Sampling circuit, control method and hardware accelerator applied to lattice cryptography algorithm
By designing parallel hash operation modules and sampling circuits for sampling modules, the problem of long sampling time in lattice cryptography algorithms was solved, achieving efficient operation of the sampling circuit and acceleration of the lattice cryptography algorithm.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA RESOURCES MICROELECTRONICS HLDG LTD
- Filing Date
- 2025-01-06
- Publication Date
- 2026-07-07
AI Technical Summary
The sampling process in lattice cryptography is time-consuming, and the sampling module is idle for a long time, resulting in low operating efficiency of the sampling circuit.
Design a sampling circuit that includes a filling module, multiple hash operation modules, and a sampling module. The circuit generates pseudo-random sequences by running multiple hash operation modules in parallel and uses the sampling module for sampling, thereby reducing the idle time of the sampling module.
The sampling circuit's operating efficiency was improved, the calculation speed of the lattice cryptography algorithm was increased, sampling time was saved, and the sampling speed was increased by 169%.
Smart Images

Figure CN122348815A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of post-quantum cryptography, and more particularly to a sampling circuit, control method, and hardware accelerator for lattice cryptography algorithms. Background Technology
[0002] Lattice cryptography, or post-quantum cryptography based on the complex problem of lattices, is resistant to attacks from quantum computers. The sampling process for polynomials in lattice cryptography is time-consuming. To accelerate its execution, appropriate sampling circuits can be designed to speed up the sampling process in hardware.
[0003] In related technologies, the sampling algorithm in lattice cryptography runs faster than the hash algorithm, and the sampling algorithm's operation depends on the hash algorithm's output. Therefore, in the sampling circuit, the sampling module used to run the sampling algorithm is often idle, resulting in a poor acceleration effect of the sampling circuit on the lattice cryptography algorithm. Summary of the Invention
[0004] To overcome the problems existing in related technologies, this disclosure provides a sampling circuit, control method and hardware accelerator for lattice cryptography algorithms.
[0005] According to a first aspect of the present disclosure, a sampling circuit for use in a lattice cryptography algorithm is provided, comprising: a filling module, a sampling module, and a plurality of hash operation modules;
[0006] The filling module is used to fill the seed according to the hash filling rules; wherein the filled seed is used to input any of the multiple hash operation modules that is in an idle state.
[0007] The hash operation module is used to perform hash operations on the input seed to generate a pseudo-random sequence. The hash operation module is in an idle state when no seed is input to it, or when the pseudo-random sequence generated by the hash operation module based on the input seed has been sampled.
[0008] The sampling module is used to sample the pseudo-random sequence generated by the hash operation module to obtain the sampling result.
[0009] In some embodiments, the sampling circuit further includes a first multiplexer;
[0010] The input of the first multiplexer is connected to the output of the filling module;
[0011] The multiple outputs of the first multiplexer are respectively connected to the inputs of different hash operation modules.
[0012] In some embodiments, the sampling circuit further includes a first multiplexer;
[0013] The multiple inputs of the first multiplexer are respectively connected to the outputs of different hash operation modules;
[0014] The output of the first multiplexer is connected to the input of the sampling module.
[0015] In some embodiments, the sampling module includes: a second multiplexer and a plurality of samplers;
[0016] The input terminal of the second multiplexer is the input terminal of the sampling module;
[0017] The multiple outputs of the second multiplexer are connected to different samplers.
[0018] In some embodiments, the hash operation module includes: a first register and an iterative operator;
[0019] The first register is used to store the filled seed and the operation result of the iterative arithmetic unit;
[0020] The iterative arithmetic unit is used to perform hash operations based on the data stored in the first register.
[0021] In some embodiments, the iterative arithmetic unit includes multiple hash units connected sequentially;
[0022] In the plurality of hash units,
[0023] The first hash unit is used to perform a hash operation based on the data stored in the first register;
[0024] The non-first hash unit is used to perform hash operations based on the result of the operation of the previous hash unit connected to it;
[0025] The result of the last hash unit is stored in the first register.
[0026] In some embodiments, the filling module includes a second register, which has a data input terminal and a parameter input terminal;
[0027] The data input terminal is used to input the seed;
[0028] The parameter input terminal is used to input the filling parameters corresponding to the hash operation type in the hash operation module.
[0029] In some embodiments, the filling parameters include filling type information and seed length information, and the filling module further includes a second multiplexer;
[0030] The first input terminal of the second multiplexer is used to input the fill type information, the second input terminal is used to input the seed length information, and the output terminal is connected to the parameter input terminal.
[0031] According to a second aspect of the present disclosure, a sampling circuit control method is provided, applied to the sampling circuit described in the first aspect, the method comprising:
[0032] The seed is filled according to the hash filling rules;
[0033] The filled seed is input into any of the multiple hash operation modules that is in an idle state; wherein, the hash operation module is in an idle state when no seed is input into the hash operation module, or after the pseudo-random sequence generated by the hash operation module based on the input seed has been sampled.
[0034] Based on the hash operation module of the input seed, a hash operation is performed on the input seed to generate a pseudo-random sequence;
[0035] The pseudo-random sequence is sampled to obtain the sampling result.
[0036] According to a third aspect of the present disclosure, a hardware accelerator for lattice cryptography algorithms is provided, comprising: the sampling circuit described in the first aspect.
[0037] The technical solutions provided in this disclosure may have the following beneficial effects:
[0038] The sampling circuit provided in this embodiment includes a filling module, a sampling module, and multiple hash operation modules. The filling module fills the seed according to hash filling rules. The filled seed is then input to any idle hash operation module. The hash operation module performs hash operations on the input seed to generate a pseudo-random sequence. The sampling module samples the pseudo-random sequence generated by the hash operation module to obtain a sampling result. This embodiment features multiple hash operation modules that can perform hash operations in parallel and independently. Therefore, the multiple hash operation modules can generate enough data to be sampled by the sampling module, thereby minimizing the idle period of the sampling module, improving the operating efficiency of the sampling circuit, and accelerating the computation process of the lattice cryptography algorithm. Attached Figure Description
[0039] Figure 1 A schematic diagram of the overall architecture of a sampling circuit according to an embodiment of this disclosure is shown.
[0040] Figure 2 A schematic diagram of a sampling circuit according to an embodiment of this disclosure is shown.
[0041] Figure 3 A schematic diagram of the structure of a filling module in an embodiment of this disclosure is shown.
[0042] Figure 4 A schematic diagram of the structure of a sampling module in an embodiment of this disclosure is shown.
[0043] Figure 5 A schematic flowchart of a sampling circuit control method according to an embodiment of this disclosure is shown. Detailed Implementation
[0044] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.
[0045] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. The singular forms “a,” “the,” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0046] Furthermore, the terms "first," "second," etc., are used only to distinguish descriptions and should not be interpreted as indicating or implying relative importance.
[0047] To facilitate understanding, the following explanations are provided for several terms used in this disclosure:
[0048] A lattice is a linear set of linearly independent vectors with integer coefficients in n-dimensional Euclidean space. Based on lattices, a series of computationally complex problems can be designed, such as the Shortest Vector Problem (SVP) and the Closest Vector Problem (CVP). As the lattice dimension increases, these vector problems become increasingly computationally difficult to solve.
[0049] Lattice cryptography, also known as lattice-based post-quantum cryptography, is a new generation of cryptographic algorithms that can resist attacks from quantum computers. The construction and computation of lattice-based cryptography algorithms can ultimately be reduced to a vector problem in an n-dimensional lattice. Since no quantum algorithm can solve complex problems on lattices in polynomial time, post-quantum cryptography based on lattice problems possesses strong resistance to quantum attacks.
[0050] Sampling circuits are one of the core components used to accelerate the operation of post-quantum cryptography algorithms. Post-quantum cryptography algorithms require repeated sampling to generate the necessary pseudo-random information. Accelerating the sampling process through sampling circuits improves sampling efficiency and facilitates the efficient implementation of post-quantum cryptography algorithms. In lattice-based post-quantum cryptography algorithms, sampling algorithms mainly include binomial distribution sampling, rejection-uniform distribution sampling, and non-negative correlation-trivalued sampling.
[0051] The sampling process in lattice cryptography will now be explained using binomial distribution sampling as an example.
[0052] First, a pseudo-random sequence (containing multiple pseudo-random strings) needs to be generated for sampling through hash operations.
[0053] Hash operations can be implemented using the third-generation secure hash function (SHA-3). SHA-3 is based on the Keccak algorithm and is defined by two important parameters: the length of the output data after the operation, and the number of iterations, or "rounds," within the function. During the hash operation, the hash function performs multiple rounds of hash operations based on the padded seed until the number of rounds reaches a predefined number, ultimately generating a fixed-length pseudo-random sequence.
[0054] Next, the pseudo-random sequence generated by the hash operation will be sampled using a binomial distribution to obtain the sampling result. The sampling result is the polynomial coefficient used in the lattice cryptography algorithm to implement polynomial multiplication.
[0055] Binomial sampling can be achieved by calculating the Hamming weights of two uniformly distributed random numbers and then calculating their difference. For example, from a random uniform sequence, take two random numbers of length k bits, calculate their Hamming weights, and then subtract the two Hamming values. Repeating this process with a sufficient number of data sets will yield the binomial distribution coefficients that conform to the standard deviation σ = √k / 2.
[0056] During the execution of the lattice cryptography algorithm, the above sampling process will be executed multiple times. Although the sampling algorithm may be different each time it is called, the sampling process is generally similar.
[0057] In other words, the design of a sampling circuit requires at least two parts: a hash operation module for performing hash operations and a sampling module for performing sampling operations.
[0058] In related technologies, there is a coupling relationship between the hash operation module and the sampling module. The operation of the sampling module depends on the data to be sampled (a pseudo-random sequence obtained through hashing) provided by the hash operation module. While the sampling module is running, the hash operation module can only be used to provide the data to be sampled and cannot be used for hashing operations. Furthermore, the sampling module's sampling speed is much faster than the hash operation module's hashing speed. This results in the sampling module being in an idle state for a long time during actual operation. That is, after each short period of time to sample the data to be sampled, it needs to wait for the hash operation module to start a new hashing operation and provide new data to be sampled, thus leading to low overall operating efficiency of the sampling circuit.
[0059] To address the aforementioned technical problems, this embodiment of the present disclosure incorporates multiple hash operation modules in the sampling circuit. These modules can perform hash operations in parallel and independently, thereby generating a sufficient amount of data to be sampled and reducing the idle time of the sampling modules. This significantly improves the operating efficiency of the sampling circuit.
[0060] The following will describe the exemplary implementation method in detail with reference to the accompanying drawings and embodiments.
[0061] Figure 1 This diagram illustrates the overall architecture of a sampling circuit according to an embodiment of the present disclosure, as shown below. Figure 1 As shown, the sampling circuit includes: a filling module 100, a sampling module 300, and multiple hash operation modules 200.
[0062] Specifically, the filling module 100 is used to fill the seed according to the hash filling rules.
[0063] The hash operation module 200 is used to perform hash operations on the input seed to generate a pseudo-random sequence.
[0064] The sampling module 300 is used to sample the pseudo-random sequence generated by the hash operation module 200 to obtain the sampling result.
[0065] The filled seed is used as input to any of the multiple hash operation modules 200 that is in an idle state. The hash operation module 200 is in an idle state when no seed is input to it, or when the pseudo-random sequence generated by the hash operation module 200 based on the input seed has been sampled.
[0066] In other words, initially, none of the hash operation modules 200 have been input with a seed, and all of them are in an idle state. At this time, the filling module 100 can input the filled seed into any of the hash operation modules 200, causing that module to enter a working state and perform a hash operation on the filled seed to generate a pseudo-random sequence. After the sampling module 300 has sampled the pseudo-random sequence generated by the hash operation module 200, the hash operation module 200 will return to an idle state.
[0067] It should be understood that the seed is an initial value that can be used for hash operations, and it can be any string. The hash padding rule is the padding rule corresponding to the hash operation performed in the hash operation module 200. Those skilled in the art will understand that before performing a hash operation on a string, it needs to be padded to ensure that its format and length meet the requirements of the hash operation for the initial value.
[0068] In some embodiments, multiple hash operation modules 200 are connected in parallel, a filling module 100 is disposed at the input end of the multiple hash operation modules 200 connected in parallel, and a sampling module 300 is disposed at the output end of the multiple hash operation modules 200 connected in parallel. All of the above modules can be implemented in hardware based on a field-programmable gate array (FPGA).
[0069] The scheme provided in this disclosure allows multiple hash operation modules 200 operating in parallel to generate a sufficient amount of data to be sampled (pseudo-random sequences). The sampling module 300 can sample the data generated by each hash operation module 200. After the sampling module 300 has sampled the data generated by a hash operation module 200, that hash operation module 200 releases the data and returns to an idle state. At this time, the filling module 100 can input a new seed into the hash operation module 200, enabling it to continue generating new data to be sampled, thus ensuring a continuous flow of data to be sampled.
[0070] On the other hand, since the multiple hash operation modules 200 are independent of each other, when the sampling module 300 samples the data to be sampled generated by one of the hash operation modules 200, the new seed, after being filled by the filling module 100, can still be input into other idle (not occupied by the sampling module) hash operation modules 200 to generate new data to be sampled. In other words, the operation of the sampling module 300 does not interrupt the generation of data to be sampled.
[0071] Figure 2 A schematic diagram of a sampling circuit according to an embodiment of this disclosure is shown. Figure 2 As shown, in the sampling circuit, each hash operation module 200 may include a first register and an iterative operation unit.
[0072] The first register is used to store the filled seed and the result of the iterator, and the iterator is used to perform hash operations based on the data stored in the first register.
[0073] For example, the seed filled by the filling module 100 is first stored in the first register. The iterative arithmetic unit can perform a hash operation on the filled seed and store the hash result in the first register. At this time, if the number of hash operations reaches the sampling requirement of the lattice cryptography algorithm, the hash result stored in the first register can be used as the data to be sampled, waiting for the sampling module 300 to sample it; otherwise, the iterative arithmetic unit will read the data stored in the first register again, perform a hash operation on it, and store the hash result in the first register.
[0074] For example, the size of the first register can be 1600 bits. This setting allows the first register to hold the data generated by the various hash operations involved in the lattice cryptography algorithm.
[0075] In some embodiments, the iterative arithmetic unit includes multiple hash units ( Figure 2 (There are two hash units in the first register). Multiple hash units are connected sequentially. In the multiple hash units, the first hash unit is used to perform a hash operation based on the data stored in the first register; the hash units that are not the first hash unit are used to perform a hash operation based on the operation result of the hash unit connected to it; the operation result of the last hash unit is stored in the first register.
[0076] In this embodiment of the disclosure, the first hash unit represents the "first" hash unit in the data transmission direction, i.e., the input terminal of the iterative operator for receiving external data. Correspondingly, the last hash unit represents the "last hash unit" in the data transmission direction, i.e., the output terminal of the iterative operator for sending data to the outside.
[0077] Understandably, each hash unit is used for one round of hashing. By setting multiple hash units in the iterative cipher, the number of rounds of hashing can be increased in each iteration, reducing the number of iterations. This allows for obtaining a pseudo-random sequence that meets the sampling requirements of the lattice cipher algorithm with fewer iterations, thereby improving the sampling efficiency of the lattice cipher algorithm.
[0078] For example, suppose the SHA-3 algorithm defines that the seed needs to undergo 24 rounds of hash operations to generate the pseudo-random sequence required by the sampling module 300. In the solution provided in this embodiment, by setting two hash units in the iterative arithmetic unit, two rounds of hash operations can be performed in each iteration, that is, the pseudo-random sequence required by the sampling module 300 can be generated in 12 rounds (24 ÷ 2) of iteration. Based on this, suppose the sampling circuit has two hash operation modules 200, and each hash operation module 200 has two hash units in its iterative arithmetic unit, the overall hash operation time in the sampling circuit can be further shortened to a cycle of 6 rounds (12 ÷ 2) of iteration.
[0079] In some embodiments, the sampling circuit further includes a first multiplexer (DMUX1). The input of the first multiplexer is connected to the output of the filling module 100, and the multiple outputs of the first multiplexer are respectively connected to the inputs of different hash operation modules 200.
[0080] The input terminal of the aforementioned first register serves as the input terminal of the hash operation module 200. By setting the first multiplexer, the output terminal of the filling module 100 can be switched between the input terminals of different hash operation modules 200, so as to select the hash operation module 200 in an idle state to receive the filled seed.
[0081] In some embodiments, the sampling circuit further includes a first multiplexer (MUX1). The multiple inputs of the first multiplexer are respectively connected to the outputs of different hash operation modules 200, and the output of the first multiplexer is connected to the input of the sampling module 300.
[0082] The output of the first register is used as the output of the hash operation module 200. By setting the first multiplexer, the hash operation module 200 after generating the data to be sampled can be connected to the sampling module 300, so that the sampling module 300 samples it.
[0083] In some embodiments, the number of hash operation modules 200 can be two. It should be understood that setting too many hash operation modules 200 will increase the area of the sampling circuit and may cause the amount of data to be sampled generated by the hash operation modules 200 to far exceed the processing capacity of the sampling module 300; while setting too few hash operation modules 200 will still result in the sampling module 300 remaining idle for a relatively long time. In practical applications, setting two hash operation modules 200 in the sampling circuit can achieve a better balance between the above issues.
[0084] In some embodiments, the sampling circuit further includes a top-level state machine 400. The top-level state machine 400 can acquire the operating state of each module in the sampling circuit and control the operating state of each module through control signals.
[0085] For example, after the filling module 100 completes filling the seed, the top-level state machine 400 obtains the working status of each hash operation module 200, and then controls the first multiplexer to make the filling module 100 connect with the first register in the hash operation module that is in the idle state, and at the same time controls the filling module 100 to input the filled seed into the first register.
[0086] It is understood that the working state of each module and unit in the embodiments of this disclosure can be controlled by the control signals output by the top-level state machine 400, and the timing requirements of each module can be met. This disclosure will not elaborate on this.
[0087] In some embodiments, taking the sampling of the common parameter matrix A in the Dilithium-2 algorithm as an example, sampling it using a sampling circuit in related technologies requires 3280 clock cycles. However, sampling it using the sampling circuit provided in this disclosure requires only 1216 clock cycles.
[0088] As can be seen, the sampling circuit provided in this embodiment can significantly save sampling time, and the sampling speed is increased by 169% under the same conditions.
[0089] Figure 3 A schematic diagram of the structure of a filling module according to an embodiment of this disclosure is shown. Figure 3 As shown, the filling module 100 includes a second register, which has a data input terminal and a parameter input terminal. The data input terminal is used to input the seed, and the parameter input terminal is used to input the filling parameters corresponding to the hash operation type in the hash operation module.
[0090] For example, the filling parameters may include filling type information and seed length information, and the filling module 100 also includes a second multiplexer (MUX2). The first input of the second multiplexer is used to input the filling type information, the second input is used to input the seed length information, and the output is connected to the parameter input.
[0091] In other words, the second multiplexer can be used to control the input of the padding parameters. After the seed is input into the second register, the first input of the second multiplexer can be connected to the second register, thereby inputting a signal indicating the padding type information into the second register. The top-level state machine can then pad the seed stored in the second register according to the padding type information. Next, the second input of the second multiplexer can be connected to the second register, thereby inputting a signal indicating the (unpadded) seed length information into the second register. The top-level state machine can then control the padding cycle according to the seed length information, ensuring that the padded seed length meets the requirements of the hash operation.
[0092] For example, during the filling process, the data in the registers can be controlled at the hardware level through Register Transfer Level (RTL) code to improve the filling efficiency of the seed.
[0093] For example, the first register can also be used as the second register, that is, the seed can be directly filled into the first register and the filled seed can be directly sent into the iterative arithmetic unit for hash operation.
[0094] Figure 4 A schematic diagram of the structure of a sampling module according to an embodiment of this disclosure is shown. Figure 4 As shown, the sampling module 300 includes a second multiplexer (DMUX2) and multiple samplers. The input of the second multiplexer can be used as the input of the sampling module 300, and the multiple outputs of the second multiplexer are connected to different samplers.
[0095] For example, the sampler may include a sampler for implementing Central Binomial Distribution (CBD) sampling, a sampler for implementing Uniform Distribution (UD) sampling, a sampler for implementing Gaussian (GS) sampling, etc. Since multiple sampling algorithms need to be invoked in lattice cryptography algorithms, the sampling module 300 includes all of these types of samplers. The second multiplexer can be used to select the sampler currently used for sampling, that is, the sampling algorithm currently used to sample the pseudo-random sequence (hash operation result).
[0096] The structure of the sampling circuit in the embodiments of this disclosure has been described in detail above. It can be understood that the state of each module and unit in the embodiments of this disclosure can be controlled by the control signal output by the pre-configured top-level state machine and meet the timing requirements of each module. The embodiments of this disclosure will not elaborate on this.
[0097] Based on the same inventive concept, this disclosure also provides a sampling circuit control method. Figure 5 A flowchart illustrating a sampling circuit control method according to an embodiment of this disclosure is shown, which is applied to the aforementioned sampling circuit. Figure 5 As shown, the method includes the following steps.
[0098] S501, fill the seed according to the hash filling rules.
[0099] The seed can be understood as the initial value used for hash operations, and it can be any string. Before performing a hash operation on the seed, the input seed needs to be filled according to the hash filling rules corresponding to the hash operation to ensure that it meets the requirements of the hash operation for the initial value.
[0100] S502, input the filled seed into any of the multiple hash operation modules that is in an idle state.
[0101] The hash operation module is in an idle state when no seed is input to it, or when the pseudo-random sequence generated by the hash operation module based on the input seed has been sampled.
[0102] S503, based on the hash operation module of the input seed, performs a hash operation on the input seed to generate a pseudo-random sequence.
[0103] For example, the hashing module receiving the seed will enter the working state and perform multiple rounds of iterative hashing based on the padded seed to generate a pseudo-random sequence for sampling. Meanwhile, other hashing modules in the idle state can still be used to receive the padded seed.
[0104] S504, sample the pseudo-random sequence to obtain the sampling result.
[0105] For example, when sampling a pseudo-random sequence generated by one of the hash operation modules, other hash operation modules can still receive the filled seed or perform hash operations on the received seed to generate a pseudo-random sequence, depending on their different states.
[0106] Therefore, the embodiments of this disclosure can improve the generation speed of pseudo-random sequences, thereby increasing the sampling rate.
[0107] Based on the same inventive concept, this disclosure also provides a hardware accelerator for lattice cryptography algorithms, which includes the above-described sampling circuit.
[0108] The hardware accelerator provided in this disclosure can accelerate the sampling process of lattice cryptography algorithms based on sampling circuits, thereby promoting the efficient implementation of lattice cryptography algorithms.
[0109] The embodiments of this disclosure have been described in detail above with reference to the accompanying drawings. However, this disclosure is not limited to the specific details of the above embodiments. Within the scope of the technical concept of this disclosure, various simple modifications can be made to the technical solutions of this disclosure, and these simple modifications all fall within the protection scope of this disclosure.
[0110] Furthermore, various different embodiments of this disclosure can be combined in any way, as long as they do not violate the spirit of this disclosure, they should also be regarded as the content disclosed in this disclosure.
Claims
1. A sampling circuit applied to a lattice-resistant quantum cryptographic algorithm, characterized in that, include: The module includes a filling module, a sampling module, and multiple hash operation modules; The filling module is used to fill the seed according to the hash filling rules; wherein the filled seed is used to input any of the multiple hash operation modules that is in an idle state. The hash operation module is used to perform hash operations on the input seed to generate a pseudo-random sequence. The hash operation module is in an idle state when no seed is input to it, or when the pseudo-random sequence generated by the hash operation module based on the input seed has been sampled. The sampling module is used to sample the pseudo-random sequence generated by the hash operation module to obtain the sampling result.
2. The sampling circuit of claim 1, wherein, The sampling circuit also includes a first multiplexer; The input of the first multiplexer is connected to the output of the filling module; The multiple outputs of the first multiplexer are respectively connected to the inputs of different hash operation modules.
3. The sampling circuit of claim 1, wherein, The sampling circuit also includes a first multiplexer; The multiple inputs of the first multiplexer are respectively connected to the outputs of different hash operation modules; The output of the first multiplexer is connected to the input of the sampling module.
4. The sampling circuit of claim 1 or 3, wherein The sampling module includes: a second multiplexer and multiple samplers; The input terminal of the second multiplexer is the input terminal of the sampling module; The multiple outputs of the second multiplexer are connected to different samplers.
5. The sampling circuit of claim 1, wherein, The hash operation module includes: a first register and an iterative operator; The first register is used to store the filled seed and the operation result of the iterative arithmetic unit; The iterative arithmetic unit is used to perform hash operations based on the data stored in the first register.
6. The sampling circuit according to claim 5, characterized in that, The iterative arithmetic unit includes multiple hash units, which are connected sequentially. In the plurality of hash units, The first hash unit is used to perform a hash operation based on the data stored in the first register; The non-first hash unit is used to perform hash operations based on the result of the operation of the previous hash unit connected to it; The result of the last hash unit is stored in the first register.
7. The sampling circuit according to claim 1, characterized in that, The filling module includes a second register, which has a data input terminal and a parameter input terminal; The data input terminal is used to input the seed; The parameter input terminal is used to input the filling parameters corresponding to the hash operation type in the hash operation module.
8. The sampling circuit according to claim 7, characterized in that, The filling parameters include filling type information and seed length information; the filling module also includes a second multiplexer. The first input terminal of the second multiplexer is used to input the fill type information, the second input terminal is used to input the seed length information, and the output terminal is connected to the parameter input terminal.
9. A sampling circuit control method, characterized in that, Applied to the sampling circuit as described in any one of claims 1 to 8, the method comprises: The seed is filled according to the hash filling rules; The filled seed is input into any of the multiple hash operation modules that is in an idle state; wherein, the hash operation module is in an idle state when no seed is input into the hash operation module, or after the pseudo-random sequence generated by the hash operation module based on the input seed has been sampled. Based on the hash operation module of the input seed, a hash operation is performed on the input seed to generate a pseudo-random sequence; The pseudo-random sequence is sampled to obtain the sampling result.
10. A hardware accelerator for lattice cryptography algorithms, characterized in that, include: The sampling circuit as described in any one of claims 1 to 8.