Side channel attack resistant circuit compiling method based on unique random protection

By adopting a circuit compilation method based on unique random protection to resist side-channel attacks, the problems of high randomness consumption and large hardware overhead in the prior art are solved. It achieves low randomness consumption and multi-round security, supports fully automated secure circuit compilation, and ensures the formal security of the circuit under the robust detection model.

CN121308947APending Publication Date: 2026-01-09INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511731980.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-24
Publication Date
2026-01-09

AI Technical Summary

Technical Problem

Existing technologies for designing circuits resistant to side-channel attacks suffer from high randomness consumption, large hardware overhead, and difficulty in performing multi-round formal security verification, especially due to their strong dependence on online random number generators.

Method used

A circuit compilation method for resisting side-channel attacks based on unique randomness protection is adopted. By introducing a unique randomness protection criterion, the mask dependency relationship in the circuit is systematically analyzed and transformed, eliminating the dependence on online random number generators, achieving low randomness consumption and multi-round security. The compiler algorithm is used to automatically process the circuit, ensuring the formal security of the circuit under the robust detection model.

Benefits of technology

It achieves rigorous formal security under a physical reality model, reduces hardware area overhead and power consumption, supports fully automated secure circuit compilation, cuts off the algebraic dependency between module output and internal random set, provides provable multi-round security, and lowers the design threshold.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SMS_26
    Figure SMS_26
  • Figure SMS_37
    Figure SMS_37
  • Figure SMS_52
    Figure SMS_52
Patent Text Reader

Abstract

The invention discloses an anti-side channel attack circuit compiling method based on unique random protection, and belongs to the field of cryptographic engineering and hardware security. In order to solve the problem of contradiction between low random consumption and multiple rounds of safety certification of the existing mask scheme, a robust detection safety model and a unique random protection criterion are constructed; initial masking is carried out on circuit main input, linear and nonlinear gates are converted according to a topological sequence, protection collision detection and correction, module output re-masking and random number recovery and safe reutilization are executed, and an overall safe combination structure is constructed. The method can systematically generate a mask circuit which has provable first-order security and can resist glitch attacks under the condition of only depending on the initial random entropy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of cryptographic engineering and hardware security, specifically to a method for compiling circuits to resist side-channel attacks based on unique random protection. Background Technology

[0002] With the widespread adoption of Internet of Things (IoT) devices in smart homes, critical infrastructure, and other fields, the security of their embedded cryptographic applications has become the cornerstone of digital trust. However, traditional cryptography typically assumes an idealized "black box" model, where algorithms are vulnerable only to mathematical attacks. In practice, this assumption is fundamentally challenged by side-channel attacks (SCAs), where attackers exploit physical leaks such as power consumption, electromagnetic radiation, and time information to extract keys directly from the hardware implementation.

[0003] To counter side-channel attacks, masking has become a mainstream provable security strategy. Based on the secret-sharing principle, it splits sensitive variables into multiple shares, ensuring that any subset of shares below a certain number cannot reveal the secret information. The security of this scheme is formally defined in the probing model: if any maximum number of shares cannot be revealed... If a combination of intermediate values ​​is statistically independent of the secret, then the implementation is called a secret. Security level.

[0004] However, real-world hardware effects, particularly glitch effects, introduce additional leakage, prompting the emergence of more robust security models, such as the Robust Probing Model. In this context, Threshold Implementation (TI) provides provable glitch resistance by enforcing correctness, incompleteness, and uniformity. However, this high level of security often comes with significant hardware overhead; for example, protecting a system with a generation number of... The function reaches Level security, the original structure requires One share, for AES S box ( For complex nonlinear functions such as , it is difficult to bear.

[0005] To manage the number of shares, existing techniques typically decompose complex functions into quadratic function components. However, this strategy, along with other efficient masking schemes (such as those requiring only...), ... All schemes (individual share schemes) face a common bottleneck: a huge reliance on fresh online randomness. This is because after nonlinear operations, new random values ​​must be consumed to restore security properties such as uniformity.

[0006] Existing technologies attempt to reduce randomness consumption in two ways: optimizing the internal design of cryptographic components (such as TI) and reusing randomness at the architectural level (such as Changing of the Guards, COTG). However, randomness reuse introduces complex dependencies, making formal security verification extremely difficult, and security proofs are often limited to a single round or a single "super-box". To achieve multi-round provable security, it is typically necessary to periodically inject fresh randomness to break long-term dependencies.

[0007] Therefore, a core challenge in this field has long existed: how to design a randomness reuse scheme that is not only efficient but also easy to perform formal multi-round security analysis in actual hardware models, while completely eliminating the dependence on online random number generators (RNGs). Summary of the Invention

[0008] The purpose of this invention is to address the technical problem of the contradiction between achieving low randomness consumption and providing provable multi-round security in existing masking schemes, especially those based on random number multiplexing technology. This invention provides a novel, universal, and low-randomness-consumption side-channel attack protection method, aiming to completely eliminate the dependence on online random number generators while providing rigorous formal security proofs for the entire cryptographic circuit (including multi-round iterations), thereby overcoming the limitations of existing technologies in security proofs.

[0009] To achieve the above objectives, the present invention adopts the following technical solution.

[0010] A method for compiling a side-channel attack resistant circuit based on unique random protection includes the following steps: 1) Obtain the formal description of the standard circuit to be compiled and set the security constraints. The formal description includes a directed acyclic graph structure consisting of a set of main inputs, a set of outputs, a set of logic gates, a set of interconnects, and a set of registers. The security constraints are set as a robust detection security model and a unique randomness protection criterion. 2) Perform initial masking processing on the main input of the standard circuit described in step 1), introduce an independent one-time random bit for each main input, and split the main input value into two or more input shares containing the random bit to construct a first-order masked input structure; 3) Traverse the logic gates in the standard circuit in topological order. When the traversed logic gate is a linear logic gate, call the input share generated in step 2) or the intermediate share generated by the preceding logic gate as the input, perform independent linear operations by share, and generate a linear output share. 4) When the logic gate encountered is a non-linear logic gate, call the input share generated in step 2) or the intermediate share generated by the preceding logic gate as input, calculate the random protection set of the connection where the input share is located and detect the intersection relationship of the two input protection sets. Based on the detection result, perform the logic transformation of introducing new random bits or inserting registers to generate a non-linear output share that satisfies the unique randomness protection criterion. 5) Define the substructure in the circuit as a circuit module. At the output interface of the circuit module, perform output remasking on the linear output share generated in step 3) or the nonlinear output share generated in step 4). Introduce independent new random bits and perform XOR operation with the original output share to generate a remasked output share that is decoupled from the random dependencies inside the module. 6) Based on the processing result of generating the remasked output share in step 5), identify the dependency relationship of random protection sets between circuit modules, perform random number reclamation operation that marks the random bits used inside the module as reusable, or perform random number sharing operation between parallel modules. 7) Based on the mask structures of each logic gate and module generated in steps 1) to 6), they are serially combined according to the connection relationship of the original standard circuit to generate the final anti-side channel attack mask circuit.

[0011] Furthermore, the unique randomness protection criterion in step 1) specifically refers to: for any internal variable in the circuit, it is decomposed into a Boolean function of secret input and partial random source, and the XOR sum of the unique random component corresponding to the internal variable, and the unique random component follows a uniform distribution.

[0012] Further, the initial masking process in step 2) specifically refers to splitting each main input into a first share and a second share, wherein the second share is an introduced one-time random bit, and the first share is the XOR value of the main input value and the one-time random bit.

[0013] Furthermore, performing independent linear operations by share in step 3) means that for the XOR gates and NOT gates in the circuit, the corresponding bitwise XOR or NOT operations are directly performed on the input shares without introducing additional random bits.

[0014] Furthermore, in step 4), the random protection set of the connection where the input share is located refers to: identifying and aggregating all random bits that affect the current connection share value.

[0015] Furthermore, step 4) involves performing logical transformations based on the detection results, such as introducing new random bits or inserting them into registers, and includes the following three processing methods: (1) When the two input protection sets do not intersect, two independent new random bits are introduced, and XORed with the product terms of the two input shares respectively and stored in registers to generate the output share; (2) When two input protection sets have a non-empty intersection but at least one input has a unique random bit that the other does not have, insert a register at the input that has the unique random bit; (3) When the two input protection sets are completely identical or there is no algebraically unique random bit, a refresh random bit is introduced to perform an XOR refresh operation on one of the input shares.

[0016] Furthermore, the specific processing of the output remasking in step 5) includes: introducing a new random bit, calculating the XOR sum of the original first output share, the new random bit, and the original second output share, and using it as the new first output share; and using the new random bit as the new second output share.

[0017] Furthermore, in step 6), performing random number sharing between parallel modules means that between two parallel circuit modules whose input protection sets do not intersect, the random value of the input mask of one module is used as the random bits required for calculation by the other module.

[0018] Furthermore, in step 6), performing a random number reclamation operation to mark the random bits used inside the module as reusable means converting a variable with multiple old random bit masks into a variable with only one new random bit mask, and marking the originally occupied old random bits as releasable.

[0019] Further, in step 7), serial combination means that when the output of the first module is used as the input of the second module, the output remasking operation described in step 5) or the refresh operation described in step 4) is performed at the output interface of the first module, and then the processed signal is transmitted to the second module to ensure that the input of the downstream module meets the unique randomness protection criterion.

[0020] Compared with the prior art, the present invention has achieved the following beneficial effects.

[0021] 1. Achieves rigorous formal security under a physical reality model: This invention is based on a robust detection model that considers the glitches effect, rather than relying on heuristic assumptions. By introducing the Unique Randomness Protection (URG) criterion, it systematically analyzes and transforms the mask dependencies in the circuit, ensuring that any detectable circuit point is protected by a unique random variable derived from the initial entropy, thus providing rigorously mathematically provable security against side-channel attacks.

[0022] 2. This invention completely solves the "trilemma" of security, area, and random number consumption: It eliminates the need for an online random number generator (RNG), requiring only a fixed initial random entropy during circuit initialization. Through a pioneering randomness security reclamation and formal reuse mechanism, first-order security is achieved using only the theoretically minimum share (2 shares). This significantly reduces hardware area overhead and power consumption, solving the problems of high cost and continuous demand for fresh random numbers in traditional high-order masking schemes.

[0023] 3. Supports fully automated compilation of secure circuits, lowering the design threshold: This invention is implemented in the form of a compiler algorithm, which can automatically convert any standard logic circuit into a mask circuit that meets first-order security requirements. This automated process not only significantly improves design efficiency but also avoids dependency vulnerabilities caused by negligence in manual design, ensuring the consistency and correctness of security policy implementation.

[0024] 4. A modular, composable, low-randomness design architecture is established: Based on the output remasking mechanism, this invention severs the algebraic dependency between the module output and the internal random set, allowing designers to independently verify the security of submodules and securely combine them according to predefined interface rules. This architecture not only supports the construction of large-scale complex cryptographic systems but also lays a solid theoretical and practical foundation for future extensions to higher-order security masking schemes. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be described in detail below with reference to specific embodiments. It should be noted that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it.

[0026] This invention proposes a method for compiling circuits to resist side-channel attacks based on unique random protection. Through a rigorous formal model and a systematic compilation process, any standard circuit can be automatically converted into a masked circuit that meets first-order robust detection security requirements. The specific implementation steps of this method are as follows.

[0027] Step 1: Establish a security model and formal foundation.

[0028] As a prerequisite for the compilation process, a formal description of the cryptographic circuit to be protected is first constructed, and the security constraints are defined.

[0029] 1. Formal circuit model.

[0030] The calculation process is formalized as a circuit. It contains the following components.

[0031] Input and output: The input is collected in a set of random variables. In the set (assuming all inputs are secrets that need to be protected), the output is in the set. middle.

[0032] Gates: The basic Boolean operators (AND, NOT, XOR) that make up combinational logic.

[0033] Line: A directed edge that passes values ​​between gates, the set of which is... During runtime, each line Each carries a random variable.

[0034] Registers: Sequential elements that separate combinational logic blocks in time. Registers are represented by [ ].

[0035] 2. Safety constraint objectives.

[0036] This invention aims to provide provable security within a robust d-probing security model. This model is designed to more realistically capture leaks in hardware, particularly glitches.

[0037] Extended Probe: In this model, a single probe of a line reveals not only the value of the line itself, but also the values ​​of all the combined inputs that drive the line.

[0038] Security determination: If for any The joint distribution of all variables revealed by this type of extended probe All of them are related to secret input. Statistical independence, i.e., satisfying If so, the mask circuit is said to be robust d-probe secure. This embodiment mainly targets... First-order safety.

[0039] 3. Unique randomness protection criterion.

[0040] This invention introduces the Unique Randomness Guard (URG) criterion to characterize the statistical independence of internal circuit variables from secret inputs.

[0041] The cryptographic circuit to be protected is represented as a directed acyclic graph consisting of logic gates, wires, and registers. For any set of internal probe points in the circuit... Each internal variable (or probe point) All possible values ​​can be represented as secret inputs. With all random sources Boolean function, denoted as .

[0042] URG definition: If there exists a subset of random sources... and a function that maintains uniformity. (in ), such that each internal variable in set A can be decomposed into: in For function The One component is used to provide internal variables. The unique random component. If the random subset If it follows a uniform distribution, then by The generated output vector is also in It is evenly distributed on the surface.

[0043] This invention demonstrates that if a set of internal variables (or a set of probe points) A possesses an URG that satisfies the above definition, then the joint probability distribution of this set is as follows: The set is uniform, and the statistical distribution of any Boolean function acting on it is identical to that of the secret input. Independent. Therefore, as long as a URG can be constructed for a certain set of internal probe points, it can be formally proven that the set does not reveal any information about the secret input.

[0044] Based on the aforementioned formal criteria, this invention further defines the security objective of the circuit as follows: Under a first-order robust probing model, the attacker's probing results for arbitrary register input signals should remain statistically independent of the secret inputs processed by the circuit. This security objective, along with the URG criterion, constitutes the theoretical basis for the subsequent compiler design and security transformation strategies of this invention.

[0045] Step 2: Perform initial masking processing on the main input of the circuit.

[0046] This invention provides a secure compiler for automatically converting any standard circuit into a first-order probe-secure masked circuit that satisfies the principle of unique randomness protection. The compiler uses secure cryptographic components as its basic building blocks and combines them with a systematic logic transformation process to replace and combine various logic gates in the original unmasked circuit one by one, thereby ensuring that the generated masked circuit meets first-order security requirements.

[0047] As the first step in getting data into the system, the compiler uses a Boolean mask to encode each main input of the original circuit: 1. Introduce a one-time random bit that is provided independently during the circuit initialization phase for each main input; 2. Split the input value into two parts to construct a first-order ( The mask structure ensures that the input data has basic randomness protection before entering the operation logic.

[0048] The core of the compiler lies in replacing standard logic gates with safe gadgets; its basic building blocks include linear and nonlinear components. Step 3: Traverse the circuit in topological order and convert linear gates.

[0049] The compiler scans the circuit topology in order, first using linear components to process low-risk linear logic gates.

[0050] For linear operations such as XOR and NOT, no additional random source is introduced because they can be executed independently across different shares without mixing share information. The mask implementation of linear gates directly computes on a share-by-share basis, for example: in, and For input shares, For output share.

[0051] Step 4: Process the nonlinear gates and perform collision detection.

[0052] For nonlinear gates (especially AND gates), since their mixed share information is a major source of side-channel leakage, fresh randomness must be introduced. This step uses nonlinear components for processing, and by analyzing the randomness dependencies, detects and resolves "guard collisions," automatically taking appropriate corrective measures at each nonlinear gate to ensure that the final circuit meets first-order probe safety.

[0053] 1. Calculate the random protection set.

[0054] For any connection in the circuit Define the randomness protection set This set includes... The share of each random bit has an effect on all random bits.

[0055] 2. Perform collision detection and correction.

[0056] When a nonlinear gate (such as a standard first-order safety AND gadget) has two inputs and When they share at least one identical initial random bit, that is, when they satisfy... If the condition is met, a protective collision is considered to have occurred. A collision implies a fresh random number introduced within standard safety AND gadgets. and This may not be sufficient to ensure the output URG, thus leading to the risk of side-channel leakage.

[0057] The compiler of this invention traverses all gates in the topological order of the circuit and implements a hierarchical collision resolution strategy for each nonlinear gate, specifically including the following three cases: (1) No collision ( ).

[0058] If the two input protection sets are disjoint, it means that each is completely protected by an independent random source, satisfying the URG precondition. In this case, the standard first-order secure AND tool can be used directly, through two independent random bits. and It provides additional random masking, using new random bits internally to guarantee the safety of the output. Its implementation is as follows: Among them, square brackets Indicates a register.

[0059] (2) Partial collision ( However, at least one side has a unique protection.

[0060] If the protection sets of two inputs overlap, but at least one input contains a unique random bit that the other does not possess (e.g., If the unique protection is present, then this unique protection can be used as the URG of the output. The compiler ensures that the nonlinear operation meets the URG requirements by inserting a register at the input with the unique protection, thus fixing this unique random bit as the unique random source of the gate.

[0061] (3) Severe collision ( (Or one party's protection set is completely contained within the other party's).

[0062] If the guard sets of the two inputs are exactly the same or there are no algebraically unique random bits, the output URG cannot be directly formed. In this case, a refresh operation must be performed on one of the inputs. The refresh device remasks the input using a new random bit, rerandomizing its components, as typically shown below: This operation constructs a completely new and independent set of protections for the input, fundamentally breaking the original protection dependencies and thus eliminating collisions.

[0063] 3. Output generation.

[0064] After the above strategy adjustments, nonlinear gate share outputs that satisfy the URG criterion are generated. Through the above-mentioned random dependency-aware collision detection and correction mechanism, it is possible to ensure that all inputs to nonlinear operations meet the URG requirements while maintaining functional correctness, thus enabling the final generated mask circuit to have formally provable detection security in the first-order model.

[0065] Step 5: Perform output remasking at the circuit module interface.

[0066] The output share of a circuit module typically depends on multiple random bits used within that module. Directly reusing these random bits can lead to the propagation of randomness dependencies across modules, compromising the security of subsequent modules. To address this, this invention proposes an Output Re-Masking mechanism. This mechanism utilizes a completely new and independent random bit. The module output is remasked to achieve the following transformation: This transformation preserves the encoded values, but makes the new output shares completely dependent on the new random bits. This severs all algebraic dependencies between the internal random set and the module's internal random set. After remasking, the internal random set is officially "released" and can be safely used for a new round of calculations in unrelated modules of the circuit.

[0067] Step 6: Perform random number reclamation and secure reuse based on the remasking results.

[0068] After remasking and severing dependencies, the randomness resources within the circuit are optimized and managed.

[0069] 1. Secure random number sharing (parallel random number borrowing).

[0070] For two parallel-executing circuit submodules and If its initial input protection set and If they do not intersect, then it is allowed. Will A random mask value from the input share is used as the "fresh" random bits required for its own computation. Because this random value... Completely unknown and unique, from From this perspective, it is equivalent to a true random number, thus achieving secure sharing of randomness.

[0071] 2. Explicit random number recycling (centralized reconstruction of randomness).

[0072] If a variable Composed of multiple random bit sets Common mask; to release these random bits, this invention uses a reconstruction device to... Converted to only one new random bit Mask share: Converted shares and Completely decoupled algebraically, making It can be safely recycled and reused in circuits.

[0073] Step 7: Construct the overall security portfolio structure based on the above steps.

[0074] Based on the above output remasking mechanism, a safe combination rule suitable for large-scale circuit design is established, including both parallel combination and serial combination scenarios.

[0075] 1. Parallel combination rules.

[0076] If the initial input mask sets of two parallel circuit modules are disjoint, their internal computations can safely "borrow" each other's input random protection as needed, achieving random bit sharing between parallel modules. This sharing method is based on the random set decoupling guaranteed by the output remasking, and its security can be proven.

[0077] 2. Serial combination rule.

[0078] When the upstream circuit module The output is used as a downstream module. When inputting into the downstream module, to ensure that the input meets the Unique Random Guard (URG) property, a remasking device can be inserted at the module interface to ensure that the circuit output still meets this property. This step is for entering... The signals are re-established with independent random protection to ensure the safety of the overall circuit after serial combination in terms of random dependencies.

[0079] Through the above steps, the present invention can systematically convert any given cryptographic circuit into a mask circuit with provable first-order security and resistance to glitch attacks, depending only on the initial random entropy of the circuit.

[0080] Although the present invention has been disclosed above with reference to embodiments, it is not intended to limit the present invention. Appropriate modifications or equivalent substitutions made by those skilled in the art to the technical solutions of the present invention should be covered within the protection scope of the present invention, which is defined by the claims.

Claims

1. A method for compiling a circuit to resist side-channel attacks based on unique random protection, characterized in that, Includes the following steps: 1) Obtain the formal description of the standard circuit to be compiled and set the security constraints. The formal description includes a directed acyclic graph structure consisting of a set of main inputs, a set of outputs, a set of logic gates, a set of interconnects, and a set of registers. The security constraints are set as a robust detection security model and a unique randomness protection criterion. 2) Perform initial masking processing on the main input of the standard circuit described in step 1), introduce an independent one-time random bit for each main input, and split the main input value into two or more input shares containing the random bit to construct a first-order masked input structure; 3) Traverse the logic gates in the standard circuit in topological order. When the traversed logic gate is a linear logic gate, call the input share generated in step 2) or the intermediate share generated by the preceding logic gate as the input, perform independent linear operations by share, and generate a linear output share. 4) When the logic gate encountered is a non-linear logic gate, call the input share generated in step 2) or the intermediate share generated by the preceding logic gate as input, calculate the random protection set of the connection where the input share is located and detect the intersection relationship of the two input protection sets. Based on the detection result, perform the logic transformation of introducing new random bits or inserting registers to generate a non-linear output share that satisfies the unique randomness protection criterion. 5) Define the substructure in the circuit as a circuit module. At the output interface of the circuit module, perform output remasking on the linear output share generated in step 3) or the nonlinear output share generated in step 4). Introduce independent new random bits and perform XOR operation with the original output share to generate a remasked output share that is decoupled from the random dependencies inside the module. 6) Based on the processing result of generating the remasked output share in step 5), identify the dependency relationship of random protection sets between circuit modules, perform random number reclamation operation that marks the random bits used inside the module as reusable, or perform random number sharing operation between parallel modules. 7) Based on the mask structures of each logic gate and module generated in steps 1) to 6), they are serially combined according to the connection relationship of the original standard circuit to generate the final anti-side channel attack mask circuit.

2. The method as described in claim 1, characterized in that, The unique randomness protection criterion in step 1) specifically refers to: for any internal variable in the circuit, it is decomposed into a Boolean function of secret input and partial random source, and the XOR sum of the unique random component corresponding to the internal variable, and the unique random component follows a uniform distribution.

3. The method as described in claim 1, characterized in that, The initial masking process in step 2) specifically refers to splitting each main input into a first share and a second share, where the second share is an introduced one-time random bit, and the first share is the XOR value of the main input value and the one-time random bit.

4. The method as described in claim 1, characterized in that, Step 3) Performing independent linear operations by share means that for the XOR gates and NOT gates in the circuit, the corresponding bitwise XOR or NOT operations are directly performed on the input shares without introducing additional random bits.

5. The method as described in claim 1, characterized in that, In step 4), the random protection set of the connection where the input share is located refers to: identifying and aggregating all random bits that affect the current connection share value.

6. The method as described in claim 1, characterized in that, Step 4) involves performing logical transformations based on the detection results, either introducing new random bits or inserting them into the register. This includes the following three processing methods: (1) When the two input protection sets do not intersect, two independent new random bits are introduced, and XORed with the product terms of the two input shares respectively and stored in registers to generate the output share; (2) When two input protection sets have a non-empty intersection but at least one input has a unique random bit that the other does not have, insert a register at the input that has the unique random bit; (3) When the two input protection sets are completely identical or there is no algebraically unique random bit, a refresh random bit is introduced to perform an XOR refresh operation on one of the input shares.

7. The method as described in claim 1, characterized in that, The specific processing of the output remasking in step 5) includes: introducing a new random bit, calculating the XOR sum of the original first output share, the new random bit and the original second output share, and using it as the new first output share; and using the new random bit as the new second output share.

8. The method as described in claim 1, characterized in that, Step 6) performing random number sharing between parallel modules means that between two parallel circuit modules whose input protection sets do not intersect, the random value of the input mask of one module is used as the random bits required for calculation by the other module.

9. The method as described in claim 1, characterized in that, Step 6) involves performing a random number reclamation operation to mark the random bits used within the module as reusable. This means converting a variable with multiple old random bit masks into a variable with only one new random bit mask, and marking the previously occupied old random bits as releasable.

10. The method as described in claim 1, characterized in that, In step 7), serial combination means that when the output of the first module is used as the input of the second module, the output remasking operation described in step 5) or the refresh operation described in step 4) is performed at the output interface of the first module, and then the processed signal is transmitted to the second module to ensure that the input of the downstream module meets the unique randomness protection criterion.