Digital approximate computing circuit for post-quantum cryptography applications

The digital circuit addresses performance and complexity issues in LWE-based cryptography by dynamically controlling error probability and architecture, providing a flexible, compact, and energy-efficient hardware accelerator for LWE algorithms.

FR3153673B1Active Publication Date: 2025-09-19COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023010361
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-09-28
Publication Date
2025-09-19
Estimated Expiration
2043-09-28

AI Technical Summary

Technical Problem

Conventional implementations of Learning With Errors (LWE)-based cryptographic primitives face performance issues due to the complexity of hardware-based true random number generators (TRNG) and the need for complex, large-footprint digital circuits, while approximate computing methods lack flexibility in error probability control.

Method used

A digital circuit for calculating a scalar product with a configurable error probability, utilizing a multiplier, accumulator, and control circuit to introduce errors dynamically, optimizing architecture with FDSOI technology and CMOS structures for RBB mode, allowing error distribution adjustment.

Benefits of technology

The solution provides a compact, energy-efficient hardware accelerator for LWE algorithms, offering flexible error probability control and entropy addition, without needing TRNGs, and maintaining precision and energy efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000017_0000
    Figure 00000017_0000
  • Figure 00000017_0001
    Figure 00000017_0001
  • Figure 00000018_0000
    Figure 00000018_0000
Patent Text Reader

Abstract

The invention relates to a digital circuit (10) for calculating a scalar product between two vectors and . The digital circuit comprises a multiplier (11), an accumulator (12) comprising at least one adder (13) and a register (14), as well as a control circuit (15) for the accumulator. At a clock tick of index , the multiplier is configured to calculate the result of the multiplication , and the accumulator is configured to add with the current value of the register. The result of the addition is then stored in the register. The control circuit is configured to control the accumulator so as to perform the addition approximately for at least one addition among the additions of the calculation of the scalar product. The digital circuit is in particular intended to be used in an electronic device implementing a cryptographic algorithm based on a "learning with errors" (LWE) technology. Figure for the abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Digital approximate computing circuit for post-quantum cryptography applications Field of invention

[0001] The present invention belongs to the field of digital approximate calculation circuits for cryptography applications, and more particularly for post-quantum cryptography applications. State of the art

[0002] Post-quantum cryptography concerns encryption algorithms that can resist mathematical attacks using a quantum computer.

[0003] Unlike a classical computer that works on binary data, a quantum computer works on qubits whose quantum state can have a quantum value with several simultaneous possibilities. Quantum computing lends itself particularly well to problems whose computational complexity lies in combinatorics. These problems are found in particular in cryptography. The high factorization capabilities of a quantum computer would thus make it possible to mathematically break many conventional cryptographic systems, in particular asymmetric encryption methods based on the RSA algorithm.

[0004] "Learning with Errors", or LWE (English acronym for "Learning With Errors") is a supposedly difficult computational problem which is the basis of many recent encryption algorithms used in post-quantum cryptography.

[0005] A conventional implementation of an LWE-based cryptographic primitive consists of generating errors that follow a predetermined error distribution, and adding these errors into exact calculations. Generating errors with a hardware-based true random number generator (TRNG, or pseudo-random number generator) leads to performance problems, however.

[0006] The paper “When Bad News Become Good News - Towards Usable Instances of Learning With Physical Errors”, D. BELLIZIA et al., IACR Transactions on Cryptography Hardware and Embedded Systems, pp. 1-24, Aug. 2022, discloses a digital circuit for calculating a scalar product of two vectors. This circuit can serve as a basic building block for implementing an LWE-type algorithm. In the proposed architecture, each vector comprises 128 numbers each coded on 8 bits. The digital circuit comprises a parallel multiplier capable of calculating 128 multiplications in parallel, as well as seven stages of parallel adders. The adders of the different stages each perform in parallel a number of additions respectively equal to 64, 32, 16, 8, 4, 2 then 1. Shift registers (flip-flops) are interposed between two adder stages to introduce an error in the sampling of the least significant bit of the result of two of the additions. The proposed architecture is particularly complex and has a fairly large footprint.

[0007] In another field, for intensive computing digital circuits used in applications with a certain resilience to errors (for example for the implementation of neural networks for image processing), it is known to introduce simplifications into the digital circuit in order to optimize its energy consumption and / or its size to the detriment of the precision of the calculation. This is called “approximate computing”. The digital circuit is then synthesized specifically to perform calculations with a certain probability of error. There is then generally no way to dynamically control the probability of error introduced into the calculations by the digital circuit. Statement of the invention

[0008] The present invention aims to remedy all or part of the drawbacks of the prior art, in particular those set out above.

[0009] To this end, and according to a first aspect, the present invention proposes a digital circuit for calculating a scalar product between two vectors of dimension N, N being an integer at least equal to two. The two vectors are denoted respectively (fl(> ab, j, ..., and (¾ Sp sj, The digital circuit comprises a multiplier, an accumulator comprising at least one adder and one register, as well as an accumulator control circuit. The digital circuit is configured to be clocked, and at a clock pulse of index j, j being an integer varying between 0 and (N - 1): - the multiplier is configured to calculate a result ri of a multiplication * Sj of the components of index j of the two vectors, - the accumulator is configured to add the result1 j of the multiplication with a current value of the register, and to store a result of the addition in the register; - the control circuit is configured to control the accumulator so as to perform the addition approximately, that is to say with a predetermined level of probability that the result of the addition contains an error, for at least one addition among the N additions of the calculation of the scalar product.

[0010] This digital circuit is particularly well suited to serve as an accelerator hardware for a cryptographic primitive based on a "learning with errors" (LWE) algorithm. The calculation of the scalar product is in fact the basis of this type of algorithm.

[0011] The control circuit makes it possible to inject an error for one or more additions of the calculation of the scalar product. This makes it possible to implement an LWE type algorithm without having to use a hardware random (or pseudo-random) number generator (TRNG or PRNG), while keeping a particularly simple and compact architecture. In particular, and unlike the solution presented in the prior art, there is no need to cascade several adder stages and there is no need to add a register bank.

[0012] The proposed solution has a compact architecture, with reduced size (small surface area occupied by the circuit) and relatively low energy consumption.

[0013] The proposed architecture provides flexibility on the level of error probability desired for the calculation of the scalar product. For example, it is possible to dynamically modify, via the control circuit, the number of additions to be executed approximately in order to modify the error distribution. The proposed architecture also makes it possible to add entropy to the error distribution obtained, in particular by adjusting the choice of the addition or additions to be executed approximately in the calculation of the scalar product.

[0014] In particular embodiments, the invention may further comprise one or more of the following features, taken individually or in any technically possible combination.

[0015] In particular embodiments: - the accumulator includes a single adder implemented using “totally depleted silicon on insulator” technology, FDSOI; - a predetermined region of the adder groups together FDSOI transistors forming logic gates which control a predetermined number L of low-order bits of the result of the addition, L being an integer at least equal to one; - said predetermined region is connected to a voltage source making it possible to apply a back gate voltage to the FDSOI transistors of the region, the value of the back gate voltage being able to be dynamically controlled by the control circuit, - the control circuit is configured to apply by default a back gate voltage reference value, and to apply a specific back gate voltage value, different from the reference value, only during the execution of said at least one addition to be performed roughly.

[0016] Such arrangements correspond to a particularly compact architecture (digital circuit with a single adder) with an increased level of flexibility on the error distribution that can be obtained. It is indeed possible to dynamically modify the error distribution according to the value of the applied back gate voltage. The back gate voltage makes it possible to vary the threshold voltage of the FDSOI transistors. A higher threshold voltage leads to an increase in the propagation time of the logic gates implemented by the transistors, and consequently a loss of precision in the calculations. The predetermination of the region concerned (which depends on the number of low-order bits that one wishes to be impacted by the approximate calculation) also contributes to the definition of the error distribution.

[0017] In particular embodiments, the control circuit is configured to dynamically determine the specific value of back gate voltage to apply based on a desired error probability level for the calculation of the scalar product.

[0018] In particular embodiments, the FDSOI transistors are arranged in CMOS structures each comprising an NMOS transistor on a P well and a PMOS transistor on an N well.

[0019] This corresponds to a digital circuit with CMOS components of traditional structure (“Regular Well” in English) optimized for reverse gate bias (“Reverse Body Bias” or RBB in the English literature). In such a configuration, the reverse gate bias (RBB) is applied to increase the threshold voltage of the transistor. The transistor is then of the RVT type (acronym for “Regular Voltage Threshold”).

[0020] In particular embodiments: - the accumulator comprises an exact adder synthesized specifically to calculate an addition exactly, an approximate adder synthesized specifically to calculate an addition with the predetermined level of error probability, and a multiplexer; - for each addition executed at a clock tick of index j, the multiplexer is configured by the control circuit to select the adder to be used among the exact adder and the approximate adder.

[0021] This architecture does not require a dynamic voltage source, but it does require two adders and a multiplexer.

[0022] In particular embodiments, said at least one addition having to be executed approximately, among the N additions of the calculation of the scalar product, is different for each new scalar product calculation.

[0023] In particular embodiments, said at least one addition to be performed approximately in the calculation of the scalar product is chosen randomly.

[0024] In particular embodiments, the number of additions to be performed approximately in the dot product calculation is dynamically controlled by the control circuitry based on a desired error probability level for the dot product calculation.

[0025] According to a second aspect, there is provided by the present invention an electronic device implementing a cryptographic algorithm based on a "learning with errors" (LWE) technology. The device comprises at least one digital circuit according to any one of the preceding embodiments. Presentation of figures

[0026] The invention will be better understood on reading the following description, given by way of non-limiting example, and made with reference to Figures 1 to 7 which represent:

[0027] [Fig.l] a generic schematic representation of a digital circuit according to the invention, for calculating a scalar product between two vectors,

[0028] [Fig.2] a schematic representation of a first particular embodiment of the digital circuit illustrated in [Fig.l],

[0029] [Fig.3] a schematic representation of a second particular embodiment of the digital circuit illustrated in [Fig.l],

[0030] [Fig.4] a schematic representation of an FDSOI transistor,

[0031] [Fig.5] a schematic representation of an optimized FDSOI CMOS structure for RBB mode,

[0032] [Fig.6] a schematic representation of an 8-bit adder, with the identification of a particular region of the adder which impacts the least significant bit of the addition result,

[0033] [Fig.7] a graph illustrating the possibility of controlling the error probability level of the adder as a function of the applied back gate voltage.

[0034] In these figures, identical references from one figure to another designate identical or similar elements. For reasons of clarity, the elements represented are not necessarily on the same scale, unless otherwise stated. Detailed description of the invention

[0035] Figure 1 schematically represents a digital circuit 10 according to the invention. The digital circuit 10 is configured to calculate a scalar product between two vectors of dimension N, N being an integer at least equal to two. In the example illustrated in Figure 1, the two vectors are denoted respectively (aiü, a^, ..., a^-, ..., a^) and (¾ ..., Sj, ..., The components av and sj of these two vectors, j being an integer varying between 0 and (N - 1), correspond for example each to an integer coded on NB bits, NB being an integer at least equal to one.

[0036] The digital circuit 10 is configured to calculate the scalar product bj of the two vectors:

[0037] [Math.l]

[0038] Repeating this operation for A different vectors (anb aib ..., a / j, ..., aiN_i), varying the index i between 0 and (N - 1), then amounts to calculating the following matrix product:

[0039] [Math.2] / «oo ■ ■ ■ û(wi -¾ / b0 \aN-l,0 \^NJ \bNA)

[0040] As will be seen later, instead of calculating this operation exactly, the digital circuit 10 is configured to calculate this operation approximately, that is to say in such a way that the result obtained is affected by an error having a predetermined distribution:

[0041] [Math.3] ^0.0 ^CW-i \ \ I e ° \ : : + : ■" \Sn-}' \eN-i! \bNAl

[0042] Each element C' corresponds to an error according to a predetermined error distribution.

[0043] Such a calculation is the basis of cryptographic primitives based on learning with errors (LWE). The digital circuit 10 is therefore particularly well suited to be used as a hardware accelerator to implement this type of cryptographic primitive.

[0044] As illustrated in [Fig.l], the digital circuit 10 comprises a multiplier 11, an accumulator 12 and a control circuit 15 for the accumulator 12. The accumulator 12 comprises at least one adder 13 and a register 14. The digital circuit 10 is configured to be clocked by a clock.

[0045] In the following, we are interested in the calculation of the scalar product described in formula [Math.l], for a given index i. Register 14 is initialized to zero at the start of the calculation of the scalar product. At a clock pulse of index j, multiplier 11 is configured to calculate a result ' j of a multiplication aij x sj of the components of index j of the two vectors, and the accumulator 12 is configured to add the result ri of the multiplication with a current value of the register 14. The result of the addition is then stored in the register 14. The result of the calculation of the scalar product described in the formula [Math.l] then corresponds to the value bl taken by the register 14 after N clock ticks corresponding to the variation of the index J from 0 to (N - 1). The result of the matrix calculation described by the formula [Math.2] can be obtained after / y2 clock ticks.

[0046] The particularity of the digital circuit 10 according to the invention is that the control circuit 15 makes it possible to dynamically control the accumulator 12 to perform the addition operation either exactly (which is illustrated by the symbol "+" in the figures) or approximately (which is illustrated by the symbol "~+" in the figures). Performing the addition approximately amounts to performing the addition with a predetermined level of probability that the result of the addition contains an error.

[0047] More particularly, the control circuit 15 is configured to control the accumulator 12 so as to perform the addition approximately for at least one addition among the N additions of the calculation of the scalar product (i.e. for at least one clock tick among the N clock ticks allowing the calculation of the scalar product).

[0048] The clock tick of index j triggers the two aforementioned operations (the calculation of the result ri of the multiplication aij x sj, and the addition of the result ri of the multiplication with the current value of register 14). It should be noted, however, that it is not essential that the (V clock ticks of index j allowing the calculation of the scalar product be consecutive. In other words, it is not essential that these two operations be carried out during a single clock tick. Nothing would prevent, for example, the multiplication and the addition from being carried out on two successive clock ticks j and j' (instead of carrying them out on a single clock tick j). Proceeding in this way constitutes only a variant of the invention.

[0049] [Fig.l] represents generically a digital circuit 10 according to the invention. The digital circuit 10 can be produced according to different particular embodiments.

[0050] [Fig. 2] schematically represents a first particular embodiment of the digital circuit 10 illustrated in [Fig. 1]. In this first embodiment, the accumulator 12 comprises both an exact adder 18 and an approximate adder 19. The exact adder 18 is configured specifically to calculate an addition exactly. The approximate adder 19 is configured specifically to calculate an addition with a predetermined level of probability. of error.

[0051] The exact adder 18 corresponds to a conventional adder. When designing the digital circuit 10, the exact adder 18 is synthesized specifically to calculate an addition exactly. In other words, the netlist of the exact adder 18 is optimized to ensure that the result of an addition performed by the exact adder 18 has a zero or negligible probability of error under normal conditions of use of the digital circuit 10.

[0052] When designing the digital circuit 10, the approximate adder 19 is specifically synthesized to calculate an addition with a predetermined level of error probability. In other words, the netlist of the approximate adder 19 is modified to ensure that the result of an addition performed by the approximate adder 19 has the desired level of error probability. The adder 19 is thus approximated using a “static” approach (when designing the digital circuit 10).

[0053] Different microarchitectures can be envisaged to design the approximate adder 19. For example, the “EvoApproxLib LITE” library offers a large number of approximate adder circuits associated with different levels of error probability.

[0054] The accumulator 12 further comprises a multiplexer 20. For each addition executed at a clock tick of index j, the multiplexer 20 is configured by the control circuit 15 to select the adder to be used from among the exact adder 18 and the approximate adder 19. With such arrangements, the control circuit 15 is configured to control the accumulator 12 so as to perform the addition approximately for at least one addition among the A additions of the calculation of the scalar product (i.e. for at least one clock tick among the A clock ticks allowing the calculation of the scalar product).

[0055] Advantageously, it is possible to dynamically control, via the control circuit 15, the number of additions to be executed approximately in the calculation of the scalar product. In other words, it is possible to dynamically control the number of clock ticks (among the A clock ticks used to calculate the scalar product) corresponding to additions to be executed approximately.

[0056] Such provisions provide some flexibility on the desired error probability level for calculating the scalar product. Indeed, the greater the number of additions performed approximately, the greater the error probability level for calculating the scalar product. For example, it is possible to empirically determine different error probability levels for calculating the scalar product depending on different values ​​of the number of additions performed approximately during the calculation of the scalar product. It is then possible to configure the control circuit 15 to determine the number of additions to be performed approximately based on a desired level of error probability for the calculation of the scalar product.

[0057] It is also possible to dynamically control, via the control circuit 15, which additions must be carried out approximately in the calculation of the scalar product.

[0058] In other words, it is possible to determine a number K between 1 and (Af - 1) and different integers Pq, ..., P^ • ' * ' Pk with 0 < p< ( N - 1 ) for any index k between 0 and K, such that the multiplexer 20 is configured by the control circuit 15 to select the approximate adder 19 on the clock ticks of index Pk, and to select the exact adder 18 on the other clock ticks.

[0059] Such arrangements make it possible to add entropy to the error distribution obtained. In particular, it is possible to change the addition or additions performed approximately at each new scalar product calculation (in other words, it is possible to vary the set of integers P& , Pk' '''' Pk at each new scalar product calculation). This addition of entropy is particularly interesting in cryptography applications.

[0060] It is also conceivable to configure the control circuit 15 to randomly select the additions to be carried out approximately in the calculation of the scalar product.

[0061] [Fig. 3] schematically represents a second particular embodiment of the digital circuit 10 illustrated in [Fig. 1]. In this second embodiment, the accumulator 12 comprises a single adder 16 implemented according to the “fully depleted silicon on insulator” or FDSOI (English acronym for “Fully Depleted Silicon On Insulator”) electronic component manufacturing technology.

[0062] FDSOI technology is known to overcome certain limitations of “bulk CMOS” (or “CMOS bulk” in English, CMOS is the English acronym for “Complementary Metal-Oxide Semiconductor”) technology. In particular, FDSOI technology offers better performance (particularly in terms of transition time and reliability) and reduced power consumption compared to “bulk CMOS” technology (in particular, FDSOI transistors can operate at lower voltages).

[0063] [Fig.4] schematically represents a 30 FDSOI transistor. As illustrated in [Fig.4], the FDSOI transistor comprises a silicon substrate 36 on which is placed an ultra-thin insulating silicon oxide layer 34. The FDSOI transistor 30 also comprises, above the insulating silicon oxide layer 34, a source 31, a drain 32 and a gate 33. A thin layer of silicon located above the insulating silicon oxide layer forms a homogeneous channel 35 under the gate 33. Since the channel layer 35 is very thin, no doping of the channel is necessary (this is why we speak of a “totally deserted” transistor). As illustrated in [Fig. 4], the FDSOI transistor 30 may also comprise insulating trenches 37.

[0064] A characteristic of the FDSOI transistor 30 is that its performance can be modified by applying a voltage VBb to the substrate 36 forming its rear face. This is called “back-face bias” or “back gate bias”. The voltage VBb is called “back-gate voltage” or “body bias voltage”. This bias of the substrate 36 makes it possible to vary the threshold voltage of the transistor 30. The variation of the threshold voltage of the transistor results in a change in the performance of the transistor in terms of speed, reliability and energy consumption.

[0065] As will be seen in more detail later, we distinguish between “Regular Well” type transistors and “Flip Well” type transistors. A “Regular Well” type transistor is based on a CMOS structure with a P well under the NMOS and an N well under the PMOS, and it is optimized for the RBB (“Reverse Body Bias”) mode which allows high threshold voltages to be favored (RVT type transistor). A “Flip Well” type transistor is based on a CMOS structure with an N well under the NMOS and a P well under the PMOS), and it is optimized for the FBB (“Forward Body Bias”) mode which allows low threshold voltages to be favored (LVT type transistor, for “Low Voltage Threshold”). The threshold voltage of RVT transistors is higher than that of LVT transistors.

[0066] The biasing of the substrate 36 creates a “back gate” buried under the channel 35. The transistor then acts as a double gate transistor. This characteristic makes it possible to apply different voltages to the upper gate 33 and to the back gate. This biasing of the substrate 36 is called “body bias” in English. By applying this biasing according to rules known to those skilled in the art (respect for the biasing conditions between the N-well and the P-well), the threshold voltage of an RVT transistor (RBB mode) is increased, and the threshold voltage of an LVT transistor (FBB mode) is lowered.

[0067] The insulating silicon oxide layer 34 limits current leakage in the substrate 36, which is why it is possible to apply a relatively high rear gate voltage to the substrate 36 of the FDSOI transistor 30 (this is not the case with the “bulk” technology).

[0068] When designing the digital circuit 10, and as illustrated in FIG. 6, a particular region 21 of the adder is predetermined. This predetermined region 21 groups FDSOI transistors 30 forming logic gates which control a predetermined number L of least significant bits of the result of the addition, L being an integer at least equal to one. In the example illustrated in FIG. 6, an 8-bit adder is considered (in other words, the adder 16 is configured to add a number a coded on eight bits with another number b coded on eight bits, and to provide the result in the form of a number c also coded on eight bits), and the number L is equal to one (in other words, only the least significant bit c[7] of the result is impacted by the predetermined region 21).

[0069] As illustrated in [Fig.6], the predetermined region 21 is connected to a voltage source 17 for applying a back gate voltage to the FDSOI transistors 30 of the region 21. The value VBb of the back gate voltage can be dynamically controlled by the control circuit 15. The other transistors which implement the adder 16 and which are not part of the predetermined region 21 are subjected to a reference voltage VreF.

[0070] As illustrated in [Fig.3], the control circuit 15 is configured to control the back gate voltage value applied to the predetermined region 21. More particularly, the control circuit 15 is configured to apply by default the back gate voltage reference value VreF, and to apply a specific back gate voltage value VBb, different from the reference value (VRFF VBb), only during the execution of the addition or additions to be performed approximately.

[0071] The transistor type (“Regular Well”, “Flip Well”) and the specific value of back gate voltage VBb can be chosen such that the threshold voltage of the FDSOI transistors 30 of the predetermined region 21 is higher with a back gate voltage equal to VBB than with a back gate voltage equal to VRFF. With such arrangements, applying the specific value VBb of back gate voltage results in a degradation of the performance of the FDSOI transistors 30 of the predetermined region 21. Thus, for the clock cycles where the specific value VBb of back gate voltage is applied, the adder 16 behaves as an approximate adder. On the other hand, for the clock cycles where the reference value V^p of back gate voltage is applied, the adder 16 behaves as an exact adder. For example, it can be considered that Vj^p is at 0V.

[0072] There are two ways of applying a bias to the substrate 36: the so-called “forward bias” mode (FBB, from the English acronym “Forward Body Bias”) and the so-called “reverse bias” mode (RBB, from the English acronym “Reverse Body Bias”).

[0073] Generally speaking, for an NMOS transistor, if VBb is positive, this corresponds to a "forward bias" (FBB), and therefore an improvement in transistor performance. On the other hand, if VBb is negative, this corresponds to "reverse bias" (RBB), and therefore a degradation in transistor performance.

[0074] For a PMOS type transistor, it is the opposite: if VBb is positive, this corresponds to a “reverse bias” (RBB), and if VBb is negative this corresponds to a “forward bias” (FBB).

[0075] A CMOS structure comprises both an NMOS transistor and a PMOS transistor. A CMOS structure in FDSOI technology can be optimized for either FBB or RBB modes.

[0076] In the present invention, it is advantageous that the FDSOI transistors 30 are arranged in CMOS structures optimized for the RBB mode.

[0077] [Fig. 5] schematically represents a CMOS FDSOI structure optimized for the RBB mode. The CMOS structure comprises an NMOS type FDSOI transistor 30a on a P well and a PMOS type FDSOI transistor 30b on an N well. Thus, in the CMOS structure illustrated in [Fig. 5], the substrate 36a of the NMOS transistor 30a is of the P type (this is then referred to as a P type “well” or a P type “well”). The source 31a and the drain 32a are on the other hand of the N type. The substrate 36b of the PMOS transistor 30b is of the N type (this is then referred to as an N type “well” or an N type “well”). Source 31b and drain 32b, on the other hand, are of type P. This corresponds to a so-called "traditional" circuit ("Regular Well" in English literature) optimized for RBB mode, i.e. allowing high threshold voltages (RVT or HVT) to be favored.

[0078] It should be noted, however, that nothing would prevent the use of CMOS structures with an NMOS on an N-well and a PMOS on a P-well (circuit called "Flip Well" in the English literature). Such a circuit is, however, generally optimized for the FBB mode, i.e. to favor low threshold voltages (LVT).

[0079] The second embodiment described with reference to [Fig. 3] corresponds to a particularly compact architecture (since it comprises a single adder). Furthermore, this second embodiment offers an increased level of flexibility on the error distribution that can be obtained. It is indeed possible to configure the control circuit 15 to dynamically determine the back gate voltage value to be applied as a function of a desired error probability level for the calculation of the scalar product. The back gate voltage makes it possible to vary the threshold voltage of the FDSOI transistors 30 of the region 21. A higher threshold voltage leads to an increase in the propagation time of the logic gates implemented by these transistors, and consequently a loss of precision in the calculations.

[0080] The graph shown in [Fig.7] illustrates the possibility of controlling the level of pro error reliability as a function of the back gate voltage VBb applied by the source dynamic voltage 17. This graph represents the error probability level (value between 0 and 1), as a function of the back gate voltage VBb (in Volts), in the case where a single low-order bit of the addition result is impacted. It can be observed on this graph that the error probability level increases with the back gate voltage and tends towards a limit value of 0.5. The measurements presented in the graph of [Fig.7] were obtained on a digital circuit 10 similar to that described above with reference to [Fig.3].

[0081] The choice of the number L of low-order bits that one wishes to be impacted by the approximate calculation, and therefore indirectly the determination of the region 21, also participates in the definition of the error distribution. This aspect is however static since it is defined at the design of the digital circuit 10, and can no longer be changed subsequently.

[0082] What was mentioned previously for the first embodiment about the possibility of configuring the control circuit 15 to dynamically control which additions are to be performed approximately in the calculation of the scalar product also applies to the second embodiment.

[0083] The above description clearly illustrates that, through its various characteristics and their advantages, the present invention achieves the set objectives. In particular, the digital circuit 10 according to the invention makes it possible to implement a cryptographic primitive for an LWE type algorithm, without having to use a TRNG or PRNG type hardware component, and while maintaining a particularly simple, compact and energy-efficient architecture.

[0084] The proposed solution further offers good flexibility and good precision on the error probability that can be obtained for the calculation of the scalar product, as well as the possibility of introducing entropy into the error distribution obtained.

[0085] The invention has been described in particular for an application in post-quantum cryptography. However, nothing excludes the possibility of using the digital circuit 10 according to the invention for other applications, in particular to reduce the energy consumption of the system. For example, the digital circuit 10 can be used in other applications requiring vector calculation accelerators, insofar as these applications are resilient to a certain degree of approximation (for example to implement neural networks, in particular in the context of image processing). The digital circuit 10 according to the invention then offers good flexibility in implementing a compromise between calculation precision and energy consumption.

Claims

Claims

1. Digital circuit (10) for calculating a scalar product between two vectors of dimension N, N being an integer at least equal to two, the two vectors being denoted respectively (“q, et], ..., j, ..., aN_^) and (¾. , Sj, ..., ; the digital circuit (10) comprises a multiplier (11), an accumulator (12) comprising at least one adder (13) and a register (14), as well as a control circuit (15) for the accumulator (12); the digital circuit (10) is configured to be clocked by a clock, and at a clock pulse of index j, j being an integer varying between 0 and (N - 1): - the multiplier (11) is configured to calculate a result >! of a multiplication x of the components of index j of the two vectors, - the accumulator (12) is configured to add the result r> of the multiplication with a current value of the register (14), and to store a result of the addition in the register (14); the control circuit (15) is configured to control the accumulator (12) so as to perform the addition approximately, that is to say with a predetermined level of probability that the result of the addition includes an error, for at least one addition among the N additions of the calculation of the scalar product.

2. A digital circuit (10) according to claim 1, wherein: - the accumulator (12) comprises a single adder (16) implemented using “totally depleted silicon on insulator” technology, FDSOI; - a predetermined region (21) of the adder (16) groups together FDSOI transistors (30) forming logic gates which control a predetermined number L of low-order bits of the result of the addition, L being an integer at least equal to one; - said predetermined region (21) is connected to a voltage source (17) making it possible to apply a back gate voltage to the FDSOI transistors of the region (21), the value of the back gate voltage which can be dynamically controlled by the control circuit (15), - the control circuit (15) is configured to apply by default a back gate voltage reference value, and to apply a specific back gate voltage value, different from the reference value, only during the execution of said at least one addition to be performed approximately.

3. The digital circuit (10) of claim 2 wherein the control circuit (15) is configured to dynamically determine the specific value of back gate voltage to be applied based on a desired error probability level for the calculation of the scalar product.

4. Digital circuit (10) according to any one of claims 2 or 3 in which the FDSOI transistors (30) are arranged in CMOS structures each comprising an NMOS transistor (30a) on a P well and a PMOS transistor (30b) on an N well.

5. Digital circuit (10) according to claim 1, wherein: - the accumulator (12) comprises an exact adder (18) synthesized specifically to calculate an addition exactly, an approximate adder (19) synthesized specifically to calculate an addition with the predetermined level of error probability, and a multiplexer (20); - for each addition executed at a clock tick of index j, the multiplexer (20) is configured by the control circuit (15) to select the adder to be used from among the exact adder (18) and the approximate adder (19).

6. A digital circuit (10) according to any one of claims 1 to 5 wherein said at least one addition to be performed approximately, among the N additions of the scalar product calculation, is different at each new scalar product calculation.

7. A digital circuit (10) according to any one of claims 1 to 6 wherein said at least one addition to be performed approximately in the calculation of the scalar product is chosen randomly. torily.

8. A digital circuit (10) according to any one of claims 1 to 7 wherein the number of additions to be performed approximately in the calculation of the scalar product is dynamically controlled by the control circuit (15) as a function of a desired error probability level for the calculation of the scalar product.

9. Electronic device implementing a cryptographic algorithm based on a “learning with errors” technology, LWE, said device being characterized in that it comprises at least one digital circuit (10) according to any one of claims 1 to 8.