Secure adder and execution method of secure addition

Through the combination of mask generator and verification circuit, the addition operation results are verified by using the safe carry pre-adder and verification circuit, the problem of the lack of verification mechanism of existing safety adders is solved, and the safety and correctness of the addition operation are achieved.

CN120386509APending Publication Date: 2025-07-29NUVOTON
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411887367.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-29
Filing Date
2024-12-20
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

The existing security adders lack effective verification mechanisms, which cannot ensure the correctness of the addition operation and prevent attacks from interested people.

Method used

The combination of mask generator, safe carry pre-adder and verification circuit is used to perform addition operations by generating mask values and masking data, and the addition and comparator are used to save the correctness of the operation results.

Benefits of technology

It improves the difficulty of the security adder to resist error collisions, ensures the security and correctness of the addition operation, and prevents the leakage of the original data value.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120386509A_ABST
    Figure CN120386509A_ABST
Patent Text Reader

Abstract

The invention discloses a secure adder and an execution method of secure addition. The secure adder includes a mask generator, a secure carry preadder, and a verification circuit. The mask generator generates a first mask value, a second mask value, a third mask value, first mask data, and second mask data. The secure carry preadder calculates the first mask data and the second mask data according to the first mask value, the second mask value and the third mask value to generate a sum output. The verification circuit includes a secure carry save adder and a comparator. The secure carry save adder generates sum data and carry data according to the first mask value, the second mask value, the third mask value, the first mask data, the second mask data and the sum output. The comparator generates a verification result according to a relationship between the sum data and the carry data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a secure adder, and more particularly to a secure adder that uses a secure carry-save adder to verify the result of a secure addition operation performed by a secure carry-lookahead adder. Background Art

[0002] Addition is an important function for many operations, so adders are widely used in applications such as signal processing and data protection. In recent years, encryption applications have attached great importance to how to protect confidential information to avoid the exposure of operation data due to analysis. Generally speaking, a common and effective protection mechanism is the exclusive-or masking technology, which performs an exclusive-or operation using random numbers and important data (or variables) in the encryption and decryption algorithms to complete the masking protection mechanism. Therefore, encryption applications require a secure adder that can perform secure addition operations.

[0003] A secure addition operation means that without removing the mask of the input data, the secure adder can complete the addition operation, and during the operation process, it will not disclose the original value of the input data, and can provide an output protected by the masked value. In various integrated circuits or electronic products applied to encryption and decryption operations, secure adders that can perform secure addition operations are widely used.

[0004] In order to ensure the correctness of the secure addition operation and prevent attacks by malicious people, the secure adder needs an effective countermeasure to detect errors. Unfortunately, there is currently no literature proposing an effective countermeasure for secure adder verification. Summary of the Invention

[0005] In view of this, the present invention provides a secure adder, including a mask generator, a secure carry-lookahead adder, and a verification circuit. The mask generator generates a first mask value, a second mask value, and a third mask value, generates a first masked data according to the first mask value, and generates a second masked data according to the second mask value. The secure carry-lookahead adder performs an operation on the first masked data and the second masked data according to the first mask value, the second mask value, and the third mask value to generate a sum output. The verification circuit includes a secure carry-save adder and a comparator. The secure carry-save adder generates a sum data and a carry data according to the first mask value, the second mask value, the third mask value, the first masked data, the second masked data, and the sum output. The comparator generates a verification result according to the relationship between the sum data and the carry data.

[0006] The present invention further provides a method for performing secure addition, and the method for performing secure addition includes the following steps. Generate a first masking value, a second masking value, and a third masking value; generate a first masked data according to the first masking value; generate a second masked data according to the second masking value; perform an operation on the first masked data and the second masked data according to the first masking value, the second masking value, and the third masking value to generate a sum output; generate a sum data and a carry data according to the first masking value, the second masking value, the third masking value, the first masked data, the second masked data, and the sum output; and generate a verification result according to the relationship between the sum data and the carry data.

[0007] The present invention provides a secure adder that uses a secure carry save adder to verify the operation result of a secure carry lookahead adder. Since the secure adder used in the verification circuit proposed by the present invention and the secure adder for performing secure operations belong to two different circuits, and their execution times are staggered from each other, the difficulty of error collision of the secure adder of the present invention is greatly increased. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 Show a block diagram of a secure adder 100 according to some embodiments of the present invention;

[0009] Figure 2 Show a flowchart of a method for performing a lookahead carry addition according to some embodiments of the present invention;

[0010] Figure 3A Show a schematic circuit diagram of a first type of secure carry lookahead adder according to some embodiments of the present invention;

[0011] Figure 3B Show a schematic circuit diagram of a second type of secure carry lookahead adder according to some embodiments of the present invention;

[0012] Figure 4 Show a circuit diagram of a 4-bit lookahead carry generator according to some embodiments of the present invention;

[0013] Figure 5 Show a flowchart of a method for performing a secure save carry addition according to some embodiments of the present invention;

[0014] Figure 6 Show a truth table of a variable Exy according to some embodiments of the present invention;

[0015] Figure 7 Show a truth table of an original output value carry of an arithmetic expression (50) according to some embodiments of the present invention;

[0016] Figure 8 Displays the truth table of the masked data "carry" of the arithmetic expression (60) according to some embodiments of the present invention;

[0017] Figure 9A Displays a schematic circuit diagram of a secure carry-save adder according to some embodiments of the present invention;

[0018] Figure 9B Displays a schematic circuit diagram of a secure carry-save adder according to some embodiments of the present invention;

[0019] Figure 9C Displays a schematic circuit diagram of a secure carry-save adder according to some embodiments of the present invention;

[0020] Figure 10 Displays a circuit diagram of a verification circuit according to an embodiment of the present invention;

[0021] Figure 11 Displays a circuit diagram of a verification circuit according to another embodiment of the present invention; and

[0022] Figure 12 Displays a flowchart of a method for performing secure addition according to an embodiment of the present invention.

[0023] Symbol Explanation

[0024] 10: Bus

[0025] 100: Secure adder

[0026] 110: Bus interface

[0027] 120: Mask generator

[0028] 122: Random number generator

[0029] 124: First mask unit

[0030] 130: Selection circuit

[0031] 131: First multiplexer

[0032] 133: Second multiplexer

[0033] 135: Third multiplexer

[0034] 137: Fourth multiplexer

[0035] 139: Fifth multiplexer

[0036] 140: Storage circuit

[0037] 141: First register

[0038] 143: Second register

[0039] 145: Third register

[0040] 147: Fourth register

[0041] 149: Fifth register

[0042] 150, 150A, 150B: Safety carry look-ahead adder

[0043] 160: Verification circuit

[0044] 161, 161A, 161B: First conversion circuit

[0045] 162, 162A, 162B, 162C: Safety carry save adder

[0046] 163, 163A, 163B: Second conversion circuit

[0047] 164: Comparator

[0048] 200: Method for performing a carry look-ahead addition

[0049] S210 - S260, S1210 - S1260: Steps

[0050] 312: Second masking unit

[0051] 314: Third masking unit

[0052] 316: Fourth masking unit

[0053] 320: Half adder

[0054] 330: First logic circuit

[0055] 340, 400: Carry look-ahead generator

[0056] 351: First exclusive-OR gate

[0057] 352: Second exclusive-OR gate

[0058] 353: Third exclusive-OR gate

[0059] 354: Fourth exclusive-OR gate

[0060] 355: Fifth exclusive-OR gate

[0061] 356: Sixth exclusive-OR gate

[0062] 357: Seventh exclusive-OR gate

[0063] 358: Eighth exclusive-OR gate

[0064] 361: First AND gate

[0065] 362: Second AND gate

[0066] 410: Second logic circuit

[0067] 420: Third logic circuit

[0068] 430: Fourth logic circuit

[0069] 440: Fifth logic circuit

[0070] 500: Method for performing secure save carry addition

[0071] S510 - S540: Steps

[0072] 810a, 810b, 810c: Fifth mask unit

[0073] 820a, 820b, 820c: Sixth mask unit

[0074] 830a, 830b, 830c: Seventh mask unit

[0075] 840: Sixth logic circuit

[0076] 852: Third AND gate

[0077] 854: Fourth AND gate

[0078] 356: Fifth AND gate

[0079] 860: OR gate

[0080] 910: Ninth exclusive - OR gate

[0081] 912: Tenth exclusive - OR gate

[0082] 914: Eleventh exclusive - OR gate

[0083] 922: Twelfth exclusive - OR gate

[0084] 924: Thirteenth exclusive - OR gate

[0085] 932: Fourteenth exclusive - OR gate

[0086] 934: Fifteenth exclusive - OR gate

[0087] Cin: Carry input

[0088] Co: Carry output

[0089] C: Carry value

[0090] C0: Input signal

[0091] C1 - C4: Output signal

[0092] Ctrl1: Control signal

[0093] G: Generated value

[0094] G': Intermediate generated value

[0095] G0 - G3: Generated signal

[0096] ra: First mask value

[0097] rb: Second mask value

[0098] ro: Third mask value

[0099] rx: Fourth mask value

[0100] ry: Fifth mask value

[0101] rz: Sixth mask value

[0102] ra_int: First internal mask value

[0103] rb_int: Second internal mask value

[0104] ro_int: Third internal mask value

[0105] ra_ext: First external mask value

[0106] rb_ext: Second external mask value

[0107] ro_ext: Third external mask value

[0108] P: Propagation value

[0109] P': Intermediate propagation value

[0110] P0 - P3: Propagation signal

[0111] SEL: Selection signal

[0112] a: First data

[0113] b: Second data

[0114] x: Third data

[0115] y: Fourth data

[0116] z: Fifth data

[0117] a': First masked data

[0118] b': Second masked data

[0119] "a": Third shielded data

[0120] "b": Fourth shielded data

[0121] "x": Fifth shielded data

[0122] "y": Sixth shielded data

[0123] "z": Seventh shielded data

[0124] x': First input data

[0125] y': Second input data

[0126] z': Third input data

[0127] o': Sum output

[0128] a'_int: First internal shielded data

[0129] b'_int: Second internal shielded data

[0130] a'_ext: First external shielded data

[0131] b'_ext: Second external shielded data

[0132] TV1: First conversion variable

[0133] TV2: Second conversion variable

[0134] Sout: Sum data

[0135] Cout: Carry data

[0136] ms: Converted sum data

[0137] mc: Converted carry data

[0138] vf: Verification result

[0139] carry: Original output value

[0140] carry”: Shielded data

[0141] D1: First intermediate data

[0142] D2: Second intermediate data

[0143] D3: Third intermediate data

[0144] D4: Fourth intermediate data

[0145] D5: Fifth intermediate data

[0146] D6: Sixth intermediate data

[0147] Exy, Eyz, Exz: Variables

[0148] Rsum: Input Variable

[0149] Rab: First Variable

[0150] R: Second Variable

[0151] Rr: Third Variable

[0152] Rxy: Fourth Variable

[0153] Rxz: Fifth Variable

[0154] Ryz: Sixth Variable

[0155] Rsum': Seventh Variable

[0156] Rsum”: Eighth Variable

[0157] SEL: Selection Signal

[0158] INV1: First Inverter

[0159] INV2: Second Inverter

[0160] SHFT1: First Shift Circuit

[0161] SHFT2: Second Shift Circuit Detailed Implementation Manner

[0162] The following description is of an embodiment of the present disclosure. Its purpose is to illustrate the general principles of the present disclosure by way of example and should not be regarded as a limitation of the present disclosure. The scope of the present disclosure shall be defined by the scope of the patent application.

[0163] It should be noted that the content disclosed below can provide multiple embodiments or examples for practicing different features of the present disclosure. The specific component examples and arrangements described below are only used to briefly elaborate the spirit of the present disclosure and are not used to limit the scope of the present disclosure. In addition, the following specification may reuse the same component symbols or words in multiple examples. However, the purpose of the reuse is only to provide a simplified and clear description and is not used to limit the relationship between the multiple embodiments and / or configurations discussed below.

[0164] In addition, the descriptions such as one feature being connected to, coupled to, and / or formed on another feature in the following specification may actually include multiple different embodiments, including the direct contact of these features, or including other additional features formed between these features, etc., such that these features are not in direct contact.

[0165] In addition, relative terms such as "lower" or "bottom" and "higher" or "top" may be used in the embodiments to describe the relative relationship of one element of the figure to another element. It is understood that if the device in the figure is flipped so that it is upside down, the element described on the "lower" side will become the element on the "higher" side.

[0166] It is understood that although terms such as "first", "second", "third", etc. may be used herein to describe various elements, components, regions, layers, and / or parts, these elements, components, regions, layers, and / or parts should not be limited by these terms, and these terms are only used to distinguish different elements, components, regions, layers, and / or parts. Therefore, a first element, component, region, layer, and / or part discussed below may be referred to as a second element, component, region, layer, and / or part without departing from the teachings of some embodiments of the present disclosure.

[0167] Some embodiments of the present disclosure can be understood in conjunction with the figures, and the figures of the embodiments of the present disclosure are also regarded as part of the description of the embodiments of the present disclosure. It should be understood that the figures of the embodiments of the present disclosure are not drawn to the scale of actual devices and elements. The shapes and thicknesses of the embodiments may be exaggerated in the figures for the sake of clearly showing the features of the embodiments of the present disclosure. In addition, the structures and devices in the figures are shown in a schematic manner for the sake of clearly showing the features of the embodiments of the present disclosure.

[0168] Herein, the terms "about", "approximately", "substantially" generally mean within 20% of a given value or range, preferably within 10%, and more preferably within 5%, or 3%, or 2%, or 1%, or 0.5%. The quantity given herein is an approximate quantity, that is, the meaning of "about", "approximately", "substantially" may still be implied even without specifically stating "about", "approximately", "substantially".

[0169] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by those skilled in the art to which this disclosure pertains. It is understood that these terms, such as those defined in a commonly used dictionary, should be interpreted to have a meaning consistent with the relevant technology and the background or context of this disclosure, and should not be interpreted in an idealized or overly formal manner, unless specifically defined in the embodiments of the present disclosure.

[0170] In some embodiments of the present disclosure, terms related to joining and connecting, such as "connect", "interconnect", etc., unless specifically defined, may mean that two structures are in direct contact, or may also mean that two structures are not in direct contact, and other structures are provided between these two structures. And these terms related to joining and connecting may also include the cases where both structures can move, or both structures are fixed.

[0171] In the drawings, like elements and / or features may have the same element symbols. Various elements of the same type may be distinguished by adding a letter or number after the element symbol, for distinguishing like elements and / or like features.

[0172] Figure 1 A block diagram showing a secure adder 100 according to some embodiments of the present invention is shown. In some embodiments, the secure adder 100 may be implemented in an integrated circuit (not shown). In addition, the secure adder 100 can perform an addition operation without revealing the operands and provide mask protection for the output result. In some embodiments, the secure adder 100 can perform data transfer with other circuits (not shown) within the integrated circuit via a bus 10. For example, a processor (not shown) may provide a plurality of input data (or operands) to the secure adder 100 via the bus 10 to perform an addition operation. In some embodiments, the input data may be raw data that is not masked. In some embodiments, the input data may be masked data. In addition, after the addition operation is completed, the secure adder 100 provides the masked operation result to the processor via the bus 10.

[0173] As Figure 1 shown, the secure adder 100 includes a bus interface 110, a mask generator 120, a selection circuit 130, a storage circuit 140, a secure carry-lookahead adder (SCLA) 150, and a verification circuit 160. The bus interface 110 is coupled to the bus 10 and is configured to provide various input data (such as operands, mask values, control signals, etc.) from the bus 10 to the mask generator 120, the selection circuit 130, and the secure carry-lookahead adder 150. After the addition operation is completed, the bus interface 110 is configured to provide the output data (such as the operation result) from the secure carry-lookahead adder 150 to the bus 10. In addition, the output data of the secure carry-lookahead adder 150 is verified by the verification circuit 160, and the verification result is provided to the bus 10.

[0174] The mask generator 120 includes a random number generator (RNG) 122 and a first mask unit 124. The random number generator 122 generates a plurality of random numbers according to the control signal Ctrl1 from the bus interface 110 to serve as a first internal mask value ra_int, a second internal mask value rb_int, and a third internal mask value ro_int. In some embodiments, the first internal mask value ra_int is different from the second internal mask value rb_int. In some embodiments, the first internal mask value ra_int is the same as the second internal mask value rb_int.

[0175] The random number generator 122 is configured to provide the first internal mask value ra_int and the second internal mask value rb_int to the first mask unit 124, and provide the first internal mask value ra_int, the second internal mask value rb_int, and the third internal mask value ro_int to the selection circuit 130. In some embodiments, the control signal Ctrl1 is provided by an external circuit (i.e., other circuits within the integrated circuit) via the bus 10. In some embodiments, the bus interface 110 generates the control signal Ctrl1 to the mask generator 120 according to the input data from the bus 10.

[0176] In addition, the first mask unit 124 performs mask operations on the first data a and the second data b according to the first internal mask value ra_int and the second internal mask value rb_int respectively to obtain a first internally masked data a'_int and a second internally masked data b'_int. Generally speaking, a mask operation means performing an exclusive-OR (XOR) operation on multiple-bit data and a multiple-bit mask value, so as to mask a part of the bits in the data and provide masked data, thus preventing the data from being stolen. In addition, the first mask unit 124 also provides the first internally masked data a'_int and the second internally masked data b'_int to the selection circuit 130. In addition, the first data a and the second data b are provided by an external circuit through the bus 10.

[0177] The selection circuit 130 includes a plurality of multiplexers (MUX), such as Figure 1As shown, namely the first multiplexer 131, the second multiplexer 133, the third multiplexer 135, the fourth multiplexer 137, and the fifth multiplexer 139. In this embodiment, the first multiplexer 131, the second multiplexer 133, the third multiplexer 135, the fourth multiplexer 137, and the fifth multiplexer 139 are controlled by the same selection signal SEL. In some embodiments, the selection signal SEL is provided by an external circuit via the bus 10. In some embodiments, the bus interface 110 generates the selection signal SEL to the selection circuit 130 according to the input data from the bus 10.

[0178] When the selection signal SEL has a first logic bit, the selection signal SEL controls the first multiplexer 131, the second multiplexer 133, the third multiplexer 135, the fourth multiplexer 137, and the fifth multiplexer 139 to provide the first external shield data a'_ext, the second external shield data b'_ext, the first external mask value ra_ext, the second external mask value rb_ext, and the third external mask value ro_ext from the bus interface 110 to the storage circuit 140 and store them in the corresponding registers (or memories). The first external shield data a'_ext, the second external shield data b'_ext, the first external mask value ra_ext, the second external mask value rb_ext, and the third external mask value ro_ext are provided by an external circuit via the bus 10.

[0179] On the other hand, when the selection signal SEL has a second logic bit, the selection signal SEL controls the first multiplexer 131, the second multiplexer 133, the third multiplexer 135, the fourth multiplexer 137, and the fifth multiplexer 139 to provide the first internal shield data a'_int, the second internal shield data b'_int, the first internal mask value ra_int, the second internal mask value rb_int, and the third internal mask value ro_int from the mask generator 120 to the storage circuit 140 and store them in the corresponding registers (or memories).

[0180] For the secure adder 100, the first internal masked data a'_int, the second internal masked data b'_int, the first internal mask value ra_int, the second internal mask value rb_int, and the third internal mask value ro_int are generated by the internal mask generator 120. As previously described, the generation of the first internal masked data a'_int is related to the first internal mask value ra_int, and the generation of the second internal masked data b'_int is related to the second internal mask value rb_int. On the other hand, for the secure adder 100, the first external masked data a’_ext, the second external masked data b'_ext, the first external mask value ra_ext, the second external mask value rb_ext, and the third external mask value ro_ext are provided by an external circuit. In addition, the generation of the first external masked data a’_ext is related to the first external mask value ra_ext, and the generation of the second external masked data b'_ext is related to the second external mask value rb_ext. In some embodiments, the first external mask value ra_ext is different from the second external mask value rb_ext. In some embodiments, the first external mask value ra_ext is the same as the second external mask value rb_ext.

[0181] The storage circuit 140 includes a first register 141, a second register 143, a third register 145, a fourth register 147, and a fifth register 149. The first register 141 can store the first internal masked data a'_int from the multiplexer 131 or the first external masked data a’_ext and serve as the first masked data a' of the secure carry-lookahead adder 150. In addition, the second register 143 can store the second internal masked data b'_int from the multiplexer 133 or the second external masked data b'_ext and serve as the second masked data b' of the secure carry-lookahead adder 150. For the secure carry-lookahead adder 150, the first masked data a' and the second masked data b' are masked data.

[0182] Furthermore, the third register 145 can store the first internal mask value ra_int or the first external mask value ra_ext from the multiplexer 135, and serve as the first mask value ra of the secure carry-lookahead adder 150. The fourth register 147 can store the second internal mask value rb_int or the second external mask value rb_ext from the multiplexer 137, and serve as the second mask value rb of the secure carry-lookahead adder 150. The fifth register 149 can store the third internal mask value ro_int or the third external mask value ro_ext from the multiplexer 139, and serve as the third mask value ro of the secure carry-lookahead adder 150. Then, the secure carry-lookahead adder 150 generates a carry output Co and a sum output o' according to the first masked data a', the second masked data b', the first mask value ra, the second mask value rb, the third mask value ro, and the carry input Cin from the storage circuit 140.

[0183] As Figure 1 shown, the verification circuit 160 includes a first conversion circuit 161, a carry-save adder (CSA) 162, a second conversion circuit 163, and a comparator 164, where the verification circuit 160 is used to verify whether the operation of the secure carry-lookahead adder 150 is correct. The first conversion circuit 161 is used to convert the first mask value ra into a first conversion variable TV1, and convert the sum output o' into a second conversion variable TV2.

[0184] The carry-save adder 162 generates a sum data Sout and a carry data Cout based on the first masked data a', the second masked data b', the first mask value ra, the second mask value rb, the third mask value ro, the first conversion variable TV1, and the second conversion variable TV2. Then, the second conversion circuit 163 converts the sum data Sout and the carry data Cout into a converted sum data ms and a converted carry data mc respectively, and the comparator 164 generates a verification result vf according to the relationship between the converted sum data ms and the converted carry data mc. In some embodiments, the external circuit determines whether the operation of the secure carry-lookahead adder 150 is correct based on the verification result vf.

[0185] Figure 2 shows a flowchart of a method for performing lookahead carry addition according to some embodiments of the present invention, applicable to Figure 1 the secure carry-lookahead adder 150. In some embodiments, Figure 2 the method 200 for performing lookahead carry addition can be executed by other circuits (such as a processor).

[0186] First, in step S210, a first mask value ra, a second mask value rb, a third mask value ro, a first masked data a', and a second masked data b' are obtained. As previously described, the first masked data a' is the masked data obtained by performing a masking operation (e.g., exclusive-or operation "⊕") on the first data a using the first mask value ra, as shown in the following equation (1):

[0187] a' = a ⊕ ra (1).

[0188] Similarly, the second masked data b' is the masked data obtained by performing a masking operation (e.g., exclusive-or operation) on the second data b using the second mask value rb, as shown in the following equation (2):

[0189] b' = b ⊕ rb (2).

[0190] Furthermore, the third mask value ro is used to perform a masking operation on the result of the look-ahead carry addition operation in order to provide security protection for the output result, which will be described in detail later.

[0191] In step S220, a first variable Rab is obtained according to the first mask value ra and the second mask value rb, as shown in the following equation (3):

[0192] Rab = ra ⊕ rb (3).

[0193] Next, according to the first mask value ra or the second mask value rb, a second variable R is obtained. The following will be described in two types, the first type and the second type.

[0194] In the first type, the second variable R is equal to the first mask value ra, as shown in the following equation (4):

[0195] R = ra (4).

[0196] In addition, according to the first masked data a', a third masked data a'' is obtained, and a masking operation is performed on the second masked data b' according to the first variable Rab in order to obtain a fourth masked data b'', as shown in the following equations (5) and (6) respectively:

[0197] a'' = a' (5); and

[0198] b'' = b' ⊕ Rab (6).

[0199] According to equations (1), (4), and (5), it can be seen that the third masked data a'' is equal to the result of performing an exclusive-or operation on the first data a and the second variable R, as shown in the following equation (7):

[0200] a'' = a' = a ⊕ ra = a ⊕ R (7).

[0201] In addition, if the second mask value rb is different from the first mask value ra (i.e., rb ≠ ra), then according to equations (2), (3), and (6), it can be known that the fourth masked data b” is equal to the exclusive OR operation of the second data b and the first variable Rab, as shown in the following equation (8):

[0202] b” = b' ⊕ Rab = (b ⊕ rb) ⊕ (ra ⊕ rb)

[0203] = b ⊕ ra ⊕ (rb ⊕ rb) = b ⊕ R (8).

[0204] Conversely, if the second mask value rb is the same as the first mask value ra (i.e., rb = ra), then Rab is equal to 0. Thus, according to equations (2) and (6), and the second mask value rb being the same as the first mask value ra and the second variable R also being equal to the first mask value ra, it can be known that the fourth masked data b” is equal to the exclusive OR operation of the second data b and the second variable R, as shown in the following equation (9):

[0205] b” = b' ⊕ Rab = b' ⊕ 0 = b'

[0206] = b ⊕ rb = b ⊕ ra = b ⊕ R (9).

[0207] From equations (7), (8), and (9), it can be seen that regardless of whether the second mask value rb is the same as the first mask value ra, the fourth masked data b” is equal to the exclusive OR operation of the second data b and the second variable R. In addition, during the operation process of equations (3) - (6), the original values of the first data a and the second data b are not revealed. In other words, when using the secure adder 100 to perform the addition operation, there is no need to restrict the second mask value rb and the first mask value ra, such as in a traditional secure adder where it is required that the second mask value rb is different from the first mask value ra.

[0208] In the second type, the second variable R is equal to the mask value rb, as shown in the following equation (10):

[0209] R = rb (10).

[0210] In addition, by performing a masking operation on the first masked data a' according to the first variable Rab, the third masked data a” can be obtained, and according to the second masked data b', the fourth masked data b” can be obtained, as shown in the following equations (11) and (12) respectively:

[0211] a” = a' ⊕ Rab (11); and

[0212] b” = b' (12).

[0213] According to Equation (2), Equation (10), and Equation (12), it can be known that the fourth masked data b” is equal to the second data b and the second variable R performing an exclusive OR operation, as shown in the following Equation (13):

[0214] b” = b' = b⊕rb = b⊕R (13).

[0215] In addition, if the second mask value rb is different from the first mask value ra (i.e., rb≠ra), then according to Equation (1), Equation (3), and Equation (11), it can be known that the third masked data a” is equal to the first data a and the first variable Rab performing an exclusive OR operation, as shown in the following Equation (14):

[0216] a”=a'⊕Rab=(a⊕ra)⊕(ra⊕rb)

[0217] = a⊕rb⊕(ra⊕ra) = a⊕R (14).

[0218] Conversely, if the second mask value rb is the same as the first mask value ra (i.e., rb=ra), then Rab is equal to 0. Thus, according to Equation (2), Equation (11), and the second mask value rb being the same as the first mask value ra and the second variable R also being equal to the second mask value rb, it can be known that the third masked data a” is equal to the first data a and the second variable R performing an exclusive OR operation, as shown in the following Equation (15):

[0219] a”=a'⊕Rab=a'⊕0=a'

[0220] = a⊕ra = a⊕rb = a⊕R (15).

[0221] From Equation (13), Equation (14), and Equation (15), it can be known that regardless of whether the second mask value rb is the same as the first mask value ra, the third masked data a" is equal to the first data a and the second variable R performing an exclusive OR operation. In addition, during the operation of Equation (3) and Equations (10)-(12), the original values of the first data a and the second data b are not revealed. In other words, when using the secure adder 100 to perform the addition operation, there is no need to restrict the second mask value rb and the first mask value ra. For example, in a traditional secure adder, it is required that the second mask value rb is different from the first mask value ra.

[0222] In step S230, according to the third masked data a” and the fourth masked data b” obtained according to the first type or the second type, an intermediate propagation value P' can be obtained, as shown in the following Equation (8):

[0223] P' = a” ⊕ b” (16).

[0224] Next, according to the arithmetic expressions (7)-(9) of the first type or the arithmetic expressions (13)-(15) of the second type, the intermediate propagation value P' of the arithmetic expression (16) (i.e., a” ⊕ b”) can be obtained as equal to the propagation value P (i.e., a ⊕ b), as shown in the following arithmetic expression (17):

[0225] P' = a” ⊕ b” = (a ⊕ R) ⊕ (b ⊕ R)

[0226] = a ⊕ b = P (17).

[0227] In addition, performing an AND operation (“&”) on the third masked data a” and the fourth masked data b” can obtain the intermediate generated value G', as shown in the following arithmetic expression (18):

[0228] G' = a” & b” (18).

[0229] In step S240, according to the distributive law between the AND operation and the exclusive OR operation (e.g., (x ⊕ y) & z = (x & z) ⊕ (y & z)), the AND operation of the arithmetic expression (18) can be distributed to the bottommost operation, as shown in the following arithmetic expression (19):

[0230] G' = a” & b” = (a ⊕ R) & (b ⊕ R)

[0231] = (a & (b ⊕ R)) ⊕ (R & (b ⊕ R))

[0232] = (a & b) ⊕ (a & R) ⊕ (R & b) ⊕ (R & R)

[0233] = (a & b) ⊕ (a & R) ⊕ (R & b) ⊕ R (19).

[0234] Next, for the adder, performing an AND operation on the first data a and the second data b can obtain the generated value G, i.e., G = a & b. Thus, the arithmetic expression (19) can be rewritten as the arithmetic expression (20), as shown below:

[0235] G' = (a & b) ⊕ (a & R) ⊕ (R & b) ⊕ R

[0236] = G ⊕ (a & R) ⊕ (b & R) ⊕ R (20).

[0237] Next, according to the distributive law between the AND operation and the exclusive OR operation, the arithmetic expression (20) can be rewritten as the arithmetic expression (21), as shown below:

[0238] G' = G ⊕ (a & R) ⊕ (b & R) ⊕ R

[0239] = G ⊕ ((a ⊕ b) & R) ⊕ R (21). Next, substituting equation (17) into equation (21), equation (22) can be obtained as shown below:

[0240] G' = G ⊕ (P' & R) ⊕ R (22).

[0241] Next, according to the associative law of exclusive OR operation and equation (22), the generated value G can be obtained according to equation (23) as shown below:

[0242] G = G' ⊕ (P' & R) ⊕ R (23).

[0243] In step S250, based on the propagation value P obtained from equation (17), the generated value G obtained from equation (23), and the carry input Cin, the carry lookahead generator can obtain the carry output Co and the carry value C, where the carry lookahead generator will be described in detail below. In some embodiments, the initial value of the carry input Cin is 0. In some embodiments, the carry input Cin is provided by an external circuit via bus 10.

[0244] In step S260, according to the operation principle of the adder, performing an exclusive OR operation on the first data a, the second data b, and the carry value C can obtain the sum output o' as shown in the following equation (24):

[0245] o' = (a + b) = a ⊕ b ⊕ C

[0246] = P' ⊕ C (24).

[0247] Next, performing an exclusive OR operation on the sum output o' and the third mask value ro to meet the condition that both the input value and the output value have masks in the addition operation. Thus, the masked sum output o' can be obtained as shown in the following equation (25):

[0248] o' = (P' ⊕ ro) ⊕ C (25).

[0249] Generally, the carry lookahead generator can obtain the carry output Co and the carry value C based on the propagation value P, the generated value G, and the carry input Cin as shown in the following equation (26):

[0250] {Co, C} = CLG (G, P, Cin) (26).

[0251] Where CLG is a function representing the carry lookahead generator. Thus, substituting the carry value C of equation (26) into equation (25) can obtain equation (27) as shown below:

[0252] o' = (P' ⊕ ro) ⊕ CLG (G, P, Cin) (27). Next, substituting the generated value G of equation (23) into equation (27) gives equation (28), as shown below:

[0253] o' = (P' ⊕ ro) ⊕ CLG (G, P, Cin)

[0254] = (P' ⊕ ro) ⊕ CLG (G' ⊕ (P' & R) ⊕ R, P, Cin) (28).

[0255] Next, substituting the propagation value P of equation (17) and the intermediate propagation value P' into equation (28) gives equation (29), as shown below:

[0256] o' = (P' ⊕ ro) ⊕ CLG (G' ⊕ (P' & R) ⊕ R, P, Cin)

[0257] = ((a” ⊕ b”) ⊕ ro) ⊕ CLG (G' ⊕ ((a” ⊕ b”) & R) ⊕ R, (a” ⊕ b”), Cin) (29). Next, substituting the intermediate generated value G' of equation (18) into equation (29) gives equation (30), as shown below:

[0258] o' = (a” ⊕ b” ⊕ ro) ⊕ CLG (((a” & b”) ⊕ ((a” ⊕ b”) & R) ⊕ R), (a” ⊕ b”), Cin)

[0259] = (a” ⊕ b” ⊕ ro) ⊕ CLG (((a” & b”) ⊕ R ⊕ ((a” ⊕ b”) & R)), (a” ⊕ b”), Cin) (30).

[0260] Thus, according to equation (30), equation (3), and the equations of the first type (7) - (9) or the equations of the second type (13) - (15), the logic circuit of the carry-lookahead adder 150 can be obtained.

[0261] Figure 3A Shows a schematic circuit diagram of the first type of carry-lookahead adder 150A according to some embodiments of the present invention. The carry-lookahead adder 150A includes a second masking unit 312, a third masking unit 314, a half adder 320, a first logic circuit 330, a carry-lookahead generator 340, a first exclusive OR (XOR) gate 351, and a second exclusive OR gate 352.

[0262] As shown in Equation (5), the third masked data a” is equal to the first masked data a'. The first exclusive-OR gate 351 is used to perform an exclusive-OR operation on the first mask value ra and the second mask value rb to obtain the first variable Rab, as shown in Equation (3). In addition, the second masking unit 312 includes a fourth exclusive-OR gate 354, which is configured to perform a masking operation (i.e., an exclusive-OR operation) on the second masked data b' according to the first variable Rab to obtain the fourth masked data b”, as shown in Equation (6).

[0263] The half adder 320 includes a sixth exclusive-OR gate 356 and a first AND gate 361. The sixth exclusive-OR gate 356 is configured to receive the third masked data a” and the fourth masked data b” and output an intermediate propagation value P', as shown in Equation (17). As previously described, the intermediate propagation value P' (i.e., x” ⊕ y”) is equal to the propagation value P (i.e., x ⊕ y). In addition, the first AND gate 361 is configured to receive the third masked data a” and the fourth masked data b” and output an intermediate generation value G', as shown in Equation (18).

[0264] The first logic circuit 330 provides a generation value G according to the second variable R, the intermediate generation value G', and the intermediate propagation value P' (i.e., the propagation value P). In some embodiments, the first logic circuit 330 includes a seventh exclusive-OR gate 357, a sixth exclusive-OR gate 358, and a second AND gate 362. The seventh exclusive-OR gate 357 is configured to receive the second variable R and the intermediate generation value G' and output a first intermediate data D1. The second AND gate 362 is configured to receive the second variable R and the intermediate propagation value P' (i.e., the propagation value P) and output an intermediate data D2. In addition, the eighth exclusive-OR gate 358 is configured to receive the first intermediate data D1 and the second intermediate data D2 and output the generation value G to the look-ahead carry generator 340. Then, the look-ahead carry generator 340 can obtain a carry output Co and a carry value C according to the propagation value P (i.e., the intermediate propagation value P'), the generation value G, and the carry input Cin. The operation of the look-ahead carry generator 340 will be described in detail below.

[0265] The third masking unit 314 includes a fifth exclusive-OR gate 355 for performing a masking operation on the intermediate propagation value P' (i.e., the propagation value P) according to the third mask value ro to obtain a third intermediate data D3. It should be noted that because the path delay of the look-ahead carry generator 340 is relatively long, the third mask value ro will first perform a masking operation on the intermediate propagation value P' through the third masking unit 314. Then, the second exclusive-OR gate 352 is configured to receive the third intermediate data D3 and the carry value C and provide a sum output o'.

[0266] After obtaining the sum output o', the secure carry-lookahead adder 150A provides the sum output o' and the carry output Co to the bus interface 110 for subsequent operations via the bus 10 to other circuits (such as a processor). As previously described, the sum output o' is masked data. Therefore, in addition to providing the sum output o' and the carry output Co, the secure adder 100 further provides a third mask value ro to other circuits. Thus, other circuits can use the third mask value ro to remove the mask of the sum output o' to obtain the original value of the sum output o'.

[0267] Figure 3B FIG. shows a schematic diagram of a second type of secure carry-lookahead adder 150B according to some embodiments of the present invention. The secure carry-lookahead adder 150B includes a third mask unit 314, a fourth mask unit 316, a half adder 320, a first logic circuit 330, a lookahead carry generator 340, a first exclusive-OR gate 351, and a second exclusive-OR gate 352.

[0268] In Figure 3B the fourth masked data b'' is equal to the second masked data b', as shown in equation (12). In addition, the fourth mask unit 316 includes a third exclusive-OR gate 353 configured to perform a masking operation (i.e., an exclusive-OR operation) on the first masked data a' according to a first variable Rab to obtain a third masked data a'', as shown in equation (11).

[0269] Similar to Figure 3A , the half adder 320 outputs an intermediate propagation value P' (propagation value P) and an intermediate generation value G' according to the third masked data a'' and the fourth masked data b''. Then, the first logic circuit 330 outputs a generation value G according to a second variable R, the intermediate generation value G', and the intermediate propagation value P'. Then, the lookahead carry generator 340 can obtain a carry output Co and a carry value C according to the propagation value P (i.e., the intermediate propagation value P'), the generation value G, and the carry input Cin. As previously described, the second exclusive-OR gate 352 is configured to receive the carry value C and a third intermediate data D3 from the third mask unit 314 and provide the sum output o'.

[0270] After obtaining the sum output o', the secure carry-lookahead adder 150B provides the sum output o' and the carry output Co to the bus interface 110 for subsequent operations via the bus 10 to other circuits (such as a processor). As previously described, the sum output o' is masked data. Therefore, in addition to providing the sum output o' and the carry output Co, the secure adder 100 further provides a third mask value ro to other circuits. Thus, other circuits can use the third mask value ro to remove the mask of the sum output o' to obtain the original value of the sum output o'.

[0271] Figure 4 The circuit diagram of the 4-bit look-ahead carry generator 400 according to some embodiments of the present invention is shown, applicable to Figure 3A and Figure 3B the look-ahead carry generator 340. In this embodiment, the propagate value P is a 4-bit data composed of the propagate signals (or bits) P3, P2, P1, and P0, that is, P = [P3, P2, P1, P0], where P3 is the most significant bit (MSB) and P0 is the least significant bit (LSB). The generate value G is a 4-bit data composed of the generate signals (or bits) G3, G2, G1, and G0, that is, G = [G3, G2, G1, G0], where G3 is the most significant bit and G0 is the least significant bit.

[0272] In addition, the input signal (or bit) C0 is a 1-bit data composed of the carry input Cin, that is, C0 = Cin. According to the propagate value P, the generate value G, and the carry input Cin, the following operations of equations (31) to (34) can be performed by the look-ahead carry generator 400 to obtain the carry output Co and the carry value C. The carry value C is a 4-bit data composed of the output signals (or bits) C3, C2, C1, and the input signal C0, that is, C = [C3, C2, C1, C0], where C3 is the most significant bit and C0 is the least significant bit. In addition, the carry output Co is composed of the output signal (or bit) C4, that is, Co = C4. Equations (31) to (34) are shown as follows:

[0273] C1 = G0 | P0 & C0 (31);

[0274] C2 = G1 | P1 & G0 | P1 & P0 & C0 (32);

[0275] C3 = G2 | P2 & G1 | P2 & P1 & G0 | P2 & P1 & P0 & C0 (33); and

[0276] C4 = G3 | P3 & G2 | P3 & P2 & G1 | P3 & P2 & P1 & G0 | P3 & P2 & P1 & P0 & C0 (34).

[0277] As previously described, "|" represents performing an OR operation, and "&" represents performing an AND operation.

[0278] The look-ahead carry generator 400 includes a second logic circuit 410, a third logic circuit 420, a fourth logic circuit 430, and a fifth logic circuit 440. The second logic circuit 410 is configured to perform the operation of equation (31) to generate an output signal C1 based on the input signals C0, generate signal G0, and propagate signal P0. The third logic circuit 420 is configured to perform the operation of equation (32) to generate an output signal C2 based on the input signals C0, generate signals G0 and G1, and propagate signals P0 and P1.

[0279] In addition, the fourth logic circuit 430 is configured to perform the operation of equation (33) to generate an output signal C3 based on the input signals C0, generate signals G0 - G2, and propagate signals P0 - P2. The fifth logic circuit 440 is configured to perform the operation of equation (34) to generate an output signal C4 based on the input signals C0, generate signals G0 - G3, and propagate signals P0 - P3. It should be noted that the 4-bit look-ahead carry generator 400 is only an example and is not intended to limit the present invention. Look-ahead carry generators with more or fewer bits can be applied to the secure adder of the present invention. In addition, the number of bits of the carry value C generated by the look-ahead carry generator 400 is the same as the number of bits of the propagate value P and the generate value G, and the number of bits of the carry output Co is one.

[0280] Figure 5 A flowchart showing a method for performing secure carry-saving addition according to some embodiments of the present invention, applicable to Figure 1 the secure carry-save adder 162. In some embodiments, Figure 5 the method 500 for performing secure carry-saving addition can be executed by other circuits (such as a processor).

[0281] First, in step S510, a fourth mask value rx, a fifth mask value ry, a sixth mask value rz, a first input data x', a second input data y', and a third input data z' are obtained, where the first input data x' is obtained by performing a masking operation on the third data x using the fourth mask value rx, as shown in the following equation (35):

[0282] x' = x ⊕ rx (35).

[0283] Similarly, the second input data y' is obtained by performing a masking operation on the fourth data y using the fifth mask value ry, as shown in the following equation (36):

[0284] y' = y ⊕ ry (36).

[0285] Furthermore, the third input data z' is obtained by performing a masking operation on the fifth data z using the sixth mask value rz, as shown in the following equation (37):

[0286] z' = z ⊕ rz (37).

[0287] In step S520, according to the fourth mask value rx, the fifth mask value ry, or the sixth mask value rz, the third variable Rr can be obtained. For example, the third variable Rr can be equal to the fourth mask value rx, the fifth mask value ry, or the sixth mask value rz. In this embodiment, the third variable Rr is equal to the fourth mask value rx, as shown in the following equation (38):

[0288] Rr = rx (38).

[0289] Furthermore, according to the fourth mask value rx, the fifth mask value ry, and the sixth mask value rz, the fourth variable Rxy and the fifth variable Rxz can be obtained, as shown in the following equations (39) and (40):

[0290] Rxy = rx ⊕ ry (39); and

[0291] Rxz = rx ⊕ rz (40).

[0292] In some embodiments, when the third variable Rr is equal to the fifth mask value ry, then according to the fourth mask value rx, the fifth mask value ry, and the sixth mask value rz, the fourth variable Rxy and the sixth variable Ryz can be obtained, where Ryz = ry ⊕ rz. In some embodiments, when the third variable Rr is equal to the sixth mask value rz, then according to the fourth mask value rx, the fifth mask value ry, and the sixth mask value rz, the fifth variable Rxz and the sixth variable Ryz can be obtained, where Rxz = rx ⊕ rz.

[0293] When the third variable Rr is equal to the fourth mask value rx, the fifth masked data x'' can be obtained according to the first input data x', as shown in the following equation (41).

[0294] x'' = x' (41).

[0295] In addition, mask operations are respectively performed on the second input data y' and the third input data z' according to the fourth variable Rxy and the fifth variable Rxz, so as to obtain the sixth masked data y'' and the seventh masked data z'', as shown in the following equations (42) and (43) respectively:

[0296] y'' = y' ⊕ Rxy (42); and

[0297] z'' = z' ⊕ Rxz (43).

[0298] According to Equation (35) and Equation (42), it can be known that the fifth masked data x” is equal to the exclusive OR operation of the third data x and the third variable Rr, as shown in the following Equation (44):

[0299] x” = x' = x⊕rx = x⊕Rr (44).

[0300] In addition, if the fifth mask value ry is different from the fourth mask value rx (i.e., ry≠rx), then according to Equation (36), Equation (38), and Equation (39), it can be known that the sixth masked data y” is equal to the exclusive OR operation of the fourth data y and the third variable Rr, as shown in the following Equation (45):

[0301] y” = y'⊕Rxy = (y⊕ry)⊕(rx⊕ry)

[0302] = y⊕rx⊕(ry⊕ry) = y⊕Rr (45).

[0303] Conversely, if the fifth mask value ry is the same as the fourth mask value rx (i.e., ry=rx), then the fourth variable Rxy is equal to 0. Thus, according to Equation (36) and Equation (39), and the fifth mask value ry is the same as the fourth mask value rx and the third variable Rr is also equal to the fourth mask value rx, it can be known that the sixth masked data y” is equal to the exclusive OR operation of the fourth data y and the third variable Rr, as shown in the following Equation (46):

[0304] y” = y'⊕Rxy = y'⊕0 = y'

[0305] = y⊕ry = y⊕rx = y⊕Rr (46).

[0306] It can be seen from Equation (45) and Equation (46) that regardless of whether the fifth mask value ry is the same as the fourth mask value rx, the sixth masked data y” is equal to the exclusive OR operation of the fourth data y and the third variable Rr. In addition, the original values of the third data x and the fourth data y are not revealed during the operation process of Equation (44) - Equation (46). In other words, when using the secure carry save adder 162 to perform the addition operation, there is no need to limit the fifth mask value ry and the fourth mask value rx.

[0307] Similarly, if the sixth mask value rz is different from the fourth mask value rx (i.e., rz≠rx), then according to Equation (37), Equation (38), and Equation (40), it can be known that the seventh masked data z” is equal to the exclusive OR operation of the fifth data z and the third variable Rr, as shown in the following Equation (47):

[0308] z” = z'⊕Rxz = (z⊕rz)⊕(rx⊕rz)

[0309] = z ⊕ rx ⊕ (rz ⊕ rz) = z ⊕ Rr (47).

[0310] Conversely, if the sixth mask value rz is the same as the fourth mask value rx (i.e., rz = rx), then the fifth variable Rxz is equal to 0. Thus, according to equations (37) and (40), and the fact that the sixth mask value rz is the same as the fourth mask value rx and the third variable Rr is also equal to the fourth mask value rx, it can be known that the seventh masked data z” is equal to the exclusive OR operation of the fifth data z and the third variable Rr, as shown in the following equation (48):

[0311] z” = z' ⊕ Rxz = z' ⊕ 0 = z'

[0312] = z ⊕ rz = z ⊕ rx = z ⊕ Rr (48).

[0313] From equations (47) and (48), it can be seen that regardless of whether the sixth mask value rz is the same as the fourth mask value rx, the seventh masked data z” is equal to the exclusive OR operation of the fifth data z and the third variable Rr. In addition, the original values of the third data x and the fifth data z are not revealed during the operations of equations (44), (47), and (48). In other words, when using the secure carry-save adder 162 to perform the addition operation, there is no need to limit the sixth mask value rz and the fourth mask value rx.

[0314] The carry-save adder mainly compresses three data x, y, and z into two original output values sum and carry (i.e., the original values without being masked), as shown in the following equations (49) and (50):

[0315] sum = x ⊕ y ⊕ z (49); and carry = (x & y) | (x & z) | (y & z) (50).

[0316] Where “|” represents the OR operation, and “&” represents the AND operation.

[0317] Assume that the exclusive OR operation of the fifth masked data x”, the sixth masked data y”, and the seventh masked data z” can obtain the masked data sum”, as shown in the following equation (51):

[0318] sum” = x” ⊕ y” ⊕ z” (51).

[0319] Next, substituting equations (44)-(49) into equation (51), equation (52) can be obtained and rewritten as equation (53), as shown below:

[0320] sum” = (x ⊕ Rr) ⊕ (y ⊕ Rr) ⊕ (x ⊕ Rr)

[0321] = (x ⊕ y ⊕ z) ⊕ Rr

[0322] = sum ⊕ Rr (52).

[0323] sum = sum” ⊕ Rr (53).

[0324] Similarly, assume that performing an OR operation and an AND operation on the fifth masked data x”, the sixth masked data y”, and the seventh masked data z” can obtain the masked data carry”, as shown in the following formula (54):

[0325] carry” = (x” & y”) | (x” & z”) | (y” & z”) (54).

[0326] Next, substituting formulas (44)-(49) into formula (54), formula (55) can be obtained, as shown below:

[0327] carry” = ((x ⊕ Rr) & (y ⊕ Rr)) | ((x ⊕ Rr) & (z ⊕ Rr)) |

[0328] ((y ⊕ Rr) & (z ⊕ Rr)) (55).

[0329] Next, according to the distributive law between the AND operation and the exclusive OR operation, formula (55) is rewritten as formula (56), as shown below:

[0330] carry” = ((x & y) ⊕ ((x ⊕ y) & Rr) ⊕ Rr) | ((x & z) ⊕ ((x ⊕ z) & Rr) ⊕ Rr) |

[0331] ((y & z) ⊕ ((y ⊕ z) & Rr) ⊕ Rr) (56).

[0332] To simplify the formula, new variables Exy, Eyz, and Exz are set, as shown in the following formulas (57)-(59):

[0333] Exy = ((x ⊕ y) & Rr) ⊕ Rr (57);

[0334] Exz = ((x ⊕ z) & Rr) ⊕ Rr (58);

[0335] Eyz = ((y ⊕ z) & Rr) ⊕ Rr (59). Next, substituting the variables Exy, Eyz, and Exz into formula (56), formula (60) can be obtained, as shown below:

[0336] carry” = ((x&y)⊕Exy) | ((x&z)⊕Exz) | ((y&z)⊕Eyz) (60).

[0337] Reference Figure 6 , Figure 6 shows the truth table of the variable Exy according to some embodiments of the present invention. As Figure 6 shown, if the third data x is equal to the fourth data y, the variable Exy is equal to the Rr value. Conversely, if the third data x is different from the fourth data y, the variable Exy is equal to 0. Similarly, if the third data x is equal to the fifth data z, the variable Exz is equal to the Rr value. Conversely, if the third data x is different from the fifth data z, the variable Exz is equal to 0. Furthermore, if the fourth data y is equal to the fifth data z, the variable Eyz is equal to the Rr value. Conversely, if the fourth data y is different from the fifth data z, the variable Eyz is equal to 0.

[0338] Figure 7 shows the truth table of the original output value carry of the formula (50) according to some embodiments of the present invention, and Figure 8 shows the truth table of the masked data carry” of the formula (60) according to some embodiments of the present invention. Also refer to Figure 7 and Figure 8 , when the third variable Rr is equal to 0, regardless of the values of the third data x, the fourth data y, and the fifth data z, the value of the masked data carry” is the same as the original output value carry. Conversely, when the third variable Rr is equal to 1, regardless of the values of the third data x, the fourth data y, and the fifth data z, the value of the masked data carry” is opposite to (or complementary to) the original output value carry. Therefore, the following formula (61) can be derived from Figure 7 and Figure 8 :

[0339] carry = carry”⊕Rr (61).

[0340] Next, set the mask values of the original output value sum and the original output value carry to the input variable Rsum and the mask value Rcarry respectively. Furthermore, to optimize the secure carry-save adder, the mask value Rcarry is set to the third variable Rr. In addition, the masked operations can be performed on the original output value carry and the original output value sum using the mask value Rcarry and the input variable Rsum respectively to obtain the carry data Cout and the sum data Sout, as shown in the following formulas (62)-(63):

[0341] Sout=sum⊕Rsum=sum”⊕Rr⊕Rsum

[0342] = x” ⊕ y” ⊕ z” ⊕ Rr ⊕ Rsum(62); and Cout = carry ⊕ Rcarry = carry” ⊕ Rr ⊕ Rcarry

[0343] = carry” (63).

[0344] Since the mask value Rcarry is equal to the third variable Rr, the equation (63) can be optimized to Cout = carry”. Furthermore, performing an exclusive OR operation on the third variable Rr and the input variable Rsum yields the seventh variable Rsum', as shown in the following equation (64):

[0345] Rsum' = (Rr ⊕ Rsum) (64).

[0346] Next, performing an exclusive OR operation on the fifth masked data x” and the seventh variable Rsum' yields the eighth variable Rsum”, as shown in the following equation (65):

[0347] Rsum” = (x” ⊕ Rsum') (65). Thus, substituting equations (64) and (65) into equation (62) gives equation (66), as shown below:

[0348] Sout = y” ⊕ z” ⊕ Rsum” (66).

[0349] Referring back to Figure 5 , in step S530, based on one of the fifth masked data x”, the sixth masked data y”, and the seventh masked data z” (e.g., the fifth masked data x”), the third variable Rr, and the input variable Rsum, the eighth variable Rsum” can be obtained, as shown in equations (64) and (65). Next, in step S540, based on the other two of the fifth masked data x”, the sixth masked data y”, and the seventh masked data z” (e.g., the sixth masked data y” and the seventh masked data z”) and the eighth variable Rsum”, the sum data Sout and the carry data Cout can be obtained, as shown in equations (63) and (66).

[0350] It should be noted that, in this embodiment, the third variable Rr is equal to the fourth mask value rx. Thus, the sum data Sout can be obtained according to the sixth masked data y”, the seventh masked data z”, and the eighth variable Rsum”, as shown in equation (66). In addition, the eighth variable Rsum” is obtained according to the fifth masked data x”, as shown in equation (65). Thus, according to equations (44)-(48), equation (52), equation (54), equation (63), equation (64), equation (65), and equation (66), the logic circuit of the secure carry-save adder 162 can be obtained.

[0351] In some embodiments, the third variable Rr is equal to the fifth mask value ry. Thus, the sum data Sout can be obtained according to the fifth masked data x”, the seventh masked data z”, and the eighth variable Rsum”, as shown in the following equation (67):

[0352] Sout = x” ⊕ z” ⊕ Rsum” (67). In addition, the eighth variable Rsum” is obtained according to the sixth masked data y”, as shown in the following equation (68):

[0353] Rsum” = (y” ⊕ Rsum') (68).

[0354] In some embodiments, the third variable Rr is equal to the sixth mask value rz. Thus, the sum data Sout can be obtained according to the fifth masked data x” and y” and the eighth variable Rsum”, as shown in the following equation (69):

[0355] Sout = x” ⊕ y” ⊕ Rsum” (69). In addition, the eighth variable Rsum” is obtained according to the seventh masked data z”, as shown in the following equation (70):

[0356] Rsum” = (z” ⊕ Rsum') (70).

[0357] Figure 9A Shows a schematic circuit diagram of the secure carry-save adder 162A according to some embodiments of the present invention. The secure carry-save adder 162A includes a fifth mask unit 810a, a sixth mask unit 820a, a seventh mask unit 830a, a sixth logic circuit 840, and a ninth exclusive-OR gate 910. In this embodiment, the third variable Rr is equal to the fourth mask value rx.

[0358] The fifth masking unit 810a is configured to perform a masking operation on the second input data y' according to the fourth mask value rx and the fifth mask value ry to obtain a sixth masked data y". In some embodiments, the fifth masking unit 810a includes a tenth exclusive-OR gate 912 and an eleventh exclusive-OR gate 914. The tenth exclusive-OR gate 912 is used to perform an exclusive-OR operation on the fifth mask value ry and the fourth mask value rx to obtain a fourth variable Rxy, as shown in equation (5). Then, the eleventh exclusive-OR gate 914 is configured to perform a masking operation (i.e., an exclusive-OR operation) on the second input data y' according to the fourth variable Rxy to obtain the sixth masked data y", as shown in equation (42).

[0359] The sixth masking unit 820a is configured to perform a masking operation on the first input data x' according to the fourth mask value rx (i.e., the third variable Rr) and the input variable (or mask value) Rsum to obtain an eighth variable Rsum", and the eighth variable Rsum" can also be regarded as masked data. In some embodiments, the sixth masking unit 820a includes a twelfth exclusive-OR gate 922 and a thirteenth exclusive-OR gate 924. The twelfth exclusive-OR gate 922 is used to perform an exclusive-OR operation on the third variable Rr (i.e., the fourth mask value rx) and the input variable Rsum to obtain a seventh variable Rsum', as shown in equation (64). Then, the thirteenth exclusive-OR gate 924 is configured to perform a masking operation on the fifth masked data x" (i.e., the first input data x') according to the seventh variable Rsum' to obtain the eighth variable Rsum", as shown in equation (65).

[0360] The seventh masking unit 830a is configured to perform a masking operation on the third input data z' according to the fourth mask value rx and the sixth mask value rz to obtain a seventh masked data z". In some embodiments, the seventh masking unit 830a includes a fourteenth exclusive-OR gate 932 and a fifteenth exclusive-OR gate 934. The fourteenth exclusive-OR gate 932 is used to perform an exclusive-OR operation on the fourth mask value rx and the sixth mask value rz to obtain a fifth variable Rxz, as shown in equation (40). Then, the fifteenth exclusive-OR gate 934 is configured to perform a masking operation on the third input data z' according to the fifth variable Rxz to obtain the seventh masked data z", as shown in equation (43).

[0361] The sixth logic circuit 840 provides a carry data Cout based on a fifth masked data x'', a sixth masked data y'', and a seventh masked data z''. In some embodiments, the sixth logic circuit 840 includes a third AND gate 852, a fourth AND gate 854, a fifth AND gate 856, and an OR gate 860. The third AND gate 852 is configured to receive the sixth masked data y'' and the seventh masked data z'', and output a fourth intermediate data D4. In addition, the fourth AND gate 854 is configured to receive the sixth masked data y'' and the fifth masked data x'', and output a fifth intermediate data D5. Furthermore, the fifth AND gate 856 is configured to receive the seventh masked data z'' and the fifth masked data x'', and output a sixth intermediate data D6. The OR gate 860 is configured to receive the fourth intermediate data D4, the fifth intermediate data D5, and the sixth intermediate data D6, and output the carry data Cout, as shown in equations (54) and (63).

[0362] The ninth exclusive-OR gate 910 is configured to receive the sixth masked data y'', the seventh masked data z'', and an eighth variable Rsum'', and output a sum data Sout, as shown in equation (66). Thus, the secure carry-save adder 162 performs an addition operation on three input data x', y', and z' without removing the fourth mask value rx, the fifth mask value ry, and the sixth mask value rz, and provides the sum data Sout and the carry data Cout.

[0363] Figure 9B A schematic circuit diagram of the secure carry-save adder 162B according to some embodiments of the present invention is shown. The secure carry-save adder 162B includes a fifth masking unit 810b, a sixth masking unit 820b, a seventh masking unit 830b, a sixth logic circuit 840, and a ninth exclusive-OR gate 910. In this embodiment, the third variable Rr is equal to the fifth mask value ry.

[0364] In Figure 9B , the fifth masking unit 810b is configured to perform a masking operation on a first input data x' according to the fourth mask value rx and the fifth mask value ry to obtain a fifth masked data x''. In addition, the sixth masking unit 820b is configured to perform a masking operation on a second input data y' according to the fifth mask value ry (i.e., the third variable Rr) and an input variable Rsum to obtain an eighth variable Rsum''. Furthermore, the seventh masking unit 830b is configured to perform a masking operation on a third input data z' according to the fifth mask value ry and the sixth mask value rz to obtain a seventh masked data z''.

[0365] Similar to Figure 9A, the sixth logic circuit 840 of the secure carry-save adder 162B provides a carry data Cout based on a fifth masked data x”, a sixth masked data y”, and a seventh masked data z”. In addition, the ninth exclusive-OR gate 910 of the secure carry-save adder 162B is configured to receive the fifth masked data x”, the seventh masked data z”, and an eighth variable Rsum”, and output a sum data Sout, as shown in equation (67).

[0366] Figure 9C Shows a schematic circuit diagram of a secure carry-save adder 162C according to some embodiments of the present invention. The secure carry-save adder 162C includes a fifth masking unit 810c, a sixth masking unit 820c, a seventh masking unit 830c, a sixth logic circuit 840, and a ninth exclusive-OR gate 910. In this embodiment, a third variable Rr is equal to a sixth masking value rz.

[0367] In Figure 9C , the fifth masking unit 810c is configured to perform a masking operation on a second input data y' according to a fifth masking value ry and a sixth masking value rz to obtain a sixth masked data y”. In addition, the sixth masking unit 820c is configured to perform a masking operation on a third input data z' according to the sixth masking value rz (i.e., the third variable Rr) and an input variable Rsum to obtain an eighth variable Rsum”. Furthermore, the seventh masking unit 830c is configured to perform a masking operation on a first input data x' according to a fourth masking value rx and a sixth masking value rz to obtain a fifth masked data x”.

[0368] Similar to Figure 9A , the sixth logic circuit 840 of the secure carry-save adder 162C provides a carry data Cout based on a fifth masked data x”, a sixth masked data y”, and a seventh masked data z”. In addition, the ninth exclusive-OR gate 910 of the secure carry-save adder 162C is configured to receive the sixth masked data y”, the seventh masked data z”, and the eighth variable Rsum”, and output a sum data Sout, as shown in equation (69).

[0369] Referring to Figure 1 , the secure carry-save adder 162 is used to verify whether the secure addition operation performed by the secure carry-lookahead adder 150 is correct. How the verification circuit 160 verifies the operation result of the secure carry-lookahead adder 150 will be described in detail below.

[0370] The secure addition operation performed by the secure carry-lookahead adder 150 is shown in equations (71) and (72):

[0371] a'=(a⊕ra)

[0372] b' = (b ⊕ rb)

[0373] o' = (o ⊕ ro) (71);

[0374] (o' ⊕ ro) = (a' ⊕ ra) + (b' ⊕ rb) (72). Equations (71) and (72) can be simplified to Equation (73) as follows:

[0375] SCLA(a', b', ra, rb, ro) = o' (73).

[0376] where SCLA is used to represent the secure addition operation performed by the secure carry look-ahead adder 150. The secure addition operation performed by the secure carry save adder 162 is as shown in Equations (74) and (75):

[0377] x' = (x ⊕ rx)

[0378] y' = (y ⊕ ry)

[0379] z' = (z ⊕ rz)

[0380] Sout = (Sum ⊕ Rsum)

[0381] Cout = (carry ⊕ rx) (74);

[0382] (Sout ⊕ Rsum) + (Cout ⊕ rx) << 1 = (x' ⊕ rx) + (y' ⊕ ry) + (z' ⊕ rz) (75).

[0383] where the fourth mask value rx is the optimized result of the original output value carry, and << 1 is used to represent a left shift of one bit for (Cout ⊕ rx). In addition, Equations (74) and (75) can be combined into Equation (76), where SCSA is used to represent the secure addition operation performed by the secure carry save adder 162.

[0384] SCSA(x', y', z', rx, ry, rz, Rsum) = (Sout, Cout << 1) (76).

[0385] Equation (77) represents the reverse value using two's complement notation, where M is any value and ~M is the inverse of M.

[0386] -M = ~M + 1 (77).

[0387] Assume M is k bits. Since the reverse value of M equals the exclusive OR mask operation between M and the {k{1}} value, as shown in equation (78).

[0388] ~M = M ⊕ {k{1}} (78).

[0389] Among them, {k{1}} in equation (78) represents "1" repeated k times. In other words, {8{1}} equals 0xFF. Next, assume M1 and M2 are also k-bit variables. The inverse of (M1⊕M2) is shown in equation (79):

[0390] ~(M1⊕M2)=(M1⊕M2)⊕{k{1}}=M1⊕(M2⊕{k{1}})

[0391] = (M1 ⊕ {k{1}}) ⊕ M2 (79).

[0392] Due to the associative property of the exclusive OR mask, the rearrangement of the {k{1}} value positions is as shown in equation (79). Next, we can rewrite equation (78) as equation (80).

[0393] ~(M1 ⊕ M2) = (M1 ⊕ ~M2) = (~M1 ⊕ M2) (80).

[0394] According to equations (71) and (72), we know that a + b = o. Subtracting o from both sides of the equation, we can obtain equation (81).

[0395] a + b - o = 0 (81). Because of the two's complement representation relationship, we can rewrite equation (81) as equation (82) using equation (77).

[0396] a + b + ~o + 1 = 0 (82).

[0397] Next, substituting the first data a, the second data b, and ~o, as well as the corresponding first mask value ra, the second mask value rb, and the third mask value ro into equations (76) and (75), we respectively obtain equations (83) and (84).

[0398] SCSA(a', b', ~o', ra, rb, ro, Rsum) = (Sout, Cout <<1) (83);

[0399] (Sout⊕Rsum)+(Cout⊕ra)<<1=(a'⊕ra)+(b'⊕rb)+

[0400] (~o'⊕ro)(84).

[0401] According to the result of formula (80), move the inversion operation (i.e., ~) of the third operand on the right side of the equation in formula (74) outside the parentheses, as shown in formula (85):

[0402] (Sout ⊕ Rsum) + (Cout ⊕ ra) << 1 = (a' ⊕ ra) + (b' ⊕ rb) +

[0403] ~(o' ⊕ ro) (85).

[0404] Next, according to formula (74), after removing the first mask value ra, the second mask value rb, and the third mask value ro, formula (86) can be obtained.

[0405] (Sout ⊕ Rsum) + (Cout ⊕ ra) << 1 = a + b + ~o (86).

[0406] Based on the two's complement representation, formula (86) can be written as formula (87) using formula (77).

[0407] (Sout ⊕ Rsum) + (Cout ⊕ ra) << 1 = a + b – o – 1 (87).

[0408] Based on the result of formula (81), formula (88) can be obtained.

[0409] (Sout ⊕ Rsum) + (Cout ⊕ ra) << 1 = –1 (88). Subtract (Sout ⊕ Rsum) from both sides of the equation in formula (88) to form formula (89).

[0410] (Cout ⊕ ra) << 1 = –(Sout ⊕ Rsum) – 1 (89).

[0411] Based on the two's complement representation, formula (89) can be written as formula (90) using formula (77).

[0412] (Cout ⊕ ra) << 1 = ~(Sout ⊕ Rsum) + 1 – 1 (90). Then use the +1 value to eliminate the -1 value and form formula (91).

[0413] (Cout ⊕ ra) << 1 = ~(Sout ⊕ Rsum) (91).

[0414] To simplify equation (91), the input variable Rsum can be specified as the first mask value ra shifted left by one bit (i.e., ra << 1), as shown in equation (92):

[0415] Rsum = ra << 1 (92).

[0416] Therefore, equation (91) can be rewritten as equation (93).

[0417] (Cout ⊕ ra) << 1 = ~(Sout ⊕ (ra << 1)) (93). According to the result of equation (80), move the inversion operation (i.e., ~) of the parentheses to before Sout, as shown in equation (94).

[0418] (Cout ⊕ ra) << 1 = ~Sout ⊕ (ra << 1) (94). Perform the exclusive OR operation on both sides of equation (94) with respect to (ra << 1), and rewrite it as equation (95).

[0419] Cout << 1 = ~Sout (95).

[0420] It should be noted that under the condition of equation (92) and when the safe look-ahead addition operation performed by the safe carry preadder 150 is correct, the sum data Sout and carry data Cout generated by the safe carry save adder 162 performing the safe save carry addition operation on the first masked data a', second masked data b', and inverted sum output ~o' should conform to the relationship shown in equation (95).

[0421] Figure 10 Show the circuit diagram of the verification circuit according to an embodiment of the present invention. As Figure 10 shown, the verification circuit 160A includes a first conversion circuit 161A, a safe carry save adder 162C, a second conversion circuit 163A, and a comparator 164. In this embodiment, taking the safe carry save adder 162C included in the verification circuit 160A as an example, an explanation is given. In other embodiments, the verification circuit 160A may also include Figure 9C the safe carry save adder 162A or Figure 9A the safe carry save adder 162B of Figure 9B .

[0422] The first conversion circuit 161A includes a first shift circuit SHFT1 and a first inverter INV1. The first shift circuit SHIFT1 is used to shift the first mask value ra to the left by one bit to generate a first conversion variable TV1, where the first conversion variable TV1 is equal to (ra << 1). The first inverter INV1 is used to invert the sum output o' to generate a second conversion variable TV2, where the second conversion variable TV2 is equal to the inverted sum output ~o'.

[0423] The second conversion circuit 163A includes a second shift circuit SHFT2 and a second inverter INV2. The second shift circuit SHFT2 is used to shift the carry data Cout to the left by one bit to generate a converted carry data mc, where the converted carry data mc is equal to (Cout << 1). The second inverter INV2 is used to reverse the sum data Sout to generate a converted sum data ms, where the converted sum data ms is equal to the inverted sum data ~Sout.

[0424] As Figure 10 shown, the verification circuit 160A uses equations (83), (92), and (95) to ensure the correctness of the secure look-ahead carry addition operation performed by the secure carry look-ahead adder 150. Moreover, the comparator 164 compares whether the converted sum data ms and the converted carry data mc are equal to generate a verification result vf. When the converted sum data ms and the converted carry data mc are equal, it means that the condition of equation (95) has been met. Therefore, the external circuit can confirm the correctness of the secure look-ahead carry addition operation performed by the secure carry look-ahead adder 150 through the verification result vf.

[0425] Next, the verification circuit 160A can be optimized. Substituting equation (70) into equation (69) gives equation (96).

[0426] Sout = x” ⊕ y” ⊕ Rsum' ⊕ z (96).

[0427] As Figure 10 shown, it can be seen that the seventh masked data z” is equal to the inverted value of the third input data z' (i.e., the fifth inverted input data ~z'). Therefore, equation (96) can be rewritten as equation (97).

[0428] Sout = x” ⊕ y” ⊕ Rsum' ⊕ ~z' (97). Next, invert both sides of the equal sign in equation (97) to obtain equation (98).

[0429] ~Sout= ~(x” ⊕ y” ⊕ Rsum' ⊕ ~z') (98).

[0430] Based on the result of arithmetic expression (80), move the inversion operation (i.e., ~) to the front of the inverted value of the third input data z' (i.e., the fifth inverted input data ~z'), as shown in arithmetic expression (99):

[0431] ~Sout = x” ⊕ y” ⊕ Rsum' ⊕ ~(~z') (99). Next, the two inversion operations can cancel each other out, as shown in arithmetic expression (100):

[0432] ~Sout = x” ⊕ y” ⊕ Rsum' ⊕ z' (100).

[0433] As shown in arithmetic expression (100), after modifying the seventh masked data z” input to Figure 10 the thirteenth exclusive-OR gate 924 to the third input data z', Figure 10 the second inverter INV2 of the second conversion circuit 163 of

[0434] can be omitted. Therefore, arithmetic expression (95) can be rewritten as arithmetic expression (101).

[0435] Figure 11 Show the circuit diagram of the verification circuit according to another embodiment of the present invention. Compared with the verification circuit 160A, the second conversion circuit 163B of the verification circuit 160B has one less second inverter INV2, and the sum output o' is directly provided to the input of the thirteenth exclusive-OR gate 924. In other words, the thirteenth exclusive-OR gate 924 is configured to perform a masking operation on the sum output o' according to the seventh variable Rsum' to obtain the eighth variable Rsum”, so that the second inverter INV2 of the second conversion circuit 163A can be omitted.

[0436] Since the second conversion circuit 163B has one less second inverter INV2, the converted sum data ms is equal to the sum data Sout, and the converted carry data mc is equal to (Cout << 1). The comparator 164 compares whether the converted sum data ms and the converted carry data mc are equal, and generates a verification result vf. In other words, the verification circuit 160B determines whether arithmetic expression (101) holds to ensure the correctness of the secure look-ahead carry addition operation performed by the secure carry-lookahead adder 150.

[0437] Figure 12 Show the flowchart of the execution method of secure addition according to an embodiment of the present invention. The following description of the execution method 1200 of Figure 12 will be described in conjunction with the secure adder 100 of Figure 1 for detailed illustration.

[0438] AsFigure 12 As shown, a first mask value ra, a second mask value rb, and a third mask value ro are generated by a mask generator 120 (step S1210). Then, a first masked data a' is generated by the mask generator 120 according to the first mask value ra (step S1220), and a second masked data b' is generated according to the second mask value rb (step S1230). Using a secure carry-lookahead adder 150, the first masked data a' and the second masked data b' are operated on according to the first mask value ra, the second mask value rb, and the third mask value ro to generate a sum output o' (step S1240).

[0439] Using a secure carry-save adder 162, a sum data Sout and a carry data Cout are generated according to the first mask value ra, the second mask value rb, the third mask value ro, the first masked data a', the second masked data b', and the sum output o' (step S1250). Finally, using a comparator 164, a verification result vf is generated according to the relationship between the sum data Sout and the carry data Cout (step S1260).

[0440] The present invention proposes a secure adder that uses a secure carry-save adder to verify the operation result of a secure carry-lookahead adder. Since the secure adder used in the verification circuit proposed by the present invention and the secure adder performing secure operations belong to two different circuits and their execution times are staggered, the difficulty of error collision of the secure adder of the present invention is greatly increased.

Claims

1. A secure adder, characterized in that, Comprising: A mask generator that generates a first mask value, a second mask value, and a third mask value, generates a first masked data according to the first mask value, and generates a second masked data according to the second mask value; A secure carry-lookahead adder that performs an operation on the first masked data and the second masked data according to the first mask value, the second mask value, and the third mask value to generate a sum output; And A verification circuit, comprising: A secure carry-save adder that generates a sum data and a carry data according to the first mask value, the second mask value, the third mask value, the first masked data, the second masked data, and the sum output; and A comparator that generates a verification result according to the relationship between the sum data and the carry data.

2. The secure adder according to claim 1, wherein The above-mentioned lookahead carry adder further comprises: A first exclusive OR gate for receiving the first mask value and the second mask value to provide a variable; A second mask unit for performing a third masking operation on the first masked data according to the variable to obtain a third masked data; A half adder for receiving the third masked data and the second masked data to generate a propagate value and an intermediate generated value; A third mask unit for performing a fourth masking operation on the propagate value according to the third mask value to obtain a fourth masked data; A first logic circuit for providing a generated value according to the propagate value, the intermediate generated value, and the second mask value variable; A lookahead carry generator for providing a carry output and a carry value according to a carry input, the generated value, and the propagate value; and A second exclusive OR gate for receiving the fourth masked data and the carry value to provide the sum output.

3. The secure adder according to claim 2, characterized in that, The above-mentioned second mask unit comprises: A third exclusive OR gate for receiving the variable and the first masked data to provide the third masked data.

4. The secure adder according to claim 2, wherein Further comprising: A bus interface for providing a first data and a second data from a bus to the mask generator.

5. The secure adder according to claim 4, characterized in that, Further comprising: A selection circuit for selectively providing the first mask value, the second mask value, the third mask value, the first masked data, and the second masked data from the mask generator or the first mask value, the second mask value, the third mask value, the first masked data, and the second masked data generated by an external circuit from the bus to the lookahead carry adder; and A storage circuit coupled between the selection circuit and the lookahead carry adder for storing the first mask value, the second mask value, the third mask value, the first masked data, and the second masked data from the selection circuit.

6. The secure adder according to claim 1, wherein The above-mentioned mask generator comprises: A random number generator for randomly generating the first mask value, the second mask value, and the third mask value; and A first masking unit is configured to perform a first masking operation on a first data according to the first masking value to obtain the first masked data, and perform a second masking operation on a second data according to the second masking value to obtain the second masked data.

7. The secure adder according to claim 1, wherein The secure carry-save adder includes: A fourth masking unit is configured to perform a fifth masking operation according to the first masking value, a first conversion variable, the sum output, and a second conversion variable to obtain a first variable; A fifth masking unit is configured to perform a sixth masking operation on the second masked data according to the first masking value and the second masking value to obtain a fifth masked data; A sixth masking unit is configured to perform a seventh masking operation on the first masked data according to the first masking value and the third masking value to obtain a sixth masked data; and An eighth exclusive-OR gate is configured to receive the fifth masked data, the sixth masked data, and the first variable to provide the sum data of the first masked data, the second masked data, and the sum output.

8. The secure adder according to claim 7, characterized in that, The secure carry-skip adder further includes: A second logic circuit is configured to receive the fifth masked data, the sixth masked data, and the second conversion variable to provide the carry data of the first masked data, the second masked data, and the sum output.

9. The secure adder according to claim 7, characterized in that, The verification circuit further includes: A first conversion circuit includes: A first shift circuit shifts the first masking value left by one bit to generate the first conversion variable; and A first inverter inverts the sum output to generate the second conversion variable.

10. A method for executing secure addition, characterized in that, Includes: Generate a first masking value, a second masking value, and a third masking value; Generate a first masked data according to the first masking value; Generate a second masked data according to the second masking value; Perform an operation on the first masked data and the second masked data according to the first masking value, the second masking value, and the third masking value to generate a sum output; Generate a sum data and a carry data according to the first masking value, the second masking value, the third masking value, the first masked data, the second masked data, and the sum output; and Generate a verification result according to the relationship between the sum data and the carry data.