A method and system for generating pseudo-random number hardware acceleration and true random seed cooperation
By using a collaborative scheduling unit and a multi-entropy source fusion generation method, the problem of rhythm mismatch between pseudo-random number and true random seed supply is solved, achieving efficient and reliable execution of encrypted tasks and multi-standard compatibility in embedded scenarios.
Patent Information
- Application Number
- CN202511641022.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-11
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-11-11
AI Technical Summary
In existing technologies, the generation of pseudo-random numbers and the supply of true random seeds suffer from a mismatch in timing in embedded scenarios, leading to wasted hardware resources and reduced security, and making it difficult to achieve multi-standard compatibility and efficient execution within a single architecture.
The frequency of pseudo-random number generation requests and the remaining amount of seeds are monitored in real time by the collaborative scheduling unit. The frequency of true random seed generation is dynamically adjusted, and multiple entropy sources are integrated for fusion generation to establish a traceable relationship between pseudo-random numbers and true random seeds.
It achieves coordinated operation of pseudo-random number generation and true random seed supply, adapts to dynamic load and environmental interference, improves system resource utilization and security, and ensures the stability and reliability of encryption tasks.
Smart Images

Figure CN121098481B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method and system for hardware acceleration of pseudo-random numbers and collaborative generation of true random seeds, belonging to the field of chip-level network security technology. Background Technology
[0002] Currently, pseudo-random number generators and true random seed generators are fundamental components of building chip-level information security systems. In specific implementations, to improve the execution efficiency of encryption operations, dedicated hardware is usually used to accelerate the generation process of pseudo-random numbers. At the same time, to ensure the cryptographic security of pseudo-random number sequences, their initial seeds must be provided by a true random seed generator that integrates a physical entropy source. Configuring multiple physical entropy sources is also considered a technical option to improve seed reliability.
[0003] When this technical architecture is applied to embedded scenarios such as smart cars and industrial control systems, its separate design exposes the inherent problem of mismatch between the consumption rhythm of pseudo-random numbers and the supply rhythm of true random seeds when dealing with dynamically changing workloads. Encryption task requests in such scenarios have bursty and non-steady-state characteristics, and electromagnetic and voltage fluctuations in their operating environment also have a continuous impact on the stability of the physical entropy source. In the existing architecture, the pseudo-random number generation unit and the true random seed generation unit work independently. To ensure that the seed supply is not interrupted during the peak period of encryption tasks, the true random seed generation unit must run continuously at the highest consumption rate. This results in idle hardware resources and wasted power consumption during the low period of tasks. If its generation rate is reduced, there is a risk of seed supply delay or exhaustion during concurrent tasks, which may force the system to reuse old seeds, thereby reducing the reliability of the entire security system.
[0004] Simply increasing the seed cache or adding more entropy sources cannot solve the structural problem of supply and consumption mismatch mentioned above. Cache can only smooth out short-term demand peaks and troughs, and cannot cope with continuous high loads, while increasing the design complexity of the system. The simple combination of entropy sources, without a mechanism for real-time evaluation and dynamic compensation of the working status of each entropy source, also makes it difficult to guarantee the constancy of the total output entropy value in complex interference environments. In practical applications, this architecture mainly presents the following technical states: 1. The hardware unit responsible for generating pseudo-random numbers has a relatively fixed algorithm, which is difficult to flexibly adapt to multiple cryptographic standards, and its drastic load changes place higher demands on the real-time nature of seed supply; 2. The unit responsible for generating true random seeds has an entropy source that is susceptible to external environmental interference, and without an internal compensation and adjustment mechanism, the quality stability of the output seed is insufficient; 3. In terms of the overall system architecture, there is a lack of a direct correlation mechanism between the pseudo-random number generation and true random seed generation processes to regulate the rhythm of the latter based on the load of the former, making it difficult for the system to achieve a balance between resource efficiency and operational security. Therefore, the technical problem to be solved by this invention is how to achieve multi-standard compatibility and efficient execution of pseudo-random number generation within a single system architecture, and how to ensure that the required high-reliability true random seed can be adaptively supplied according to real-time load, while ensuring the environmental stability of the seed generation process. Summary of the Invention
[0005] This invention provides a method and system for hardware acceleration of pseudo-random numbers and collaborative generation of true random seeds. Its main purpose is to solve the problem in the prior art that it is difficult to simultaneously achieve the multi-standard adaptability of pseudo-random number generation and the real-time performance and reliability of true random seed supply within a single architecture.
[0006] To achieve the above objectives, this invention provides a method for hardware-accelerated pseudo-random number generation combined with true random seed generation, comprising:
[0007] The frequency of generation requests from the pseudo-random number hardware acceleration unit and the current remaining seed amount are collected to jointly determine the current load status.
[0008] Based on the current load status, a dynamic scheduling instruction is generated and sent to the true random seed generation unit. This dynamic scheduling instruction limits the seed generation frequency of the true random seed generation unit.
[0009] The true random seed generation unit receives dynamic scheduling instructions and executes the multi-entropy source fusion generation process to produce a true random seed. The multi-entropy source fusion generation process includes: real-time monitoring of the working status of each entropy source that constitutes the multi-entropy source, and dynamically adjusting the weight ratio of each entropy source in the weight model according to the working status, so as to compensate for the impact of external environmental interference on the stability of the entropy source output.
[0010] The pseudo-random number hardware acceleration unit loads a true random seed and generates pseudo-random numbers via a pipelined processing architecture;
[0011] Assign a unique identifier to the true random seed and embed the unique identifier into the preset header field of the pseudo random number, thereby establishing a traceable link between the pseudo random number and the true random seed.
[0012] Preferably, the step of determining the current load state and generating dynamic scheduling instructions specifically includes: when it is detected that the frequency of generation requests is higher than the high load threshold and the current remaining seed quantity is lower than the low remaining seed quantity threshold, the current load state is determined to be a high load state, and an expedited generation instruction is generated as a dynamic scheduling instruction to increase the seed generation frequency; when it is detected that the frequency of generation requests is lower than the low load threshold and the current remaining seed quantity is higher than the high remaining seed quantity threshold, the current load state is determined to be a low load state, and a reduced frequency generation instruction is generated as a dynamic scheduling instruction to reduce the seed generation frequency.
[0013] Preferably, the multi-entropy source fusion generation process performed by the true random seed generation unit includes at least two of the following entropy sources: subthreshold circuit thermal noise entropy source, clock jitter entropy source, and voltage ripple entropy source.
[0014] Preferably, the pseudo-random number hardware acceleration unit includes multiple dedicated hardware cores covering different cryptographic standards, and an algorithm selector for activating a specific hardware core according to external instructions; the step of loading a true random seed by the pseudo-random number hardware acceleration unit is specifically performed by the dedicated hardware core of the algorithm activated by the algorithm selector.
[0015] Preferably, the pipelined processing architecture is configured to execute the three processing stages of seed loading, iterative computation, and result output in parallel.
[0016] Preferably, the method further includes an anomaly tracing step: when an anomaly monitoring instruction for a certain pseudo-random number is received, the unique identifier in the header field of the pseudo-random number is read, and based on the unique identifier, the working status of each entropy source is traced back when the true random seed corresponding to the unique identifier is generated, and the weight ratio of each entropy source in the weight model is dynamically adjusted. The update logic follows the following rules: ,in, For the first The weight percentage of each entropy source in the next control cycle. For the first The quality factor calculated by each entropy source based on its operating state within the current control cycle. This represents the total number of entropy sources.
[0017] Preferably, in the step of determining the current load status, the high load threshold, low margin threshold, low load threshold and high margin threshold are all configured as thresholds with hysteresis, thereby avoiding frequent switching of dynamic scheduling instructions caused by small fluctuations in the input signal.
[0018] Preferred quality factor The calculation is based on at least the following working states: Bit deviation rate, jitter variance, and health test pass rate of each entropy source.
[0019] Preferably, the method further includes an initialization step: before performing the acquisition step, an algorithm selector is pre-configured according to external instructions, so that the pseudo-random number hardware acceleration unit is adapted to a specific cryptographic standard system.
[0020] A hardware-accelerated pseudo-random number generation system that coordinates with a true random seed includes:
[0021] The collaborative scheduling unit is configured to: collect the generation request frequency and the current remaining amount of seeds from the pseudo-random number hardware acceleration unit, thereby jointly determining the current load status; and generate and send dynamic scheduling instructions to the true random seed generation unit based on the current load status, which limit the seed generation frequency of the true random seed generation unit.
[0022] The true random seed generation unit is configured to: receive dynamic scheduling instructions and execute a multi-entropy source fusion generation process to produce a true random seed. The multi-entropy source fusion generation process includes real-time monitoring of the working status of each entropy source constituting the multi-entropy source and dynamically adjusting the weight ratio of each entropy source in the weight model according to the working status.
[0023] The pseudo-random number hardware acceleration unit is configured to load a true random seed and generate pseudo-random numbers via a pipelined processing architecture.
[0024] The binding module is configured to assign a unique identifier to the true random seed and embed the unique identifier into the preset header field of the pseudo random number, thereby establishing a traceable association between the pseudo random number and the true random seed.
[0025] Compared with the prior art, the beneficial effects of the present invention are:
[0026] 1. By establishing a collaborative scheduling unit, the frequency of generation requests from the pseudo-random number hardware acceleration unit and the current remaining amount of seeds are collected in real time. Based on the collection results, the working mode of the true random seed generation unit is adjusted. A dynamic closed-loop supply and demand response relationship is established between the high-speed consumption demand of pseudo-random number generation and the supply capacity of the physical process of true random seed generation. This structure enables the generation rhythm of true random seeds to actively adjust to the consumption rhythm when facing non-stationary pseudo-random number requests caused by high-concurrency encryption tasks. This avoids the technical problem of seed supply interruption under high load or continuous waste of hardware resources under low load caused by the mismatch between the rhythms of the two in the traditional independent working mode.
[0027] 2. The true random seed generation unit integrates several entropy sources with different physical characteristics, including subthreshold circuit thermal noise, clock jitter, and voltage ripple. Through an anti-interference compensation module, it monitors the working status of each entropy source. When the stability of a certain entropy source decreases due to external environmental interference, the system does not simply discard that entropy source. Instead, it automatically adjusts the weight ratio of each entropy source in the final entropy value composition and uses the stable output of other unaffected entropy sources for compensation. This inherent mechanism of multi-source complementarity and dynamic compensation enables the true random seed generation process to exhibit a structural adaptability to electromagnetic interference or voltage fluctuations commonly found in scenarios such as intelligent vehicle industrial control, ensuring the continuous stability of the total output entropy value.
[0028] 3. The pseudo-random number hardware acceleration unit is configured with dedicated hardware cores for multiple algorithms covering different cryptographic standards, and the algorithm selector is dynamically activated according to upper-layer instructions. At the same time, its internal pipelined processing design executes the seed loading, iterative operation, and result output processes in parallel. This processing architecture, combined with the stable and timely seed supply guaranteed by the aforementioned collaborative scheduling unit, enables the system to smoothly switch and efficiently execute pseudo-random number generation tasks under multiple encryption algorithms without changing the hardware, meeting the application requirements of chip-level security products in multi-standard compatible scenarios.
[0029] 4. This method establishes a seed-pseudo-random number binding module, assigning a unique identifier to each generated true random seed. When the pseudo-random number hardware acceleration unit uses this seed to generate pseudo-random numbers, this seed identifier is automatically embedded in the header identifier of the pseudo-random number. This mechanism establishes a clear and traceable data link for the generation process of random number sequences. When encryption anomalies occur subsequently, the initial true random seed can be directly located by reading the seed identifier in the header of the abnormal pseudo-random number, and the working status of each entropy source and the execution status of the pseudo-random number hardware core when the seed was generated can be traced back. This provides a technical basis for quickly diagnosing the root cause of the problem and improves the maintainability and post-event auditing capabilities of the entire security system. Attached Figure Description
[0030] Figure 1 This is a diagram of the architecture of the random number generation system with collaborative scheduling and traceable association according to the present invention.
[0031] Figure 2 This is a diagram showing the dynamic response and complementary characteristics of the multi-entropy source quality factor under disturbance in this invention;
[0032] Figure 3 This is the state transition logic diagram for the adaptive load and fault-safety system of the present invention. Detailed Implementation
[0033] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this invention, not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0034] This invention provides a method and system for co-generating pseudo-random numbers with hardware acceleration and true random seeds. The system is configured to include a pseudo-random number hardware acceleration unit, a true random seed generation unit, a co-scheduling unit, and a binding module. The co-scheduling unit connects the pseudo-random number hardware acceleration unit and the true random seed generation unit and is used to output control commands to the true random seed generation unit according to the workload of the pseudo-random number hardware acceleration unit. The binding module is connected to the output of the pseudo-random number hardware acceleration unit and is used to establish a traceable association of data.
[0035] In specific applications, such as when an automotive domain controller performs high-frequency encrypted communication, the consumption of pseudo-random numbers by its security chip exhibits sudden and unsteady characteristics, constraining the limited hardware resources and power consumption of the embedded system. To address this situation, the collaborative scheduling unit of this solution continuously collects two status parameters of the pseudo-random number hardware acceleration unit through its internal load monitoring module at a preset sampling period, such as 5ms: generation request frequency and current seed remaining quantity. Here, the generation request frequency refers to the number of times the upper-layer encryption task calls the pseudo-random number generation interface per unit time, and the current seed remaining quantity refers to the number of bits of the unused true random seed in the internal seed buffer. Based on the collected parameter values, the collaborative scheduling unit jointly determines a current load state. This mechanism establishes a closed-loop adaptive supply and demand response relationship between the consumption demand of pseudo-random numbers and the physical supply capacity of true random seeds. To transform the current load state into an executable control behavior, the dynamic scheduling module of the collaborative scheduling unit internally sets a set of parameters based on a dual threshold ratio. The system employs a robust decision-making logic that pre-sets high load thresholds, low margin thresholds, and low load thresholds. To prevent frequent control command switching due to minor fluctuations in the input signal at threshold boundaries, all thresholds are configured with hysteresis. For example, the trigger value for the high load threshold is 1000 times / second, and its recovery value is set to 800 times / second. When the load monitoring module detects a generation request frequency higher than 1000 times / second and the current seed remaining quantity is lower than a set low margin threshold, such as 1024 bits, the dynamic scheduling module determines the current load state as a high load state and generates an expedited generation command as a dynamic scheduling command, sending it to the true random seed generation unit. Conversely, when the detected generation request frequency is lower than a set low load threshold, such as 100 times / second, and the current seed remaining quantity is higher than a high margin threshold, such as 8192 bits, the system determines the load state as low and generates a frequency reduction generation command. In this way, the system can adjust the seed generation frequency according to the real-time load.
[0036] In an operating environment with electromagnetic interference, the output stability of a single physical entropy source may decrease. Therefore, the true random seed generation unit in this scheme, upon receiving the dynamic scheduling instruction from the cooperative scheduling unit, performs a multi-entropy source fusion generation process. This process integrates subthreshold circuit thermal noise entropy sources, clock jitter entropy sources, and voltage ripple entropy sources. An anti-interference compensation module dynamically adjusts the weight ratio of each entropy source in a weighted model based on its operating state, thereby compensating for the impact of external environmental interference on the output stability of the entropy sources. The update logic for the weight ratio follows these rules: In the formula, For the first The weight percentage of each entropy source in the next control cycle is a dimensionless pure number. For the first The quality factor calculated by an entropy source based on its working state within the current control cycle is a dimensionless pure number. The total number of entropy sources is an integer, and in this embodiment... ; The index number of the entropy source; The index number of the current control cycle; quality factor The calculation is based on at least the bit deviation rate, jitter variance, and pass rate of the standard health test of the original bit stream output by the entropy source. When an entropy source is detected to have a bit deviation rate, jitter variance, and pass rate of the standard health test, the calculation is performed. When the value decreases, the update rule automatically increases the weight of other unaffected entropy sources to maintain the stability of the total entropy value of the final fused true random seed. To adapt to the application requirements of multi-standard compatibility, the internal architecture of the pseudo-random number hardware acceleration unit adopts a multi-algorithm parallel architecture and pipelined processing design. The multi-algorithm parallel architecture integrates multiple dedicated hardware cores for algorithms, such as the SM4 hardware core supporting the Chinese commercial cryptography standard and a dedicated hardware core supporting the post-quantum cryptography standard, and is configured with an algorithm selector. In an initialization step, the system can pre-configure the algorithm selector according to external instructions to adapt the pseudo-random number hardware acceleration unit to a specific cryptographic standard system. When the encryption task issues an instruction, the algorithm selector activates a specific hardware core, which loads the true random seed provided by the true random seed generation unit. Simultaneously, its internal pipelined processing architecture is configured to execute the seed loading iteration operation and result output in parallel across three processing stages. While performing batch pseudo-random number iterations, the system pre-caches and preprocesses the true random seeds needed for the next round, reducing the overall generation latency. To provide traceability in case of anomalies during the encryption process, the binding module is configured to assign a unique identifier to the true random seed during generation, such as a 64-bit ID generated based on a timestamp and hardware serial number. This unique identifier is stored together with the true random seed in the seed cache. When the pseudo-random number hardware acceleration unit loads the true random seed from the cache to generate pseudo-random numbers, the binding module automatically embeds this unique identifier into the preset header field of the generated pseudo-random number, thereby establishing a traceable association between the pseudo-random number and the true random seed. When it is necessary to perform anomaly tracing steps, the unique identifier in the header field of the abnormal pseudo-random number can be read to trace back the working status and weight model of each entropy source when the true random seed corresponding to that unique identifier was generated, as well as the algorithm execution log of the pseudo-random number hardware acceleration unit, providing data for diagnosing the root cause of the problem.
[0037] Example 1: In a fieldbus network of an industrial control system, when hundreds of distributed remote terminal units need to undergo synchronous firmware upgrades, the process requires generating a large number of pseudo-random numbers for establishing temporary secure channels within a preset time window for the security boot program of each unit. Simultaneously, the start-up and shutdown of high-power equipment in the operating environment can cause transient electromagnetic interference. In the initial stage of the firmware upgrade task, the frequency of generation requests received by the pseudo-random number hardware acceleration unit remains below 100 times / second. At this time, the load monitoring module of the collaborative scheduling unit determines that the current seed remaining quantity is higher than the high remaining quantity threshold of 8192 bits. Therefore, the dynamic scheduling module sends a frequency reduction generation command to the true random seed generation unit, making... This unit operates in low-power mode. When the upgrade command is broadcast to the entire network, hundreds of terminal units simultaneously initiate encrypted handshakes within a short period of time, causing the frequency of generation requests to jump to over 1000 times per second. The remaining seed quantity is then consumed and falls below the low reserve threshold of 1024 bits. The collaborative scheduling unit determines that the system has entered a high-load state and switches to sending expedited generation commands. The seed generation frequency of the true random seed generation unit is correspondingly increased to continuously replenish the rapidly consumed seed buffer. This closed-loop adjustment mechanism established by the collaborative scheduling unit based on the consumption of pseudo-random numbers and the supply of true random seeds enables the system to avoid interruption of secure channel establishment due to insufficient seed supply when facing sudden high-concurrency requests.
[0038] During high-load operation, the closing operation of a high-voltage circuit breaker in the field caused continuous voltage ripple and clock signal jitter on the bus. The anti-interference compensation module inside the true random seed generation unit detected the deterioration of the operating status of the clock jitter entropy source and the voltage ripple entropy source, and their respective quality factors. The value decreases; at this point, the unit does not stop seed generation, but rather... The weight update rules automatically reduce the weight ratio of the two disturbed entropy sources, while increasing the weight ratio of the unaffected subthreshold circuit thermal noise entropy source. Through this dynamic compensation of multiple entropy sources, the total entropy value of the final fused true random seed still meets the preset safety requirements under external environmental interference. Then, the pipelined processing architecture of the pseudo-random number hardware acceleration unit loads this true random seed, and the SM4 hardware core activated by the algorithm selector generates a pseudo-random number sequence that conforms to the standard, ensuring that the firmware upgrade tasks of all remote terminal units can be completed under the conditions of electromagnetic interference and time constraints. After the task is completed, as the frequency of generation requests decreases, the system returns to the low-load frequency reduction generation mode, and the hardware resource consumption and power consumption decrease accordingly.
[0039] Example 2: To verify the performance of the technical solution of the present invention under dynamic load and external interference, an experiment was conducted. This experiment was built on a hardware-in-the-loop test platform. The platform used a Field-Programmable Gate Array (FPGA) as the carrier to implement the system under test. A host computer was responsible for generating pseudo-random numbers to request load and recording performance indicators. Simultaneously, a controllable interference signal was injected into the power and clock pins of the FPGA through a signal generator to simulate voltage ripple and clock jitter. The experiment included a sample group and a control group. The sample group fully implemented the technical solution in the specific implementation method, while the control group used a fixed-frequency true random seed supply method, and its multi-entropy source fusion process was an arithmetic average, lacking the ability to adjust based on the working state of the entropy sources. The system features dynamic weight compensation. During the experiment, the same phased request load sequence was applied to both sample groups: first, a low-load phase lasting 30 seconds with a request frequency of 50 requests / second; then, a high-concurrency surge phase lasting 10 seconds with the request frequency jumping to 1500 requests / second; and finally, a high-load stable phase lasting 30 seconds with the request frequency maintained at 1200 requests / second. During the 45th to 55th seconds of the entire test cycle, interference signals were injected into the system via a signal generator. Throughout the experiment, the number of seed buffer underflows, total system power consumption, and average entropy value of the output true random seed were monitored and recorded for each sample group. The average entropy value was obtained by statistically testing the collected seed sequence using the NISTSP800-22 standard test suite.
[0040] Experimental data show that during the low-load phase, the collaborative scheduling unit of the present invention issues a frequency-reduced generation command, and its average power consumption is lower than that of the control group that operates at a constant high frequency. After entering the high-concurrency impact phase, the collaborative scheduling unit of the present invention switches to an expedited generation command, and its seed buffer does not overflow. In contrast, the control group, due to its fixed seed supply rate, experiences multiple buffer overflow events. During the phase of applying external interference signals, the anti-interference compensation module of the present invention adjusts the weight ratio of each entropy source, and its average entropy value of the output seed remains above 0.99 bits / bit. In contrast, the control group, lacking a compensation mechanism, sees its average entropy value of the output seed drop to 0.92 bits / bit. For specific comparison data, please refer to Table 1.
[0041] Table 1: Comparison of key performance indicators of the two sample groups under different working conditions.
[0042] Test sample group Load phase External interference Cache underflow count Average power consumption (mW) Average entropy (bits / bit) control group low load none 0 15.2 0.99 Sample of the present invention low load none 0 4.3 0.99 control group High concurrency impact none 17 15.3 0.99 Sample of the present invention High concurrency impact none 0 18.1 0.99 control group High load stability have 8 15.2 0.92 Sample of the present invention High load stability have 0 18.2 0.99 control group High load stability none 5 15.3 0.99 Sample of the present invention High load stability none 0 18.0 0.99
[0043] Experimental results show that the method claimed in this invention, through the cooperative scheduling unit, can reduce the power consumption of the system during low load periods while satisfying high-concurrency pseudo-random number requests, and through its multi-entropy source fusion and weight compensation mechanism, maintains the high entropy value of the output true random seed when there is external environmental interference.
[0044] Example 3: This example combines Figures 1 to 3 This document describes a method and system for hardware-accelerated pseudo-random number generation combined with true random seed generation, such as... Figure 1 As shown, the architecture consists of a collaborative scheduling unit, a true random seed generation unit, a pseudo-random number hardware acceleration unit, and a binding module. The collaborative scheduling unit generates dynamic scheduling instructions based on the frequency of generation requests and the current remaining seed quantity, which it detects and receives feedback from the pseudo-random number hardware acceleration unit. These instructions are then sent to the true random seed generation unit, which uses these instructions to fuse multi-entropy sources to generate a highly reliable true random seed. This seed is provided to the pseudo-random number hardware acceleration unit to respond to upper-layer encryption task requests and to generate pseudo-random numbers at high speed via a pipeline architecture. It is also provided to the binding module to assign a unique identifier. Subsequently, the pseudo-random number generated by the pseudo-random number hardware acceleration unit is combined with the unique identifier provided by the binding module to finally output a pseudo-random number carrying a unique identifier, thereby establishing a complete traceable association.
[0045] like Figure 2 As shown, the quality factors of the three different physical entropy sources it integrates—subthreshold circuit thermal noise entropy source, clock jitter entropy source, and voltage ripple entropy source—are as follows. The dynamic process over time is shown in the graph. During the time interval from 40 to 60 seconds, when the quality factors of the clock jitter entropy source and the voltage ripple entropy source decrease significantly due to external interference, the quality factor of the subthreshold circuit thermal noise entropy source can still remain at a relatively stable high level.
[0046] like Figure 3 As shown, after initialization, the system enters a low-load state, in which it issues a reduced-frequency generation command. When the generation request frequency is higher than the high threshold and the remaining seed quantity is lower than the low threshold, the system migrates to a high-load state and switches to sending an expedited generation command. When the high-load condition is no longer met, the system returns to the low-load state. In addition, under any normal operating condition, once all entropy sources are detected to be continuously faulty, the system will immediately enter a fault-safe state, performing a series of actions such as pausing response, clearing the cache, and enabling emergency mechanisms, until the entropy source state is restored and stabilized for a preset duration before returning to the initial low-load state. This constitutes a complete closed-loop control process covering normal operation and abnormal handling.
[0047] Example 4: To calibrate the various thresholds of the collaborative scheduling unit and clarify the quality factor in the anti-interference compensation module. The calculation procedure involves an offline parameter calibration. This procedure is executed on a hardware-in-the-loop test platform. A series of preset pseudo-random number request sequences, designed to simulate the load characteristics of different application scenarios, are loaded onto the host computer, and the system's power consumption and response latency are monitored simultaneously. The high load threshold is set by balancing the system's response timeliness with instantaneous power consumption. By gradually increasing the request frequency and observing the seed cache consumption rate, the minimum request frequency that prevents the number of seeds in the cache from continuously decreasing is multiplied by a safety factor of 1.2 and determined as the high load threshold. The low load threshold is set by balancing power consumption with state switching frequency. By gradually decreasing the request frequency, the request frequency corresponding to the inflection point where the slope of the system's average power consumption curve first shows a decrease is determined as the low load threshold.
[0048] Furthermore, in order to transform the evaluation process of the entropy source's working state into a deterministic calculation process, the quality factor... The calculation is defined as a standardized weighted summation process, which normalizes the operating state parameters of each measurable entropy source and assigns different weights based on their influence on the stability of the final entropy value; the specific calculation method is as follows: In the formula, For the first An entropy source in the current control cycle The quality factor is a dimensionless value. The bit deviation rate of the original bit stream output by the entropy source is a dimensionless value. This represents the jitter variance, expressed in squared time units. This is a preset upper limit reference value for jitter variance based on hardware characteristics, and its unit is... same; The pass rate of this entropy source in the current period for passing the NISTSP800-90B standard health test is a dimensionless value between 0 and 1. The weighting coefficients are preset and sum to 1. In this embodiment, the three are labeled as 0.5, 0.3, and 0.2, respectively. This procedure transforms the evaluation of the quality factor from a qualitative description into a calculation process determined by objectively measurable inputs and fixed coefficients.
[0049] Example 5: When the technical solution of the present invention is deployed in an on-board computing unit, in order to cope with the boundary condition that all physical entropy sources experience functional failures, the system has a built-in fault-safe procedure; the trigger condition of this procedure is set as follows: when the anti-interference compensation module detects the quality factor of all entropy sources. The sum of When the value is consistently below a pre-defined system-level safety threshold for more than a preset time period (e.g., 100ms), the failsafe procedure is automatically activated.
[0050] Once the procedure is activated, the cooperative scheduling unit suspends its response to all new pseudo-random number generation requests and instructs the clearing of all seeds in the current seed buffer to avoid using any data that may have insufficient entropy. Simultaneously, the system enters a predefined safe state. In this state, a device-unique key, pre-configured before chip shipment and stored in the on-chip one-time programmable fuse memory, is used to generate an emergency pseudo-random number sequence through a deterministic key derivation function. This emergency sequence is used only to perform a preset highest-priority operation: recording critical system status logs and triggering a safe restart. After this, the system will continuously monitor the working status of each entropy source until its total quality factor recovers to above the safe threshold and remains stable for a preset duration before exiting the safe state and resuming the pseudo-random number generation service.
[0051] Example 6: Before deploying the system in the target operating environment, a pre-calibration process is performed to solidify the key parameters in its fail-safe procedures. This process utilizes the same hardware-in-the-loop test platform as in Example 2, applying quantifiable, progressively stronger interference signals to each entropy source through a signal generator, and simultaneously evaluating the entropy value of the final output true random seed using the NISTSP800-22 standard test suite. The entropy value is determined when the output entropy value first falls below the 0.99 bits / bit safety baseline. The numerical value, multiplied by a safety factor of 0.9, is determined as the system-level safety threshold; simultaneously, the quality factor of each entropy source after the interference is removed is recorded. The maximum time required to recover to a stable state is determined, and three times this maximum recovery time is set as the preset duration for maintaining stability to exit the safe state.
[0052] In addition, to address the situation where a certain entropy source is in a low-quality output state for an extended period, the anti-interference compensation module integrates a slow-state monitoring logic; this logic calculates the quality factor of each entropy source over a relatively long time window, such as 10 seconds. If the moving average of the quality factor of a certain entropy source is continuously lower than a preset maintenance threshold, the system will mark the entropy source as being in a long-term unstable state and temporarily suspend it from the multi-entropy source fusion generation process. Only the other entropy sources will participate in the weight calculation, and a maintenance alarm will be issued to the external management system. The suspended entropy source will be automatically woken up by the system at a preset period and undergo a short-term quality check until its quality factor moving average recovers to above the maintenance threshold before it can be rejoined in the fusion generation process. This mechanism avoids the long-term occupation of the dynamic weight compensation computing resources due to the continuous failure of a certain entropy source.
[0053] Example 7: During a routine security audit following an industrial control system firmware upgrade, the monitoring system detected that a pseudo-random number sequence generated by one of the remote terminal units for session key negotiation failed subsequent randomness checks, triggering an encryption anomaly alarm. To trace the root cause of this anomaly, auditors read the unique identifier embedded in the header field of the abnormal pseudo-random number sequence and used this identifier to trace back to the generation record of its initial true random seed through the binding module. The record showed that at the time the true random seed was generated, its corresponding quality factor was... In the calculation results, the score contributed by the clock jitter entropy source showed a momentary decrease, while the weighted model correspondingly increased the proportion of the other two entropy sources. By comparing this data with the device operation log, the root cause of the anomaly was finally located to a power module upstream of the terminal unit that experienced a momentary failure. Although the failure did not interrupt the service, the electromagnetic interference it generated briefly affected the stability of the clock entropy source. This process verified the role of traceable correlation in quickly and accurately locating the root cause of occasional hardware security risks.
[0054] To verify from the reverse direction the non-obviousness and technical advantages of the collaborative scheduling and dynamic compensation mechanism described in this invention compared to existing conventional technology combinations, the following comparative example 1 is set up.
[0055] Comparative Example 1: This comparative example aims to simulate the conventional technical path most likely to be adopted by those skilled in the art when facing the same technical problem as the present invention. To this end, this comparative example uses the same hardware-in-the-loop test platform, FPGA carrier, host computer and signal generator as the aforementioned Example 2, and applies the same phased request load sequence and external interference signal. The only difference between this comparative example and Example 2 is that its system architecture follows a separate design approach lacking a direct correlation mechanism, specifically reflected in the following two points: No collaborative scheduling unit: The true random seed generation unit adopts a fixed frequency working mode. In order to cope with high concurrency impact, this fixed frequency is redundantly designed according to the peak request frequency (1500 times / second) in Example 2 and is set as a constant high generation rate, which does not change dynamically with the load; No dynamic weight compensation: The multi-entropy source fusion process adopts the arithmetic average method known in the art, that is, simply averages and mixes the outputs of each entropy source, without having the function of dynamically adjusting the weight according to the real-time working status of each entropy source.
[0056] During the initial low-load phase of the experiment (50 requests / second), the system's true random seed generation unit continuously operated at the designed high rate, resulting in a significantly higher average power consumption than the sample group in Example 2, reaching 15.2mW, causing obvious energy waste. When entering the high-concurrency surge phase (request frequency jumps to 1500 requests / second), although its fixed generation frequency was designed according to the peak value, due to the lack of closed-loop perception and predictive acceleration capability for the remaining amount in the seed buffer, 17 brief underflow events still occurred in the buffer at the moment the request frequency switched from low to high. These underflow events caused delays in the upper-layer encryption task due to waiting for the seed, with 4 of these delays exceeding the system's preset timeout threshold. The layer application returned an error indicating failure to acquire encrypted resources. During the high-load stable phase (45 to 55 seconds) when external interference signals were applied, due to the deterioration of the output quality of the clock jitter entropy source and the voltage ripple entropy source, an arithmetic averaging fusion method was used to indiscriminately mix the high-quality thermal noise entropy source with the outputs of the two low-quality entropy sources. After sampling and statistically testing the seed sequence output during this phase using the NISTSP800-22 standard test suite, it was found that the average entropy value dropped significantly to 0.92 bits / bit. This value is lower than the security baseline of 0.99 bits / bit typically required for cryptographic applications, which means that the generated pseudo-random number sequence has a predictable risk and constitutes a security vulnerability. See Table 2 for specific comparative data.
[0057] Table 2: Comparison of key performance indicators between Comparative Example 1 and the present invention sample under the same working conditions.
[0058] Test sample group Load phase External interference Cache underflow count Average power consumption (mW) Average entropy (bits / bit) Comparative Example 1 low load none 0 15.2 0.99 Sample of the present invention low load none 0 4.3 0.99 Comparative Example 1 High concurrency impact none 17 15.3 0.99 Sample of the present invention High concurrency impact none 0 18.1 0.99 Comparative Example 1 High load stability have 8 15.2 0.92 Sample of the present invention High load stability have 0 18.2 0.99
[0059] The experimental results show that the conventional combination of fixed-frequency seeding and arithmetic averaging cannot balance power efficiency and business continuity when dealing with dynamic loads, and cannot guarantee the cryptographic security of the output true random seed when there is external environmental interference.
[0060] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0061] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for hardware-accelerated pseudo-random number generation combined with true random seed generation, characterized in that, include: The frequency of generation requests from the pseudo-random number hardware acceleration unit and the current remaining seed quantity are collected to jointly determine the current load status. Based on the current load status, a dynamic scheduling instruction is generated and sent to the true random seed generation unit. This dynamic scheduling instruction limits the seed generation frequency of the true random seed generation unit. The true random seed generation unit receives dynamic scheduling instructions and executes the multi-entropy source fusion generation process to produce a true random seed. The multi-entropy source fusion generation process includes: real-time monitoring of the working status of each entropy source that constitutes the multi-entropy source, and dynamically adjusting the weight ratio of each entropy source in the weight model according to the working status, so as to compensate for the impact of external environmental interference on the stability of the entropy source output. The pseudo-random number hardware acceleration unit loads a true random seed and generates pseudo-random numbers via a pipelined processing architecture; Assign a unique identifier to the true random seed and embed the unique identifier into the preset header field of the pseudo random number, thereby establishing a traceable link between the pseudo random number and the true random seed.
2. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 1, characterized in that, The steps for determining the current load state and generating dynamic scheduling instructions specifically include: when the frequency of generation requests is detected to be higher than the high load threshold and the current remaining seed quantity is lower than the low remaining seed quantity threshold, the current load state is determined to be a high load state, and an expedited generation instruction is generated as a dynamic scheduling instruction to increase the seed generation frequency; when the frequency of generation requests is detected to be lower than the low load threshold and the current remaining seed quantity is higher than the high remaining seed quantity threshold, the current load state is determined to be a low load state, and a reduced frequency generation instruction is generated as a dynamic scheduling instruction.
3. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 1, characterized in that, The multi-entropy source fusion generation process performed by the true random seed generation unit includes at least two of the following entropy sources: subthreshold circuit thermal noise entropy source, clock jitter entropy source, and voltage ripple entropy source.
4. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 1, characterized in that, The pseudo-random number hardware acceleration unit includes multiple algorithm hardware cores covering different cryptographic standards, and an algorithm selector for activating a specific hardware core according to external instructions; the step of loading a true random seed in the pseudo-random number hardware acceleration unit is specifically performed by the algorithm hardware core activated by the algorithm selector.
5. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 4, characterized in that, The pipelined processing architecture is configured to execute the three processing stages of seed loading, iterative computation, and result output in parallel.
6. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 1, characterized in that, The method also includes an anomaly tracing step: when an anomaly monitoring instruction for a certain pseudo-random number is received, the unique identifier in the header field of the pseudo-random number is read, and based on the unique identifier, the working status of each entropy source is traced back when the true random seed corresponding to the unique identifier is generated, and the weight ratio of each entropy source in the weight model is dynamically adjusted. The update logic follows the following rules: ,in, For the first The weight percentage of each entropy source in the next control cycle. For the first The quality factor calculated by each entropy source based on its operating state within the current control cycle. This represents the total number of entropy sources.
7. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 2, characterized in that, In the step of determining the current load status, the high load threshold, low margin threshold, low load threshold, and high margin threshold are all configured as thresholds with hysteresis.
8. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 7, characterized in that, quality factor The calculations are based on at least the following working states: Bit deviation rate, jitter variance, and health test pass rate of each entropy source.
9. The method for hardware-accelerated pseudo-random number generation and true random seed co-generation according to claim 4, characterized in that, The method also includes an initialization step: before performing the acquisition step, the algorithm selector is pre-configured according to external instructions.
10. A pseudo-random number hardware acceleration and true random seed collaborative generation system, used to implement the method of any one of claims 1 to 9, characterized in that, include: The collaborative scheduling unit is configured to collect the generation request frequency and the current remaining seed amount of the pseudo-random number hardware acceleration unit, so as to jointly determine the current load status. Based on the current load status, a dynamic scheduling instruction is generated and sent to the true random seed generation unit. This dynamic scheduling instruction limits the seed generation frequency of the true random seed generation unit. The true random seed generation unit is configured to: receive dynamic scheduling instructions and execute a multi-entropy source fusion generation process to produce a true random seed. The multi-entropy source fusion generation process includes real-time monitoring of the working status of each entropy source constituting the multi-entropy source and dynamically adjusting the weight ratio of each entropy source in the weight model according to the working status. The pseudo-random number hardware acceleration unit is configured to load a true random seed and generate pseudo-random numbers via a pipelined processing architecture. The binding module is configured to assign a unique identifier to the true random seed and embed the unique identifier into the preset header field of the pseudo random number, thereby establishing a traceable association between the pseudo random number and the true random seed.
Citation Information
Patent Citations
Ultrahigh-safety true random number generation method and ultrahigh-safety true random number generation system
CN104317551A
Encryption key generator and transmitting system
CN112291056A