.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the quantum-resistant public key cryptographic operation method based on reconfigurable technology is implemented as described in any one of claims 7 to 9.