Calculation device
The arithmetic unit enhances finite field operation efficiency by performing modular calculations with an odd prime modulus, optimizing comparison and subtraction operations, and achieving high-speed processing for signature verification.
Patent Information
- Application Number
- JP2021153456
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-21
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2041-09-21
AI Technical Summary
Existing arithmetic units for finite field operations in signature verification processes are inefficient due to the need for multiple-precision comparison and subtraction operations, which degrade processing performance.
The arithmetic unit performs modular calculations using an odd prime number P as the modulus, reading out comparison results in advance and using them to optimize operations, thereby reducing the need for multiple-precision comparison and subtraction.
This approach enables high-speed arithmetic processing on finite fields, improving the efficiency of signature verification processes and reducing processing latency.
Smart Images

Figure 0007693483000001 
Figure 0007693483000002 
Figure 0007693483000003
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to an arithmetic unit.
Background Art
[0002] Arithmetic processing on a finite field may be performed for signature verification or signature generation processing. At this time, it is desirable to perform arithmetic processing on the finite field at high speed.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] One embodiment aims to provide an arithmetic unit that performs arithmetic processing on a finite field at high speed.
Means for Solving the Problems
[0005] According to one embodiment, there is provided an arithmetic unit that outputs an arithmetic result on a finite field having a characteristic P, Perform multiple-precision reads a plurality of input values, and for each word of the plurality of input values, uses a comparison value between the input value and the characteristic P and a value based on the characteristic P to addition or subtraction, outputs a first output value obtained by performing an arithmetic operation on a value based on the input value, the comparison value, and the characteristic P, and outputs a second output value obtained by comparing the first output value with the characteristic P.
Brief Description of the Drawings
[0006]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
MODE FOR CARRYING OUT THE INVENTION
[0007] Hereinafter, as an example, a memory system to which the arithmetic unit according to the embodiment is applied will be described. Note that the device to which the arithmetic unit according to the embodiment can be applied is not limited to only the memory system. The arithmetic unit according to the embodiment can be applied to any device including a memory storing a computer program and a processor executing the computer program. Hereinafter, with reference to the accompanying drawings, a memory system to which the arithmetic unit according to the embodiment is applied will be described in detail. Note that the present invention is not limited by this embodiment.
[0008] (First Embodiment) The arithmetic device according to the first embodiment is a device that outputs an arithmetic result on a finite field with a norm P, and can be used for digital signatures of firmware in a memory system such as an SSD (Solid State Drive). In digital signatures, a key generation algorithm, a signature generation algorithm, and a signature verification algorithm are used. The key generation algorithm generates a pair of a public key and a private key. The signature generation algorithm receives the firmware and the private key, performs signature generation processing, and generates a signature. The signature verification algorithm receives the firmware, the public key, and the signature, performs signature verification processing, and verifies the signature.
[0009] For example, a memory system 300 to which a controller 100 including an arithmetic device 1 is applied is configured as shown in FIG. 1. FIG. 1 is a diagram showing the configuration of a memory system 300 to which a controller 100 including an arithmetic device 1 is applied. The memory system 300 includes a controller 100 and a semiconductor memory 200. The controller 100 includes a main control circuit 101, a signature adding circuit 102, a signature verification circuit 103, and a buffer memory 104. The signature verification circuit 103 includes the arithmetic device 1. The arithmetic device 1 can be configured as an arithmetic circuit. The semiconductor memory 200 is a non-volatile semiconductor memory (for example, a NAND type flash memory), and has a storage area 201 and a management information storage area 202. User data can be stored in the storage area 201. The management information storage area 202 stores firmware (FW) 501 and a signature 502. The signature 502 is a digital signature. The signature 502 may be generated by the signature adding circuit 102 or may be generated outside the memory system 300.
[0010] In the memory system 300, when the controller 100 starts the firmware 501, it temporarily stores the firmware 501 and the signature 502 in the buffer memory 104, and the signature verification circuit 103 performs signature verification processing on the firmware 501. In the signature verification process, the signature verification circuit 103 calculates the hash value of the firmware 501, extracts the value based on the public key from the signature 502, and determines whether a predetermined condition is satisfied using the hash value of the firmware 501 and the extracted value.
[0011] For example, the signature verification circuit 103 may perform signature verification processing according to the ECDSA (Elliptic Curve Digital Signature Algorithm) method. The signature verification circuit 103 calculates the hash value of the firmware 501. The signature verification circuit 103 performs arithmetic processing on a predetermined part of the signature 502 by the arithmetic unit 1. The signature verification circuit 103 calculates a predetermined parameter using the hash value and the signature 502. The signature verification circuit 103 calculates the coordinate value of a point on the elliptic curve using the public key and a predetermined part of the signature 502. As a predetermined condition, the signature verification circuit 103 determines whether the second part different from the above-mentioned predetermined part of the signature 502 matches the coordinate value of the point on the elliptic curve.
[0012] If the predetermined condition is satisfied, the signature verification circuit 103 outputs an approval result, assuming that there is no unauthorized modification. In response, the controller 100 starts the firmware 501 and expands, for example, the function module of the firmware 501 in the buffer memory 104. If the predetermined condition is not satisfied, the signature verification circuit 103 outputs a rejection result, assuming that there may be unauthorized modification. In response, the controller 100 does not start the firmware 501. As a result, in the memory system 300, unauthorized modification of the firmware 501 can be detected and prevented at startup.
[0013] In the memory system 300, in order to speed up the startup of the firmware 501, it is required to speed up the signature verification process performed during startup. In order to speed up the signature verification process, it is required to speed up the operations in the signature verification process. When the signature verification circuit 103 verifies a digital signature according to a method such as ECDSA, the arithmetic unit 1 performs operations on a finite field. This operation needs to perform iterative processing with multiple-precision, and the operation cost becomes very large. Multiple-precision means the precision corresponding to the total bit length of multiple words calculated using a multiplier multiple times.
[0014] In this operation on a finite field, comparison processing with the prime number P and subtraction processing of the prime number P are included. This comparison processing and subtraction processing are multiple-precision operations, and both are processed over multiple cycles. At this time, based on the comparison result of the comparison processing, it is determined whether to perform the subtraction processing, so it is necessary to wait for the end of the comparison processing and then perform the subtraction processing, which degrades the processing performance of the operation processing.
[0015] Therefore, in the present embodiment, the arithmetic unit 1 reads out the comparison result between the input value and the prime number P in advance and performs operations using the comparison result. For example, the arithmetic unit in the present embodiment performs modular calculation with an odd prime number P as the modulus on a multiple-precision integer composed of multiple words.
[0016] FIG. 2 is a block diagram showing an example of the functional configuration of the arithmetic unit 1 according to the embodiment. As shown in FIG. 2, the arithmetic unit 1 includes an input unit 10, an addition / multiplication unit 11, a quotient buffer 12, a comparison unit 13, and an output unit 14.
[0017] The input unit 10 reads out a plurality of input values. The input unit 10 acquires the address of the signature 502 data from the signature verification circuit 103 and inputs the input value, which is the value of the address. Further, the input unit 10 inputs the prime number P(k) from the signature verification circuit 103.
[0018] The addition and multiplication unit 11 adds or multiplies the input values input by the input unit 10. The addition and multiplication unit 11 calculates and outputs the sum S = A1 + ··· + An for the input values A1, ···, An. The quotient buffer 12 is a buffer that stores the division results by the comparison unit 13 for each address. The comparison unit 13 calculates the quotient Q = S / P based on the sum S and the norm P. The output unit 14 writes the addition result to the output address.
[0019] Note that, for example, an external memory such as SRAM (Static Random Access Memory) or DRAM (Dynamic Random Access Memory) stores the multiple-precision integer X. In the initial state, for example, 0 ≤ X < P. In this case, all the quotient values included in the quotient buffer are initialized to 0. Also, for example, it is not necessary that 0 ≤ X < P. In this case, the initial value of the quotient may be received from the outside.
[0020] The modular calculation with the modulus P is, for example, the following operations. (1) Z = A + B | mod | P (2) Z = A - B | mod | P (3) Z = A × B | mod | P (4) Z = A × B -1 | mod | P
[0021] However, the arithmetic unit 1 does not need to support all these operations, and it is sufficient that it can calculate at least addition or subtraction. Also, the arithmetic unit 1 may be configured to support compound operations that calculate multiple operations simultaneously, for example, as follows. (5) Z = A + B + C + D | mod | P (6) Z = A + B - C - D | mod | P (7) Z = A × B + C × D | mod | P (8) Z = A × B + C + D | mod | P
[0022] Here, when n = 2, that is, when the input values are A1 and A2, the processing procedure for the arithmetic unit 1 to calculate Z = A1 + A2 | mod | P will be described using the pseudo code shown in FIG. 3. Here, X(k) represents the k-th word counted from the LSB of X. q[X] represents the quotient value for X contained in the quotient buffer. m is the number of words of Z and A k Let it be. One word is W bits.
[0023] As shown in FIG. 3, the input unit 10 inputs the norm P(k) (description 601). Further, the input unit 10 inputs A1(k) (description 602). The addition and multiplication unit 11 adds the difference value between A1(k) and P(k) × q[A1] to the variable U (description 603). Further, the input unit 10 inputs A2(k) (description 604). The addition and multiplication unit 11 adds the difference value between A2(k) and P(k) × q[A2] to the variable U (description 605). Then, the output unit 14 inputs U(0) to Z(k) and outputs the Z(k) (description 606).
[0024] The comparison unit 13 adds the difference between U(0) and P(k) to the variable D (description 607). Further, the variables D and U are shifted by W bits (description 608).
[0025] After the arithmetic unit 1 executes the loop process, if the variable D is greater than 0, 1 is input to q[Z], and if the variable D is 0 or less, 0 is input to q[Z] (description 609).
[0026] According to this process, for 0 ≦ A1, A2 ≦ 2P, 0 ≦ Z ≦ 2P holds. Therefore, the calculation result Z of the modular addition can be used as the input of another modular addition. When performing a plurality of operations in this way, 0 ≦ Z' ≦ 2P also holds for the final operation result Z'. At this time, by additionally performing the modular addition Z″ = Z' | mod | P with n = 1, the final operation result can be set to 0 ≦ Z″ <P.
[0027] Subsequently, Z = A1 + ··· + A based on the above pseudo code nThe calculation procedure of |mod|P will be described using the flowchart shown in FIG. 4.
[0028] First, the input unit 10 initializes the variables U and D i (step S1). Subsequently, the arithmetic unit 1 executes a loop process until the variable k becomes m (step S2). In the loop process shown in step S2, the input unit 10 inputs P(k) (step S3). Subsequently, in the loop process of step S4, the input unit 10 inputs each input value A i (step S5). Thereafter, the addition and multiplication unit 11 adds the difference value between A i (k) and P(k)×q[A i to the variable U (step S6). The output unit 14 inputs U(0) to Z(k) and outputs the Z(k) (step S7).
[0029] Subsequently, in the loop process of step S8, the comparison unit 13 adds the difference between U(0) and P(k)×i to the variable D i (step S9). The comparison unit 13 shifts the variable D i by W bits (step S10). The arithmetic unit 1 shifts the variable U by W bits (step S11).
[0030] Subsequently, in the loop process of step S12, the output unit 14 determines whether the variable D i exceeds 0 (step S13). If the variable D i exceeds 0 (step S13: Yes), the value of i is output to q[Z] stored in the quotient buffer 12 (step S14). Also, during the loop of step S12, if the variable D i does not exceed 0 (step S13: No), the output unit 14 outputs 0 to q[Z] stored in the quotient buffer (step S15).
[0031] Also, in order to calculate efficiently as described above, the arithmetic unit 1 may change the processing order or execute a plurality of processes in parallel while maintaining the dependency relationship. Here, the pipeline processing in the present embodiment will be described with reference to FIG. 5.
[0032] FIG. 5 is a sequence diagram of pipeline processing for calculating Z = A1 + A2 | mod | P. The input unit 10 inputs P(0) (step S101). Then, the input unit 10 inputs A1(0) (step S102). Then, the input unit 10 inputs A2(0) (step S103). In parallel with step S103, the addition multiplication unit 11 adds the difference value between A i (k) and P(k)×q[A1] to the variable U (step S104). Next, the addition multiplication unit 11 adds the difference value between A2(k) and P(k)×q[A2] to the variable U (step S105).
[0033] Subsequently, the input unit 10 inputs P(1) (step S106). At the timing of executing S106 in parallel, the output unit 14 inputs U(0) to Z(k) and outputs the Z(k) (step S107). Also in parallel with this, the comparison unit 13 adds the difference between U(0) and P(0) to the variable D (step S108).
[0034] Next, the input unit 10 inputs A1(1) (step S109). At the timing of ending step S109, the addition multiplication unit 11 adds the difference value between A1(1) and P(1)×q[A1] to the variable U (step S110). Then, the input unit 10 inputs A2(1) (step S111). Also, the addition multiplication unit 11 adds the difference value between A2(1) and P(1)×q[A2] to the variable U (step S112). Also in parallel at this timing, the output unit 14 inputs U(0) to Z(1) and outputs the Z(1) (step S113). Also in parallel with S113, the comparison unit 13 adds the difference between U(0) and P(1) to the variable D (step S114).
[0035] Subsequently, the input unit 10 inputs P(2) (step S115). Then, the input unit 10 inputs A1(2) (step S116). At the timing when step S116 ends, the addition-multiplication unit 11 adds the difference value between A1(2) and P(2)×q[A2] to the variable U (step S117). Next, the input unit 10 inputs A2(2) (step S118). Also, the addition-multiplication unit 11 adds the difference value between A2(2) and P(2)×q[A2] to the variable U (step S119). Next, the output unit 14 inputs U(0) to Z(2) and outputs the Z(2) (step S120). Also, the comparison unit 13 adds the difference between U(0) and P(2) to the variable D (step S121).
[0036] In this way, the arithmetic unit 1 can process the input unit 10, the addition-multiplication unit 11, the comparison unit 13, and the output unit 14 in parallel.
[0037] In the above example, the case of n = 2 has been described. However, for the case of n = 4, that is, when the input values are A1, A2, A3, and A4, the processing will be described using the pseudo-code shown in FIG. 6.
[0038] As shown in FIG. 6, in addition to A1(k) and A2(k), the input unit 10 inputs A3(k) and A4(k) (descriptions 621, 623). Also, the addition-multiplication unit 11 adds the difference value between A3(k) and P(k)×q[A3] to the variable U, and adds the difference value between A4(k) and P(k)×q[A4] to the variable U (descriptions 622, 624).
[0039] Also, the comparison unit 13 adds the difference between U(0) and P(k)×2 to the variable D2, and adds the difference between U(0) and P(k)×3 to the variable D3 (description 625). Also, after the loop process ends, the variable D 1、 Variable D 2、 and the value of the variable D3 are used to set the value of q[Z] (description 626).
[0040] According to this process, for 0≦A1, A2, A3, A4≦4P, 0≦Z≦4P holds. Also, Z = A1 + ··· + A nTo calculate the quotient q[Z] for, the comparison unit 13 may be configured with at most n - 1 subtractors.
[0041] In the above-described embodiment, the processing executed by the arithmetic unit 1 in the signature verification process of the signature verification circuit 103 has been described. However, in the signature generation process in the signature granting circuit 102, the signature may be generated using the functions of the arithmetic unit 1.
[0042] In the above-described embodiment, the input unit 10 reads the plurality of input values A1 and A2 word by word. The addition multiplication unit 11 performs operations word by word for each input value using the comparison value between the norm P and the input value and the value based on the norm P. Further, the output unit 14 of the arithmetic unit 1 outputs the addition result Z by adding the input value, the comparison value, and U calculated based on the norm P. Further, the comparison unit 13 of the arithmetic unit 1 outputs q[Z], which is the result of comparing U and the norm P, to the quotient buffer.
[0043] In this case, the arithmetic unit 1 performs operations word by word for each input value using the comparison value between the norm P and the input value and the value based on the norm P, and then outputs q[Z], which is the result of comparing the addition result Z and the norm P. By using this q[Z] in subsequent processing, pipeline processing can be realized. As a result, the arithmetic unit 1 can perform arithmetic processing on a finite field at high speed.
[0044] (Second Embodiment) In the second embodiment, an example of modular subtraction will be described. Here, the configuration of the memory system 300 of the present embodiment is the same as that of the first embodiment shown in FIG. 1, and the functional configuration of the arithmetic unit 1 of the present embodiment is the same as that of the first embodiment shown in FIG. 2. Taking the case of n = 2 as an example, the modular subtraction Z = A1 - A2 | mod | P is considered as Z = A1+(P - A2) | mod | P. Here, the processing procedure of the modular subtraction according to the second embodiment will be described with reference to the pseudo code shown in FIG. 7. Here, the description will focus on the parts different from the pseudo code shown in FIG. 3.
[0045] For example, it is calculated using the following pseudo-code. According to this process, for 0 ≦ A1, A2 ≦ 2P, 0 ≦ Z ≦ 2P holds. Therefore, the calculation result Z of modular subtraction can be used as the input for another modular subtraction. Also, it is possible to use the calculation result of modular subtraction as the input for another modular addition, or to use the calculation result of modular addition as the input for another modular subtraction.
[0046] As shown in FIG. 7, the input unit 10 inputs the scalar P(k) from the signature verification circuit 103, and the addition and multiplication unit 11 adds the scalar P(k) to the value stored in the variable U (description 631). After that, the input unit 10 executes the description 602 shown in FIG. 3, and the addition and multiplication unit 11 executes the process of description 603, so that the difference value between A1(k) and P(k)×q[A1] is added to the variable U. In this way, the addition and multiplication unit 11 adds the value of the scalar P(k) to the variable U before adding the difference value between A1(k) and P(k)×q[A1] to the variable U. Also, after the input unit 10 inputs A2(k), the addition and multiplication unit 11 subtracts the result of subtracting the difference value between A2(k) and P(k)×q[A2] from the variable U. The subsequent processing is executed in the same manner as the processing from description 606 to description 609 described with reference to FIG. 3.
[0047] Subsequently, the calculation processing procedure of Z = A1 - A2 |mod| P based on the above pseudo-code will be described using the flowchart shown in FIG. 8.
[0048] First, the input unit 10 initializes the variable U and the variable D i (step S21). Subsequently, the arithmetic unit 1 executes a loop process until the variable k becomes m (step S22). In the loop process shown in step S22, the processes of steps S23 to S32 are executed.
[0049] In step S23, the input unit 10 inputs P(k) (step S23). Subsequently, in step S24, the addition multiplication unit 11 adds the norm P(k) to the variable U (step S24). The input unit 10 inputs the input value A1(k) (step S25). Subsequently, the addition multiplication unit 11 adds the difference value between A1(k) and P(k)×q[A1] to the variable U (step S26). Then, the input unit 10 inputs the input value A2(k) (step S27). The addition multiplication unit 11 subtracts the difference value between A2(k) and P(k)×q[A2] from the variable U (step S28). The output unit 14 inputs U(0) to Z(k) and outputs the Z(k) (step S29). The comparison unit 13 adds the difference between U(0) and P(k)×i to the variable D (step S30). The comparison unit 13 shifts the variable D by W bits (step S31). The arithmetic unit 1 shifts the variable U by W bits (step S32).
[0050] Subsequently, in the process of step S33, the output unit 14 determines whether the variable D exceeds 0 (step S33). If the variable D exceeds 0 (step S33: Yes), the output unit 14 outputs a value of 1 to q[Z] (step S34). Also, in the process of step S33, if the variable D does not exceed 0 (step S33: No), the output unit 14 outputs 0 to q[Z] of the quotient buffer 12 (step S35).
[0051] In the arithmetic unit 1 according to the present embodiment, before performing arithmetic operations on a plurality of input values, a process of adding the norm P is performed. Thereby, even when subtracting a plurality of input values, the arithmetic unit 1 according to the present embodiment outputs q[Z] like the arithmetic unit 1 according to the first embodiment, and can obtain the same effect as the arithmetic unit 1 according to the first embodiment.
[0052] (Third Embodiment) In the third embodiment, an example of performing Montgomery multiplication will be described. Here, the configuration of the memory system 300 of the present embodiment is the same as that of the first embodiment shown in FIG. 1, and the functional configuration of the arithmetic unit 1 of the present embodiment is the same as that of the first embodiment shown in FIG. 2. Montgomery multiplication Z = A×B×2-N |mod|The procedure for processing P will be described using the pseudo-code shown in FIG. 9. It is assumed that N is set to a value larger than the bit length of P using the method by the non-patent document: Walter, C. (1999). Montgomery exponentiation needs no final subtractions. Electronics Letters, 35, 1831-1832.
[0053] For example, when N is set to the bit length of P + 2, if this pseudo-code is processed for 0 ≦ A, B ≦ 2P, then 0 ≦ Z < 2P. Also, for example, when N is set to the bit length of P + 4, if this pseudo-code is processed for 0 ≦ A, B ≦ 4P, then 0 ≦ Z < 4P. Therefore, the calculation result Z of Montgomery multiplication can be used as the input for another Montgomery multiplication. Also, the calculation result of modular addition can be used as the input for Montgomery multiplication. Furthermore, in the same way as modular addition, if a quotient is calculated for Z using a comparison unit and stored in a quotient buffer, the calculation result of Montgomery multiplication can be used as the input for another modular addition.
[0054] Before executing the pseudo-code shown in FIG. 9, the input unit 10 inputs the norm P(k), A(k), and B(k). Also, the input unit 10 inputs P'. This P' is -P -1 |mod|2 N and is. Note that the arithmetic unit 1 may be configured to calculate P'.
[0055] In the first loop process (description 641) where k ranges from 0 to less than m×2 - 1, the arithmetic unit 1 performs the second loop process (description 642) and the comparison process between k and m + 1. Also, in the second loop process where j ranges from the maximum value of 0 and k - m + 1 to the minimum value of m and k + 1, a process of adding to the variable U is performed.
[0056] Next, the processing procedure according to the third embodiment will be described using a flowchart based on the pseudo code shown in FIG. 9. First, the input unit 10 initializes the variable U and the variable D (step S41). Subsequently, the arithmetic unit 1 executes a loop process until the variable k becomes m×2−1 (step S42). In the loop process shown in step S42, the arithmetic unit 1 executes the loop process in step S43 and the comparison process shown in step S54.
[0057] In the loop process shown in step S43, the input unit 10 inputs A(k−j) (step S44). Then, the input unit 10 inputs B(k) (step S45).
[0058] Thereafter, the addition multiplication unit 11 adds A(k−j)×B(j) to the variable U (step S46). When j is the same as k (step S47: Yes), the addition multiplication unit 11 inputs U(0)×P’|mod|2 W to the variable Q(j) (step S48). Then, the output unit 14 outputs Q(j) (step S49) and proceeds to step S51.
[0059] In step S47, when j is different from k (step S47: No), the input unit 10 inputs the variable Q(j) (step S50). In step S51, the addition multiplication unit 11 adds the norm P(k−j)×the variable Q(j) to the variable U (step S51).
[0060] After exiting the loop process S43, when k is m + 1 or more (step S52: Yes), the output unit 14 inputs U(0) to Z(k−(m + 1)) and outputs the Z(k−(m + 1)) (step S53). The comparison unit 13 adds the difference between U(0) and P(k) to the variable D (step S54). The comparison unit 13 shifts the variable D by W bits (step S55). In step S56, the arithmetic unit 1 shifts the variable U by W bits (step S56).
[0061] After exiting the loop process S42, the output unit 14 inputs U(0) to Z(m−1) and outputs the Z(k−(m + 1)) (step S57). The comparison unit 13 adds the difference between U(0) and P(k) to the variable D (step S58). The comparison unit 13 shifts the variable D by W bits (step S59).
[0062] Subsequently, in the process of step S60, the output unit 14 determines whether the variable D exceeds 0 (step S60). When the variable D exceeds 0 (step S60: Yes), the output unit 14 outputs a value of 1 to q[Z] (step S61). Also, in the process of step S60, when the variable D does not exceed 0 (step S60: No), the output unit 14 outputs 0 to q[Z] of the quotient buffer (step S62).
[0063] The arithmetic unit 1 according to the present embodiment uses the value N of the bit length of the norm P to perform Montgomery multiplication Z = A×B×2 -N |mod|P, and even in the case of performing Montgomery multiplication, the same effect as the arithmetic unit 1 according to the first embodiment can be obtained.
[0064] (Fourth Embodiment) In the fourth embodiment, an example of performing a remainder operation will be described. Here, the configuration of the memory system 300 of the present embodiment is the same as that of the first embodiment shown in FIG. 1, and the functional configuration of the arithmetic unit 1 of the present embodiment is the same as that of the first embodiment shown in FIG. 2. The arithmetic unit 1 calculates the remainder operation Z = A|mod|P. Here, the procedure for processing the remainder operation Z = A|mod|P will be described using the flowchart shown in FIG. 11. In this remainder operation, the number of words of A may be larger than the number of words of P. This remainder operation is used, for example, to calculate the constant R 2 = 2 2m |mod|P.
[0065] First, the input unit 10 inputs A to Z (step S71). Then, the arithmetic unit 1 executes the loop process of step S72. The arithmetic unit 1 executes the loop process of step S72 while k is less than or equal to l - 1 and greater than or equal to m - 1. Here, l is the number of words of Z, and m is the number of words of the index P.
[0066] The addition multiplication unit 11 calculates an approximate value Q of the quotient using only the upper words of Z and P. For example, the addition multiplication unit 11 calculates an approximate value Q of the quotient Z / (P << s) with the shift amount s = W * (k - (m - 1)) (step S73). Subsequently, the addition multiplication unit 11 updates Z (step S74). Specifically, the addition multiplication unit 11 calculates Z = Z - Q * (P << s). In this way, the addition multiplication unit 11 performs multiplication of 1 word × multiple - length integers and subtraction of multiple - length integers. Also, the output unit 14 outputs the calculated Z.
[0067] By executing this loop process, the remainder Z can be obtained, but due to using an approximate value, it may not always be the case that 0 ≤ Z < P. For example, 0 ≤ Z < 2P. The comparison unit 13 compares the value of Z with the value of P and updates q[Z] (step S75). Here, when Z is larger than P, the value of Z can be corrected so that 0 ≤ Z < P by subtracting P from Z, but the arithmetic unit 1 according to the present embodiment omits the correction of Z here.
[0068] The arithmetic unit 1 according to the fourth embodiment calculates an approximate value of the quotient when the input value is divided by the index P using the upper word of the input value and the upper word of the index P, and repeatedly subtracts the product of P and the approximate value from the input value to calculate the remainder Z. Even when Z is larger than P, by omitting the correction of the value of Z, the processing amount is reduced, and q[Z] is output like the arithmetic unit 1 according to the first embodiment, and the same effect as the arithmetic unit 1 according to the first embodiment can be obtained.
[0069] (Fifth Embodiment) In the fifth embodiment, an example of modular division will be described. Here, the configuration of the memory system 300 of this embodiment is the same as that of the first embodiment shown in FIG. 1, and the functional configuration of the arithmetic unit 1 of this embodiment is the same as that of the first embodiment shown in FIG. 2. The arithmetic unit 1 calculates modular division Z = A × B -1 |mod|P. Here, the procedure for processing modular division Z = A × B -1 |mod|P based on the extended binary GCD method will be described using the flowchart shown in FIG. 12.
[0070] First, the arithmetic unit 1 sets X = P, Y = A, U = 0, and V = 0 (step S81). In this way, the arithmetic unit 1 initializes the quotient flags of U and V to 0. Then, the arithmetic unit 1 sets 0 in the variable q[U] and the variable q[V] (step S82). The arithmetic unit 1 executes the loop process of step S83.
[0071] Specifically, in the loop process of step S83, first, the arithmetic unit 1 calculates an update matrix M using some words of X and Y (step S84). Thereby, the arithmetic unit 1 can calculate the update matrix without using multi-precision arithmetic.
[0072] Also, the addition-multiplication unit 11 updates X and Y based on the update matrix M, X, and Y (step S85). For example, the addition-multiplication unit 11 multiplies the update matrix M by a vector including the current X and Y as elements, and generates a vector including the updated X and Y as elements to update X and Y. Further, when the result of determining the sign of the updated Y is negative, the addition-multiplication unit 11 updates Y by inverting its sign. In this case, the addition-multiplication unit 11 may update the update matrix M.
[0073] Also, the addition and multiplication unit 11 updates U and V (step S86). The addition and multiplication unit 11 updates the values of U and V as U = U - P * q[U] and V = V - P * q[V]. Then, the addition and multiplication unit 11 multiplies by the update matrix M to update U and V. Then, the comparison unit 13 calculates the quotient obtained by dividing the updated U and V by P, and stores the calculated results in q[U] and q[V], which are the quotient buffers respectively (step S87).
[0074] The output unit 14 inputs U to Z and outputs the Z (step S88). Then, the output unit 14 copies q[U] to q[Z].
[0075] As described above, the arithmetic unit 1 according to the fifth embodiment stores q[U] and q[V] for the intermediate variables U and V when executing the extended binary GCD method, so that in the calculation of U and V, the same effect as in the first embodiment is obtained. Also, for the calculation result Z of the extended binary GCD method, by outputting q[Z] like the arithmetic unit 1 according to the first embodiment, in subsequent processing, the same effect as in the first embodiment is obtained.
[0076] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and their modifications are included in the scope and gist of the invention, and are also included in the invention described in the claims and its equivalent scope.
Explanation of Reference Numerals
[0077] 1 Arithmetic unit, 10 Input unit, 11 Addition and multiplication unit, 12 Quotient buffer, 13 Comparison unit, 14 Output unit, 100 Controller, 200 Semiconductor memory, 300 Memory system.
Claims
1. An arithmetic unit that outputs an arithmetic result on a finite field with a characteristic P, reads a plurality of input values with multiple precision, for the plurality of input values, performs addition or subtraction for each word using a value based on a comparison value between the input value and the characteristic P and the characteristic P, outputs a first output value obtained by calculating a value based on the input value, the comparison value, and the characteristic P, outputs a second output value obtained by comparing the first output value with the characteristic P, arithmetic unit.
2. Before performing arithmetic operations on the plurality of input values, performs a process of adding the characteristic P to the value of a variable that stores the arithmetic result for the input values, The arithmetic unit according to claim 1.
3. The comparison value is obtained by a comparison process between the input value and the characteristic P, The comparison process is an arithmetic operation with multiple precision. The arithmetic unit according to claim 1.
4. The comparison value is obtained by a comparison process between the input value and the characteristic P, The arithmetic unit according to claim 1, wherein the process of reading the input value and the comparison process between the read input value and the characteristic P are performed in parallel.
Citation Information
Patent Citations
Information input method by facsimile
JP1978073026A
Mutifold length arithmetic unit
JP2000353077A
Arithmetic unit and program
JP2013148767A