Modular reduction of cryptographic operations

FR3166774A1Pending Publication Date: 2026-03-27INFINEON TECHNOLOGIES AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2026-03-27

Smart Images

  • Figure 00000025_0000
    Figure 00000025_0000
  • Figure 00000025_0001
    Figure 00000025_0001
Patent Text Reader

Abstract

Modular Reduction of Cryptographic Operations. Modular reduction includes (i) calculating an intermediate value q, from which a quotient of the input number C by the modulus N is obtained, (ii) extracting a number Q for a reduction operation C – Q·N from the intermediate value q, (iii) extracting information from the intermediate value q, in which, using this information, it can be determined before performing the reduction operation C – Q·N, whether a final reduction is to be performed, (iv) performing the reduction operation C – Q·N, (v) depending on the information, performing the final reduction or not performing the final reduction. Figure for the abstract: Fig. 2
Need to check novelty before this filing date? Find Prior Art

Claims

Demands

1. Device for performing a modular reduction of an input number C modulo a module A1, wherein the device comprises a processing unit, which is arranged to: - calculate an intermediate value q, from which is obtained, as an approximation, a quotient of the input number C by the module N, - extract a number Q for a reduction operation C - QN from the intermediate value q, - extract information from the intermediate value q, in which, using the information, it can be determined, even before performing the reduction operation C - QN, that a final reduction is to be performed, - perform the reduction operation C - QN, - depending on the information, perform the final reduction or not perform the final reduction.

2. Device according to claim 1, wherein the processing unit is arranged to perform a cryptographic operation, in particular encryption, decryption, affixing of signature and / or verification of signature.

3. Device according to claim 2, wherein the processing unit comprises one of the following or is conformed into one of the following: - a processor, - a chip, - a cryptographic model.

4. A device according to any one of claims 1 to 3, wherein the processing unit is arranged to perform modular reduction as part of a modular multiplication.

5. Device according to any one of claims 1 to 4, - in which the module N has a number of m words and the number of inputs C is longer by at most 0 < d words than the module N, - in which the intermediate value q is determined by calculating elementary products C i and lj with i + j > m + d - 1, in which C i is a word with value i of the number of inputs C and lj with value j, in which the value j is determined according to PP or one of its integer multiples, in which W = 2" and n is a word width.

6. Device according to any one of claims 1 to 5, wherein the processing unit is arranged to extract information, wherein the information corresponds to a Boolean value ql > Wd-3 or is a logical attenuation.

7. Device according to claim 6, wherein the processing unit is arranged to perform the final reduction, if the boolean value or the logic attenuation is true.

8. A method for performing a modular reduction of an input number C modulo a modulo N, comprising the stages: - calculating an intermediate value q, from which an approximate quotient of the input number C by the modulo N is obtained, - extracting, from the intermediate value q, a number Q for a reduction operation C - QN - extracting information from the intermediate value q, in which, using the information, it can be determined, even before performing the reduction operation C - QN, whether a final reduction is to be performed, - performing the reduction operation C - QN, - depending on the information, performing the final reduction or not performing the final reduction.

9. A method according to claim 8, wherein modular reduction is carried out as part of modular multiplication.

10. A method according to claim 8 or 9, - the module N has a number of m words and the input number C is longer by at most 0 < d words than the module N, - in which the intermediate value q is determined by calculating elementary products C i and 1 j with i + j > m + d - 1, in which C i is a word with value i of the input number C and Ij a word with value j of a value I, in which the value 1 is determined according to PP or one of its integer multiples, in which W = 2" and n is a word width.

11. A method according to any one of claims 8 to 10, wherein the information corresponds to a Boolean value ql > Wd-3 or is a logical attenuation.

12. Method according to claim 11, wherein the final reduction is performed, if the boolean value or the logical attenuation is true.

13. A method according to any one of claims 8 to 12, wherein the modular reduction is carried out in a cryptographic method or in a cryptographic system.

14. A method according to any one of claims 8 to 13, wherein modular reduction is carried out within the framework of a cryptographic operation comprising: - encryption, - decryption, - affixing a signature, - verifying a signature.