Ciphertext compression and decompression circuit and method, electronic equipment and chip
By using ciphertext compression and decompression circuits in the post-quantum cryptography algorithm, and using shift and addition operations instead of the divider, the problem of excessive hardware resource consumption is solved, and the saving of hardware resources and the improvement of computing efficiency is achieved.
Patent Information
- Application Number
- CN202510633983.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-07-29
AI Technical Summary
In the existing hardware implementation of grid-based post-quantum cryptographic algorithms, the resource consumption of the ciphertext compression and decompression module is too large, especially due to the existence of a divider, the hardware resource consumption is too large and the computing complexity is high.
The ciphertext compression decompression circuit is adopted to realize ciphertext compression through a first multiplier, a first shifter, a first adder, a subtractor and a comparator. Instead of the divider, the calculation is performed using shift operations and addition operations, which specifically includes multiplying the ciphertext with a preset constant, shifting right, rounding, subtracting 2d, and comparing operations.
It saves hardware resources, reduces computing complexity and compression time, improves hardware implementation efficiency, and reduces the area of hardware resources.
Smart Images

Figure CN120389848A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information security technology, and in particular, to a circuit and method for ciphertext compression and decompression, an electronic device, and a chip. Background Art
[0002] The security relied on by traditional cryptographic algorithms is based on some specific mathematical problems that cannot be broken by computers or humans within polynomial time. The emergence of quantum computers will break this situation and will be able to crack problems that current computers cannot solve within polynomial time, including the two major mathematical problems relied on by most current public-key cryptographic systems: the large integer prime factorization problem and the discrete logarithm problem. Therefore, it is urgent to study cryptographic systems that can resist quantum attacks. In 2016, NIST (National Institute of Standards and Technology) started a program to solicit post-quantum cryptographic systems. After three rounds of strict evaluation, NIST announced the first batch of 4 post-quantum cryptographic standard algorithms in July 2023. Among them, the CRYSTALS-KYBER algorithm, the CRYSTALS-DILITHIUM algorithm, and the Falcon algorithm are all lattice-based cryptographic schemes. Therefore, the research on lattice-based post-quantum cryptographic algorithms has broad prospects.
[0003] In lattice-based post-quantum cryptographic algorithms, compression and decompression operations are used to reduce the length of ciphertext transmitted between two communication parties, thereby effectively reducing the data transmission bandwidth requirements. However, the hardware implementation of existing lattice-based post-quantum cryptographic algorithms requires a divider, resulting in excessive resource consumption. Therefore, it is currently urgent to optimize the hardware implementation of the ciphertext compression and decompression module in lattice-based post-quantum cryptographic algorithms to save hardware resources. Summary of the Invention
[0004] To solve the problems in the related art, embodiments of the present disclosure provide a circuit and method for ciphertext compression and decompression, an electronic device, and a chip.
[0005] In a first aspect, embodiments of the present disclosure provide a circuit for ciphertext compression and decompression, including a compression circuit, where the compression circuit includes:
[0006] A first multiplier, configured to multiply an input ciphertext by a first preset constant to obtain a first multiplication result;
[0007] A first shifter, connected to the first multiplier, configured to shift the first multiplication result output by the first multiplier to the right by a first shift number of bits to obtain a first shift result;
[0008] A first adder, connected to the first shifter, configured to round the first shift result output by the first shifter to obtain a rounded result;
[0009] A subtractor, connected to the first adder, for subtracting 2 from the rounded result output by the first adder d , to obtain a subtraction result, where d is a value corresponding to the security level of the ciphertext;
[0010] A comparator, connected to the subtractor, for comparing the size of the subtraction result output by the subtractor and 0. When the subtraction result is less than 0, the rounded result is output; when the subtraction result is greater than or equal to 0, the subtraction result is output.
[0011] In a possible implementation manner, the first preset constant is 0.6151998, and the first shift number of bits is 11 - d.
[0012] In a possible implementation manner, the first multiplier is specifically configured to perform 15 right shift operations and 14 addition operations on the input ciphertext x according to the following formula to obtain a first multiplication result y:
[0013] y = (x >> 21) + (x >> 20) + (x >> 19) + (x >> 17) + (x >> 16) + (x >> 14) + (x >> 13) + (x >> 12) + (x >> 11) + (x >> 10) + (x >> 8) + (x >> 6) + (x >> 5) + (x >> 4) + (x >> 1).
[0014] In a possible implementation manner, the first adder is specifically configured to add 0.5 to the first shift result output by the first shifter, and output the 32nd to 21st bits of the addition result as the rounded result.
[0015] In a possible implementation manner, it further includes a decompression circuit, and the decompression circuit includes:
[0016] A second multiplier, for multiplying the input compressed ciphertext by a second preset constant to obtain a second multiplication result, and the second preset constant corresponds to the first preset constant;
[0017] A second shifter, connected to the second multiplier, for shifting the second multiplication result output by the second multiplier to the left by the second shift number of bits d to obtain a second shift result;
[0018] A second adder, connected to the second shifter, for rounding the second shift result output by the second shifter to obtain a decompressed ciphertext.
[0019] In a possible implementation manner, when the first preset constant is 0.6151998, the second preset constant is 3329.
[0020] Second aspect, an embodiment of the present disclosure provides a method for ciphertext compression and decompression. The method is implemented by the above-mentioned ciphertext compression and decompression circuit, and the method includes:
[0021] Multiply the input ciphertext by a first preset constant to obtain a first multiplication result;
[0022] Shift the first multiplication result to the right by a first shift number of bits to obtain a first shift result;
[0023] Round the first shift result output by the first shifter to obtain a rounded result;
[0024] Subtract 2 d , to obtain a subtraction result, where d is a value corresponding to the security level of the input ciphertext;
[0025] Compare the subtraction result with 0;
[0026] When the subtraction result is less than 0, output the rounded result; when the subtraction result is greater than or equal to 0, output the subtraction result.
[0027] In a possible implementation manner, the first preset constant is 0.6151998, and the first shift number of bits is 11 - d.
[0028] In a possible implementation manner, the multiplying the input ciphertext by a first preset constant to obtain a first multiplication result includes:
[0029] Perform 15 right shift operations and 14 addition operations on the input ciphertext x according to the following formula to obtain a first multiplication result y:
[0030] y = (x >> 21) + (x >> 20) + (x >> 19) + (x >> 17) + (x >> 16) + (x >> 14) + (x >> 13) + (x >> 12) + (x >> 11) + (x >> 10) + (x >> 8) + (x >> 6) + (x >> 5) + (x >> 4) + (x >> 1).
[0031] In a possible implementation manner, the rounding the first shift result output by the first shifter to obtain a rounded result includes:
[0032] Add 0.5 to the first shift result, and use the 32nd to 21st bits of the addition result as the rounded result.
[0033] In a possible implementation manner, the method further includes:
[0034] Multiply the input compressed ciphertext by a second preset constant to obtain a second multiplication result, where the second preset constant corresponds to the first preset constant;
[0035] Shift the second multiplication result to the left by a second shift number of bits d to obtain a second shift result;
[0036] Round the second shift result to obtain the decompressed ciphertext.
[0037] In a possible implementation, when the first preset constant is 0.6151998, the second preset constant is 3329.
[0038] In a third aspect, an embodiment of the present disclosure provides an electronic device, including a memory and a processor, where the memory is used to store one or more computer instructions, and the one or more computer instructions are executed by the processor to implement the method according to any one of the second aspects.
[0039] In a fifth aspect, an embodiment of the present disclosure provides a chip, and the chip is used to implement the method according to any one of the second aspects.
[0040] According to the technical solution provided by the embodiment of the present disclosure, the ciphertext compression of lattice-based post-quantum cryptography can be implemented by a first multiplier, a first shifter, a first adder, a subtractor, and a comparator. A divider is not used, which can avoid the problems of high computational complexity and excessive consumption of hardware resources caused by the inability to replace the divider with shift operations, saving hardware resources; and since complex division operations are not required, the compression time is also reduced accordingly, improving the hardware implementation efficiency.
[0041] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In combination with the drawings, through the following detailed description of non-limiting embodiments, other features, objects, and advantages of the present disclosure will become more obvious. In the drawings:
[0043] Figure 1 The structural schematic diagram of a compression circuit in a ciphertext compression and decompression circuit provided by an embodiment of the present disclosure is shown.
[0044] Figure 2 The structural schematic diagram of a decompression circuit in a ciphertext compression and decompression circuit provided by an embodiment of the present disclosure is shown.
[0045] Figure 3 The flowchart of a ciphertext compression and decompression method provided by an embodiment of the present disclosure is shown.
[0046] Figure 4 Shows a structural block diagram of an electronic device according to an embodiment of the present disclosure.
[0047] Figure 5 Shows a schematic structural diagram of a computer system suitable for implementing the method of the embodiment of the present disclosure. Detailed implementation manners
[0048] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings so that those skilled in the art can easily implement them. In addition, for clarity, parts irrelevant to the description of the exemplary embodiments are omitted in the drawings.
[0049] In the present disclosure, it should be understood that terms such as "including" or "having" are intended to indicate the presence of features, numbers, steps, actions, components, parts, or combinations thereof disclosed in this specification, and are not intended to exclude the possibility of the presence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0050] In addition, it should be noted that, without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other. The present disclosure will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0051] Figure 1 Shows a schematic structural diagram of a compression circuit in a ciphertext compression and decompression circuit provided by an embodiment of the present disclosure. As Figure 1 shown, the compression circuit 10 includes: a first multiplier 101, a first shifter 102, a first adder 103, a subtractor 104, and a comparator 105.
[0052] In a possible implementation manner, the ciphertext compression provided by the present disclosure is a ciphertext compression scheme based on lattice-based post-quantum cryptography, and the calculation formula of the corresponding compression function where x is the ciphertext to be compressed input to the compression circuit, q is a first preset constant, the 2 d* is the first shift number of bits, d is a value corresponding to the security level of the ciphertext. Generally, d has five possible values, which are 1, 4, 5, 10, and 11 respectively; the compression principle of the compression function is to be able to discard some low-order bits in the ciphertext that have little impact on the correct probability of decryption, thereby reducing the size of the ciphertext and realizing the compression of the ciphertext.
[0053] As Figure 1As shown in the figure, in order to implement the above compression function, the compression circuit provided by the present disclosure includes: a first multiplier 101 for multiplying the input ciphertext x by a first preset constant q to obtain a first multiplication result q·x; a first shifter 102 connected to the first multiplier 101 for shifting the multiplication result q·x output by the first multiplier 101 to the right by a first shift number d* to obtain a first shift result q·x / 2 d* ; a first adder 103 connected to the first shifter 102 for rounding the first shift result q·x / 2 d* output by the first shifter 102 to obtain a rounded result It should be noted here that the first preset constant q, the first shift number d*, and another input value of the first adder 103 can be obtained from a register.
[0054] In a possible implementation, z′ mod + 2 d refers to the positive modulus operation between z′ and 2 d , where z′ is the dividend and 2 d is the divisor. If z′ < 2 d , then z′ is output; otherwise, z′ - 2 d is output. Therefore, a subtractor 104 and a comparator 105 can be used to implement this positive modulus operation. The subtractor 104 is connected to the first adder 103 for subtracting 2 d from the rounded result z′ output by the first adder 103 to obtain a subtraction result; the comparator 105 is connected to the subtractor 104 for comparing the subtraction result w = z′ - 2 d output by the subtractor 104 with 0. When the subtraction result w is less than 0, the rounded result z′ is output; when the subtraction result is greater than or equal to 0, the subtraction result z′ - 2 d is output. It should be noted here that the input value d in this subtractor can be obtained from a register.
[0055] This embodiment can implement the ciphertext compression of lattice-based post-quantum cryptography through a first multiplier, a first shifter, a first adder, a subtractor, and a comparator. Without using a divider, it can avoid the problems of high computational complexity and excessive consumption of hardware resources caused by the inability to replace the divider with shift operations, saving hardware resources; and since complex division operations are not required, the compression time is also reduced accordingly, improving the hardware implementation efficiency.
[0056] In a possible implementation, the first preset constant is 0.6151998, and the first shift number is 11 - d, where d is a value corresponding to the security level of the ciphertext.
[0057] In this embodiment, for the compression function the operation replaces the division operation 2 d / q, which results in a relatively high computational complexity of the ciphertext compression scheme. To solve this problem, take 2 11 / 3329≈0.6151998, and use these 7 decimal places for approximation substitution. By pre-storing the value 0.6151998, the division operation (2 d / q)·x is replaced with 0.6151998·x / 2 11-d , avoiding the division operation and replacing it with a multiplication operation that can use shift operations. First, use the first multiplier 101 to multiply the input ciphertext x by the first preset constant 0.6151998 to obtain a first multiplication result. Then, through the first shifter 102, shift the multiplication result 0.6151998·x to the right by the first shift number 11 - d, and 0.6151998·x / 2 can be obtained 11-d .
[0058] Of course, in other embodiments, if q* is not 3329 but other constant values that cannot replace the division operation through shift operations, at this time, in order to implement this compression scheme, the first preset constant and the first shift number can be adjusted accordingly based on this constant value, which will not be exemplified one by one here.
[0059] In a possible implementation manner, the first multiplier 101 is specifically configured to perform 15 right shift operations and 14 addition operations on the input ciphertext x according to the following formula to obtain a first multiplication result y:
[0060] y=(x>>21)+(x>>20)+(x>>19)+(x>>17)+(x>>16)+(x>>14)+(x>>13)+(x>>12)+(x>>11)+(x>>10)+(x>>8)+(x>>6)+(x>>5)+(x>>4)+(x>>1).
[0061] In this embodiment, Therefore, the first multiplier 101 multiplying the input ciphertext by the first preset constant can be implemented as the above 15 right shift operations and 14 addition operations, and 0.6151998·x can be obtained.
[0062] This embodiment realizes the first multiplier 101 through shift operations and addition operations, which can reduce the computational complexity and save hardware resources.
[0063] In a possible implementation, the first adder 103 is specifically configured to add the shifted result output by the shifter to 0.5, and use bits 32 to 21 of the addition result as the rounding result.
[0064] In this implementation, the bit width of the multiplication result 0.6151998·x output by the first multiplier 101 is 33 bits, and the bit width of the first shifted result after shifting 11 - d bits to the right is 33 bits. To round the first shifted result, we can first calculate z = y′+0000_0000_0000_1000_0000_0000_0000_0000_0 (i.e., z = y′+0.5), and then take bits [32:21] of the addition result to obtain the rounding result z′ = z[32:21].
[0065] In a possible implementation, Figure 2 FIG. shows a schematic structural diagram of a decompression circuit in a ciphertext compression and decompression circuit provided by an embodiment of the present disclosure, as Figure 2 shown, corresponding to the above compression circuit, the decompression circuit includes:
[0066] A second multiplier 201, configured to multiply the input compressed ciphertext by a second preset constant to obtain a second multiplication result, where the second preset constant corresponds to the first preset constant;
[0067] A second shifter 202, connected to the second multiplier, configured to shift the second multiplication result output by the second multiplier to the left by a second shift number of bits to obtain a second shifted result, where the second shift number of bits corresponds to the first shift number of bits;
[0068] A second adder 203, connected to the second shifter, configured to round the second shifted result output by the second shifter to obtain the decompressed ciphertext.
[0069] In this implementation, for the calculation formula of the compression function The calculation formula of its corresponding decompression function where X is the compressed ciphertext to be decompressed input to this decompression circuit, q* is the second preset constant, corresponding to the first preset constant q during compression, and d is the second shift number of bits.
[0070] To implement the above decompression function, as Figure 2 shown, the decompression circuit 20 includes: a second multiplier 201, a second shifter 202, and a second adder 203.
[0071] Among them, the second multiplier 201 multiplies the input compressed ciphertext X by the second preset constant q*, obtaining a second multiplication result X·q*. The second shifter shifts the second multiplication result X·q* output by the second multiplier to the left by a second shift number of bits d, obtaining a second shift result q* / 2 d ·X; the second adder rounds the second shift result q* / 2 d ·X, and the decompressed ciphertext obtained is
[0072] In a possible implementation manner, when the first preset constant is 0.6151998, the second preset constant is 3329. Of course, if the first preset constant used in the compression circuit is other constant values, the corresponding other constant values are used in the decompression circuit.
[0073] In a possible implementation manner, since 3329 = 2 11 + 2 10 + 2 8 + 2 0 , so the second multiplier is specifically used to perform 4 left shift operations and 3 addition operations on the input compressed ciphertext X according to the following formula to obtain a second multiplication result Y: Y=(X << 11)+(X << 10)+(X << 8)+(X << 0), that is, 3329·X can be obtained. Implementing the second multiplier through shift operations and addition operations can reduce the computational complexity and save hardware resources.
[0074] In a possible implementation manner, the second adder is used to round the second shift result output by the second shifter. Specifically, it means adding 0.5 to the second shift result output by the second shifter, and the 11th to 0th bits of the addition result are the decompressed ciphertext.
[0075] In this implementation manner, the bit width of the second multiplication result 3329·x output by the second multiplier is 22 bits, and the bit width of the second shift result Y' after shifting d bits to the left is 22 bits. In order to round the second shift result, we can first calculate W = Y'+0000_0000_0000_1000_0000_0000_0000_0000_0 (that is, W = Y'+0.5), and then take the 11th to 0th bits of the addition result, and the decompressed ciphertext obtained is: W' = W[11:0].[[]]
[0076] Here, taking the implementation of the ciphertext compression module of lattice-based post-quantum cryptography as an example, the calculation formula of the traditional compression function Since q = 3329 = 2 11 + 2 10 + 2 8 + 2 0, therefore, it is impossible to replace the division operation with a shift operation 2 d / q; and the present disclosure takes 2 11 / 3329≈0.6151998, uses these 7 decimal places for approximation and replacement, and by pre-storing the value 0.6151998, replaces the division operation (2 d / q)·x with 0.6151998·x / 2 11-d , the calculation formula of the compression function of the present disclosure is: can be implemented by Figure 1 the first multiplier 101, the first shifter 102, the first adder 103, the subtractor 104 and the comparator 105 shown in the following. Table 1 below shows the comparison table of the hardware synthesis results of the traditional algorithm and the optimized algorithm of the ciphertext compression:
[0077]
[0078] Table 1
[0079] As can be seen from Table 1, when prepared using the same process UMC55 (a 55-nanometer process technology), at the same frequency of 100.00 MHZ, the hardware occupied area of the traditional algorithm is equivalent to the area of 221.25 NAND gates, and the hardware occupied area of the optimized algorithm of the present disclosure is equivalent to the area of 171.00 NAND gates. The hardware area is saved by 61.3%. Moreover, since the present disclosure does not need to perform complex division operations, the running time is also optimized compared with the traditional method, and it has better hardware implementation efficiency and lower hardware resource consumption.
[0080] The present disclosure also provides a method for decompressing ciphertext compression, Figure 3 shows a schematic flowchart of a method for decompressing ciphertext compression provided by an embodiment of the present disclosure. The method includes the following steps:
[0081] In step S301, multiply the input ciphertext by a first preset constant to obtain a first multiplication result;
[0082] In step S302, shift the first multiplication result to the right by a first shift number of bits to obtain a first shift result;
[0083] In step S303, round the first shift result output by the first shifter to obtain a rounded result;
[0084] In step S304, subtract 2 d from the rounded result to obtain a subtraction result, where d is a value corresponding to the security level of the input ciphertext;
[0085] In step S305, compare the subtraction result with 0;
[0086] In step S306, when the subtraction result is less than 0, the rounded result is output; when the subtraction result is greater than or equal to 0, the subtraction result is output.
[0087] In a possible implementation manner, the ciphertext compression provided by the present disclosure is a ciphertext compression scheme for lattice-based post-quantum cryptography, and the calculation formula of the corresponding compression function where x is the ciphertext to be compressed input to the compression circuit, q is a first preset constant, and the 2 d* is the first shift number of bits, d is a value corresponding to the security level of the ciphertext. Generally, d has five possible values, which are 1, 4, 5, 10, and 11 respectively; the compression principle of the compression function is to be able to discard some low-order bits in the ciphertext that have little impact on the correct probability of decryption, thereby reducing the size of the ciphertext and achieving compression of the ciphertext.
[0088] In a possible implementation manner, in order to implement the above compression function, the input ciphertext x can be multiplied by the first preset constant q to obtain a first multiplication result q·x; the first multiplication result q·x is right-shifted by the first shift number of bits d*, to obtain a first shift result q·x / 2 d* ; then the first shift result q·x / 2 d* is rounded to obtain a rounded result
[0089] In a possible implementation manner, z′ mod + 2 d refers to the positive modulo operation between z′ and 2 d , z′ is the dividend, and 2 d is the divisor. If z′ < 2 d , then z′ is output; otherwise, z′ - 2 d is output. Therefore, the rounded result z′ can be first subtracted by 2 d to obtain a subtraction result; then compare the subtraction result w = z′ - 2 d output by the subtractor 104 with 0. When the subtraction result w is less than 0, the rounded result z′ is output; when the subtraction result is greater than or equal to 0, the subtraction result z′ - 2 d is output.
[0090] In this implementation manner, the ciphertext compression for lattice-based post-quantum cryptography can be realized through operations such as multiplication, shifting, addition, and subtraction. The division operation is not required, which can avoid the problems of high computational complexity and excessive consumption of hardware resources caused by the inability to replace the divider with a shift operation, and saves hardware resources.
[0091] In a possible implementation, the first preset constant is 0.6151998, and the first shift number is 11 - d.
[0092] In this implementation, for the existing compression function Since q* = 3329 = 2 11 + 2 10 + 2 8 + 2 0 , thus, it is impossible to replace the division operation 2 d / q with a shift operation, which results in a relatively high computational complexity of the ciphertext compression scheme. To solve this problem, take 2 11 / 3329 ≈ 0.6151998, and use these 7 decimal places for approximation and replacement. By pre - storing the value 0.6151998, replace the division operation (2 d / q)·x with 0.6151998·x / 2 11-d . Avoid the division operation and replace it with a multiplication operation that can use shift operations. First, multiply the input ciphertext x by the first preset constant 0.6151998 to obtain the first multiplication result. Then, shift the first multiplication result 0.6151998·x to the right by the first shift number 11 - d, and 0.6151998·x / 2 11-d can be obtained.
[0093] Of course, in other implementations, if q* is not 3329 but other constant values that cannot replace the division operation with a shift operation, at this time, to implement this compression scheme, the first preset constant and the first shift number can be adjusted accordingly based on this constant value, and no detailed examples will be given here.
[0094] In a possible implementation, the step of multiplying the input ciphertext by the first preset constant to obtain the first multiplication result includes:
[0095] Perform 15 right - shift operations and 14 addition operations on the input ciphertext x according to the following formula to obtain the first multiplication result y:
[0096] y=(x >> 21)+(x >> 20)+(x >> 19)+(x >> 17)+(x >> 16)+(x >> 14)+(x >> 13)+(x >> 12)+(x >> 11)+(x >> 10)+(x >> 8)+(x >> 6)+(x >> 5)+(x >> 4)+(x >> 1).
[0097] In this implementation, Therefore, the first multiplier 101 can multiply the input ciphertext by the first preset constant by performing the above 15 right shifts and 14 additions, and thus obtain 0.6151998·x.
[0098] In this embodiment, the multiplication operation is implemented by shift operations and addition operations, which can reduce the computational complexity and save hardware resources.
[0099] In a possible implementation, rounding the first shift result output by the first shifter to obtain a rounded result includes:
[0100] Adding the first shift result to 0.5, and taking the 32nd to 21st bits of the addition result as the rounded result.
[0101] In this embodiment, the bit width of the first multiplication result 0.6151998·x is 33 bits, and the bit width of the first shift result after shifting right by 11 - d is 33 bits. To round the first shift result, z = y′ + 0000_0000_0000_1000_0000_0000_0000_0000_0 (i.e., z = y′ + 0.5) can be calculated first, and then the [32:21] bits of the addition result are taken to obtain the rounded result z′ = z[32:21].
[0102] In a possible implementation, corresponding to the above compression method, the decompression method includes:
[0103] Multiplying the input compressed ciphertext by a second preset constant to obtain a second multiplication result, where the second preset constant corresponds to the first preset constant;
[0104] Shifting the second multiplication result to the left by a second shift number d to obtain a second shift result;
[0105] Rounding the second shift result to obtain the decompressed ciphertext.
[0106] In this embodiment, for the calculation formula of the above compression function The calculation formula of its corresponding decompression function where X is the compressed ciphertext to be decompressed input to the decompression circuit, q* is the second preset constant corresponding to the first preset constant q during compression, and d is the second shift number.
[0107] In this embodiment, the input compressed ciphertext X can be multiplied by the second preset constant q* to obtain a second multiplication result X·q*, and the second multiplication result X·q* is shifted to the left by the second shift number d to obtain a second shift result q* / 2d ·X; then take the second shifted result q* / 2 d ·Round X to get the decompressed ciphertext as
[0108] In a possible implementation, when the first preset constant is 0.6151998, the second preset constant is 3329. Of course, if the first preset constant used in the compression circuit is other constant values, then the corresponding other constant values are used in the decompression circuit.
[0109] In a possible implementation, since 3329 = 2 11 + 2 10 + 2 8 + 2 0 , so the input compressed ciphertext X can be left-shifted 4 times and 3 addition operations can be performed according to the following formula to obtain the second multiplication result Y: Y=(X << 11)+(X << 10)+(X << 8)+(X << 0), and then 3329·X can be obtained. Implementing the second multiplier through shift operations and addition operations can reduce the computational complexity and save hardware resources.
[0110] In a possible implementation, rounding the second shifted result output by the second shifter includes: adding the second shifted result to 0.5, and taking the 11th to 0th bits of the added result as the decompressed ciphertext.
[0111] In this implementation, the bit width of the second multiplication result 3329·x output by the second multiplier is 22 bits, and the bit width of the second shifted result Y' after being left-shifted d bits is 22 bits. In order to round the second shifted result, we can first calculate W = Y'+0000_0000_0000_1000_0000_0000_0000_0000_0 (i.e., W = Y'+0.5), and then take the 11th to 0th bits of the added result to get the decompressed ciphertext as: W' = W[11:0].
[0112] The present disclosure also discloses an electronic device, Figure 4 showing a structural block diagram of an electronic device according to an embodiment of the present disclosure.
[0113] As Figure 4 shown, the electronic device 400 includes a memory 401 and a processor 402, wherein the memory 401 is used to store one or more computer instructions, and wherein the one or more computer instructions are executed by the processor 402 to implement the method according to the embodiment of the present disclosure.
[0114] Embodiments of the present disclosure also provide a chip, which includes the above-mentioned ciphertext compression and decompression circuit. The chip can be any chip that can implement the above-mentioned ciphertext compression and decompression method, and can be implemented as part or all of the chip through software, hardware, or a combination of both.
[0115] Figure 5 The structural schematic diagram of a computer system suitable for implementing the method of the embodiments of the present disclosure is shown.
[0116] As Figure 5 shown, the computer system 500 includes a processing unit 501, which can perform various processes in the above embodiments according to the program stored in the read-only memory (ROM) 502 or the program loaded from the storage section 508 into the random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the computer system 500 are also stored. The processing unit 501, the ROM 502, and the RAM 503 are connected to each other through a bus 504. The input / output (I / O) interface 505 is also connected to the bus 504.
[0117] The following components are connected to the I / O interface 505: an input section 506 including a keyboard, a mouse, etc.; an output section 507 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, a modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the I / O interface 505 as needed. A removable medium 511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 510 as needed, so that the computer program read from it can be installed into the storage section 508 as needed. Among them, the processing unit 501 can be implemented as a processing unit such as a CPU, a GPU, a TPU, an FPGA, an NPU, etc.
[0118] Specifically, according to the embodiments of the present disclosure, the above-described method can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product, which includes computer instructions that, when executed by a processor, implement the method steps described above. In such an embodiment, the computer program product can be downloaded and installed from the network through the communication section 509, and / or installed from the removable medium 511.
[0119] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0120] The units or modules involved in the embodiments described in the present disclosure can be implemented in software or by programmable hardware. The described units or modules can also be provided in a processor, and the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.
[0121] On the other hand, the present disclosure also provides a computer-readable storage medium, which may be the computer-readable storage medium included in the electronic device or computer system in the above embodiments; or it may exist separately and be a computer-readable storage medium not assembled into the device. The computer-readable storage medium stores one or more programs, and the programs are used by one or more processors to execute the methods described in the present disclosure.
[0122] The above description is only for the preferred embodiments of the present disclosure and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in the present disclosure.
Claims
1. A circuit for encrypting and decrypting compressed text, characterized in that Comprising a compression circuit, the compression circuit includes: A first multiplier for multiplying the input ciphertext by a first preset constant to obtain a first multiplication result; A first shifter connected to the first multiplier for shifting the first multiplication result output by the first multiplier to the right by a first shift number of bits to obtain a first shift result; A first adder connected to the first shifter for rounding the first shift result output by the first shifter to obtain a rounded result; A subtractor, connected to the first adder, for subtracting 2 from the rounded result output by the first adder d , to obtain a subtraction result, where d is a value corresponding to the security level of the ciphertext; A comparator connected to the subtractor for comparing the subtraction result output by the subtractor with 0. When the subtraction result is less than 0, the rounded result is output; when the subtraction result is greater than or equal to 0, the subtraction result is output.
2. The circuit according to claim 1, wherein The first preset constant is 0.6151998, and the first shift number of bits is 11 - d.
3. The circuit according to claim 2, wherein The first multiplier is specifically configured to perform 15 right shift operations and 14 addition operations on the input ciphertext x according to the following formula to obtain a first multiplication result y: y = (x >> 21) + (x >> 20) + (x >> 19) + (x >> 17) + (x >> 16) + (x >> 14) + (x >> 13) + (x >> 12) + (x >> 11) + (x >> 10) + (x >> 8) + (x >> 6) + (x >> 5) + (x >> 4) + (x >> 1).
4. The circuit according to claim 2, wherein The first adder is specifically configured to add 0.5 to the first shift result output by the first shifter and output the 32nd to 21st bits of the addition result as the rounded result.
5. The circuit according to claim 1, characterized in that, Further comprising a decompression circuit, the decompression circuit includes: A second multiplier for multiplying the input compressed ciphertext by a second preset constant to obtain a second multiplication result, and the second preset constant corresponds to the first preset constant; A second shifter connected to the second multiplier for shifting the second multiplication result output by the second multiplier to the left by a second shift number of bits d to obtain a second shift result; A second adder connected to the second shifter for rounding the second shift result output by the second shifter to obtain the decompressed ciphertext.
6. The circuit according to claim 5, wherein When the first preset constant is 0.6151998, the second preset constant is 3329.
7. A method for encrypting and decrypting compressed text, characterized in that, The method is implemented by the ciphertext compression and decompression circuit according to claim 1, and the method includes: Multiplying the input ciphertext by a first preset constant to obtain a first multiplication result; Shifting the first multiplication result to the right by a first shift number of bits to obtain a first shift result; Rounding the first shift result output by the first shifter to obtain a rounded result; Subtract 2 from the rounding result d , to obtain a subtraction result, where d is a value corresponding to the security level of the input ciphertext; Comparing the subtraction result with 0; When the subtraction result is less than 0, the rounded result is output; when the subtraction result is greater than or equal to 0, the subtraction result is output.
8. The method according to claim 7, wherein The first preset constant is 0.6151998, and the first shift number of bits is 11 - d.
9. The method according to claim 8, wherein Multiplying the input ciphertext by a first preset constant to obtain a first multiplication result includes: Performing 15 right shift operations and 14 addition operations on the input ciphertext x according to the following formula to obtain a first multiplication result y: y = (x >> 21) + (x >> 20) + (x >> 19) + (x >> 17) + (x >> 16) + (x >> 14) + (x >> 13) + (x >> 12) + (x >> 11) + (x >> 10) + (x >> 8) + (x >> 6) + (x >> 5) + (x >> 4) + (x >> 1).
10. The method according to claim 7, characterized in that Rounding the first shift result output by the first shifter to obtain a rounded result includes: Adding 0.5 to the first shift result, and taking the 32nd to 21st bits of the addition result as the rounded result.
11. The method according to claim 7, characterized in that, The method further includes: Multiplying the input compressed ciphertext by a second preset constant to obtain a second multiplication result, where the second preset constant corresponds to the first preset constant; Shifting the second multiplication result to the left by a second shift number d to obtain a second shift result; Rounding the second shift result to obtain a decompressed ciphertext.
12. The method according to claim 11, wherein when the first preset constant is 0.6151998, the second preset constant is 3329.
13. An electronic device, characterized in that, Including a memory and a processor, the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the method according to any one of claims 7 to 12.
14. A chip, characterized in that, The chip is used to implement the method according to any one of claims 7 to 12.