Method, device and equipment for executing cryptographic algorithm

By optimizing the SM2 algorithm through the RISC-V architecture and utilizing instruction set extensions and memory access optimization, the problem of low execution efficiency of the SM2 algorithm is solved, and efficient cryptographic operations with hardware acceleration and low power consumption are achieved.

CN120611397APending Publication Date: 2025-09-09SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510724854.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

The SM2 algorithm has problems in software implementation, such as high complexity of point multiplication operation, time-consuming modular inverse operation, and frequent memory access, which leads to low execution efficiency.

Method used

By combining the RISC-V architecture with the SM2 cryptographic algorithm, and through instruction set extension, memory access optimization, and compiler and toolchain support, we design elliptic curve point addition, point multiplication, modular inversion and other instructions to simplify the software implementation process and improve computing efficiency.

Benefits of technology

It reduces the execution complexity of cryptographic algorithms and improves the execution efficiency of SM2 algorithms. It is suitable for hardware acceleration and low-power scenarios in the field of information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120611397A_ABST
    Figure CN120611397A_ABST
Patent Text Reader

Abstract

The invention discloses a cryptographic algorithm execution method, device and equipment, and relates to the technical field of information security, and the method comprises the steps: obtaining target data and a target control signal; a corresponding target instruction sequence is obtained from an instruction set based on the target control signal, the instruction set is composed of a calling relation and execution logic among multiple calculation levels, the instruction set is composed of multiple instruction sequences, and each instruction sequence is used for executing a cryptographic algorithm of one control signal; obtaining a first instruction in the target instruction sequence; analyzing the first instruction to obtain a to-be-executed program; and executing corresponding processing logic on the target data based on the program to obtain a target result. According to the cryptographic algorithm execution structure based on the acquisition instruction, the analysis instruction and the execution instruction, the instruction sets of the multiple calculation levels are called to execute the cryptographic algorithm, hardware acceleration can be achieved, the software implementation process can be simplified, and therefore the cryptographic algorithm execution complexity is reduced, and the cryptographic algorithm execution efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to methods, devices, and equipment for executing cryptographic algorithms. Background Art

[0002] In today's digital age, information security is of paramount importance. As one of the core technologies for ensuring information security, the performance and efficiency of cryptographic algorithms directly affect the confidentiality, integrity, and availability of information.

[0003] The SM2 algorithm, an elliptic curve public-key cryptography algorithm, operates on core operations including elliptic curve point multiplication (scalar multiplication), modular inversion, and hash calculation. However, in software implementation, the SM2 algorithm suffers from high point multiplication complexity, time-consuming modular inversion, and frequent memory access. Consequently, the current SM2 algorithm suffers from low execution efficiency and urgently needs optimization. Summary of the Invention

[0004] The present application provides a method, apparatus and device for executing a cryptographic algorithm to at least solve the problem of low execution efficiency of cryptographic algorithms in related technologies.

[0005] This application provides a method for executing a cryptographic algorithm, including:

[0006] Obtaining target data and a target control signal, wherein the target control signal is used to trigger execution of a corresponding target cryptographic algorithm;

[0007] Obtaining a corresponding target instruction sequence from an instruction set based on a target control signal, wherein the instruction set is composed of call relationships and execution logic between multiple computing levels, and the instruction set is composed of multiple instruction sequences, each instruction sequence being used to implement a cryptographic algorithm for executing a control signal;

[0008] Obtaining a first instruction in a target instruction sequence;

[0009] Parsing the first instruction to obtain a program to be executed;

[0010] Based on the program, the corresponding processing logic is executed on the target data to obtain the target result.

[0011] The present application also provides a cryptographic algorithm execution device, comprising:

[0012] A first acquisition module is used to acquire target data and a target control signal, wherein the target control signal is used to trigger the execution of a corresponding target cryptographic algorithm;

[0013] a second acquisition module, configured to acquire a corresponding target instruction sequence from an instruction set based on the target control signal, wherein the instruction set is composed of call relationships and execution logic between multiple computing levels, and the instruction set is composed of multiple instruction sequences, each instruction sequence being used to implement a cryptographic algorithm for executing a control signal;

[0014] A third acquisition module, configured to acquire a first instruction in a target instruction sequence;

[0015] A parsing module, configured to parse the first instruction to obtain a program to be executed;

[0016] The execution module is used to execute corresponding processing logic on the target data based on the program to obtain the target result.

[0017] The present application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of the execution method of any of the above-mentioned cryptographic algorithms when executing the computer program.

[0018] Through this application, due to the cryptographic algorithm execution structure based on obtaining instructions, parsing instructions, and executing instructions, calling instruction sets of multiple computing levels to execute cryptographic algorithms, it is possible to achieve hardware acceleration and simplify the software implementation process, thereby reducing the complexity of cryptographic algorithm execution and improving the efficiency of cryptographic algorithm execution. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0020] Figure 1 A flowchart of a method for executing a cryptographic algorithm provided in an embodiment of the present application;

[0021] Figure 2 A flowchart of another method for executing a cryptographic algorithm provided in an embodiment of the present application;

[0022] Figure 3 A flowchart of another method for executing a cryptographic algorithm provided in an embodiment of the present application;

[0023] Figure 4 A schematic diagram of the functional modules of the cryptographic algorithm instruction set provided in an embodiment of the present application;

[0024] Figure 5 A system structure diagram of a method for executing a cryptographic algorithm provided in an embodiment of the present application;

[0025] Figure 6 A flowchart of another method for executing a cryptographic algorithm provided in an embodiment of the present application;

[0026] Figure 7 A structural block diagram of a cryptographic algorithm execution device provided in an embodiment of the present application;

[0027] Figure 8 A schematic diagram of the hardware structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0028] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0029] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.

[0030] In order to enable those skilled in the art to better understand the present application, the present application is further described in detail below with reference to the accompanying drawings and specific implementation methods.

[0031] The fifth-generation Reduced Instruction Set Computing-V (RISC-V) is an open-source instruction set architecture that supports third-party extensions and features a highly flexible modular design. Developers can choose appropriate extensions based on their application needs and customize the processor. Whether in embedded systems or high-performance computing, there's a suitable RISC-V configuration. The RISC-V instruction set boasts a simple design, using fixed-length instructions and a load-store architecture, facilitating efficient hardware architectures. This simplifies instruction decoding and pipelining, significantly improving processor execution efficiency.

[0032] SM2 is an elliptic curve public-key cryptography algorithm whose core operations include elliptic curve point multiplication (scalar multiplication), modular inversion, and hash calculations. However, in software implementation, the SM2 algorithm suffers from high point multiplication complexity, time-consuming modular inversion, and frequent memory access. Current optimization methods primarily involve hardware acceleration and software optimization. While hardware acceleration can accelerate elliptic curve point multiplication and modular inversion operations through dedicated circuitry, it requires the design of additional modular arithmetic units and large number arithmetic logic, significantly increasing area and power costs. Software optimization can improve performance by refining algorithm implementation, optimizing memory access, and utilizing vectorized processing. For example, compiler optimization techniques, such as instruction inlining and static code analysis, can improve code execution efficiency.

[0033] The RISC-V architecture demonstrates unique advantages in cryptographic algorithm optimization. In terms of instruction set extensions, it can design elliptic curve point addition instructions, point multiplication instructions, modular inversion instructions, and large number operation instructions, reducing software loop overhead and improving computational efficiency. In terms of memory access optimization, it can reduce memory access latency through prefetching and cache optimization. For example, dedicated cache partitions are designed for frequently accessed data by cryptographic algorithms, and instruction prefetching (such as PREFETCH) is used to reduce latency. In terms of compiler and toolchain support, the RISC-V compiler and toolchain can identify hot code and automatically replace it with extended instructions to improve code execution efficiency. They also provide static code analysis tools to automatically migrate code adaptation issues (such as endianness and alignment requirements) for cross-platform porting. Utilizing RISC-V vector extensions (RVV), batch signing or encryption tasks can be processed using SIMD parallelization to improve throughput. Furthermore, extended instructions can be dynamically enabled or disabled based on task requirements, balancing performance and power consumption, making it suitable for low-power scenarios such as the Internet of Things.

[0034] This application combines the RISC-V architecture with the SM2 cryptographic algorithm. Leveraging the open source, flexible, and scalable nature of the RISC-V architecture, it is expected to open up new paths in cryptographic algorithm optimization. Through instruction set extensions, memory access optimization, compiler and toolchain support, etc., it can significantly improve the performance of the SM2 cryptographic algorithm, reduce hardware costs, and provide more efficient solutions for the field of information security.

[0035] In this embodiment, a method for executing a cryptographic algorithm is provided, such as Figure 1 As shown, Figure 1 1 is a flow chart of a method for executing a cryptographic algorithm according to an embodiment of the present disclosure. The flow chart can be applied to a coprocessor and includes the following steps:

[0036] Step S101 , obtaining target data and a target control signal, wherein the target control signal is used to trigger the execution of a corresponding target cryptographic algorithm.

[0037] Optionally, in the embodiment of the present disclosure, the target data includes but is not limited to elliptic curve parameters (such as prime number p, curve coefficients a / b, coordinates of the curve base point G, etc.), user keys (user private key d A , user public key P A ), target plaintext M (i.e., the message to be processed), etc. The target control signal is an instruction signal sent by the main processor to instruct the coprocessor to execute the corresponding target cryptographic algorithm. Target cryptographic algorithms include, but are not limited to, cryptographic algorithms such as key generation, signature generation, signature verification, encryption, and decryption.

[0038] Specifically, the coprocessor communicates with the main processor using the external interface unit, receives target data and target control signals from the main processor, then stores the target data in the data storage unit, and transmits the target control signal to the control unit.

[0039] It should be noted that the elliptic curve equation defined by the SM2 standard is used in this embodiment: 2 =x 3 +ax+b, where p is a prime number, a and b are curve parameters, G is the base point of the curve, and the coordinates of G are (x G ,y G ), and all operations are performed on the finite field GF(p), including modular addition, modular subtraction, modular multiplication and modular inverse operations.

[0040] Step S102, obtaining a corresponding target instruction sequence from an instruction set based on a target control signal, wherein the instruction set is composed of a calling relationship and execution logic between multiple computing levels, and the instruction set is composed of multiple instruction sequences, each instruction sequence being used to execute an implementation of a cryptographic algorithm of a control signal.

[0041] Optionally, in an embodiment of the present disclosure, an instruction set is pre-constructed by calling relationships and execution logic between multiple computing layers (including a finite field operation layer, an elliptic curve operation layer, and an algorithm layer), and is pre-stored in a program storage unit. The instruction set includes multiple instruction sequences, each of which includes multiple instructions, and each instruction sequence is used to implement a cryptographic algorithm for executing a control signal.

[0042] Specifically, after receiving the target control signal, the control unit of the coprocessor searches for a corresponding instruction sequence from the instruction set of the program storage unit based on the target control signal to obtain a target instruction sequence.

[0043] In addition, the coprocessor can also store instruction sets through the microprogram memory. When the control unit of the coprocessor receives the target control signal, it can parse the algorithm flow of the target cryptographic algorithm corresponding to the target control signal in real time, and call microinstructions from the microprogram memory, dynamically combine multiple microinstructions into a temporary instruction sequence in a logical order, and then store the temporary instruction sequence in the dynamic instruction cache, so that the instruction fetch unit can execute the target cryptographic algorithm based on the temporary instruction sequence in the dynamic instruction cache.

[0044] Step S103: Obtain the first instruction in the target instruction sequence.

[0045] Optionally, in an embodiment of the present disclosure, multiple instructions in each instruction sequence are arranged in a logical order, and the first instruction is the first instruction in the target instruction sequence, that is, the starting point of the target algorithm execution.

[0046] Specifically, after determining the target instruction sequence, the coprocessor uses the instruction fetch unit to obtain the first instruction in the target instruction sequence from the program storage unit to obtain the first instruction, and transmits the first instruction to the decoding unit.

[0047] Step S104: parse the first instruction to obtain a program to be executed.

[0048] Optionally, in an embodiment of the present disclosure, the program to be executed is a set of micro-operations required when the first instruction is executed, including control signals and data path configuration information required when the first instruction is executed.

[0049] Specifically, the coprocessor utilizes the decoding unit to parse the first instruction, determines the function and operand of the first instruction, obtains the program to be executed, and sends the program to be executed to the execution unit.

[0050] Step S105: executing corresponding processing logic on the target data based on the program to obtain the target result.

[0051] Optionally, in the embodiment of the present disclosure, the target result refers to the processing result output by the coprocessor after executing the target cryptographic algorithm.

[0052] Specifically, the coprocessor uses the execution unit to call the corresponding hardware module according to the program to be executed to process the target data, and returns the processing result to the main processor through the external interface unit to obtain the target result.

[0053] In an embodiment of the present disclosure, target data and a target control signal are obtained, wherein the target control signal is used to trigger the execution of a corresponding target cryptographic algorithm; based on the target control signal, a corresponding target instruction sequence is obtained from an instruction set, wherein the instruction set is composed of a calling relationship and execution logic between multiple computing levels, and the instruction set is composed of multiple instruction sequences, each instruction sequence being used to execute a cryptographic algorithm for a control signal; the first instruction in the target instruction sequence is obtained; the first instruction is parsed to obtain a program to be executed; and based on the program, the corresponding processing logic is executed on the target data to obtain a target result. Since the embodiment of the present disclosure is based on a cryptographic algorithm execution structure that obtains instructions, parses instructions, and executes instructions, and calls instruction sets of multiple computing levels to execute the cryptographic algorithm, it can achieve hardware acceleration and simplify the software implementation process, thereby reducing the complexity of the cryptographic algorithm execution and improving the efficiency of the cryptographic algorithm execution.

[0054] In this embodiment, a method for executing a cryptographic algorithm is provided, such as Figure 2 As shown, Figure 2 FIG. 1 is a flow chart of another method for executing a cryptographic algorithm according to an embodiment of the present disclosure. The flow chart can be applied to a coprocessor and includes the following steps:

[0055] Step S201: Obtain target data and target control signals, wherein the target control signals are used to trigger the execution of the corresponding target cryptographic algorithm. Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.

[0056] Step S202: Based on the target control signal, a corresponding target instruction sequence is obtained from an instruction set. The instruction set is composed of the calling relationship and execution logic between multiple computing layers. The instruction set is composed of multiple instruction sequences, each of which is used to implement a cryptographic algorithm for executing a control signal. Figure 1 Step S102 of the illustrated embodiment will not be described in detail here.

[0057] Step S203: Get the first instruction in the target instruction sequence. Figure 1 Step S103 of the illustrated embodiment will not be described in detail here.

[0058] Step S204: parse the first instruction to obtain the program to be executed. Figure 1 Step S104 of the illustrated embodiment will not be described in detail here.

[0059] Step S205: executing corresponding processing logic on the target data based on the program to obtain the target result.

[0060] Specifically, the above step S205 includes:

[0061] Step S2051: Execute corresponding processing logic on the target data based on the program.

[0062] Specifically, after obtaining the program to be executed based on the first instruction, the coprocessor uses the execution unit to call the corresponding hardware module based on the program to be executed to process the target data, obtain an intermediate processing result, and store the intermediate processing result in the data storage unit.

[0063] Step S2052: Obtain the second instruction in the target instruction sequence, and use the second instruction as the first instruction, and repeat the process from obtaining the first instruction in the target instruction sequence until all instructions in the target instruction sequence are executed and the target result is obtained.

[0064] Optionally, in the embodiment of the present disclosure, the second instruction refers to the next instruction of the first instruction in the target instruction sequence.

[0065] Specifically, after executing the first instruction, the coprocessor uses the instruction fetch unit to obtain the second instruction from the program storage unit and updates the counter, then uses the decoding unit to parse the second instruction to obtain the program to be executed, and sends the program to be executed to the execution unit, and then uses the execution unit to call the corresponding hardware module according to the program to be executed to process the target data.

[0066] Afterwards, the coprocessor uses a counter to determine whether all instructions in the target instruction sequence have been executed. If not, the coprocessor repeats the above-mentioned instruction fetch, decoding, and execution process until all instructions in the target instruction sequence have been executed and the target result is obtained, and then uses the external interface unit to return the target result to the main processor.

[0067] In the embodiment of the present disclosure, through the cryptographic algorithm execution structure based on obtaining instructions, parsing instructions, and executing instructions, the instructions in the target instruction sequence are executed until all instructions in the target instruction sequence are executed. This can ensure that the target instruction sequence is executed in order and efficiently, realize hardware acceleration, and thus improve the execution efficiency of the cryptographic algorithm.

[0068] In this embodiment, a method for executing a cryptographic algorithm is provided, such as Figure 3 As shown, Figure 3 FIG. 1 is a flow chart of another method for executing a cryptographic algorithm according to an embodiment of the present disclosure. The flow chart can be applied to a coprocessor and includes the following steps:

[0069] Step S301: Obtain target data and target control signals, wherein the target control signals are used to trigger the execution of the corresponding target cryptographic algorithm. Figure 2 Step S201 of the illustrated embodiment will not be described in detail here.

[0070] Step S302: Based on the target control signal, a corresponding target instruction sequence is obtained from an instruction set. The instruction set is composed of the calling relationship and execution logic between multiple computing layers. The instruction set is composed of multiple instruction sequences, each of which is used to implement a cryptographic algorithm for executing a control signal. Figure 2 Step S202 of the illustrated embodiment will not be described in detail here.

[0071] Step S303: Get the first instruction in the target instruction sequence. Figure 2 Step S203 of the illustrated embodiment will not be described in detail here.

[0072] Step S304: parse the first instruction to obtain the program to be executed. Figure 2 Step S204 of the illustrated embodiment will not be described in detail here.

[0073] Step S305: executing corresponding processing logic on the target data based on the program to obtain the target result.

[0074] Specifically, the above step S305 includes:

[0075] Step S3051: Based on the program, call the algorithm instructions of the algorithm level.

[0076] Optionally, in an embodiment of the present disclosure, the algorithm instructions at the algorithm level include key generation instructions, signature generation instructions, signature verification instructions, encryption instructions, and decryption instructions, etc.

[0077] Specifically, when the coprocessor receives a program to be executed, it calls the algorithm instructions of the corresponding algorithm level according to the type of the target cryptographic algorithm.

[0078] Step S3052 : Based on the algorithm instruction, call a first operation instruction of the first operation level and a second operation instruction of the second operation level, wherein the algorithm level, the first operation level, and the second operation level are included in the calculation level.

[0079] Optionally, in an embodiment of the present disclosure, the first operation level is a finite field operation level, and the second operation level is an elliptic curve operation level. The first operation instructions of the first operation level include modular addition instructions, modular subtraction instructions, modular multiplication instructions, modular inverse instructions, and load constant instructions. The second operation instructions of the second operation level include point addition instructions, point multiplication instructions, and scalar multiplication instructions.

[0080] Specifically, after determining the algorithm instruction, the coprocessor calls the corresponding first operation instruction from the first operation level based on the algorithm instruction, and calls the corresponding second operation instruction from the second operation level.

[0081] Step S3053: Based on the first operation instruction and the second operation instruction, execute corresponding processing logic on the target data to obtain a target result.

[0082] Specifically, after determining the first operation instruction and the second operation instruction required to execute the target cryptographic algorithm, the coprocessor uses the execution unit to call the corresponding hardware module based on the first operation instruction and the second operation instruction to process the target data, and returns the processing result to the main processor through the external interface unit to obtain the target result.

[0083] When the coprocessor executes the modular addition instruction, it uses the execution unit to first read two 32-bit integers from registers rs1 and rs2, calculate the sum of the two integers, and then take the calculated sum modulo the prime number p to obtain the modular addition result, and ensure that the modular addition result is within the finite field GF(p), and finally store the modular addition result in register rd.

[0084] When the coprocessor executes the modular subtraction instruction, it uses the execution unit to first read two 32-bit integers from registers rs1 and rs2, then calculate the difference between the two integers, and then take the calculated difference modulo the prime number p to obtain the modular subtraction result, and ensure that the modular subtraction result is within the finite field GF(p), and finally store the modular subtraction result in register rd.

[0085] When the coprocessor executes the modular multiplication instruction, it uses the execution unit to first read two 32-bit integers from registers rs1 and rs2, then calculates the product of the two integers using the Montgomery modular multiplication algorithm to obtain the modular multiplication result, and finally stores the modular multiplication result in register rd.

[0086] When the coprocessor executes the modular inverse instruction, it uses the execution unit to first read a 32-bit integer from register rs1, then uses the binary extended Euclidean algorithm to calculate the inverse element of the integer under modulo p, obtains the modular inverse result, and finally stores the modular inverse result in register rd.

[0087] When the coprocessor executes the load constant instruction, it uses the execution unit to load the constant in the finite field into the register rd in the form of an immediate value, and ensures that the constant is correctly defined and in the finite field GF(p).

[0088] The first operation instruction of the first operation level is shown in Table 1:

[0089] Table 1: First operation instruction of the first operation level

[0090]

[0091] When the coprocessor executes the point addition instruction, it uses the execution unit to first obtain point P = (x1, y1) and point Q = (x2, y2), and then determines whether P and Q are infinite points. If P or Q is infinite, it directly returns the other point; if neither P nor Q is infinite, it calls the modular inverse instruction to calculate (x2-x1). -1 modp, and then call the modular addition instruction, modular subtraction instruction and modular multiplication instruction to calculate the slope λ = (y2-y1) / (x2-x1)modp, x3 = λ 2 -x1-x2 mod p, y3=λ(x1-x3)-y1 mod p, and finally based on x3 and y3, we get the point R=(x3,y3), which is the result of point addition.

[0092] When the coprocessor executes the point multiplication instruction, it uses the execution unit to first obtain the point P = (x1, y1), and then judge whether P is an infinity point. If P is an infinity point, it directly returns to the infinity point P; if P is not an infinity point, it calls the modular inverse instruction to calculate (2y1) modp, and then calls the modular addition instruction, modular subtraction instruction and modular multiplication instruction to calculate the slope λ = (3x1 2 +a) / (2y1)modp,x3=λ 2 -2x1modp, y3=λ(x1-x3)-y1 mod p, and finally based on x3 and y3, we get the point R=(x3,y3), which is the point doubling result.

[0093] When the coprocessor executes a scalar multiplication instruction, it uses the execution unit to first obtain the scalar k and the point P = (x1, y1). It then uses the sliding window method to convert the scalar k into a binary representation. It then calls the modular inverse, modular addition, modular subtraction, and modular multiplication instructions. By combining the point addition and point multiplication instructions, it gradually calculates the scalar multiplication result, namely the point R = (x3, y3). For example, for k = 13 (binary 1101), the calculation process is: 2P, 4P = 2(2P), 8P = 2(4P), and 13P = 8P + 4P + P.

[0094] The second operation instructions of the second operation level are shown in Table 1:

[0095] Table 2 Second operation instructions of the second operation level

[0096]

[0097]

[0098] In some optional implementations, the above step S305 includes:

[0099] Step a1: Obtain preset parameters and a target private key, wherein the preset parameters are used to characterize geometric information in the cryptographic algorithm.

[0100] Step a2: calling the first operation instruction and the second operation instruction, executing corresponding processing logic on the preset parameters and the target private key, and obtaining the target public key.

[0101] Step a3: Get the target result based on the target private key and the target public key.

[0102] Optionally, this embodiment is the execution process of the key generation instruction in the algorithm instruction, and the preset parameters refer to elliptic curve parameters, including but not limited to prime number p, curve coefficients a / b, coordinates of the curve base point G, etc.

[0103] Specifically, when the coprocessor executes the key generation instruction, it uses the execution unit to first use a random number generator to generate a large integer d A As the target private key, the range is [1,n-1], where n is the order of the elliptic curve, and the output of the random number generator is ensured to be of high quality to prevent the target private key from being predicted or attacked.

[0104] Then, the coprocessor calls the scalar multiplication instruction and the corresponding first operation instruction based on the target private key d A Calculate the target public key P with the curve base point G A =d A ×G.

[0105] Afterwards, the coprocessor uses the target private key d A and the target public key P A The target result is obtained and stored in a secure storage unit to ensure that it is not accessed by unauthorized persons.

[0106] In the above implementation, by calling instructions in the instruction sets of the algorithm level, the first operation level and the second operation level, and executing corresponding processing logic on the preset parameters and the target private key, the software implementation process of the key generation algorithm can be simplified, thereby reducing the execution complexity of the cryptographic algorithm and improving the execution efficiency of the cryptographic algorithm.

[0107] In some optional implementations, the above step S305 includes:

[0108] Step b1, obtaining preset parameters, target key, target private key and target plaintext, wherein the preset parameters are used to characterize geometric information in the cryptographic algorithm.

[0109] Step b2: calling the first operation instruction and the second operation instruction, executing corresponding processing logic on the preset parameters and the target key, and obtaining the target coordinates.

[0110] Step b3: perform a modulo operation on the target coordinates to obtain a first signature parameter.

[0111] Step b4: Call the first operation instruction and the second operation instruction, execute corresponding processing logic on the first signature parameter, the target key, the target private key and the target plaintext, and obtain the target signature.

[0112] Step b5: Obtain the target result based on the target signature.

[0113] Optionally, this embodiment is an execution process of a signature generation instruction in an algorithm instruction.

[0114] Specifically, when executing the signature generation instruction, the coprocessor uses the execution unit to first perform message preprocessing, and uses the cryptographic hash algorithm hardware accelerator to generate a message digest ZA through the ZA hash function for the target plaintext M to obtain a hash value of fixed length.

[0115] Then, the coprocessor generates a random number k as the target key in the signing process and ensures the uniformity and unpredictability of the random number k to prevent attackers from using weak random numbers to perform key recovery attacks.

[0116] Afterwards, the coprocessor calls the corresponding first and second operation instructions, and calculates the elliptic curve point R = k × G based on the curve base point G and the target key k, and obtains the coordinates of point R (x1, y1), which are the target coordinates. Then, the coprocessor performs a modulo operation on the coordinates of point R (x1, y1) to obtain the first signature parameter r = x1modn. If r = 0, it regenerates the random number k and recalculates the first signature parameter. Then, the coprocessor performs a modulo operation on the coordinates of point R (x1, y1) to obtain the first signature parameter r = x1modn. If r = 0, it regenerates the random number k and recalculates the first signature parameter. Then, the coprocessor performs a modulo operation on the target private key d A , the first signature parameter r, the target key k and the hash value H(M) of the target plaintext M, and the first signature parameter s=(d A ×r+k -1 ×H(M))modn, if s=0, regenerate the random number k and recalculate the first signature parameter and the second signature parameter.

[0117] Finally, the coprocessor obtains a signature result (r, s), ie, a target result, based on the first signature parameter and the second signature parameter, and stores the target result in a designated storage unit for subsequent verification.

[0118] In the above implementation, by calling the instructions in the instruction sets of the algorithm level, the first operation level and the second operation level, and executing the corresponding processing logic on the preset parameters, the target key, the target private key and the target plaintext, the software implementation process of the signature generation algorithm can be simplified, thereby reducing the execution complexity of the cryptographic algorithm and improving the execution efficiency of the cryptographic algorithm.

[0119] In some optional implementations, the above step S305 includes:

[0120] Step c1, obtain the target public key, the target plaintext, and the target signature.

[0121] Step c2, when the target signature does not conform to the preset rules, determine that the verification result of the target signature is invalid.

[0122] Step c3, when the target signature conforms to the preset rules, call the first operation instruction and the second operation instruction, and execute the corresponding processing logic on the target public key, the target plaintext, and the target signature to obtain the verification parameter.

[0123] Step c4, when the verification parameter is not equal to the preset result, determine that the verification result of the target signature is invalid.

[0124] Step c5, when the verification parameter is equal to the preset result, determine that the verification result of the target signature is valid.

[0125] Step c6, obtain the target result based on the verification result of the target signature. <00​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​Finally, the coprocessor takes the verification result (valid or invalid) as the target result and notifies the main processor through the status register or interrupt.

[0131] In the above implementation, by calling the instructions in the instruction sets of the algorithm level, the first operation level and the second operation level, the corresponding processing logic is executed on the target public key, the target plaintext and the target signature, which can simplify the software implementation process of the signature verification algorithm, thereby reducing the execution complexity of the cryptographic algorithm and improving the execution efficiency of the cryptographic algorithm.

[0132] In some optional implementations, the above step S305 includes:

[0133] Step d1, obtain the target plaintext, session key and target public key.

[0134] Step d2: Call the first operation instruction and the second operation instruction to encrypt the target plaintext to obtain a first ciphertext.

[0135] Step d3: Call the first operation instruction and the second operation instruction, use the target public key to encrypt the session key, and obtain a second ciphertext.

[0136] Step d4: merge the first ciphertext and the second ciphertext to obtain the target ciphertext.

[0137] Step d5: Obtain the target result based on the target ciphertext.

[0138] Optionally, this embodiment is an execution process of an encryption instruction in an algorithm instruction.

[0139] Specifically, when the coprocessor executes the encryption instruction, it uses the execution unit to first generate a random number k as the session key, and then calls the corresponding first operation instruction and second operation instruction to encrypt the target plaintext M using the symmetric encryption algorithm to obtain the first ciphertext C1, and then uses the target public key P to encrypt the target plaintext M. A The session key k is encrypted to obtain the second ciphertext C2.

[0140] Finally, the coprocessor combines the first ciphertext C1 and the second ciphertext C2 to obtain the target ciphertext (C1, C2), that is, the target result, and stores the target result in a designated storage unit for subsequent decryption.

[0141] In the above implementation, by calling instructions in the instruction sets of the algorithm level, the first operation level and the second operation level, corresponding processing logic is executed on the target plaintext, the session key and the target public key, which can simplify the software implementation process of the encryption algorithm, thereby reducing the execution complexity of the cryptographic algorithm and improving the execution efficiency of the cryptographic algorithm.

[0142] In some optional implementations, the above step S305 includes:

[0143] Step e1: Obtain the target ciphertext and target private key.

[0144] Step e2: calling the first operation instruction and the second operation instruction to parse the target ciphertext to obtain the first ciphertext and the second ciphertext.

[0145] Step e3: Call the first operation instruction and the second operation instruction, use the target private key to decrypt the second ciphertext, and obtain the session key.

[0146] Step e4: Call the first operation instruction and the second operation instruction, use the session key to decrypt the first ciphertext, and obtain the target plaintext.

[0147] Step e5: Obtain the target result based on the target plaintext.

[0148] Optionally, this embodiment is an execution process of a decryption instruction in an algorithm instruction.

[0149] Specifically, when the coprocessor executes the decryption instruction, it uses the execution unit to first call the corresponding first operation instruction and second operation instruction to parse the target ciphertext (C1, C2) to obtain the first ciphertext C1 and the second ciphertext C2, and then based on the target private key d A The second ciphertext C2 is decrypted to obtain the session key k, and then the first ciphertext C1 is parsed based on the session key k to obtain the target plaintext M, that is, the target result, and the target result is returned to the main processor through the data storage unit or register.

[0150] In the above implementation, by calling instructions in the instruction sets of the algorithm level, the first operation level and the second operation level, corresponding processing logic is executed on the target ciphertext and the target private key, which can simplify the software implementation process of the decryption algorithm, thereby reducing the execution complexity of the cryptographic algorithm and improving the execution efficiency of the cryptographic algorithm.

[0151] Among them, the algorithm instructions at the algorithm level are shown in Table 3:

[0152] Table 3 Algorithm instructions at the algorithm level

[0153]

[0154] In the embodiment of the present disclosure, by calling the instruction sets of the algorithm level, the first operation level and the second operation level to execute the cryptographic algorithm, the software implementation process can be simplified, thereby reducing the execution complexity of the cryptographic algorithm and improving the execution efficiency of the cryptographic algorithm.

[0155] In some optional embodiments, such as Figure 4 As shown, Figure 4A schematic diagram of the functional modules of the cryptographic algorithm instruction set provided in an embodiment of the present application, wherein the cryptographic algorithm instruction set includes three levels: a first operation layer (i.e., a finite field operation layer), a second operation layer (i.e., an elliptic curve operation layer), and an algorithm layer.

[0156] Among them, the first operation layer includes first operation instructions such as modular addition instructions, modular subtraction instructions, modular multiplication instructions, modular inverse instructions and load constant instructions; the second operation layer includes second operation instructions such as point addition instructions, point multiplication instructions and scalar multiplication instructions; the algorithm layer includes algorithm instructions such as key generation instructions, signature generation instructions, signature verification instructions, encryption instructions and decryption instructions.

[0157] In some optional embodiments, such as Figure 5 As shown, Figure 5 This is a system architecture diagram for a cryptographic algorithm execution method provided in an embodiment of the present application. The system includes a main processor, a coprocessor, and a memory unit. The coprocessor includes an external interface unit, a program storage unit, a data storage unit, a bus interface unit, an instruction fetch unit, a decoding unit, an execution unit, and a control unit.

[0158] The external interface unit is used to communicate with the main processor, receive target data and target control signals sent by the main processor, and return the target result to the main processor. The program storage module is used to store the instruction sequence of the instruction set that implements the cryptographic algorithm. The data storage module is used to store elliptic curve parameters and intermediate data for data processing. The bus interface module is used to communicate with the memory unit via the data path. The instruction fetch unit is used to fetch instructions based on the address in the program counter and update the counter. The decoding unit is used to decode the fetched instructions and determine the instruction function and operands. The execution unit is used to perform specific computing tasks based on the decoding results. The control unit is used to coordinate the work of each unit to ensure the correct execution of instructions.

[0159] In some optional embodiments, such as Figure 6 As shown, Figure 6A flow chart of another method for executing a cryptographic algorithm provided in an embodiment of the present application is provided, wherein the coprocessor first uses the external interface unit to obtain target data and target control signals from the main processor, and stores the target data in the data storage unit, and then searches for the corresponding instruction sequence from the instruction set of the program storage unit based on the target control signal to obtain the target instruction sequence, and then uses the instruction fetch unit to fetch the instruction in the target instruction sequence according to the address in the program counter and updates the counter, uses the decoding unit to decode the fetched instruction to determine the function and operand of the instruction, and uses the execution unit to perform a specific computing task according to the decoding result, and then uses the counter to determine whether all instructions in the target instruction sequence have been executed. If not, the above-mentioned instruction fetch, decoding, and execution process are repeated until all instructions in the target instruction sequence are executed and the target result is obtained, and the target result is returned to the main processor using the external interface unit.

[0160] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0161] This embodiment provides a cryptographic algorithm execution device, such as Figure 7 Shown, including:

[0162] A first acquisition module 701 is configured to acquire target data and a target control signal, wherein the target control signal is used to trigger execution of a corresponding target cryptographic algorithm;

[0163] A second acquisition module 702 is configured to acquire a corresponding target instruction sequence from an instruction set based on the target control signal, wherein the instruction set is composed of call relationships and execution logic between multiple computing layers, and the instruction set is composed of multiple instruction sequences, each instruction sequence being used to implement a cryptographic algorithm for executing a control signal;

[0164] A third acquisition module 703 is used to acquire the first instruction in the target instruction sequence;

[0165] The parsing module 704 is used to parse the first instruction to obtain a program to be executed;

[0166] The execution module 705 is used to execute corresponding processing logic on the target data based on the program to obtain the target result.

[0167] In an embodiment of the present disclosure, target data and a target control signal are obtained, wherein the target control signal is used to trigger the execution of a corresponding target cryptographic algorithm; based on the target control signal, a corresponding target instruction sequence is obtained from an instruction set, wherein the instruction set is composed of a calling relationship and execution logic between multiple computing levels, and the instruction set is composed of multiple instruction sequences, each instruction sequence being used to execute a cryptographic algorithm for a control signal; the first instruction in the target instruction sequence is obtained; the first instruction is parsed to obtain a program to be executed; and based on the program, the corresponding processing logic is executed on the target data to obtain a target result. Since the embodiment of the present disclosure is based on a cryptographic algorithm execution structure that obtains instructions, parses instructions, and executes instructions, and calls instruction sets of multiple computing levels to execute the cryptographic algorithm, it can achieve hardware acceleration and simplify the software implementation process, thereby reducing the complexity of the cryptographic algorithm execution and improving the efficiency of the cryptographic algorithm execution.

[0168] In some optional implementations, the execution module 705 includes:

[0169] A first execution submodule, configured to execute corresponding processing logic on target data based on the program;

[0170] The first obtaining submodule is used to obtain the second instruction in the target instruction sequence, and use the second instruction as the first instruction, repeatedly executing from obtaining the first instruction in the target instruction sequence until all instructions in the target instruction sequence are executed to obtain the target result.

[0171] In some optional implementations, the execution module 705 includes:

[0172] The first calling submodule is used to call algorithm instructions at the algorithm level based on the program;

[0173] A second calling submodule is configured to call a first operation instruction of a first operation level and a second operation instruction of a second operation level based on the algorithm instruction, wherein the algorithm level, the first operation level, and the second operation level are included in the calculation level;

[0174] The second execution submodule is used to execute corresponding processing logic on the target data based on the first operation instruction and the second operation instruction to obtain a target result.

[0175] In some optional implementations, the execution module 705 includes:

[0176] A first acquisition submodule is used to obtain preset parameters and a target private key, wherein the preset parameters are used to represent geometric information in the cryptographic algorithm;

[0177] A third execution submodule is used to call the first operation instruction and the second operation instruction, execute corresponding processing logic on the preset parameters and the target private key, and obtain the target public key;

[0178] The second submodule is used to obtain the target result based on the target private key and the target public key.

[0179] In some optional implementations, the execution module 705 includes:

[0180] A second acquisition submodule is used to obtain preset parameters, a target key, a target private key, and a target plaintext, wherein the preset parameters are used to represent geometric information in the cryptographic algorithm;

[0181] A fourth execution submodule is configured to call the first operation instruction and the second operation instruction, execute corresponding processing logic on the preset parameters and the target key, and obtain target coordinates;

[0182] The third submodule is used to perform a modulo operation on the target coordinates to obtain a first signature parameter;

[0183] a fifth execution submodule, configured to call the first operation instruction and the second operation instruction, execute corresponding processing logic on the first signature parameter, the target key, the target private key, and the target plaintext, and obtain a target signature;

[0184] The fourth obtaining submodule is used to obtain a target result based on the target signature.

[0185] In some optional implementations, the execution module 705 includes:

[0186] The third acquisition submodule is used to obtain the target public key, target plaintext and target signature;

[0187] A first determination submodule, configured to determine that a verification result of the target signature is invalid if the target signature does not conform to a preset rule;

[0188] a sixth execution submodule, configured to, when the target signature meets the preset rules, call the first operation instruction and the second operation instruction, execute corresponding processing logic on the target public key, the target plaintext, and the target signature, and obtain verification parameters;

[0189] A second determining submodule, configured to determine that the verification result of the target signature is invalid if the verification parameter is not equal to the preset result;

[0190] A third determination submodule is configured to determine that the verification result of the target signature is valid when the verification parameter is equal to the preset result;

[0191] The fifth obtaining submodule is used to obtain the target result based on the verification result of the target signature.

[0192] In some optional implementations, the execution module 705 includes:

[0193] The fourth acquisition submodule is used to obtain the target plaintext, session key and target public key;

[0194] A first encryption submodule is configured to call a first operation instruction and a second operation instruction to encrypt a target plaintext to obtain a first ciphertext;

[0195] A second encryption submodule is configured to call the first operation instruction and the second operation instruction, and encrypt the session key using the target public key to obtain a second ciphertext;

[0196] A merging submodule, configured to merge the first ciphertext and the second ciphertext to obtain a target ciphertext;

[0197] The sixth obtaining submodule is used to obtain a target result based on the target ciphertext.

[0198] In some optional implementations, the execution module 705 includes:

[0199] The fifth acquisition submodule is used to obtain the target ciphertext and the target private key;

[0200] A parsing submodule, configured to call a first operation instruction and a second operation instruction to parse the target ciphertext to obtain a first ciphertext and a second ciphertext;

[0201] A first decryption submodule is configured to call the first operation instruction and the second operation instruction, and decrypt the second ciphertext using the target private key to obtain a session key;

[0202] A second decryption submodule is configured to call the first operation instruction and the second operation instruction, and decrypt the first ciphertext using the session key to obtain a target plaintext;

[0203] The seventh obtaining submodule is used to obtain a target result based on the target plaintext.

[0204] For the description of the features in the embodiment corresponding to the execution device of the cryptographic algorithm, please refer to the relevant description of the embodiment corresponding to the execution method of the cryptographic algorithm, and no further details will be given here.

[0205] The embodiment of the present application also provides an electronic device, such as Figure 8 As shown, it includes a memory 10 and a processor 20, the memory 10 stores a computer program, and the processor 20 is configured to run the computer program to execute the steps in the embodiment of the execution method of any of the above-mentioned cryptographic algorithms.

[0206] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0207] The above describes in detail the method, apparatus, and device for executing a cryptographic algorithm provided by this application. Specific examples are used herein to illustrate the principles and implementation methods of this application. The description of the above embodiments is intended only to facilitate understanding of the method and core concepts of this application. It should be noted that those skilled in the art may, without departing from the principles of this application, make various improvements and modifications to this application, and such improvements and modifications fall within the scope of protection of the claims of this application.

Claims

1. A method for executing a cryptographic algorithm, characterized in that: include: Acquiring target data and a target control signal, wherein the target control signal is used to trigger execution of a corresponding target cryptographic algorithm; Obtaining a corresponding target instruction sequence from an instruction set based on the target control signal, wherein the instruction set is composed of a calling relationship and execution logic between multiple computing levels, and the instruction set is composed of multiple instruction sequences, each of which is used to execute an implementation of a cryptographic algorithm for a control signal; Obtaining a first instruction in the target instruction sequence; Parsing the first instruction to obtain a program to be executed; Based on the program, corresponding processing logic is executed on the target data to obtain a target result.

2. The method for executing a cryptographic algorithm according to claim 1, wherein: The executing corresponding processing logic on the target data based on the program to obtain a target result includes: executing corresponding processing logic on the target data based on the program; A second instruction in the target instruction sequence is obtained, and the second instruction is used as the first instruction, and the first instruction in the target instruction sequence is repeatedly executed from the step of obtaining the first instruction in the target instruction sequence until all instructions in the target instruction sequence are executed, thereby obtaining the target result.

3. The method for executing a cryptographic algorithm according to claim 1, wherein: The executing corresponding processing logic on the target data based on the program to obtain a target result includes: Based on the program, calling algorithm instructions of the algorithm level; Based on the algorithm instruction, calling a first operation instruction of a first operation level and a second operation instruction of a second operation level, wherein the algorithm level, the first operation level and the second operation level are included in the calculation level; Based on the first operation instruction and the second operation instruction, corresponding processing logic is executed on the target data to obtain the target result.

4. The method for executing a cryptographic algorithm according to claim 3, wherein: The executing corresponding processing logic on the target data based on the program to obtain a target result includes: Obtaining preset parameters and a target private key, wherein the preset parameters are used to characterize geometric information in the cryptographic algorithm; Calling the first operation instruction and the second operation instruction, executing corresponding processing logic on the preset parameters and the target private key, and obtaining a target public key; Based on the target private key and the target public key, the target result is obtained.

5. The method for executing a cryptographic algorithm according to claim 3, wherein: The executing corresponding processing logic on the target data based on the program to obtain a target result includes: Obtaining preset parameters, a target key, a target private key, and a target plaintext, wherein the preset parameters are used to characterize geometric information in the cryptographic algorithm; Calling the first operation instruction and the second operation instruction, executing corresponding processing logic on the preset parameters and the target key, and obtaining target coordinates; Performing a modulo operation on the target coordinates to obtain a first signature parameter; Calling the first operation instruction and the second operation instruction, executing corresponding processing logic on the first signature parameter, the target key, the target private key, and the target plaintext, to obtain a target signature; The target result is obtained based on the target signature.

6. The method for executing a cryptographic algorithm according to claim 3, wherein: The executing corresponding processing logic on the target data based on the program to obtain a target result includes: Get the target public key, target plaintext and target signature; If the target signature does not comply with a preset rule, determining that the verification result of the target signature is invalid; If the target signature meets the preset rule, calling the first operation instruction and the second operation instruction, executing corresponding processing logic on the target public key, the target plaintext and the target signature, and obtaining verification parameters; If the verification parameter is not equal to the preset result, determining that the verification result of the target signature is invalid; When the verification parameter is equal to the preset result, determining that the verification result of the target signature is valid; The target result is obtained based on the verification result of the target signature.

7. The method for executing a cryptographic algorithm according to claim 3, wherein: The executing corresponding processing logic on the target data based on the program to obtain a target result includes: Get the target plaintext, session key, and target public key; Calling the first operation instruction and the second operation instruction to encrypt the target plaintext to obtain a first ciphertext; Calling the first operation instruction and the second operation instruction, and encrypting the session key using the target public key to obtain a second ciphertext; Merging the first ciphertext and the second ciphertext to obtain a target ciphertext; The target result is obtained based on the target ciphertext.

8. The method for executing a cryptographic algorithm according to claim 3, wherein: The executing corresponding processing logic on the target data based on the program to obtain a target result includes: Get the target ciphertext and target private key; Calling the first operation instruction and the second operation instruction to parse the target ciphertext to obtain a first ciphertext and a second ciphertext; Calling the first operation instruction and the second operation instruction, decrypting the second ciphertext using the target private key to obtain a session key; Calling the first operation instruction and the second operation instruction, and decrypting the first ciphertext using the session key to obtain a target plaintext; The target result is obtained based on the target plaintext.

9. A cryptographic algorithm execution device, characterized in that: include: A first acquisition module is configured to acquire target data and a target control signal, wherein the target control signal is used to trigger execution of a corresponding target cryptographic algorithm; a second acquisition module, configured to acquire a corresponding target instruction sequence from an instruction set based on the target control signal, wherein the instruction set is composed of call relationships and execution logic between multiple computing levels, and the instruction set is composed of multiple instruction sequences, each of which is used to implement a cryptographic algorithm for executing a control signal; A third acquisition module, configured to acquire a first instruction in the target instruction sequence; a parsing module, configured to parse the first instruction to obtain a program to be executed; An execution module is used to execute corresponding processing logic on the target data based on the program to obtain a target result.

10. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the method for executing the cryptographic algorithm as claimed in any one of claims 1 to 8 when executing the computer program.