Transposition of a matrix
The method efficiently and securely transposes matrices by employing logical operations and masking, addressing inefficiencies and security gaps in existing methods.
Patent Information
- Application Number
- FR2023015344
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-04
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing matrix transposition methods are inefficient, insecure, and lack effective masking operations, which are essential for secure data processing and encryption.
A method and electronic device implementation that efficiently transposes matrices through a series of logical operations, including shifting, XOR functions, and masking, ensuring data security by hiding the transposed data during the process.
The method provides a secure and efficient matrix transposition that protects data integrity by masking operations, preventing unauthorized access during the transposition process.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Transposition of a matrix Technical field
[0001] The present description relates generally to electronic circuits and devices, and, more particularly, to the implementation, by an electronic circuit or device, of a method of transposing a matrix. Prior art
[0002] In the field of data processing and encryption, it is common to use matrices and apply different operations to them.
[0003] A commonly applied operation to a matrix is a transposition operation, during which the rows and columns of said matrix are swapped.
[0004] It would be desirable to be able to improve, at least in part, certain aspects of the implementations of the matrix transposition method. Summary of the invention
[0005] There is a need for an implementation of a more efficient matrix transposition method.
[0006] There is a need for an implementation of a more secure matrix transposition method.
[0007] There is a need for an implementation of a matrix transposition method providing masking operations.
[0008] There is a need for electronic circuits and devices suitable for implementing such a matrix transposition method.
[0009] One embodiment overcomes all or part of the drawbacks of known methods for implementing a matrix transposition.
[0010] One embodiment overcomes all or part of the drawbacks of known methods for implementing a matrix transposition providing masking operations.
[0011] One embodiment overcomes all or part of the drawbacks of known electronic circuits and devices suitable for implementing a matrix transposition.
[0012] An embodiment overcomes all or part of the drawbacks of known electronic circuits and devices adapted to the implementation of a matrix transposition providing masking operations.
[0013] One embodiment provides a method, by an electronic device, of transposing a matrix comprising n rows and n columns, each row of said matrix forming a first vector m[i], i being an integer varying from 0 to n-1, the method comprising the following successive steps: (a) Obtain second vectors x[i] by shifting to the right each first vector m[i] by a step corresponding to the number of said line; (b) Generate a second vector w by applying the following mathematical formula: [Math 1] in which the XOR1^ function corresponds to the successive application of the logical EXCLUSIVE OR function to several data; (c) Generate third vectors z[i,l], 1 being an integer varying from 0 to n-1, by applying the following mathematical formula for each value of i: [Math 2] z [ i, l ] = x [ i ] & ROTI^ Vect”, i +1), in which: - & represents the logical AND function; - ! represents the logical function allowing to obtain the complement of a binary data; ■ ROTRtyectn, i + t) represents a unit vector whose elements are all equal to zero except the element of rank i+1 which is equal to one; and (d) Generate a fourth vector v[l], representing a row of the transpose of the matrix A, by applying the following mathematical formula: [Math 3] v[ / ] = ROTL^w xor XOR^(z[i,l])\ in which: - ROTL represents a left shift function; - xor represents the logical function EXCLUSIVE OR, in which steps and are repeated for all values of 1.
[0014] Another embodiment provides an electronic device suitable for implementing a method of transposing a matrix comprising n rows and p columns, each row of said matrix forming a first vector m[i], i being an integer varying from 0 to n-1, the method comprising the following successive steps: (a) Obtain second vectors x[i] by shifting to the right each first vector m[i] by a step corresponding to the number of said line; (b) Generate a second vector w by applying the following mathematical formula: [Math 4] in which the XOR1^ function corresponds to the successive application of the logical EXCLUSIVE OR function to several data; (c) Generate third vectors z[i,l], 1 being an integer varying from 0 to p-1, by applying the following mathematical formula for each value of i: [Math 5] z[z, j] = x[z] & Vect(i,l), in which: - & represents the logical AND function; - ! represents the logical function allowing to obtain the complement of a binary data; - ROT^Vectn, i + / ) represents a unit vector whose elements are all equal to zero except the element of rank i+1 which is equal to one; and (d) Generate a fourth vector v[l], representing a row of the transpose of the matrix A, by applying the following mathematical formula: [Math 6] v[z] = ROTL(w xor XOR" in which: - ROTL represents a left shift function; - xor represents the logical function EXCLUSIVE OR, in which steps and are repeated for all values of 1.
[0015] According to one embodiment, the method further comprises masking operations.
[0016] According to one embodiment, a masking operation is a masking operation by applying the xor function.
[0017] According to one embodiment, the method further comprises a step of masking the second vectors x[i] implemented during the step.
[0018] According to one embodiment, the step of the third masked vectors z'[i,l] are generated by applying the following mathematical formula for each value of i: [Math 7] z[i,Z]=(x[i] xorr[Z])& in which r[l] is a mask.
[0019] According to one embodiment, the mask r[l] is generated randomly.
[0020] According to one embodiment, the integers n and p are equal.
[0021] According to one embodiment, the integer n is between 1 and 20. Brief description of the drawings
[0022] These characteristics and advantages, as well as others, will be explained in detail in the following description of particular embodiments given without limitation in relation to the attached figures among which:
[0023] [Fig.l] represents, very schematically and in the form of blocks, an embodiment of an electronic device adapted to implement the embodiments of figures 4 and 5;
[0024] [Fig.2] schematically represents a transposition operation of a matrix;
[0025] [Fig.3] represents, very schematically and in block form, a masking operation;
[0026] [Fig.4] represents a block diagram illustrating a first mode of implementation of a method of transposing a matrix; and
[0027] [Fig.5] represents a block diagram illustrating a second mode of implementation of a method of transposing a matrix. Description of the embodiments
[0028] The same elements have been designated by the same references in the different figures. In particular, the structural and / or functional elements common to the different embodiments may have the same references and may have identical structural, dimensional and material properties.
[0029] For the sake of clarity, only the steps and elements useful for understanding the embodiments described have been represented and are detailed.
[0030] Unless otherwise specified, when referring to two elements connected to each other, this means directly connected without intermediate elements other than conductors, and when referring to two elements connected (in English "coupled") to each other, this means that these two elements can be connected or be connected by means of one or more other elements.
[0031] In the following description, when reference is made to absolute position qualifiers, such as the terms "front", "back", "top", "bottom", "left", "right", etc., or relative position qualifiers, such as the terms "above", "below", "upper", "lower", etc., or to orientation qualifiers, such as the terms "horizontal", "vertical", etc., reference is made unless otherwise specified to the orientation of the figures.
[0032] Unless otherwise specified, the expressions "about", "approximately", "substantially", and "of the order of" mean to within 10%, preferably to within 5%.
[0033] The embodiments described below relate to the implementation of a transposition of a matrix. A transposition operation of a matrix is an operation during which the rows and columns of an input matrix are swapped. The embodiments described below further relate to the implementation implementation of a transposition operation providing masking operations, and therefore making it possible to securely support a matrix to be transposed.
[0034] [Fig.l] is a block diagram representing, very schematically, an architecture of an example of an electronic device 100 adapted to implement a method of transposing a matrix.
[0035] According to one example, the electronic device 100 comprises a processor 101 (CPU) adapted to implement different processing of data stored in memories and / or provided by other circuits of the device 100. According to one embodiment, the processor 101 is adapted to implement a method of transposing a matrix.
[0036] According to one example, the electronic device 100 further comprises different types of memories 102 (MEM), including, for example, a non-volatile memory, a volatile memory 103, and / or a read-only memory 104. Each memory 102 is adapted to store different types of data.
[0037] According to one example, the electronic device 100 further comprises, for example, a secure element 103 (SE) adapted to process sensitive and / or secret data. The secure element 103 may comprise its own processor(s), its own memory(s), etc. According to one embodiment, the secure element 101 is adapted to implement a method of transposing a matrix.
[0038] According to one example, the electronic device 100 may further comprise interface circuits 104 (IN / OUT) adapted to send and / or receive data originating from outside the device 100. The interface circuits 104 may further be adapted to implement a data display, for example, a display screen.
[0039] According to one example, the electronic device 100 further comprises different circuits 105 (FCT1) and 106 (FCT2) adapted to perform different functions. For example, the circuits 105 and 106 may comprise measurement circuits, data conversion circuits, etc. According to one embodiment, the circuits 105 and 106 may comprise a circuit adapted to implement a method of transposing a matrix.
[0040] According to one example, the electronic device 100 further comprises one or more data buses 107 adapted to transfer data between its different components.
[0041] According to a particular example, the electronic device 100 is adapted to implement computer programs, and in particular a computer program making it possible to implement a method of transposing a matrix.
[0042] [Fig.2] represents the application of a transposition operation Trans to a Matrix Matrix.
[0043] The Matrix Matrix is a matrix comprising n rows and p columns, n and p being integers greater than or equal to one. The elements, or coefficients, of the Matrix matrix are denoted m,,, i being an integer varying from 0 to p-1, and j being an integer varying from 0 to n-1. According to a preferred embodiment, the integers n and p are identical. For example, the integer n is between 1 and 20, for example is equal to 4, 6 or 16, and the integer p is between 1 and 40, for example is equal to 32.
[0044] The transposition operation Trans provides a matrix Trans(Matrix) comprising p rows and n columns. The elements, or coefficients, of the matrix Trans(Matrix) are denoted m'jj, and are given by the following mathematical formula: [Math 8]
[0045] In other words, the transposition operation Trans allows the rows and columns of the matrix Matrix to be inverted. In other words, a vector representing a row of elements of index k of the matrix Matrix comprises the same elements as a vector representing a column of index k of elements of the matrix Trans(Matrix), k being an integer varying between 1 and n or p.
[0046] The methods described in relation to Figures 4 and 5 illustrate practical implementation modes of a transposition operation of the type of the Trans transposition operation.
[0047] [Fig.3] represents, very schematically and in block form, a masking operation MASK of a data item Data by a masking data item Mask.
[0048] According to one embodiment, the Data data is binary data representing sensitive or secret data, i.e. data whose content must not be accessible to everyone, and / or whose access to the content is restricted to an entity or a group of entities.
[0049] According to one embodiment, the masking data Mask, or mask Mask, is data used to mask the content of the data Data. It is common to use pseudo-randomly or randomly generated data as a mask Mask.
[0050] There are several types of masking operation. The masking operation MASK concerned here is a masking operation using the logical EXCLUSIVE OR (EXCLUSIVE OR, XOR) function, hereinafter denoted xor function.
[0051] According to one embodiment, the application of the masking operation MASK makes it possible to obtain a masked data MASK(Data). The masked data MASK(Data) is given by the following mathematical formula: [Math 9] MASK (Data) = Data xor Mask
[0052] An operation of unmasking the masked data corresponds to the application, once again, of the masking operation MASK. Indeed: [Math 10] M AS K (MASK (Data)) = (Data xor Mask) xor Mask = Data
[0053] [Fig.5] concerns the implementation of a method for transposing a matrix whose data are masked. The application of the masking operation to a data matrix is detailed in relation to [Fig.5].
[0054] [Fig.4] is a block diagram illustrating a practical mode of implementation of a method 400 executing a transposition operation of a matrix of the type of the transposition operation Trans described in relation to [Fig.2]. According to one embodiment, this method 400 can be implemented by the device 100 described in relation to [Fig.1], and, more particularly, by the processor and / or one of the circuits making up the device 100.
[0055] To illustrate the operation of the method 400, a matrix Mat of size 4x4 given by the following mathematical formula is considered: [Math 11] [ABC D\ EFGH Mat~ IJKL \MNO PI in which elements A to P are data.
[0056] The method 400 is also suitable for obtaining the transpose of a rectangular matrix of size n*p of the type of the Matrix matrix described in relation to [Fig.2]. This is sufficient to divide the rectangular matrix into several square matrices and to apply the method 400 to each square matrix, or to complete the rectangular matrix with empty elements to obtain square matrices. The skills of the person skilled in the art are sufficient to make the necessary adaptations in view of the explanations given below. The implementation of the method 400 is detailed by considering subsequently only a square Matrix matrix where the integers n and p are equal.
[0057] At an initial step 401 (Mat), and as previously stated, we consider the matrix Mat whose data are stored in the form of four row vectors m[0], m[l], m[2] and m[3] each representing a row of the matrix Mat. In other words, the vectors m[0] to m[3] are given by the following mathematical formula: [Math 12] ;40] = (AB, C, D) 41] = te F, g, H) 42] = ( / , FK, L) '43] = (M, N, O, P)
[0058] In the case of the matrix Matrix described in relation to [Fig.2], the vectors m[i], i varying from 0 to n-1, are given by the following mathematical formula: [Math 13] n(i] = (m^0, miA, min^
[0059] At a step 402 (RotR), following step 401, vectors x[0], x[l], x[2] and x[3] are generated from the vectors mO, ml, m2, and m3. The vectors x[0] to x[3] are given by the following mathematical formulas: [Math 14] ^Q] = ROTR(M 0) B, C, D) 41] = ROTRUtü 1) =te, E, F. G) j{2] = ROTR 2) =(K, L, I, j) '^3]-ROTR(ni^ 3)=te, O, P, M) in which ROTR represents a function for shifting the elements of a vector to the right, its first argument corresponding to the vector whose elements are to be shifted, and its second argument corresponding to the shift step, that is to say the integer added to the index of each element, modulo the number of elements included in the vector.
[0060] In the case of the matrix Matrix described in relation to [Fig.2], the vectors x[i], i varying from 0 to n-1, are given by the following mathematical formula: [Math 15] 4 / ]=i?^ri?(4 / li)
[0061] At a step 403 (Work Reg), following step 402, a work vector w is generated from the vectors x[0] to x[3]. The work vector w is given by the following mathematical formula: [Math 16] w = 4o] xor 41] xor 42] xor 43]
[0062] In the case of the matrix Matrix described in relation to [Fig.2], the work vector w is given by the following mathematical formula: [Math 17] w = ^0^4 / 1=40]xor 41] xor... xor 4«-1] in which XOR'q 1 represents the successive application of the logical EXCLUSIVE OR function, or xor function, to several data.
[0063] At a step 404 (!Vect(i)), following step 403, vectors z[0,l], z[1,1], z[2,l] and z[3,l] are generated from the vectors x[0], x[l], x[2], and x[3], j being an integer varying between 0 and n-1. The vectors z[0,l] to z[3,l] are given by the following mathematical formulas: [Math 18] ' 4Q Z] = x[0] & ROTR(Vecf\ï) = (Q, B, C, D) 41, Z] = Ml] & ROTR^Vect4, 1 + Z) = (H, 0, F, G) 42, l] = 4M & ROTR( Vecé, 2 + l) = (K, L, 0, j) . 43, l] = 43] & lROTR(Vect\ 3 + 1) = (N, O, P, 0)
[0064] In which: - & represents the logical AND function; - ! represents the logical function allowing to obtain the complement of a binary word, in other words ! allows to invert the elements of a vector representing a binary one and a binary zero; - Vect4 is a unit vector of size 4 whose first element is equal to one, and the other elements are equal to zero; - and 1 being an integer ranging from 0 to 3.
[0065] More particularly, a unit vector is here called a vector all of whose elements comprise data representing a binary zero, except one element which comprises data representing a binary one. In particular, the function ROTR(Vect4,i+l) makes it possible to generate a unit vector of size 4 and whose index of the element comprising data representing a binary one is given by the result of the sum of the integers i and 1 modulo 4.
[0066] According to one embodiment, during the first occurrence of step 404, the integer 1 is equal to zero. The conditions for incrementing the integer 1 are described below.
[0067] In the case of the matrix Matrix described in relation to [Fig.2], the vectors z[i, 1], i varying from 0 to n-1, are given by the following mathematical formula: [Math 19] ii, l] = 4ï] & ROTR^Vect”, i +1) in which Vectn is a unit vector comprising n elements.
[0068] At a step 405 (XOR), following step 404, a vector y[l] is generated using the following mathematical formula: [Math 20] 4 / ] = w xor 40, Z] xor 4 hl] xor 42, Z] xor 4 a Z]
[0069] In the case where 1 is equal to zero, y[0] is given by the following mathematical formula: [Math 21] j[0] = w xor z[0,0] xor z[ 1,0] xor z[2,0] xor z[3,0] = (A, KI, M)
[0070] In the case of the matrix Matrix described in relation to [Fig.2], the vector y[l] is given by the following mathematical formula: [Math 22] j[Z] = w xor <n-l ?), successive à l'étape 405, si la valeur de l'entier 1 utilisée à l'étape 405 est strictement inférieure à trois alors (sortie Y de l'étape 406) l'étape suivante est une étape 407 (1++), sinon (sortie N de l'étape 406) l'étape suivante est une étape 408 (RotL).
[0072] In the case of the matrix Matrix of [Fig.2], the value of the integer 1 is compared to n-1.
[0073] In step 407, following step 406, the integer 1 is incremented by one, i.e. by one.
[0074] In step 408, vectors v[0], v[l], v[2], and v[3] are generated from vectors y[0], y[l], y[2], and y[3]. Vectors v[0] to v[3] are given by the following mathematical formulas: [Math 7] (401=^^(^0),0)=(^^,4 Wl v[ 1] =^077.(41]. 1) =(B,FJN) 42] = / MZTL(42],2) = (C,G,Æ,O) '43]=ROTL(.43],3) =(D, HLP) in which ROTL represents a function for shifting the elements of a vector to the left, its first argument corresponding to the vector whose elements are to be shifted, and its second argument corresponding to the shift step, that is to say the integer removed from the index of each element modulo the number of elements included in a vector.
[0075] In the case of the matrix Matrix described in relation to [Fig.2], the vector v[i] is given by the following mathematical formula: [Math 23] v[i]=ROTL(y[i],i)
[0076] At a final step 409 (Trans(Matrix)), following step 408, all the vectors v[0], v[l], v[2] and v[3] have been generated and make it possible to obtain the transpose Trans(Mat) of the matrix Mat. Indeed, the vectors v[0], v[l], v[2] and v[3] represent all the rows of the transpose Trans(Mat).
[0077] In the case of the Matrix matrix of [Fig.2], the vectors v[i] form the rows of the Matrix matrix.
[0078] An advantage of this mode of implementation is that it allows a matrix transposition operation to be carried out without the data of the matrix to be transposed being made accessible. Indeed, using the working vector w allows the data to be hidden during the implementation of the method 400.
[0079] [Fig. 5] is a block diagram illustrating another practical implementation mode of a method 500 executing a transposition operation of a matrix of the type of the transposition operation Trans described in relation to [Fig. 2]. According to one embodiment, this method 500 can be implemented by the device 100 described in relation to [Fig. 1], and, more particularly, by the processor and / or one of the circuits making up the device 100.
[0080] The method 500 is similar to the method 400 described in relation to [Fig.4]. Indeed, the method 500 allows the implementation of a transposition operation of a matrix providing as output the transpose of the masked matrix. For this, the method comprises all the steps of the method 400, but also comprises a masking step detailed below.
[0081] To illustrate the operation of method 500, and as for method 400, we again consider the matrix Mat of size 4x4 given by the following mathematical formula: [Math 24] Matt = D\ H L \MNO PI
[0082] The method 500 is also suitable for obtaining the transpose of a rectangular matrix of size n*p of the type of the matrix Matrix described in relation to [Fig.2]. It is sufficient for this to divide the rectangular matrix into several square matrices and to apply the method 400 to each square matrix, or to complete the rectangular matrix with empty elements to obtain square matrices. The skills of the person skilled in the art are sufficient to make the necessary adaptations in view of the explanations data below. The implementation of the method 400 is detailed by considering subsequently only a square matrix Matrix where the integers n and p are equal.
[0083] At an initial step 501 (Mat), identical to step 401 of [Fig.4], the data of the matrix Mat are stored in the form of the four row vectors m[0], m[l], m[2] and m[3] each representing a row of the matrix Mat. In other words, the vectors m[0] to m[3] are given by the following mathematical formulas: [Math 25] 40] = (AB, C, D) = F, G, H) n{2}^(LFK, L) 43] = (M, N, O, P)
[0084] In the case of the matrix Matrix described in relation to [Fig.2], the vectors m[i], i varying from 0 to n-1, are given by the following mathematical formula: [Math 26] »(^ = (^0, m iA , ...,
[0085] At a step 502 (RotR), identical to step 402 and successive to step 501, vectors x[0], x[l], x[2] and x[3] are generated from the vectors mO, ml, m2, and m3. The vectors x[0] to x[3] are given by the following mathematical formulas: [Math 27] / 40] = ROTR(niQl Q) = (A, B, C, D) 41] = ROTR(nü 1) E, F, G) ^2] = ROTR(m[2} 2) = (< L, I, J) ■j{3] = ROTR(iîi3l 3) =(N, O, P, M)
[0086] In the case of the matrix Matrix described in relation to [Fig.2], the vectors x[i], i varying from 0 to n-1, are given by the following mathematical formula: [Math 28] 4*] = ROT R ( / «[di )
[0087] At a step 503 (Work Reg), identical to step 403 and subsequent to step 502, a work vector w is generated from the vectors x[0] to x[3]. The work vector w is given by the following mathematical formula: [Math 29] w = 40] xor 41] xor 42] xor 43]
[0088] In the case of the matrix Matrix described in relation to [Fig.2], the work vector w is given by the following mathematical formula: [Math 30] w = X^y / ] = 40] xor 41] xor... xor 4« - l]in which XOI^1 represents the successive application of the logical function EXCLUSIVE OR, or xor function, to several data.
[0089] At a step 504 (MASK !Vect(i)), following step 503, vectors z'[0,l], z'[l,1], z'[2,l] and z'[3,l] are generated from the vectors x[0], x[l], x[2], and x[3], and from a mask r[l], 1 being an integer varying from 0 to n-1. The vectors z[0,l] to z[3,l] are given by the following mathematical formulas: [Math 31] Mo, ZH*[0] xorr[Z]) & ROTR(Vectt Ï) = (Q, B, C, D) ROTR(Vect\ï+ï)^(H,0,F,G) 42, / H42jwrr[ / ]) & IROTR(Vect, 2 + / ) = (K, F 0, j) M3j] = (431wrrU]) & ROTR^Vec^, 3+l) = (.N, O, P, 0)
[0090] According to one embodiment, the mask r[l] is a masking data item. According to one example, the mask r[l] is generated randomly or pseudo-randomly. The mask r[l] is used in step 504 to mask the vectors x[0], x[l], x[2], and x[3].
[0091] According to one embodiment, during the first occurrence of step 504, the integer 1 is equal to zero. The conditions for incrementing the integer 1 are described below.
[0092] In the case of the matrix Matrix described in relation to [Fig.2], the vectors z'[i, 1], i varying from 0 to n-1, are given by the following mathematical formula: [Math 32] zfe l] = (x[i] xor r[ / D & ROTR^Vecf, i+ / )
[0093] At a step 505 (XOR), following step 504, a vector y'[l] is generated using the following mathematical formula: [Math 33] jfz] = tv xor zfo, Z] xor zf 1, Z] xor zf2, Z] xor z(3, / ]
[0094] In the case where 1 is equal to zero, y'[0] is given by the following mathematical formula: [Math 34] y'[0] = w xor z'[0,0] xor z'[ 1,0] xor z'[2,0] xor z'[3,0] =(AE, LM)
[0095] In the case of the matrix Matrix described in relation to [Fig.2], the vector y'[l] is given by the following mathematical formula: [Math 35] y'[Z] -w xor XOR'^z'li, Z] = wxorz'[0,0] xor z'[l,0] xor ...xor z[n-1, / ]
[0096] At a step 506 (l <n-l ?), successive à l'étape 505, si la valeur de l'entier 1 utilisée 505 est strictement inférieure trois alors (sortie y 506) suivante une étape 507 (j++), sinon n 508 (rotl).
[0097] In the case of the matrix Matrix of [Fig.2], the value of the integer 1 is compared to n-1.
[0098] In step 507, following step 506, the integer 1 is incremented by one, i.e. by one.
[0099] In step 508, vectors v'[0], v'[l], v'[2], and v'[3] are generated from vectors y'[0], y'[l], y'[2], and y'[3]. Vectors v'[0] to v'[3] are given by the following mathematical formulas: [Math 7] zv'[O] =^071.0101,0) =(A,E,I, M) p'[ 11 = ROTL(y'[ 1 ], 1 ) = (fl, F, J, N) F[ï]^R0TL{y'm,2) 4CG / COI ^[3(=77077.( / (3(,3) =(D, H,L,P)
[0100] In the case of the matrix Matrix described in relation to [Fig.2], the vector v'[i] is given by the following mathematical formula: [Math 36] v'[i]-ROTL(yr[i],i)
[0101] At a final step 509 (Trans(Matrix)), following step 508, all the vectors v'[0], v'[l], v'[2] and v'[3] have all been generated and make it possible to obtain the transpose Trans(Mat) of the matrix Mat whose rows have all been masked by a different mask, the masks r[l]. Indeed, the vectors v'[0], v'[l], v'[2] and v'[3] represent all the rows of the transpose Trans(Mat).
[0102] In the case of the matrix Matrix of [Fig.2], the vectors v'[i] form the rows of the matrix Matrix.
[0103] An advantage of this mode of implementation is that it allows a matrix transposition operation to be carried out without the data of the matrix to be transposed being made accessible. Indeed, using the working vector w makes it possible to mask the data during the implementation of the method 500.
[0104] Another advantage of this mode of implementation is that it makes it possible to provide a masked matrix transpose.
[0105] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these various embodiments and variations could be combined, and other variations will occur to those skilled in the art.
[0106] Finally, the practical implementation of the embodiments and variants described is within the reach of those skilled in the art from the functional indications given above.
Claims
Claims
1. Method (400; 500), by an electronic device, of transposing a matrix (Mat) comprising n rows and n columns, each row of said matrix (Mat) forming a first vector m[i], i being an integer varying from 0 to n-1, the method comprising the following successive steps: (a) Obtaining second vectors x[i] by shifting each first vector m[i] to the right by a step corresponding to the number of said row; (b) Generating a second vector w by applying the following mathematical formula: [Math 37] in which the XOR^^ function corresponds to the successive application of the EXCLUSIVE OR logical function to several data; (c) Generate third vectors z[i,l], 1 being an integer varying from 0 to n-1, by applying the following mathematical formula for each value of i: [Math 38] Z [ i, l ] = x [ i ] & \ROTR( Vectn, i + Z), in which: - & represents the logical AND function;- ! represents the logical function for obtaining the complement of a binary data; ■ ROTR^Vect”, i + Z) represents a unit vector whose elements are all equal to zero except the element of rank i+1 which is equal to one; and (d) Generate a fourth vector v[l], representing a row of the transpose of the matrix A, by applying the following mathematical formula: [Math 39] v[z] ROTL^w xor XO^(z[i,l])} in which: - ROTL represents a left shift function; - xor represents the logical function EXCLUSIVE OR,; in which steps (c) and (d) are repeated for all del values.
2. The method of claim 1, wherein the method further comprises masking operations.
3. The method of claim 2, wherein a masking operation is a masking operation by applying the xor function.
4. A method according to claim 2 or 3, wherein the method further comprises a step (e) of masking the second vectors x[i] implemented during step (c).
5. The method of claim 4, wherein step (c) the third masked vectors z'[i,l] are generated by applying the following mathematical formula for each value of i: [Math 43] z[i,Z] = (x[Z] xorr[fl)& where r[1] is a mask.
6. A method according to claim 5, wherein the mask r[l] is randomly generated.
7. A method according to any one of claims 1 to 6, wherein the integers n and p are equal.
8. A method according to any one of claims 1 to 7, wherein the integer n is between 1 and 20.
9. Electronic device adapted to implement a method (400; 500) of transposing a matrix (Mat) comprising n rows and p columns, each row of said matrix (Mat) forming a first vector m[i], i being an integer varying from 0 to n-1, the method comprising the following successive steps: (a) Obtaining second vectors x[i] by shifting each first vector m[i] to the right by a step corresponding to the number of said row; (b) Generating a second vector w by applying the following mathematical formula: [Math 40] in which the function corresponds to the successive application of the logical function EXCLUSIVE OR to several data; (c) Generate third vectors z[i,l], 1 being an integer varying from 0 to p-1, by applying the following mathematical formula for each value of i: [Math 41] z[i, j]=x[ï] & in which: - & represents the logical AND function; - ! represents the logical function allowing to obtain the complement of a binary data; ■ ROTR{Vectn. i + l) represents a unit vector whose elements are all equal to zero except the element of rank i+1 which is equal to one; and (d) Generate a fourth vector v[l], representing a row of the transpose of the matrix A, by applying the following mathematical formula: [Math 42] v[z] = ROTliw xor XO^ ( z [ i, l ] )} in which: - ROTL represents a left shift function; - xor represents the logical function EXCLUSIVE OR, in which steps (c) and (d) are repeated for all del values.
10. The device of claim 9, wherein a masking operation is a masking operation by applying the xor function.