Apparatus and method for calculating modular multiplication of signed integers, and program

By designing a device and method for calculating signed integer residual product, and directly performing calculations in signed integer representations, the problems of low processing efficiency and insufficient security in the prior art are solved, and efficient and safe calculation results are achieved.

JP7673871B2Active Publication Date: 2025-05-09NEC CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024515243
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-04-13
Publication Date
2025-05-09
Estimated Expiration
2042-04-13

AI Technical Summary

Technical Problem

When calculating the residual product of signed integers, the prior art needs to convert negative data into unsigned data for calculation, resulting in reduced processing efficiency and inability to achieve constant-time calculations, which affects the security of anti-side channel attacks.

Method used

By designing a device and method, the device includes an input unit, a multiplication unit and an upper ratio acquisition unit, the residual product of signed integers is calculated using specific algorithms and steps, and the calculation is performed directly in the signed integer representation, avoiding the conversion of unsigned data.

Benefits of technology

It realizes efficient calculation of signed integer residual product products without converting negative data into unsigned data, improving processing efficiency, and ensuring the security of constant-time calculation and anti-lateral channel attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007673871000056
    Figure 0007673871000056
  • Figure 0007673871000057
    Figure 0007673871000057
  • Figure 0007673871000058
    Figure 0007673871000058
Patent Text Reader

Abstract

The present invention provides a signed integer remainder products calculation device. The signed integer remainder products calculation device includes: an input unit for receiving a first signed integer, a second signed integer, a remainder modulo P, a positive integer n, and a constant R; a multiplication unit; and a high-order bit acquisition unit. The multiplication unit calculates a 2n-bit long first product from the second signed integer and the constant R. The multiplication unit calculates a 2n-bit long second product from the first product and the first signed integer. The high-order bit acquisition unit performs integer approximation on the result of having shifted the second product n bits to the right, with the sign included, and acquires a first high-order bit. The multiplication unit calculates a 2n-bit long third product from the first high-order bit and the remainder modulo P. The high-order bit acquisition unit performs integer approximation on the result of having shifted the third product n bits to the right, with the sign included, and acquires a second high-order bit. The constant R is the reciprocal of the remainder modulo P by a mod 22n remainder calculation on the signed integers.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a signed integer modular multiplication calculation device, a signed integer modular multiplication calculation method, and a program. [Background technology]

[0002] Patent Document 1 relates to a modular calculation method for efficiently calculating modular multiplication using a bisection modular multiplication method with a simple hardware configuration.

[0003] Patent Document 2 relates to a modular exponentiation method for quickly calculating an inverse element required in the Montgomery multiplication algorithm without using a dedicated inverse element computing unit.

[0004] Patent Document 3 relates to a cryptographic processing device that improves the processing speed when performing modular division using the Montgomery method. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] JP 2007-219261 A [Patent Document 2] Special Publication No. 2004-226516 [Patent Document 3] JP 2003-150050 A Summary of the Invention [Problem to be solved by the invention]

[0006] The following analysis is given by the inventors.

[0007] There are various applications of efficient methods for calculating modular products, one example being number theoretic transforms. Number theoretic transforms (NTTs) are a technique similar to the Fast Fourier Transform (FFT), and in particular refer to FFTs on modulus rings. Since it is necessary to calculate a large number of modular products, an efficient method for calculating modular products is important.

[0008] Number theoretic transformations are also applied to algorithms for fast multiplication of polynomials. Polynomial rings are often used in lattice cryptography, a type of public key cryptography that bases its security on the computational complexity of a mathematical problem called the lattice problem, and fast polynomial multiplication algorithms are important in practice, so number theoretic transformations are often used.

[0009] However, number theoretic transformations are not necessarily applicable to all lattice cryptography that uses polynomial rings due to the limitations of parameters, etc. For example, lattice cryptography such as Saber and NTRU were finalists in the National Institute of Standards and Technology's standardization competition for quantum-resistant cryptography, but they do not employ number theoretic transformations in their polynomial multiplication algorithms because they use polynomial rings that are unsuitable for number theoretic transformations.

[0010] However, in recent years, a method has been proposed for performing number theoretic transformations even in polynomial rings that are not suitable for number theoretic transformations, making it possible to use number theoretic transformations in the polynomial multiplication algorithms in the above-mentioned Saber and NTRU. It would be extremely significant if we could speed up polynomial multiplication in Saber and NTRU by improving the efficiency of modular multiplication.

[0011] In order to introduce number theoretic transformations into polynomial rings that are not suitable for number theoretic transformations, it is necessary to use signed integer representations.

[0012] Regarding the calculation of the modular product, there is, for example, a calculation method of Montgomery multiplication, as introduced in Patent Document 1. In the calculation method of Montgomery multiplication, the division by the modulus required for the calculation of the modular product is performed by multiplication, a modulus operation of a power of 2, and a division by a power of 2, thereby calculating the modular product without performing the division by the modulus, and it is possible to speed up the calculation of the modular product.

[0013] Also, a method has been proposed that is derived from the Montgomery multiplication calculation method and enables further speedup of modular product calculation. However, all methods including Montgomery multiplication can only handle unsigned data. Therefore, when calculating modular product using signed data, the previously proposed methods for speeding up modular product calculation require a process of converting negative data to unsigned data, calculating the modular product of the unsigned data, performing a conditional branch, and converting the result of the modular product into signed data.

[0014] In addition, the method of converting negative data into data represented by an unsigned integer, calculating the remainder product of the unsigned data, performing a conditional branch, and converting the result of the remainder operation into data represented by a signed integer not only increases the amount of processing and reduces efficiency, but also makes constant-time implementation impossible due to the conditional branch, making it unresistant to side-channel attacks known as timing attacks, and therefore unusable for cryptographic implementation.

[0015] The present invention aims to provide a signed integer modular product calculation device, a signed integer modular product calculation method, and a program that contribute to making it possible to calculate modular products for data represented by signed integers without converting negative data into data represented by unsigned integers. [Means for solving the problem]

[0016] According to a first aspect of the present invention, there is provided an input section for receiving a first signed integer, a second signed integer, a modulus P of a remainder, a positive integer n, and a constant R; A multiplication unit; A signed integer modulus multiplication calculation device including a high-order bit acquisition unit, the multiplication unit calculates a first product of the second signed integer and the constant R, the first product having a length of 2n bits; the multiplication unit calculates a second product having a length of 2n bits from the first product and the first signed integer; the most significant bit acquisition unit acquires first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; the multiplication unit calculates a third product of the first most significant bits and a modulus P of the remainder, the third product having a length of 2n bits; the most significant bit obtaining unit obtains second most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the third product; The constant R is a 2 for signed integers. 2n It is possible to provide a signed integer modular multiplication calculation device which calculates a modular product of a signed integer, the modular product being the inverse of the modulus P of the remainder calculated using the modulus P.

[0017] According to a second aspect of the present invention, there is provided an input section for receiving a first signed integer, a first product of a second signed integer and a constant R having a length of 2n bits, the first product being calculated in advance, a modulus P of the remainder, and a positive integer n; A multiplication unit; A signed integer modulus multiplication calculation device including a high-order bit acquisition unit, the multiplication unit calculates a second product having a length of 2n bits from the first product and the first signed integer; the most significant bit acquisition unit acquires first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; the multiplication unit calculates a third product of the first most significant bits and a modulus P of the remainder, the third product having a length of 2n bits; the most significant bit obtaining unit obtains second most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the third product; The constant R is a 2 for signed integers. 2n It is possible to provide a signed integer modular multiplication calculation device which calculates a modular product of a signed integer, the modular product being the inverse of the modulus P of the remainder calculated using the modulus P.

[0018] According to a third aspect of the present invention, there is provided a method for multiplying a modulus by a constant R, the method comprising: an input unit receiving a first signed integer, a second signed integer, a modulus P of a remainder, a positive integer n, and a constant R; A multiplication unit calculates a first product of the second signed integer and the constant R, the first product being 2n bits long; a multiplication unit calculating a second product having a length of 2n bits from the first product and the first signed integer; a step in which a most significant bit obtaining unit obtains first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; a step of the multiplication unit calculating a third product having a length of 2n bits from the first most significant bits and a modulus P of the remainder; the most significant bit obtaining unit performing integer approximation on a result of performing a signed n-bit right shift on the third product to obtain second most significant bits; The constant R is a 2 for signed integers. 2n It is possible to provide a method for calculating a modular product of signed integers, which is the inverse of the modulus P of the remainder by a remainder calculation modulo P. This method is tied to a specific machine, that is, a computer, which performs modular product calculations on data represented by signed integers.

[0019] According to a fourth aspect of the present invention, a method for multiplying a multiplier includes the steps of: an input unit receiving a first signed integer, a first product of a 2n-bit length calculated in advance from a second signed integer and a constant R, a modulus P of the remainder, and a positive integer n; A multiplication unit calculates a second product having a length of 2n bits from the first product and the first signed integer; a step in which a most significant bit obtaining unit obtains first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; a step of the multiplication unit calculating a third product having a length of 2n bits from the first most significant bits and a modulus P of the remainder; the most significant bit obtaining unit performing integer approximation on a result of performing a signed n-bit right shift on the third product to obtain second most significant bits; The constant R is a 2 for signed integers. 2n It is possible to provide a method for calculating a modular product of signed integers, which is the inverse of the modulus P of the remainder by a remainder calculation modulo P. This method is tied to a specific machine, that is, a computer, which performs modular product calculations on data represented by signed integers.

[0020] According to a fifth aspect of the present invention, a computer is provided with: an operation of receiving a first signed integer, a second signed integer, a modulus P, a positive integer n, and a constant R; calculating a first product of the second signed integer and the constant R, the first product having a length of 2n bits; calculating a second product of 2n bits length from the first product and the first signed integer; performing integer approximation on a result of a signed n-bit right shift of the second product to obtain first most significant bits; calculating a third product of the first most significant bit and a modulus P of the remainder, the third product having a length of 2n bits; performing a process of performing an integer approximation on the result of a signed n-bit right shift of the third product to obtain second most significant bits; The constant R is a 2 for signed integers. 2n It is possible to provide a program in which the modulus P is the inverse of the remainder obtained by modulo P.

[0021] According to a sixth aspect of the present invention, a computer is provided with: receiving a first signed integer, a first product of a second signed integer and a constant R, the first product being 2n bits long and pre-calculated from the second signed integer and a constant R, a modulus P of the remainder, and a positive integer n; calculating a second product of 2n bits length from the first product and the first signed integer; performing integer approximation on a result of a signed n-bit right shift of the second product to obtain first most significant bits; calculating a third product of the first most significant bit and a modulus P of the remainder, the third product having a length of 2n bits; performing a process of performing an integer approximation on the result of a signed n-bit right shift of the third product to obtain second most significant bits; The constant R is a 2 for signed integers. 2n It is possible to provide a program for obtaining a reciprocal of the modulus P of a remainder obtained by a remainder calculation modulo P. This program can be recorded on a computer-readable storage medium. The storage medium can be a non-transient medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. The present invention can also be embodied as a computer program product. Effect of the Invention

[0022] According to the present invention, it is possible to provide a signed integer modular product calculation device, a signed integer modular product calculation method, and a program that contribute to making it possible to calculate modular products for data represented by signed integers without converting negative data into data represented by unsigned integers. [Brief description of the drawings]

[0023] [Figure 1] 1 is a diagram showing an example of a schematic configuration of a signed integer modular multiplication calculation device according to an embodiment of the present invention; [Diagram 2] 1 is a flowchart illustrating an example of a process performed by a signed integer modular product calculation device according to an embodiment of the present invention. [Diagram 3] FIG. 13 is a diagram illustrating an example of a schematic configuration of a signed integer modular multiplication calculation device according to another embodiment of the present invention. [Figure 4] 13 is a flowchart illustrating an example of a process performed by a signed integer modular product calculation device according to another embodiment of the present invention. [Diagram 5] FIG. 1 is a diagram illustrating an example of a configuration of a signed integer modular multiplication calculation device according to a first exemplary embodiment of the present invention. [Figure 6] 2 is a diagram illustrating an example of a configuration of a high-order bit acquisition unit of the signed integer modular multiplication calculation device according to the first exemplary embodiment of the present invention. FIG. [Figure 7]FIG. 11 is a diagram illustrating an example of the configuration of a signed integer modular multiplication calculation device according to a second exemplary embodiment of the present invention. [Figure 8] FIG. 11 is a diagram illustrating an example of the configuration of a signed integer modular multiplication calculation device according to a third exemplary embodiment of the present invention. [Figure 9] FIG. 13 is a diagram illustrating an example of the configuration of a signed integer modular multiplication calculation device according to a fourth exemplary embodiment of the present invention. [Figure 10] FIG. 1 is a diagram showing the configuration of a computer that constitutes the signed integer remainder multiplication calculation device of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0024] [One embodiment of the present invention] First, an overview of one embodiment of the present invention will be described with reference to the drawings. Note that the reference numerals in the drawings attached to this overview are attached to each element for convenience as an example to aid in understanding, and are not intended to limit the present invention to the illustrated form. Furthermore, the connection lines between blocks in the drawings and the like referred to in the following description include both bidirectional and unidirectional lines. The unidirectional arrows are intended to diagrammatically indicate the flow of the main signal (data), and do not exclude bidirectionality.

[0025] [Contents of signed integer modulus multiplication calculation] In one embodiment of the present invention, the inputs are a first signed integer A, a second signed integer B, a modulus P, a positive integer n, and a constant R, where the integer n is the computer performing the calculation or the half-word length of the product to be calculated. TIFF0007673871000001.tif6150...(Formula 1) and TIFF0007673871000002.tif6150 is 2 for signed integers 2n The result of the remainder calculation is TIFF0007673871000003.tif6150 The first signed integer A and the second signed integer B have the following values: It is a signed integer that satisfies TIFF0007673871000004.tif11150.

[0026] In one embodiment of the present invention, the input is multiplied by a signed integer modulo P. TIFF0007673871000005.tif6150...(Formula 2) of, TIFF0007673871000006.tif18150...(Formula 3) It is calculated as follows.

[0027] In addition, TIFF0007673871000007.tif6150 is an integer approximation function for any integer z and real number TIFF0007673871000008.tif9150 In contrast, TIFF0007673871000009.tif6150 We choose such an integer approximation function. TIFF0007673871000010.tif6150 For example, a function that rounds a real number x to the nearest tenth: TIFF0007673871000011.tif6150 There is.

[0028] [Outline of the structure and operation of a signed integer modulus multiplication device] First, a schematic configuration of a signed integer modular multiplication calculation device according to an embodiment of the present invention will be described. Fig. 1 is a diagram showing an example of a schematic configuration of a signed integer modular multiplication calculation device according to an embodiment of the present invention. Referring to Fig. 1, a signed integer modular multiplication calculation device 10 includes an input unit 100, a multiplication unit 210, and a high-order bit acquisition unit 220.

[0029] Next, the operation of the signed integer modular product calculation device 10 according to one embodiment of the present invention shown in Fig. 1 will be described with reference to Fig. 2. Fig. 2 is a flowchart showing an example of processing by the signed integer modular product calculation device 10 according to one embodiment of the present invention. The processing starts at step S100.

[0030] In step S101, the input unit 100 receives an input 20 including a first signed integer A, a second signed integer B, a modulus P of the remainder, a positive integer n, and a constant R. The input unit 100 may be realized, for example, by a character input device such as a keyboard for inputting the input 20. The constant R is expressed as follows for the modulus P of the remainder and the positive integer n: TIFF0007673871000012.tif6150 is an integer that satisfies TIFF0007673871000013.tif6150 is 2 for signed integers 2n This shows the remainder calculation modulo .

[0031] In step S102, the multiplication unit 210 calculates a first product of a 2n-bit length from the second signed integer B and a constant R. TIFF0007673871000014.tif6150 Calculate.

[0032] Next, in step S103, the multiplication unit 210 multiplies the first product by the first signed integer A to obtain a second product having a length of 2n bits. TIFF0007673871000015.tif6150 Calculate.

[0033] Next, in step S104, the most significant bit acquisition unit 220 performs a signed n-bit right shift on the second product Q (Q>>n(=Q / 2 n )) and apply integer approximation to the result to get the first most significant bit. TIFF0007673871000016.tif6150 Get the.

[0034] Next, in step S105, the multiplication unit 210 multiplies the first most significant bit and the modulus P of the remainder by a third product having a length of 2n bits. TIFF0007673871000017.tif6150 Calculate.

[0035] Finally, in step S106, the most significant bit acquisition unit 220 performs integer approximation on the result of the signed n-bit right shift of the third product to obtain the second most significant bit TIFF0007673871000018.tif16150 is obtained and output as output 30. The process ends in step S107.

[0036] [Example of calculating modular multiplication of signed integers] Next, an example of a remainder calculation by the signed integer remainder product calculation device 10 of one embodiment of the present invention will be described. Note that the signed integer remainder product calculation device 10 of one embodiment of the present invention receives signed integers in two's complement representation and performs each calculation using signed integers in two's complement representation, but in the following description, each numerical value will be expressed in decimal. The signed integer remainder product calculation device 10 of one embodiment of the present invention receives a first signed integer A=-12, a second signed integer B=19, a remainder modulus P=101, a positive integer n=8, a constant R, where TIFF0007673871000019.tif6150...(Formula 4) Takes as input.

[0037] Using the above input, we directly calculate the modular product of signed integers modulo P using equation (2): TIFF0007673871000020.tif6150...(Formula 5) It becomes.

[0038] In contrast to this, the calculation process when the above (Equation 3) is calculated by the signed integer modular product calculation device 10 according to one embodiment of the present invention will be described below.

[0039] When the multiplication unit 210 calculates the first product of the second signed integer B × constant R = 19 × (-20115), which is 2n bits (16 bits) long, the following equation (3) is obtained: TIFF0007673871000021.tif6150 can be calculated and the result is 11031.

[0040] Next, the multiplication unit 210 calculates the second product of 2n bits (16 bits) in length by the first signed integer A×the first product=−12×11031, as shown in (Equation 3). TIFF0007673871000022.tif6150 can be calculated and the result is -1300.

[0041] Next, the most significant bit acquisition unit 220 performs a signed n-bit right shift on the second product, and performs integer approximation on the result to acquire the first most significant bit, TIFF0007673871000023.tif6150 can be calculated and the result is -5.

[0042] Next, the multiplication unit 210 calculates the third product of 2n bits (16 bits) in length by multiplying the first most significant bit by the modulus P of the remainder, TIFF0007673871000024.tif6150 can be calculated and the result is -505.

[0043] Finally, the most significant bit acquisition unit 220 performs a signed n-bit right shift on the third product, and performs integer approximation on the result to acquire the second most significant bit. In the formula 3, TIFF0007673871000025.tif16150...(Formula 6) can be calculated, and the result is -2, which is output as the output 30 of the modular product.

[0044] Comparing the above formulas (Formula 5) and (Formula 6), the signed integer modular multiplication calculation device 10 according to one embodiment of the present invention can calculate the signed integer modular multiplication. TIFF0007673871000026.tif6150 can be calculated.

[0045] According to one embodiment of the present invention, it is possible to provide a signed integer modular product calculation device, a signed integer modular product calculation method, and a program that contribute to making it possible to calculate modular products on data represented by signed integers without converting negative data into data represented by unsigned integers.

[0046] Another embodiment of the present invention Next, an outline of another embodiment of the present invention will be described with reference to the drawings. Fig. 3 is a diagram showing an example of the outline of a signed integer modular multiplication calculation device 10 according to another embodiment of the present invention. In Fig. 3, components with the same reference numerals as those in Fig. 1 are regarded as the same components, and the description thereof will be omitted.

[0047] Next, the operation of the signed integer modular product calculation device 10 according to another embodiment of the present invention will be described with reference to Fig. 4. Fig. 4 is a flowchart showing an example of processing by the signed integer modular product calculation device 10 according to another embodiment of the present invention. The processing starts in step S200.

[0048] In some applications of modular multiplication, the first product TIFF0007673871000027.tif6150 Another embodiment of the present invention is where the first product is pre-computed.

[0049] In step S201, the input unit 100 receives a first signed integer A and a first multiplier without receiving a second signed integer B and a constant R. TIFF0007673871000028.tif6150 It receives as input 20 the modulus P of the remainder and an integer n.

[0050] Next, in step S202, the multiplication unit 210 multiplies the first product by the first signed integer to obtain a second product having a length of 2n bits. TIFF0007673871000029.tif6150 Calculate.

[0051] Next, in step S203, the most significant bit acquisition unit 220 performs integer approximation on the result of the signed n-bit right shift of the second product to obtain the first most significant bit TIFF0007673871000030.tif6150 Get the.

[0052] Next, in step S204, the multiplication unit 210 multiplies the first most significant bit by the modulus P of the remainder by 2n bits. TIFF0007673871000031.tif6150 Calculate.

[0053] Next, in step S205, the most significant bit acquisition unit 220 performs integer approximation on the result of the signed n-bit right shift of the third product to obtain the second most significant bit. TIFF0007673871000032.tif16150 is obtained and output as output 30. The process ends in step S206.

[0054] The signed integer modular product calculation device 10 of another embodiment of the present invention shown in Figure 3 can obtain, from the above input, a second most significant bit that is the same as the second most significant bit obtained by the signed integer modular product calculation device 10 of one embodiment of the present invention shown in Figure 1, and output it as output 30.

[0055] According to another embodiment of the present invention, it is possible to provide a signed integer modular product calculation device, a signed integer modular product calculation method, and a program that contribute to making it possible to calculate a modular product on data represented by a signed integer without converting negative data into data represented by an unsigned integer.

[0056] Furthermore, according to another embodiment of the present invention, in an application example in which the first product can be pre-calculated, step S102 of calculating the first product in one embodiment of the present invention described with reference to FIGS. 1 and 2 can be omitted, thereby enabling the calculation of the modular product to be performed at a high speed.

[0057] [First embodiment] Next, a signed integer modular multiplication calculation device according to a first embodiment of the present invention will be described with reference to the drawings. Fig. 5 is a diagram showing an example of the configuration of a signed integer modular multiplication calculation device 10 according to a first embodiment of the present invention. In Fig. 5, components with the same reference symbols as those in Fig. 1 are assumed to be the same components, and their description will be omitted.

[0058] 5, the signed integer modular product calculation device 10 of the first embodiment of the present invention includes an input unit 100, a selection unit 200, a multiplication unit 210, a high-order bit acquisition unit 220, a first storage unit 230, a second storage unit 240, and a control unit 300. Note that the signed integer modular product calculation device 10 of each embodiment of the present invention described below receives signed integers in two's complement representation and performs each calculation using the signed integers in two's complement representation.

[0059] The control unit 300 controls the selection process performed by the selection unit 200 of the signed integer modular multiplication calculation device 10, and also controls the entire integer modular multiplication calculation device 10.

[0060] Next, the operation of the signed integer modular multiplication calculation device 10 according to the first embodiment of the present invention will be described with reference to Fig. 2 of an embodiment of the present invention. The process of the signed integer modular multiplication calculation device 10 according to the first embodiment of the present invention starts in step S100.

[0061] In step S101, the input unit 100 receives an input 20 including a first signed integer A, a second signed integer B, a modulus P, a positive integer n, and a constant R. The definitions of the first signed integer A, the second signed integer B, the modulus P, the positive integer n, and the constant R are the same as those in one embodiment of the present invention described with reference to Figures 1 and 2.

[0062] Next, in step S102, the control unit 300 selects the second signed integer B 121 and the constant R 122 input to the selection unit 200, and sends the selection outputs 201 and 202 to the multiplication unit 210. The multiplication unit 210 generates a first multiplier of 2n bits length from the second signed integer B and the constant R. TIFF0007673871000033.tif6150 The calculated first product is output to output 211 of multiplication unit 210, stored in first storage unit 230, and then output.

[0063] Next, in step S103, the control unit 300 selects the first signed integer A 123 input to the selection unit 200 and the output 231 of the first storage unit, and sends the selected outputs 201 and 202 to the multiplication unit 210. Since the output 231 of the first storage unit is the first product of 2n bits, the multiplication unit 210 multiplies the first signed integer A and the first product by 2n bits. TIFF0007673871000034.tif6150 The calculated second product is output to the output 211 of the multiplication unit 210, stored in the first storage unit 230, and then output.

[0064] Next, in step S104, the output 231 of the first storage unit and the positive integer n125 are input to the most significant bit acquisition unit 220. The output 231 of the first storage unit is a second product of 2n bits in length, and the most significant bit acquisition unit 220 performs a signed n-bit right shift on the second product of 2n bits in length, and performs integer approximation on the result to obtain the first most significant bit. TIFF0007673871000035.tif6150 and outputs it as output 221. The second storage unit 240 stores the first most significant bit and further outputs it as output 241.

[0065] Next, in step S105, the control unit 300 selects the remainder modulus P124 input to the selection unit 200 and the output 241 of the second storage unit, and sends the selected outputs 201 and 202 to the multiplication unit 210. Since the output 241 of the second storage unit contains the first most significant bit, the multiplication unit 210 derives a third multiplier of 2n bits length from the first most significant bit and the remainder modulus P. TIFF0007673871000036.tif6150 The calculated third product is output to output 211 of multiplication unit 210. First storage unit 230 stores the third product and outputs it as output 231.

[0066] Finally, in step S106, the output 231 of the first storage unit and the positive integer n125 are input to the most significant bit acquisition unit 220. The output 231 of the first storage unit is the third product having a length of 2n bits, and the most significant bit acquisition unit 220 performs a signed n-bit right shift on the third product having a length of 2n bits, and performs integer approximation on the result to obtain the second most significant bit. TIFF0007673871000037.tif16150 is obtained and output as output 221. The second most significant bit is stored in the second storage unit 240 and output as output 30. The process ends in step S107.

[0067] An example of a signed integer modular product calculation device 10 according to the first embodiment of the present invention is similar to an example of a remainder calculation by the signed integer modular product calculation device 10 according to one embodiment of the present invention described with reference to Figures 1 and 2.

[0068] [Configuration of the high-order bit acquisition part] Next, the configuration and operation of the high-order bit acquisition unit 220 will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the configuration of the high-order bit acquisition unit 220 of the signed integer modular multiplication calculation device 10 according to the first embodiment of the present invention.

[0069] 6, the most significant bit acquisition unit 220 includes a shift register 550 and an adder 560. The most significant bit acquisition unit 220 receives an input 500 having a length of 2n bits and an integer n125 as an input.

[0070] 6, a 2n-bit (16-bit) long input 500 includes a most significant bit (MSB) 501 on the left, bits 502 to 515, and a least significant bit (LSB) 516 on the right. The input 500 is made up of n most significant bits 5001, bits 501 to 508, and n least significant bits 5002, bits 509 to 516.

[0071] In one embodiment of the present invention, in the example of calculating the modular product of signed integers, an example is shown in which -1300 (dec, decimal notation) in two's complement representation is input as an input to the higher bit acquisition unit 220. Note that this value corresponds to the value of the second product input to the higher bit acquisition unit 220 in the example of calculating the modular product of signed integers in one embodiment of the present invention. Below, the calculation operation of the higher bit acquisition unit 220 when -1300 (dec, decimal notation) in two's complement representation is input will be described.

[0072] The shift register 550 includes an upper n (8) bit register section 551 and a lower n (8) bit register section 552 for a 2n-bit (16-bit) long input 500, and a 1st decimal place register 553. The upper n (8) bits 5001 and the lower n (8) bits 5002 of the 2n-bit (16-bit) long input 500 are loaded into the upper n (8) bit register section 551 and the lower n (8) bit register section 552 of the shift register 550, respectively.

[0073] Next, the 2n-bit (16-bit) long input 500 loaded into the shift register 550 undergoes a signed n-bit right shift in accordance with the input integer n125. The signed n-bit right shift is a process of shifting the input 500 loaded into the shift register 550 by n bits in the direction from the MSB to the LSB. At this time, the value of the MSB indicating the sign of the bit 501 is set in the upper n (8) bit register section 551 of the shift register 550.

[0074] 6, the values ​​shown in each register of shift register 550 indicate the result of loading input 500 into shift register 550 and performing a signed n (8) bit right shift. The value of MSB 501 is set in upper n (8) bit register section 551 of shift register 550, upper n (8) bit register section 552 of shift register 550 has upper n bits 5001 of input 500 placed therein, and the value of bit 509 of input 500 is set in 1s decimal place register 553 of shift register 550.

[0075] Next, integer approximation is performed on the output of the shift register 550 after the signed n-bit right shift. The integer approximation is performed, for example, by rounding off to the nearest tenth. The rounding off to the nearest tenth is performed, for example, by an adder 560.

[0076] Referring to FIG. 6, adder 560 includes 2n (16) full adders 5601-5616, each having two inputs, a carry input, and a carry output, with the carry output of a lower full adder (e.g., full adder 5603) connected to the carry input of the next higher full adder (e.g., full adder 5602).

[0077] An output of the most significant n bit register section 551 of the shift register 550 is input to one input of each of the full adders 5601-5608 of the adder 560, and an output of the least significant n bit register section 552 of the shift register 550 is input to one input of each of the full adders 5609-5616. A value of 0 (zero) is input to all the other inputs of each of the full adders 5601-5616 of the adder 560. Also, an output of the 1st decimal place register 553 is input to a carry input 5616CIN of the full adder 5616.

[0078] 6, the output 221 of the adder 560 is −5 in two's complement representation, and the most significant bit acquisition unit 220 of the signed integer modular multiplication calculation device 10 according to the first embodiment of the present invention outputs the following: TIFF0007673871000038.tif6150 This value corresponds to the value of the first most significant bit, −5, in the example of calculating the modular product of signed integers according to an embodiment of the present invention.

[0079] In addition, the upper bit acquisition unit 220 of the signed integer modular multiplication calculation device 10 of one embodiment of the present invention and another embodiment described with reference to Figures 1 and 3 may have the same configuration as the upper bit acquisition unit 220 of the signed integer modular multiplication calculation device 10 of the first embodiment of the present invention.

[0080] As described above, the signed integer modular multiplication calculation device 10 according to the first embodiment of the present invention performs signed integer modular multiplication. TIFF0007673871000039.tif6150 can be calculated.

[0081] According to the first embodiment of the present invention, it is possible to provide a signed integer modular product calculation device, a signed integer modular product calculation method, and a program that contribute to making it possible to calculate modular products for data represented by signed integers without converting negative data into data represented by unsigned integers.

[0082] [Second embodiment] Next, a signed integer modular multiplication device according to a second embodiment of the present invention will be described with reference to the drawings. Fig. 7 is a diagram showing an example of the configuration of a signed integer modular multiplication device according to a second embodiment of the present invention. In Fig. 7, components with the same reference symbols as those in Fig. 5 are assumed to be the same components.

[0083] Depending on the application of the modular multiplication, the first multiplication described in the first embodiment of the present invention may be TIFF0007673871000040.tif6150 In some cases, it may be possible to pre-calculate the first product, and the second embodiment of the present invention is an embodiment in which the first product is pre-calculated.

[0084] Next, the operation of the signed integer modular product calculation device 10 according to the second embodiment of the present invention will be described with reference to Fig. 4 of another embodiment of the present invention. The process of the signed integer modular product calculation device 10 according to the second embodiment of the present invention starts in step S200.

[0085] In step S201, the input unit 100 receives a first signed integer A and a first product of a 2n-bit length without receiving a second signed integer B and a constant R. TIFF0007673871000041.tif6150 The input 20 includes a first signed integer A, a second signed integer B, a modulus P, a positive integer n, and a constant R. The definitions of the first signed integer A, the second signed integer B, the modulus P, the positive integer n, and the constant R are the same as those described in the embodiment of the present invention described with reference to Figures 1 and 2.

[0086] Next, in step S202, the control unit 300 selects the first signed integer A 123 input to the selection unit 200 and the first product 126 of 2n bits length, and sends the selection outputs 201 and 202 to the multiplication unit 210. The multiplication unit 210 derives a second product 126 of 2n bits length from the first signed integer A and the first product. TIFF0007673871000042.tif6150 The calculated second product is output to the output 211 of the multiplication unit 210, stored in the first storage unit 230, and then output.

[0087] Next, in step S203, the output 231 of the first storage unit and the positive integer n125 are input to the most significant bit acquisition unit 220. The output 231 of the first storage unit is a second product of 2n bits length, and the most significant bit acquisition unit 220 performs a signed n-bit right shift on the second product of 2n bits length, and performs integer approximation on the result to obtain the first most significant bit. TIFF0007673871000043.tif6150 and outputs it as output 221. The second storage unit 240 stores the first most significant bit and outputs it as output 241.

[0088] Next, in step S204, the control unit 300 selects the remainder modulus P124 input to the selection unit 200 and the output 241 of the second storage unit, and sends the selected outputs 201 and 202 to the multiplication unit 210. Since the first most significant bit is output to the output 241 of the first storage unit, the multiplication unit 210 derives a third multiplier of 2n bits length from the first most significant bit and the remainder modulus P. TIFF0007673871000044.tif6150 The calculated third product is output to output 211 of multiplication unit 210. First storage unit 230 stores the third product, and further outputs it as output 231.

[0089] Finally, in step S205, the output 231 of the first storage unit and the positive integer n125 are input to the most significant bit acquisition unit 220. The output 231 of the first storage unit is the third product having a length of 2n bits, and the most significant bit acquisition unit 220 performs a signed n-bit right shift on the third product having a length of 2n bits, and performs integer approximation on the result to obtain the second most significant bit. TIFF0007673871000045.tif16150 is obtained and output as output 221. The second most significant bit is stored in the second storage unit 240 and further output as output 30. The process ends in step S206.

[0090] An example of a signed integer modular product calculation device 10 according to the second embodiment of the present invention is similar to the example of a remainder calculation by the signed integer modular product calculation device 10 according to one embodiment of the present invention described with reference to Figures 1 and 2.

[0091] The operation of the most significant bit acquisition unit 220 of the signed integer modular multiplication calculation device 10 of the second embodiment of the present invention may be similar to the configuration and operation of the first most significant bit acquisition unit 220 of the signed integer modular multiplication calculation device 10 of the first embodiment of the present invention, which has been described with reference to Figure 6.

[0092] As described above, the signed integer modular multiplication calculation device 10 according to the first embodiment of the present invention performs signed integer modular multiplication. TIFF0007673871000046.tif6150 can be calculated.

[0093] According to the second embodiment of the present invention, it is possible to provide a signed integer modular product calculation device, a signed integer modular product calculation method, and a program that contribute to making it possible to calculate modular products on data represented by signed integers without converting negative data into data represented by unsigned integers.

[0094] Furthermore, according to the second embodiment of the present invention, in an application example in which the first product can be pre-calculated, step S102 of calculating the first product in the first embodiment of the present invention described with reference to FIG. 2 can be omitted, and the calculation of the modular product can be speeded up.

[0095] [Third embodiment] Next, a signed integer modular multiplication calculation device according to a third embodiment of the present invention will be described with reference to the drawings. Fig. 8 is a diagram showing an example of the configuration of a signed integer modular multiplication calculation device according to a third embodiment of the present invention. In Fig. 8, components with the same reference symbols as those in Fig. 5 are assumed to be the same components.

[0096] The signed integer modular multiplication calculation device 10 of the third embodiment of the present invention shown in Figure 8 includes an input unit 100, a first multiplication unit 130, a second multiplication unit 140, a first most significant bit acquisition unit 150, a third multiplication unit 160, and a second most significant bit acquisition unit 170, which each execute each step of the flowchart showing an example of processing by the signed integer modular multiplication calculation device of one embodiment of the present invention shown in Figure 2.

[0097] The input unit 100 executes the process of step S101 in FIG. 2 and receives an input 20 including a first signed integer A, a second signed integer B, a modulus P of the remainder, a positive integer n, and a constant R.

[0098] The first multiplication unit 130 executes the process of step S102 in FIG. 2, and calculates a first product 131 of 2n bits length from the second signed integer B121 and the constant R122.

[0099] The second multiplication unit 140 executes the process of step S103 in FIG. 2, and calculates a second product 141 of 2n bits length from the first product 131 and the first signed integer A123.

[0100] The first most significant bit acquisition unit 150 executes the process of step S104 in FIG. 2, and acquires the first most significant bit 151 by performing integer approximation on the result of the signed n-bit right shift of the second product 141.

[0101] The third multiplication unit 160 executes the process of step S105 in FIG. 2, and calculates a third product 161 of 2n bits length from the first most significant bits 151 and the modulus P124 of the remainder.

[0102] The second most significant bit acquisition unit 170 executes the process of step S106 in FIG. 2, and performs integer approximation on the result of the signed n-bit right shift of the third product 161 to acquire the second most significant bit, and outputs it as the output 30.

[0103] [Fourth embodiment] Next, a signed integer modular multiplication device according to a fourth embodiment of the present invention will be described with reference to the drawings. Fig. 9 is a diagram showing an example of the configuration of a signed integer modular multiplication device according to the fourth embodiment of the present invention. In Fig. 9, components with the same reference symbols as those in Fig. 7 are the same components.

[0104] The signed integer modular multiplication calculation device 10 of the fourth embodiment of the present invention shown in Figure 9 includes an input unit 100, a first multiplication execution unit 145, a first most significant bit acquisition unit 150, a second multiplication execution unit 165, and a second most significant bit acquisition unit 170, which each execute each step of the flowchart showing an example of processing by a signed integer modular multiplication calculation device of another embodiment of the present invention shown in Figure 4.

[0105] The input unit 100 executes the process of step S201 in FIG. 4 to obtain a first signed integer A and a first product TIFF0007673871000047.tif6150 It receives input 20 including the modulus P of the remainder and a positive integer n.

[0106] The first multiplication execution unit 145 executes the process of step S202 in FIG. 4, and calculates a second product 141 having a length of 2n bits from the first product 126 and the first signed integer A 123.

[0107] The first most significant bit obtaining unit 150 executes the process of step S203 in FIG. 4, and obtains the first most significant bit 151 by performing integer approximation on the result of the signed n-bit right shift of the second product 141.

[0108] The second multiplication execution unit 165 executes the process of step S204 in FIG. 4, and calculates a third product 161 of 2n bits length from the first most significant bits 151 and the modulus P124 of the remainder.

[0109] The second most significant bit acquisition unit 170 executes the process of step S205 in FIG. 4, and performs integer approximation on the result of the signed n-bit right shift of the third product 161 to acquire the second most significant bit, and outputs it as the output 30.

[0110] Moreover, the procedures shown in the above-mentioned first to fourth embodiments can be realized by a program that causes a computer (9000 in FIG. 10) functioning as the signed integer modular multiplication calculation device 10 to realize the function as the signed integer modular multiplication calculation device 10. Such a computer is exemplified by a configuration including a CPU (Central Processing Unit) 9010, a communication interface 9020, a memory 9030, and an auxiliary storage device 9040 in FIG. 10. That is, the CPU 9010 in FIG. 10 executes a program for the signed integer modular multiplication calculation, and performs an update process for each calculation parameter held in the auxiliary storage device 9040 or the like.

[0111] The memory 9030 is a RAM (Random Access Memory), a ROM (Read Only Memory), or the like.

[0112] In other words, each part (processing means, function) of the signed integer modular multiplication calculation device 10 shown in the above-mentioned first to fourth embodiments can be realized by a computer program that causes the processor of the above-mentioned computer to execute each of the above-mentioned processes using its hardware.

[0113] Finally, preferred embodiments of the present invention will be summarized. [First form] (See the above-mentioned signed integer modular multiplication device from the first viewpoint.) [Second Form] (See the above second aspect of the signed integer modular multiplication calculation device.) [Third Form] In the signed integer modular multiplication calculation device according to the first or second aspect, the constant R is expressed as follows for the modulus P of the remainder and the positive integer n: TIFF0007673871000048.tif6150 is an integer that satisfies TIFF0007673871000049.tif6150 is 2 for signed integers 2n It is preferable to denote the remainder calculation modulo x. [Fourth Form] In the signed integer modular product calculation device according to the third aspect, it is preferable that the integer approximation is performed by rounding off the first decimal place. [Fifth Form] (See the third aspect of signed integer modular multiplication calculation method above.) [Sixth Form] (See the fourth aspect of signed integer modular multiplication calculation method above.) [7th form] (See the fifth perspective program above) [8th form] (See Programme for the 6th Aspect above) [9th form] In the program according to the seventh or eighth aspect, the constant R is, for the modulus P of the remainder and the positive integer n, TIFF0007673871000050.tif6150 is an integer that satisfies TIFF0007673871000051.tif6150 is 2 for signed integers 2n It is preferable to denote the remainder calculation modulo x. [10th form] In the program according to the ninth aspect, it is preferable that the integer approximation is performed by rounding off to one decimal place. The fifth or sixth embodiment can be expanded into the third or fourth embodiment.

[0114] The disclosures of the above patent documents are incorporated herein by reference. Within the framework of the entire disclosure of the present invention (including the scope of claims), modifications and adjustments of the embodiments and examples are possible based on the basic technical ideas. Furthermore, within the framework of the disclosure of the present invention, various combinations and selections of the various disclosed elements (including each element of each claim, each element of each embodiment or example, each element of each drawing, etc.) are possible. In other words, the present invention naturally includes various modifications and corrections that a person skilled in the art would be able to make in accordance with the entire disclosure including the scope of claims and the technical ideas. In particular, with regard to the numerical ranges described in this specification, any numerical value or subrange included in the range should be interpreted as being specifically described even if not otherwise specified. [Explanation of symbols]

[0115] 10 Signed integer modulus multiplication unit 20 Input 30 Output 100 Input section 121 Second signed integer B 122 Constant R 123 First signed integer A 124 Modulus of Remainder P 125 integer n 130 First multiplication section 140 Second multiplication section 145 First multiplication execution unit 150 First most significant bit acquisition unit 160 Third Multiplication Section 165 Second Multiplication Execution Unit 170 Second most significant bit acquisition unit 200 Selection 210 Multiplication section 220 Higher bit acquisition section 230 First memory unit 240 Second memory unit 300 Control section 550 Shift Register 551 Upper n (8) bit register section 552 Lower n (8) bit register section 553 1st decimal place register 560 Adder 5001 Upper n(8) bits 5002 Lower n(8) bits 5601~5616 Full adder 9000 Computers 9010 CPU 9020 Communication Interface 9030 Memory 9040 Auxiliary storage device

Claims

1. an input for receiving a first signed integer, a second signed integer, a modulus P, a positive integer n, and a constant R; A multiplication unit; A signed integer modulus multiplication calculation device including a high-order bit acquisition unit, the multiplication unit calculates a first product of the second signed integer and the constant R, the first product having a length of 2n bits; the multiplication unit calculates a second product having a length of 2n bits from the first product and the first signed integer; the most significant bit acquisition unit acquires first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; the multiplication unit calculates a third product of the first most significant bits and a modulus P of the remainder, the third product having a length of 2n bits; the most significant bit acquisition unit performs integer approximation on a result of performing a signed n-bit right shift on the third product to acquire second most significant bits; The constant R is a 2 for signed integers. 2n A signed integer modular multiplication calculation device, which is an inverse of the modulus P of the remainder calculated by modulo P.

2. an input for receiving a first signed integer, a first product of 2n bits length pre-calculated from a second signed integer and a constant R, a modulus P of the remainder, and a positive integer n; A multiplication unit; A signed integer modulus multiplication calculation device including a high-order bit acquisition unit, the multiplication unit calculates a second product having a length of 2n bits from the first product and the first signed integer; the most significant bit acquisition unit acquires first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; the multiplication unit calculates a third product of the first most significant bits and a modulus P of the remainder, the third product having a length of 2n bits; the most significant bit acquisition unit performs integer approximation on a result of performing a signed n-bit right shift on the third product to acquire second most significant bits; The constant R is a 2 for signed integers. 2n A signed integer modular multiplication calculation device, which is an inverse of the modulus P of the remainder calculated by modulo P.

3. The constant R is expressed as follows for the modulus P of the remainder and the positive integer n: is an integer that satisfies is the 2 for signed integers 2n 3. The signed integer remainder multiplication calculation device according to claim 1, which indicates a remainder calculation modulo .

4. 4. The signed integer modulus multiplication calculation device according to claim 3, wherein the integer approximation is performed by rounding off the first decimal place.

5. an input unit receiving a first signed integer, a second signed integer, a modulus P of the remainder, a positive integer n, and a constant R; A multiplication unit calculates a first product of 2n bits length from the second signed integer and the constant R; a multiplication unit calculating a second product having a length of 2n bits from the first product and the first signed integer; a step in which a most significant bit obtaining unit obtains first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; a step of the multiplication unit calculating a third product having a length of 2n bits from the first most significant bits and a modulus P of the remainder; the most significant bit obtaining unit performing integer approximation on a result of performing a signed n-bit right shift on the third product to obtain second most significant bits, The constant R is a 2 for signed integers. 2n A method for calculating a modular product of signed integers, the modular product being the inverse of the modulus P of the remainder calculated by modulus P.

6. An input unit receives a first signed integer, a first product of 2n bits length pre-calculated from a second signed integer and a constant R, a modulus P of the remainder, and a positive integer n; A multiplication unit calculates a second product having a length of 2n bits from the first product and the first signed integer; a step in which a most significant bit obtaining unit obtains first most significant bits by performing integer approximation on a result of performing a signed n-bit right shift on the second product; a step of the multiplication unit calculating a third product having a length of 2n bits from the first most significant bits and a modulus P of the remainder; the most significant bit obtaining unit performing integer approximation on a result of performing a signed n-bit right shift on the third product to obtain second most significant bits, The constant R is a 2 for signed integers. 2n A method for calculating a modular product of signed integers, the modular product being the inverse of the modulus P of the remainder calculated by modulus P.

7. On the computer, an operation of receiving a first signed integer, a second signed integer, a modulus P, a positive integer n, and a constant R; calculating a first product of the second signed integer and the constant R, the first product having a length of 2n bits; calculating a second product of 2n bits length from the first product and the first signed integer; a step of performing integer approximation on a result of a signed n-bit right shift of the second product to obtain first most significant bits; calculating a third product of the first most significant bit and a modulus P of the remainder, the third product having a length of 2n bits; performing a process of performing an integer approximation on a result of a signed n-bit right shift of the third product to obtain second most significant bits; The constant R is a 2 for signed integers. 2n The program is a program in which the modulus P is the inverse of the remainder modulo P by remainder calculation using the modulus P.

8. On the computer, A process for receiving a first signed integer, a first product of 2n bits length pre-calculated from a second signed integer and a constant R, a modulus P of the remainder, and a positive integer n; calculating a second product of 2n bits length from the first product and the first signed integer; a step of performing integer approximation on a result of a signed n-bit right shift of the second product to obtain first most significant bits; calculating a third product of the first most significant bit and a modulus P of the remainder, the third product having a length of 2n bits; performing a process of performing an integer approximation on a result of a signed n-bit right shift of the third product to obtain second most significant bits; The constant R is a 2 for signed integers. 2n The program is a program in which the modulus P is the inverse of the remainder modulo P by remainder calculation using the modulus P.

9. The constant R is expressed as follows for the modulus P of the remainder and the positive integer n: is an integer that satisfies is the 2 for signed integers 2n 9. The program according to claim 7 or 8, which indicates a remainder calculation modulo

10. The program according to claim 9 , wherein the integer approximation is performed by rounding off to the nearest decimal place.

Citation Information

Patent Citations

  • Cipher processing apparatus and method, and program and recording medium therefor

    JP2003150050A

  • Power remainder computing method and program for the same

    JP2004226516A

  • Utilizing SIMD instruction within montgomery multiplication

    JP2005122141A

  • Computing method and device of residue system

    JP2007219261A

  • Data processing device

    JP2010091913A