SM2 digital signature generation system and method suitable for security chip

By designing an SM2 digital signature generation system on a security chip and utilizing a random number generator and modular architecture, we can implement discontinuous and continuous SM2 digital signature generation, solving the problems of low efficiency and complex interactions in existing systems and improving generation efficiency and performance.

CN120602093APending Publication Date: 2025-09-05GUANGZHOU XINYUNYUAN MICROELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510684824.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The existing SM2 digital signature generation system is inefficient and has complex key exchange, which is limited by CPU processing speed and complex interaction design.

Method used

An SM2 digital signature generation system suitable for security chips is designed. It includes a random number generator, a digital signature generation top-level module, a register configuration module, a private and public key generation module, a hash module, a dot product top-level module, and a DMA module. Through the AMBA bus interface and FIFO storage, discontinuous and continuous digital signature generation modes are implemented to avoid CPU-assisted operations.

Benefits of technology

It improves the efficiency of SM2 digital signature generation, avoids CPU processing speed limitations, simplifies the key exchange process, and improves system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602093A_ABST
    Figure CN120602093A_ABST
Patent Text Reader

Abstract

The invention relates to digital signature generation, in particular to an SM2 digital signature generation system and method suitable for a security chip, a digital signature generation control module controls the overall process of SM2 digital signature generation, controls a private key and public key generation module to read random numbers from a random number generator, and calls a Hash module and a point multiplication top layer module. Meanwhile, other data calculations except the Hash calculation and the finite field point multiplication calculation are completed; the private key and public key generation module reads the random number from the random number generator, performs private key detection, and generates a local private key and a local public key according to a private key detection result; the Hash module is used for carrying out Hash calculation; the point multiplication top layer module is used for carrying out finite field point multiplication calculation through a finite field point multiplication module; the DMA module is used for moving a plaintext sequence in the on-chip SRAM into the hash module; according to the technical scheme provided by the invention, the defect of relatively low SM2 digital signature generation efficiency in the prior art can be effectively overcome.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to digital signature generation, and in particular to an SM2 digital signature generation system and method applicable to a security chip. Background Art

[0002] SM2 elliptic curve digital signature generation exploits the difficulty of solving the discrete logarithm problem on elliptic curves in finite fields to generate digital signatures. Due to the complexity of SM2 digital signature generation, traditional SM2 digital signature generation systems are often built based on CPU cores. This has the advantage of being flexible and convenient to build, but has the following disadvantages:

[0003] 1) Limited by the CPU processing speed, the efficiency of completing an SM2 digital signature generation is low, often requiring millions of clock cycles;

[0004] 2) The construction of SM2 key exchange is based on the cooperation of the CPU, and the interaction design between it and the CPU is relatively complex. Summary of the Invention

[0005] (1) Technical problems solved

[0006] In view of the above-mentioned shortcomings of the prior art, the present invention provides an SM2 digital signature generation system and method suitable for a security chip, which can effectively overcome the defect of low efficiency of SM2 digital signature generation in the prior art.

[0007] (2) Technical solution

[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions:

[0009] An SM2 digital signature generation system suitable for a security chip includes a random number generator and a digital signature generation top-level module. The digital signature generation top-level module includes a register configuration module, a digital signature generation control module, a private key and public key generation module, a hash module, a point multiplication top-level module, and a DMA module.

[0010] Random number generator, generates random numbers according to the configuration through the AMBA bus interface and stores the random numbers in the embedded FIFO;

[0011] Register configuration module, which completes register configuration and interrupt register enable / clear through the AMBA bus interface;

[0012] The digital signature generation control module controls the overall process of SM2 digital signature generation, controls the private key and public key generation modules to read random numbers from the random number generator, and calls the hash module and the point multiplication top-level module, while completing other data calculations except hash calculations and finite field point multiplication calculations;

[0013] The private key and public key generation module reads random numbers from the random number generator, performs private key detection, and generates the party's private key and public key based on the private key detection results;

[0014] Hash module, performs hash calculation;

[0015] The top-level module of point product performs finite field point product calculation through the finite field point product module;

[0016] The DMA module moves the plaintext sequence in the on-chip SRAM to the hash module to complete the digital signature generation operation for the plaintext sequence.

[0017] Preferably, the private key and public key generation module reads a random number from a random number generator, performs a private key detection, and generates the party's private key and the party's public key according to the private key detection result, including:

[0018] The private key and public key generation module reads a random number from the random number generator and performs a private key test. If the private key test passes, the random number is used as the party's private key. Otherwise, a new random number is read from the random number generator and private key test is performed again until the private key test passes.

[0019] After the party's private key is generated, the private key and public key generation module calls the point multiplication top-level module to perform finite field point multiplication calculation on the party's private key and the base point on the elliptic curve to generate the party's public key.

[0020] A method for generating an SM2 digital signature for a security chip, in a discontinuous digital signature generation mode, comprises the following steps:

[0021] S11, power on, clock signal works;

[0022] S12, reset signal completes asynchronous reset and synchronous release;

[0023] S13, prepare the plaintext sequence M in the on-chip SRAM outside the IP, so that the DMA module can move it to the hash module later;

[0024] S14, respectively set the identity identification number ID of the user at end A through the configuration register ID_value_REG. A 、ID A The length of ENTL A Write to the corresponding location;

[0025] S15, starting the random number generator via the AMBA bus;

[0026] S16. Configure 1'b1 to register DATA_CONFIGED_REG[0] to start SM2 digital signature, and configure 1'b1 to register DATA_CONFIGED_REG[1] to indicate that a new private key-public key pair needs to be generated;

[0027] S17, the private key and public key generation module generates a private key d A [255:0], point multiplication top module generates public key P A (x A [255:0],y A [255:0]), and enter S18 and S111 at the same time;

[0028] The range of the private key is [1, n-2], the range of the public key is [1, n-1], and n is the P-256 elliptic curve parameter shared by end A and end B;

[0029] S18, hash module uses public key P A (x A [255:0],y A [255:0]) calculate Z A [255:0]:

[0030] Z A =H 256 (ENTL A ||ID A ||a||b||G x ||G y ||x A ||y A );

[0031] Among them, a, b, G x , G y The shared base point G in the P-256 elliptic curve is G=(G x [255:0],G y [255:0]), H 256 Indicates hash calculation, || indicates string concatenation;

[0032] S19, when the CPU polls the interrupt register INTERRUPT_REG[0]=1'b1, it means Z A [255:0] Calculation completed;

[0033] S110, configure the DMA module to move the plaintext sequence M in the on-chip SRAM to the hash module for hash operation, and then enter S113:

[0034] e=H 256 (ZA ||M);

[0035] Where, e is the hash compression result of the plaintext sequence M;

[0036] S111, a random number generator generates a random number k;

[0037] S112, the dot product top-level module calculates (x1, y1) = kG, where (x1, y1) is the dot multiplication result of kG;

[0038] S113, the digital signature generation control module calculates the R coordinate data r=(e+x1)mod(n) of the SM2 digital signature. If r=0 or r+k=n, the module returns to S111 to regenerate the random number k. Otherwise, the module enters S114.

[0039] S114, the digital signature generation control module and the dot product top-level module cooperate to calculate the S coordinate data of the SM2 digital signature If s=0, return to S111 to regenerate the random number k, otherwise go to S115;

[0040] S115. Write the calculated r and s into registers ECDSA_SIGN_R_REG[255:0] and ECDSA_SIGN_S_REG[255:0] respectively, and automatically set the interrupt register INTERRUPT_REG[1] to 1'b1. When the CPU polls the interrupt register INTERRUPT_REG[1] = 1'b1, read the registers ECDSA_SIGN_R_REG[255:0] and ECDSA_SIGN_S_REG[255:0] as the SM2 digital signature, and read the registers Q_SELF_X_REG[255:0] and Q_SELF_Y_REG[255:0] as the public key of the party.

[0041] S116. To facilitate the generation of the next SM2 digital signature, before the next SM2 digital signature is started, the interrupt registers involved are cleared by clearing the interrupt registers, and 2'b0 is written to the register DATA_CONFIGED_REG[1:0].

[0042] Preferably, the non-continuous digital signature generation mode requires that a corresponding private key-public key pair be newly generated for each plaintext sequence when generating the SM2 digital signature.

[0043] A method for generating an SM2 digital signature for a security chip, in a continuous digital signature generation mode, comprises the following steps:

[0044] S21, power on, clock signal works;

[0045] S22, reset signal completes asynchronous reset and synchronous release;

[0046] S23, executing the steps of the above-mentioned non-continuous digital signature generation mode;

[0047] S24. After the next plaintext sequence is prepared in the on-chip SRAM outside the IP, configure 1'b1 to register DATA_CONFIGED_REG[2] to start the continuous SM2 digital signature, and return to S23. At the same time, enter the steps S110 and S111 of the above-mentioned non-continuous digital signature generation mode until the SM2 digital signature generation of multiple plaintext sequences is completed.

[0048] Preferably, the continuous digital signature generation mode requires that multiple plaintext sequences share a set of private key-public key pairs when generating SM2 digital signatures to improve signature generation efficiency.

[0049] (3) Beneficial effects

[0050] Compared with the existing technology, the SM2 digital signature generation system and method for security chips provided by the present invention is a hardened design based on pure RTL and does not rely on CPU calculation assistance, so it is not limited by the CPU processing speed. Compared with traditional CPU-based implementation solutions, the efficiency of SM2 digital signature generation is greatly improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort.

[0052] Figure 1 Schematic diagram of the system of the present invention. DETAILED DESCRIPTION

[0053] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0054] An SM2 digital signature generation system suitable for security chips, such as Figure 1As shown, it includes a random number generator and a digital signature generation top-level module. The digital signature generation top-level module includes a register configuration module, a digital signature generation control module, a private key and public key generation module, a hash module, a point multiplication top-level module and a DMA module.

[0055] Random number generator, generates random numbers according to the configuration through the AMBA bus interface and stores the random numbers in the embedded FIFO;

[0056] Register configuration module, which completes register configuration and interrupt register enable / clear through the AMBA bus interface;

[0057] The digital signature generation control module controls the overall process of SM2 digital signature generation, controls the private key and public key generation modules to read random numbers from the random number generator, and calls the hash module and the point multiplication top-level module, while completing other data calculations except hash calculations and finite field point multiplication calculations;

[0058] The private key and public key generation module reads random numbers from the random number generator, performs private key detection, and generates the party's private key and public key based on the private key detection results;

[0059] Hash module, performs hash calculation;

[0060] The top-level module of point product performs finite field point product calculation through the finite field point product module;

[0061] The DMA module (by embedding a dedicated DMA in the IP to facilitate the integration of the IP and plug-and-play) moves the plaintext sequence in the on-chip SRAM to the hash module to complete the digital signature generation operation for the plaintext sequence.

[0062] The private key and public key generation module reads random numbers from the random number generator, performs private key detection, and generates the party's private key and public key based on the private key detection results, including:

[0063] The private key and public key generation module reads a random number from the random number generator and performs a private key test. If the private key test passes, the random number is used as the party's private key. Otherwise, a new random number is read from the random number generator and private key test is performed again until the private key test passes.

[0064] After the party's private key is generated, the private key and public key generation module calls the point multiplication top-level module to perform finite field point multiplication calculation on the party's private key and the base point on the elliptic curve to generate the party's public key.

[0065] In the technical solution of this application, the registers designed according to the AMBA bus interface (32-bit width) are shown in the following table:

[0066] Table 1 Register Q_SELF_X_REG Description

[0067]

[0068] Table 2 Register Q_SELF_Y_REG Description

[0069]

[0070] Table 3 Register ECDSA_SIGN_R_REG Description

[0071]

[0072] Table 4 Register ECDSA_SIGN_S_REG Description

[0073]

[0074] Table 5 Register ID_value_REG Description

[0075]

[0076] Table 6 Register INTERRUPT_REG Description

[0077]

[0078] Table 7 Register CLR_INTERRUPT_REG Description

[0079]

[0080] Table 8 Register DATA_CONFIGED_REG Description

[0081]

[0082] like Figure 1 As shown, the on-chip SRAM and on-chip CPU do not belong to the IP internal modules in the technical solution of this application. By hanging the on-chip SRAM and on-chip CPU on the bus in the form of an AMBA interface, and coordinating with the SM2 digital signature generation system suitable for security chips proposed in the technical solution of this application, a relatively complete on-chip system for SM2 digital signature generation is formed.

[0083] Based on the above-disclosed SM2 digital signature generation system applicable to security chips, the technical solution of this application further discloses an SM2 digital signature generation method applicable to security chips, which, in a discontinuous digital signature generation mode, includes the following steps:

[0084] S11, power on, clock signal works;

[0085] S12, reset signal completes asynchronous reset and synchronous release;

[0086] S13, prepare the plaintext sequence M in the on-chip SRAM outside the IP, so that the DMA module can move it to the hash module later;

[0087] S14, respectively set the identity identification number ID of the user at end A through the configuration register ID_value_REG. A 、ID A The length of ENTL A Write to the corresponding location;

[0088] S15, starting the random number generator via the AMBA bus;

[0089] S16. Configure 1'b1 to register DATA_CONFIGED_REG[0] to start SM2 digital signature, and configure 1'b1 to register DATA_CONFIGED_REG[1] to indicate that a new private key-public key pair needs to be generated;

[0090] S17, the private key and public key generation module generates a private key d A [255:0], point multiplication top module generates public key P A (x A [255:0],y A [255:0]), and enter S18 and S111 at the same time;

[0091] The range of the private key is [1, n-2], the range of the public key is [1, n-1], and n is the P-256 elliptic curve parameter shared by end A and end B;

[0092] S18, hash module uses public key P A (x A [255:0],y A [255:0]) calculate Z A [255:0]:

[0093] Z A =H 256 (ENTL A ||ID A ||a||b||G x ||G y ||x A ||y A );

[0094] Among them, a, b, G x , G y The shared base point G in the P-256 elliptic curve is G=(G x[255:0],G y [255:0]), H 256 Indicates hash calculation, || indicates string concatenation;

[0095] S19, when the CPU polls the interrupt register INTERRUPT_REG[0]=1'b1, it means Z A [255:0] Calculation completed;

[0096] S110, configure the DMA module to move the plaintext sequence M in the on-chip SRAM to the hash module for hash operation, and then enter S113:

[0097] e=H 256 (Z A ||M);

[0098] Where, e is the hash compression result of the plaintext sequence M;

[0099] S111, a random number generator generates a random number k;

[0100] S112, the dot product top-level module calculates (x1, y1) = kG, where (x1, y1) is the dot multiplication result of kG;

[0101] S113, the digital signature generation control module calculates the R coordinate data r=(e+x1)mod(n) of the SM2 digital signature. If r=0 or r+k=n, the module returns to S111 to regenerate the random number k. Otherwise, the module enters S114.

[0102] S114, the digital signature generation control module and the dot product top-level module cooperate to calculate the S coordinate data of the SM2 digital signature If s=0, return to S111 to regenerate the random number k, otherwise go to S115;

[0103] S115. Write the calculated r and s into registers ECDSA_SIGN_R_REG[255:0] and ECDSA_SIGN_S_REG[255:0] respectively, and automatically set the interrupt register INTERRUPT_REG[1] to 1'b1. When the CPU polls the interrupt register INTERRUPT_REG[1] = 1'b1, read the registers ECDSA_SIGN_R_REG[255:0] and ECDSA_SIGN_S_REG[255:0] as the SM2 digital signature, and read the registers Q_SELF_X_REG[255:0] and Q_SELF_Y_REG[255:0] as the public key of the party.

[0104] S116. To facilitate the generation of the next SM2 digital signature, before the next SM2 digital signature is started, the interrupt registers involved are cleared by clearing the interrupt registers, and 2'b0 is written to the register DATA_CONFIGED_REG[1:0].

[0105] In the technical solution of the present application, the non-continuous digital signature generation mode requires that a corresponding private key-public key pair be newly generated for each plaintext sequence when generating the SM2 digital signature.

[0106] Based on the above-disclosed SM2 digital signature generation system applicable to a security chip and the specific working process of the discontinuous digital signature generation mode, the technical solution of this application further discloses another SM2 digital signature generation method applicable to a security chip, which, in the continuous digital signature generation mode, includes the following steps:

[0107] S21, power on, clock signal works;

[0108] S22, reset signal completes asynchronous reset and synchronous release;

[0109] S23, executing the step of the non-continuous digital signature generation mode in claim 3;

[0110] S24. After the next plaintext sequence is prepared in the on-chip SRAM outside the IP, configure 1'b1 to register DATA_CONFIGED_REG[2] to start the continuous SM2 digital signature, and return to S23. At the same time, enter steps S110 and S111 of the non-continuous digital signature generation mode in claim 3 until the SM2 digital signature generation of multiple plaintext sequences is completed.

[0111] In the technical solution of this application, the continuous digital signature generation mode requires that multiple plaintext sequences share a set of private key-public key pairs when generating SM2 digital signatures to improve the efficiency of signature generation.

[0112] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. An SM2 digital signature generation system applicable to a security chip, characterized by: It includes a random number generator and a digital signature generation top-level module, wherein the digital signature generation top-level module includes a register configuration module, a digital signature generation control module, a private key and public key generation module, a hash module, a point multiplication top-level module and a DMA module; Random number generator, generates random numbers according to the configuration through the AMBA bus interface and stores the random numbers in the embedded FIFO; Register configuration module, which completes register configuration and interrupt register enable / clear through the AMBA bus interface; The digital signature generation control module controls the overall process of SM2 digital signature generation, controls the private key and public key generation modules to read random numbers from the random number generator, and calls the hash module and the point multiplication top-level module, while completing other data calculations except hash calculations and finite field point multiplication calculations; The private key and public key generation module reads random numbers from the random number generator, performs private key detection, and generates the party's private key and public key based on the private key detection results; Hash module, performs hash calculation; The top-level module of point product performs finite field point product calculation through the finite field point product module; The DMA module moves the plaintext sequence in the on-chip SRAM to the hash module to complete the digital signature generation operation for the plaintext sequence.

2. The SM2 digital signature generation system for a security chip according to claim 1, characterized in that: The private key and public key generation module reads random numbers from a random number generator, performs private key detection, and generates the party's private key and party's public key according to the private key detection result, including: The private key and public key generation module reads a random number from the random number generator and performs a private key test. If the private key test passes, the random number is used as the party's private key. Otherwise, a new random number is read from the random number generator and private key test is performed again until the private key test passes. After the party's private key is generated, the private key and public key generation module calls the point multiplication top-level module to perform finite field point multiplication calculation on the party's private key and the base point on the elliptic curve to generate the party's public key.

3. A method for generating an SM2 digital signature for a security chip, applied to the SM2 digital signature generation system for a security chip according to claim 1, characterized in that: In the non-continuous digital signature generation mode, the following steps are included: S11, power on, clock signal works; S12, reset signal completes asynchronous reset and synchronous release; S13, prepare the plaintext sequence M in the on-chip SRAM outside the IP, so that the DMA module can move it to the hash module later; S14, respectively set the identity identification number ID of the user at end A through the configuration register ID_value_REG. A 、ID A The length of ENTL A Write to the corresponding location; S15, starting the random number generator via the AMBA bus; S16. Configure 1'b1 to register DATA_CONFIGED_REG[0] to start SM2 digital signature, and configure 1'b1 to register DATA_CONFIGED_REG[1] to indicate that a new private key-public key pair needs to be generated; S17, the private key and public key generation module generates a private key d A [255:0], point multiplication top module generates public key P A (x A [255:0],y A [255:0]), and enter S18 and S111 at the same time; The range of the private key is [1, n-2], the range of the public key is [1, n-1], and n is the P-256 elliptic curve parameter shared by end A and end B; S18, hash module uses public key P A (x A [255:0],y A [255:0]) calculate Z A [255:0]: Z A H. H 256 (ENTL A ||ID A ||a||b||G x ||G y ||x A ||y A )4 Among them, a, b, G x , G y The shared base point G in the P-256 elliptic curve is G=(G x [255:0],G y [255:0]), H 256 Indicates hash calculation, || indicates string concatenation; S19, when the CPU polls the interrupt register INTERRUPT_REG[0]=1'b1, it means Z A [255:0] Calculation completed; S110, configure the DMA module to move the plaintext sequence M in the on-chip SRAM to the hash module for hash operation, and then enter S113: e=H 256 (Z A ||M); Where, e is the hash compression result of the plaintext sequence M; S111, a random number generator generates a random number k; S112, the dot product top-level module calculates (x1, y1) = kG, where (x1, y1) is the dot multiplication result of kG; S113, the digital signature generation control module calculates the R coordinate data r=(e+x1)mod(n) of the SM2 digital signature. If r=0 or r+k=n, the module returns to S111 to regenerate the random number k. Otherwise, the module enters S114. S114, the digital signature generation control module and the dot product top-level module cooperate to calculate the S coordinate data of the SM2 digital signature If s=0, return to S111 to regenerate the random number k, otherwise go to S115; S115. Write the calculated r and s into registers ECDSA_SIGN_R_REG[255:0] and ECDSA_SIGN_S_REG[255:0] respectively, and automatically set the interrupt register INTERRUPT_REG[1] to 1'b1. When the CPU polls the interrupt register INTERRUPT_REG[1] = 1'b1, read the registers ECDSA_SIGN_R_REG[255:0] and ECDSA_SIGN_S_REG[255:0] as the SM2 digital signature, and read the registers Q_SELF_X_REG[255:0] and Q_SELF_Y_REG[255:0] as the public key of the party. S116. To facilitate the generation of the next SM2 digital signature, before the next SM2 digital signature is started, the interrupt registers involved are cleared by clearing the interrupt registers, and 2'b0 is written to the register DATA_CONFIGED_REG[1:0].

4. The method for generating an SM2 digital signature for a security chip according to claim 3, wherein: The non-continuous digital signature generation mode requires that a corresponding private key-public key pair be newly generated for each plaintext sequence when generating the SM2 digital signature.

5. A method for generating an SM2 digital signature for a security chip, applied to the SM2 digital signature generation system for a security chip according to claim 1, characterized in that: In the continuous digital signature generation mode, the following steps are included: S21, power on, clock signal works; S22, reset signal completes asynchronous reset and synchronous release; S23, executing the step of the non-continuous digital signature generation mode in claim 3; S24. After the next plaintext sequence is prepared in the on-chip SRAM outside the IP, configure 1'b1 to register DATA_CONFIGED_REG[2] to start the continuous SM2 digital signature, and return to S23. At the same time, enter steps S110 and S111 of the non-continuous digital signature generation mode in claim 3 until the SM2 digital signature generation of multiple plaintext sequences is completed.

6. The method for generating an SM2 digital signature for a security chip according to claim 5, wherein: The continuous digital signature generation mode requires that multiple plaintext sequences share a set of private key-public key pairs when generating SM2 digital signatures to improve signature generation efficiency.