Cryptographic system, cryptographic device, cryptographic method, and program
The cryptographic system uses an optoelectronic integrated processor with Y-gate circuits and optical switching to perform cryptographic operations, addressing the challenge of multi-stage XOR and other logical operations in optical computation.
Patent Information
- Application Number
- JP2023544890
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-01
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2041-09-01
AI Technical Summary
Existing cryptographic technologies face difficulties in performing multi-stage XOR operations and operations of different types of logical operations, such as XOR and AND, using optical computation, which are essential for cryptographic operations in devices with optical technology.
A cryptographic system utilizing an optoelectronic integrated processor with Y-gate circuits, optical switching circuits, and phase modulators to perform cryptographic operations through optical processing, including exclusive OR and nonlinear operations on multiple bit values.
Enables cryptographic operations to be realized through optical processing, overcoming the limitations of multi-stage XOR and other logical operations in optical computation.
Smart Images

Figure 0007806799000004 
Figure 0007806799000005 
Figure 0007806799000006
Abstract
Description
[Technical Field]
[0001] The present invention relates to a cryptographic system, a cryptographic device, a cryptographic method, and a program. [Background technology]
[0002] In recent years, research and development has been underway to realize an all-photonics network. The all-photonics network aims to achieve low-power consumption, high-quality, large-capacity, and low-latency transmission by incorporating optical technology into everything from the network to the terminals. As part of this effort, research and development has also been conducted on photonics-electronics convergence processors, which envision the introduction of optical technology into terminals. In this research and development, Ψ gates, which are optical operation gates capable of performing logical operations on optical signals themselves, and optical pass-gate logic circuits have been proposed. For example, Non-Patent Document 1 proposes a Ψ gate that adds the concept of bias light to perform logical operations on two-input optical signals equivalent to two bits, making it a three-input optical system. By varying the intensity of the bias light or the phase difference between the bias light and the two input optical signals, arbitrary logical operations can be performed.
[0003] When using a single wavelength multiplexing system with two wavelengths, the Ψ gate can perform 128 (=2 7 It is known that multi-stage connection of 128-bit inputs and 1-bit outputs (1-bit output representing the result of a 128-bit logical operation) is possible. Furthermore, wavelength multiplexing makes it possible, in principle, to double the number of input bits by the number of wavelength channels. On the other hand, for two types of linearly inseparable operations, exclusive OR (XOR) and XNOR, it is difficult to achieve multi-stage connection based solely on the state of the optical signal, as long as optical interference is used, and only 1-bit operations (2-bit input, 1-bit output) are possible. Furthermore, it is difficult to perform multi-stage operations of different types of logical operations, such as AND and XOR. [Prior art documents] [Non-patent literature]
[0004] [Non-Patent Document 1] Nikkei Electronics 2020.05, NTT achieves logic operations using only light - 300 times lower latency than electricity - Summary of the Invention [Problem to be solved by the invention]
[0005] When optical technology is implemented in devices such as terminals, cryptographic technology (encryption method, authentication method) is required to perform cryptographic operations using optical bit information and to authenticate devices and detect data tampering, etc. In addition, cryptographic operations in existing cryptographic technology are realized using multi-stage operations of different types of logical operations, such as multi-stage XOR operations or AND and XOR operations.
[0006] On the other hand, as mentioned above, it is difficult to realize multi-stage XOR operations using optical computation, and it is also difficult to realize multi-stage operations of different types of logical operations, such as XOR and AND operations. For this reason, it is difficult to realize cryptographic operations using optical computation.
[0007] An embodiment of the present invention has been made in view of the above points, and has as its object to realize cryptographic operations by optical operation processing. [Means for solving the problem]
[0008] To achieve the above objective, in one embodiment of the cryptographic system, an optoelectronic integrated processor is configured with at least one of a Y-gate circuit that superimposes optical signals, an optical switching circuit that controls the path of the optical signal using an electrical signal, and a phase modulator that modulates the phase of the optical signal, and the cryptographic system performs cryptographic operations using optical processing, including an exclusive OR operation on two or more bit values and a nonlinear operation on two or more bit values. [Effects of the Invention]
[0009] Cryptographic operations can be realized by optical processing. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of a cryptographic device according to an embodiment of the present invention. [Figure 2] FIG. 10 is a diagram for explaining an example of a 2-bit XOR operation using a Y gate circuit. [Figure 3] FIG. 1 is a diagram (part 1) for explaining an example of a 2-bit XOR operation using an MZI circuit. [Figure 4] FIG. 1 is a diagram (part 1) for explaining an example of the operation of an MZI circuit. [Figure 5] FIG. 2 is a diagram (part 2) for explaining an example of a 2-bit XOR operation using an MZI circuit. [Figure 6] FIG. 10 is a diagram (part 2) for explaining an example of the operation of the MZI circuit. [Figure 7] FIG. 10 is a diagram illustrating an example of implementation of AddRoundKey. [Figure 8] FIG. 10 is a diagram illustrating an example of implementation of the lowest 1 bit of SubBytes. [Figure 9] FIG. 10 is a diagram illustrating an example of implementation of SubBytes. [Figure 10] FIG. 1 is a diagram illustrating an example of an implementation of SubBytes, which parallelizes optical passgate logic circuits. [Figure 11] FIG. 10 is a diagram illustrating an implementation example of ShiftRows. [Figure 12] FIG. 10 is a diagram for explaining an example of calculation of MixColumns. [Figure 13] FIG. 10 is a diagram for explaining an example of a 6-bit XOR operation using a Y gate circuit. [Figure 14] FIG. 10 is a diagram for explaining an example of an 8-bit XOR operation using a Y gate circuit. [Figure 15] FIG. 1 is a diagram (part 1) for explaining an example of a 6-bit XOR operation using a phase modulator. [Figure 16]FIG. 10 is a diagram (part 2) for explaining an example of a 6-bit XOR operation using a phase modulator. [Figure 17] FIG. 1 is a diagram (part 1) for explaining an example of an 8-bit XOR operation using a phase modulator. [Figure 18] FIG. 10 is a diagram (part 2) for explaining an example of an 8-bit XOR operation using a phase modulator. [Figure 19] FIG. 10 is a diagram (part 3) for explaining an example of a 6-bit XOR operation using a phase modulator. [Figure 20] FIG. 10 is a diagram (part 3) for explaining an example of an 8-bit XOR operation using a phase modulator. [Figure 21] FIG. 1 is a diagram (part 1) for explaining an example of a 6-bit XOR operation using an MZI circuit. [Figure 22] FIG. 1 is a diagram (part 1) for explaining an example of an 8-bit XOR operation using an MZI circuit. [Figure 23] FIG. 10 is a diagram (part 2) for explaining an example of a 6-bit XOR operation using an MZI circuit. [Figure 24] FIG. 10 is a diagram (part 2) for explaining an example of an 8-bit XOR operation using an MZI circuit. [Figure 25] FIG. 10 is a diagram illustrating an example of an implementation of MixColumns. [Figure 26] FIG. 1 is a diagram for explaining an example of the overall implementation of encryption using AES. [Figure 27] This is a diagram (part 1) for explaining an implementation example of the XOR operation for the first round of the key schedule. [Figure 28] This is a diagram (part 2) for explaining an implementation example of the XOR operation for the first round of the key schedule. [Figure 29] FIG. 10 is a diagram for explaining an example of implementation of the entire key scheduling part. DETAILED DESCRIPTION OF THE INVENTION
[0011] An embodiment of the present invention will be described below. In this embodiment, an encryption device 10 will be described that realizes the encryption operations of existing encryption techniques (encryption method, authentication method) by optical operation processing. Note that since the authentication method can be considered as a type of application of the encryption method, the encryption operation includes not only operations for encryption and decryption in the encryption method, but also operations for authentication, tamper detection, etc. in the authentication method.
[0012] <Configuration Example of Encryption Device 10> An example of the configuration of an encryption device 10 according to this embodiment is shown in Fig. 1. As shown in Fig. 1, the encryption device 10 according to this embodiment includes an optical arithmetic circuit 101, an optical transmitter 102, a photodetector 103, and a memory 104.
[0013] The optical arithmetic circuit 101 is a circuit (optoelectronic integrated processor) that realizes optical arithmetic processing. The optical arithmetic circuit 101 realizes an optical encryption arithmetic unit 111 and an optical arithmetic control unit 112 by one or more programs installed in the encryption device 10.
[0014] The optical cryptographic calculation unit 111 realizes cryptographic calculations by optical calculation processing. In particular, the optical cryptographic calculation unit 111 realizes cryptographic calculations using multi-stage XOR calculations, or multi-stage calculations of different types of logical calculations such as XOR and AND calculations, by optical calculation processing. Furthermore, the optical cryptographic calculation unit 111 not only performs optical calculation processing, but also realizes photoelectric conversion (photoelectric-electrical conversion) that converts an intermediate value (intermediate value) into an electrical value, for example. Note that in optical calculation processing, an optical signal is used as input, calculation is performed on the optical signal as it is, and the calculation result is output as the optical signal as it is.
[0015] When a circuit that realizes optical arithmetic processing (for example, an optical switching circuit) is controlled by an electrical signal, the optical arithmetic control unit 112 realizes the control. For example, as will be described later, when a Mach-Zehnder Interferometer switch circuit, which is one of the optical switching circuits, is used, the optical arithmetic control unit 112 controls the path of the optical signal input to the Mach-Zehnder Interferometer switch circuit by an electronic signal.
[0016] The optical transmitter 102 is a device (peripheral device of the optical arithmetic circuit 101) that outputs an optical signal to the optical arithmetic circuit 101. The optical transmitter 102 realizes a laser transmitter unit 121 and a light source controller 122 by one or more programs installed in the encryption device 10.
[0017] The laser transmitter 121 functions as a light source for the optical arithmetic circuit 101, and outputs an optical signal by laser light to the optical arithmetic circuit 101 under the control of the light source controller 122. Hereinafter, the laser transmitter 121 will also be referred to as the "light source 121." The light source controller 122 controls the laser transmitter 121 with an electrical signal (for example, controls the laser transmitter 121 so that it outputs an optical signal).
[0018] The optical detector 103 is a device (peripheral device of the optical arithmetic circuit 101) that detects the optical signal output from the optical arithmetic circuit 101 and stores the arithmetic result represented by the optical signal in a memory 104. The optical detector 103 realizes an optical detection unit 131 and an opto-electric conversion unit 132 by one or more programs installed in the encryption device 10.
[0019] The optical detection unit 131 detects the optical signal output from the optical arithmetic circuit 101. The photoelectric conversion unit 132 converts the optical signal detected by the optical detection unit 131 into an electrical signal, and stores information represented by the electrical signal (i.e., information representing the calculation result of the optical encryption calculation unit 111) in the memory 104.
[0020] The memory 104 is a storage device that stores information representing the calculation results of the optical calculation circuit 101 (for example, encryption results, decryption results, etc.).
[0021] 1 is merely an example, and the encryption device 10 may include various other hardware components in addition to the optical arithmetic circuit 101, the optical transmitter 102, the optical detector 103, and the memory 104. Since the encryption device 10 is configured with multiple pieces of hardware, it may be referred to as, for example, a cryptographic system.
[0022] <AES(Advanced Encryption Standard)> The cryptographic device 10 according to this embodiment can perform cryptographic operations for any encryption method or authentication method using optical computation processing. Hereinafter, we will explain the cryptographic operations for encryption processing using AES (Reference 1), the de facto standard for symmetric key cryptography, as an example. However, it goes without saying that the cryptographic operations for decryption processing using AES can be performed in a similar manner. It also goes without saying that the cryptographic operations for any encryption method or authentication method other than AES, such as one-time pad cryptography, can be performed in a similar manner.
[0023] AES consists of a data calculation part and a key schedule part. The data calculation part encrypts (or decrypts) data by performing calculations on the data (this calculation is also called "round processing"), and the key schedule part generates round keys used in the round processing from a secret key. Below, we will explain how the calculations in the data calculation part and key schedule part are realized using optical calculation processing.
[0024] <Data calculation section> Each round of processing in the data calculation unit consists of four processes: SubBytes, ShiftRows, MixColumns, and AddRoundKey. Generally, encryption and decryption processes involve a nonlinear calculation unit, which is realized by combining different types of logical operations such as XOR and AND. In AES, SubBytes corresponds to the nonlinear calculation unit.
[0025] Here, the number of rounds to be performed varies depending on the key length. The length of the plaintext data (block length) is 128 bits, and the key length is 128 bits, 192 bits, or 256 bits. In this embodiment, the key length is assumed to be 128 bits as an example, but calculations can be performed using the same process for other key lengths.
[0026] An example of implementation of the optical arithmetic circuit 101 for realizing each component of the data arithmetic unit of the AES by optical arithmetic processing will be described below.
[0027] <<AddRoundKey with initial key>> The first calculation process of AES is to perform an XOR operation between the 128-bit initial key (secret key) generated in the key schedule part and 128 bits of plaintext. To perform a 1-bit XOR operation (a total of 128-bit XOR operations), there are three implementation examples: (A), (B)-1, and (B)-2 below.
[0028] Implementation example (A): Implementation method using a Y-gate circuit As shown in Fig. 2, the optical arithmetic circuit 101 is implemented to perform an XOR operation with 2-bit input and 1-bit output using a Y gate circuit 201. The Y gate circuit 201 receives an optical signal a corresponding to 1 bit of a private key and an optical signal b corresponding to 1 bit of plaintext as input, and outputs an optical signal c. The optical signals a and b are output from a light source 121. At this time, by shifting the phase difference between the optical signals a and b by π, it is possible to perform an XOR operation on a and b (Reference 2).
[0029] After optical signals a and b pass through Y gate circuit 201, an optical signal c is input to photodetector 103. Then, photodetector unit 131 of photodetector 103 detects optical signal c by direct detection, which detects the intensity of the optical signal, and photoelectric conversion unit 132 outputs voltage V or 0 according to the intensity of optical signal c. That is, photoelectric conversion unit 132 outputs voltage V when the intensity of optical signal c is equal to or greater than a certain threshold, and voltage 0 when it is less than the threshold. In this case, voltage V is set to bit 1, and voltage 0 is set to bit 0. As a result, the result of the XOR operation of a and b is obtained as the output of photodetector 103 and stored in memory 104.
[0030] To perform an XOR operation for 128 bits, one Y gate circuit may be used 128 times, or 128 Y gate circuits may be used. Alternatively, by using multiple light sources 121 and inputting multiple optical signals with different frequencies, it is possible to perform an XOR operation for 128 bits using fewer than 128 Y gate circuits.
[0031] In this implementation example, since the private key information is an optical signal, the method for generating the private key does not require maintaining the optical state, and an implementation method in which key scheduling is performed in parallel with encryption (on-the-fly key scheduling) is preferable.
[0032] Implementation example (a)-1: Implementation method using a Mach-Zehnder type interference switch circuit As shown in Fig. 3, an optical arithmetic circuit 101 is implemented to perform an XOR operation with 2-bit input and 1-bit output using a Mach-Zehnder interference switch circuit (hereinafter referred to as an MZI circuit) 202. This is a desirable implementation method when storing a private key electrically.
[0033] When storing information representing a private key electrically, an electrical signal b corresponding to one bit of the private key is assigned to the input of MZI circuit 202, and an optical signal a corresponding to one bit of plaintext and an optical signal a' obtained by inverting that bit value are assigned to the upper and lower optical signal ports as inputs to the path of MZI circuit 202. Note that if a is an optical signal representing bit 1, then a' is an optical signal representing bit 0, and if a is an optical signal representing bit 0, then a' is an optical signal representing bit 1. Furthermore, optical signals a and a' are output from light source 121.
[0034] As shown in Figure 4, the MZI circuit changes the path of the optical signal when the input electrical signal is 0 (this is called the Cross state. In the Cross state, an optical signal input from the upper optical signal port is output from the lower optical signal port, and an optical signal input from the lower optical signal port is output from the upper optical signal port), and passes the optical signal as is when the electrical signal is 1 (this is called the Bar state). Below, the port to which the electronic signal is input will also be called the path control port.
[0035] The paths of optical signals a and a' are controlled by the value of electrical signal b, which corresponds to one bit of the private key, and the value represented by the optical signal output from the lower optical signal port of MZI circuit 202 is equivalent to the result of the XOR operation of a and b. That is, if the optical signal output from the lower optical signal port of MZI circuit 202 is c, when the optical detection unit 131 of photodetector 103 detects optical signal c (that is, when optical signal c of a certain intensity or greater reaches photodetector 103), the photoelectric conversion unit 132 outputs voltage V; otherwise, the photoelectric conversion unit 132 outputs voltage 0. In this case, voltage V is bit 1, and voltage 0 is bit 0. As a result, the result of the XOR operation of a and b is obtained as the output of photodetector 103 and stored in memory 104.
[0036] Here, to perform an XOR operation for 128 bits, one MZI circuit may be used 128 times, or 128 MZI circuits may be used. Also, by using multiple light sources 121 and inputting multiple optical signals with different frequencies, it is possible to perform an XOR operation for 128 bits using fewer than 128 MZI circuits.
[0037] Implementation example (a) - 2: Implementation method using a 2-input port MZI circuit As shown in FIG. 5, an optical arithmetic circuit 101 is implemented to perform an XOR operation with 2-bit input and 1-bit output using an MZI circuit 203 having two path control ports for controlling the path of an optical signal (hereinafter also referred to as a 2-input port MZI circuit).
[0038] At this time, an optical signal representing bit 0 and an optical signal representing bit 1 are input as fixed optical signals to the upper and lower optical signal ports of the two-input port MZI circuit 203, respectively, and two electrical signals (electrical signal a corresponding to 1 bit of plaintext and electrical signal b corresponding to 1 bit of the private key) are input to the two route control ports, respectively. The fixed optical signals are output from the light source 121.
[0039] Here, as shown in FIG. 6, in a two-input port MZI circuit, when the values of two electrical signals a and b are both 1 or 0, the circuit is in the Cross state, and otherwise the circuit is in the Bar state.
[0040] Therefore, the path of the optical signal is controlled by the value of electrical signal a, which corresponds to one bit of plaintext, and the value of electrical signal b, which corresponds to one bit of the private key. The value represented by the optical signal output from the lower optical signal port of the two-input port MZI circuit 203 is equivalent to the result of the XOR operation of a and b. That is, if the optical signal output from the lower optical signal port of the two-input port MZI circuit 203 is c, when the optical detection unit 131 of the photodetector 103 detects optical signal c (i.e., when optical signal c of a certain intensity or greater reaches the photodetector 103), the photoelectric conversion unit 132 outputs voltage V; otherwise, the photoelectric conversion unit 132 outputs voltage 0. In this case, voltage V is set to bit 1, and voltage 0 is set to bit 0. As a result, the result of the XOR operation of a and b is obtained as the output of the photodetector 103 and stored in the memory 104. Note that in this implementation example, both the plaintext and the private key, which are the targets of the XOR operation, need to be electrically stored in advance (or converted from optical signals to electrical signals).
[0041] Here, as in implementation example (A)-1, to perform an XOR operation for 128 bits, one two-input port MZI circuit may be used 128 times, or 128 two-input port MZI circuits may be used. Also, by using multiple light sources 121 and inputting multiple optical signals with different frequencies as fixed optical signals, it is possible to perform an XOR operation for 128 bits with fewer than 128 two-input port MZI circuits.
[0042] Figure 7 shows a summary of the above implementation examples (A), (B)-1, and (B)-2. As shown in Figure 7, in implementation example (A), the plaintext and the secret key are both input to the Y-gate circuit as optical signals. In implementation example (B)-1, the plaintext is input to the MZI circuit as an optical signal, and the secret key is input to the MZI circuit as an electrical signal. In implementation example (B)-2, the plaintext and the secret key are both input to the two-input port MZI circuit as electrical signals.
[0043] SubBytes The AES SubBytes process can be performed using a table conversion table called an S-Box, or using an extension field (GF(2 8 In some cases, an affine transformation consisting of an inverse operation on the sigma-based transformation and an XOR operation is used. The following describes the case where a table transformation table is used.
[0044] As an example, we will explain SubBytes (8-bit input, 8-bit output) used for AES encryption (Reference 1). Note that SubBytes used for decryption can also be configured in a similar way.
[0045] In this embodiment, we will explain an implementation example using an optical pass-gate logic circuit (Reference 3), which receives an electrical signal representing an 8-bit input of SubBytes and outputs an optical signal representing one bit of the 8-bit output of SubBytes.
[0046] An example of implementation in which the 8-bit input of SubBytes is (x7x6x5x4x3x2x1x0)2 and the least significant 1 bit of the 8-bit output of SubBytes is output is shown in Figure 8. As shown in Figure 8, the first stage consists of 128 MZI circuits 1001 to 1128 in which electrical signal x7 is input to the routing control port, the second stage consists of 64 MZI circuits 2001 to 2054 in which electrical signal x6 is input to the routing control port, the third stage consists of 32 MZI circuits 3001 to 3032 in which electrical signal x5 is input to the routing control port, the fourth stage consists of 16 MZI circuits 4001 to 4016 in which electrical signal x4 is input to the routing control port, and the fourth stage consists of 128 MZI circuits 1001 to 1128 in which electrical signal x7 is input to the routing control port. The optical arithmetic circuit 101 is implemented using these MZI circuits, with eight MZI circuits 5001-5008 in which electrical signal x3 is input to the routing control port as the fifth stage, four MZI circuits 6001-6004 in which electrical signal x2 is input to the routing control port as the sixth stage, two MZI circuits 7001-7002 in which electrical signal x1 is input to the routing control port as the seventh stage, and one MZI circuit 8001 in which electrical signal x0 is input to the routing control port as the eighth stage. Note that only some of the MZI circuits are shown in Figure 8, with the rest not being shown.
[0047] At this time, the optical signals output from the upper optical signal ports of the two MZI circuits in the previous stage are connected so as to be input to the optical signal port of the MZI circuit in the next stage. Specifically, as shown in Fig. 8, the optical signal output from the upper optical signal port of MZI circuit 1001 and the optical signal output from the upper optical signal port of MZI circuit 1002 are input to the upper optical signal port and lower optical signal port of MZI circuit 2001, respectively. That is, for example, in each stage, the MZI circuits in that stage are numbered sequentially from top to bottom, starting from 0. At this time, for i = 0, 2, 4,..., 126, the optical signal output from the upper optical signal port of the i-th MZI circuit in the first stage and the optical signal output from the upper optical signal port of the (i+1)th MZI circuit in the first stage are input to the upper optical signal port and lower optical signal port of the (i / 2)th MZI circuit in the second stage, respectively. Similarly, for i = 0, 2, 4, , 62, the optical signal output from the upper optical signal port of the i-th MZI circuit in the second stage and the optical signal output from the upper optical signal port of the (i+1)-th MZI circuit in the second stage are input to the upper optical signal port and lower optical signal port of the (i / 2)-th MZI circuit in the third stage, respectively. Similarly, for i = 0, 2, 4, , 30, the optical signal output from the upper optical signal port of the i-th MZI circuit in the third stage and the optical signal output from the upper optical signal port of the (i+1)-th MZI circuit in the third stage are input to the upper optical signal port and lower optical signal port of the (i / 2)-th MZI circuit in the fourth stage, respectively. For i = 0, 2, 4, . . . , 14, the optical signal output from the upper optical signal port of the i-th MZI circuit in the fourth stage and the optical signal output from the upper optical signal port of the (i+1)-th MZI circuit in the fourth stage are input to the upper optical signal port and lower optical signal port of the (i / 2)-th MZI circuit in the fifth stage, respectively. For i = 0, 2, 4, 6, the optical signal output from the upper optical signal port of the i-th MZI circuit in the fifth stage and the optical signal output from the upper optical signal port of the (i+1)-th MZI circuit in the fifth stage are input to the upper optical signal port and lower optical signal port of the (i / 2)-th MZI circuit in the sixth stage, respectively.For i = 0, 2, the optical signal output from the upper optical signal port of the i-th MZI circuit in the 6th stage and the optical signal output from the upper optical signal port of the (i+1)-th MZI circuit in the 6th stage are input to the upper optical signal port and lower optical signal port of the (i / 2)-th MZI circuit in the 7th stage, respectively. The optical signal output from the upper optical signal port of the 0th MZI circuit in the 7th stage and the optical signal output from the upper optical signal port of the 1st MZI circuit in the 7th stage are input to the upper optical signal port and lower optical signal port of the 8th MZI circuit, respectively.
[0048] Furthermore, memory 104 is assigned the least significant bit of the output result when each byte (0x00 to 0xFF in hexadecimal notation) is input to SubBytes as a memory value. For example, the output of SubBytes for 0x00 is 0x63, so 1, the least significant bit of 0x63, is assigned to the beginning (most significant bit) of the memory value. Similarly, the output of SubBytes for 0x01 is 0x7c, so 0, the least significant bit of 0x7c, is assigned to the second (next to the beginning) of the memory value. Similarly, the least significant bit of the output of SubBytes for 0x02 to 0xFF is assigned to the memory value in order.
[0049] For i=0, , 127, an optical signal representing the 2i-th value from the beginning of the memory values and an optical signal representing the 2i+1-th value are input to the upper and lower optical signal ports of the i-th MZI circuit in the first stage, respectively. These optical signals are output from the light source 121.
[0050] As a result, the 1 bit represented by the optical signal output from the upper optical signal port of the 8th stage MZI circuit 8001 becomes the least significant 1 bit of the SubBytes output for (x7x6x5x4x3x2x1x0)2. The optical signal output from the upper optical signal port of the MZI circuit 8001 is detected by the photodetector 103, and the 1-bit value represented by the optical signal is stored in the memory 104. Specifically, when the photodetector unit 131 of the photodetector 103 detects an optical signal whose intensity is equal to or greater than a certain threshold, the photoelectric conversion unit 132 outputs a voltage V corresponding to bit 1, and a voltage 0 corresponding to bit 0 otherwise.
[0051] By implementing the optical arithmetic circuit 101 as described above and controlling the path of each MZI circuit using the combination of (x7x6x5x4x3x2x1x0)2, which is the input of SubBytes, 256 (=2 8 ) can be output as the least significant bit of the 8-bit output of SubByte.
[0052] Similarly, other bits of the 8-bit output of SubByte can be implemented by assigning the value of the corresponding bit of the output result when each byte is input to SubBytes as the memory value. In other words, to output the value of the nth bit (n=0,1,...,7) of the 8-bit output of SubByte, simply assign the value of the nth bit of the output result when each byte is input to SubBytes as the memory value. Note that the bit where n=0 corresponds to the least significant bit.
[0053] The relationship between input / output and memory values when realizing SubBytes using optical passgate logic circuits is summarized below.
[0054] Optical pass gate logic circuit input: 8-bit input of SubBytes Output of the optical pass gate logic circuit: The value of the nth bit of the 8-bit output of SubBytes (n=0, 1, . . . , 7) Memory value: A 256-bit value (n=0,...,7) that stores the n-th bit value of the output result (8 bits) when each byte from 0x00 to 0xFF is input to SubBytes, starting from the top (most significant bit). An example implementation of the above SubBytes is shown in Figure 9. As shown in Figure 9, this implementation takes an 8-bit electrical signal as input and outputs an 8-bit optical signal. Since AES requires 16 SubBytes with 8-bit input and output, for example, if an 8-bit operation is multiplexed using eight types of light sources (i.e., eight types of memory values) in one optical passgate logic circuit, 16 optical passgate logic circuits must be implemented. On the other hand, if eight optical passgate logic circuits are implemented using one light source, 8 × 16 = 128 optical passgate logic circuits are required. As an example, Figure 10 shows an implementation example in which eight types of light sources are multiplexed in one optical passgate logic circuit. In the implementation example shown in Figure 10, optical passgate logic circuits incorporating eight types of light sources, capable of 8-bit operations, are arranged in parallel, making it possible to suppress delays due to operations.
[0055] ≪ShiftRows≫ The ShiftRows operation is realized by changing the optical wiring connections. In AES, a cyclic shift of 0, 8, 16, or 24 bits is performed depending on the position of the intermediate value, so the optical arithmetic circuit 101 is implemented so that the optical wiring for each bit is physically connected to the arrangement after the cyclic shift.
[0056] An example implementation of the above ShiftRows is shown in Figure 11. As shown in Figure 11, in this implementation example, both input and output are optical signals.
[0057] MixColumns and AddRoundKey Although MixColumns and AddRoundKey in AES are separate arithmetic operations (Reference 1), this embodiment assumes that these two arithmetic operations are implemented simultaneously.
[0058] MixColumns is an arithmetic operation equivalent to transposition in AES, and is realized by multiplying 32-bit matrices as shown in Figure 12. Note that y1 to y4 are in the extension field GF(2 8 )(irreducible polynomial:x 8 +x 4 +x 3 +x+1) i ,y i (8 bits, i=1, 2, 3, 4). Now, consider y1 shown in the following equation (1). Note that y2 to y4 can also be calculated in the same way as y1.
[0059]
number
[0060] x1:(a7a6a5a4a3a2a1a0)2 x2:(b7b6b5b4b3b2b1b0)2 x3:(c7c6c5c4c3c2c1c0)2 x4:(d7d6d5d4d3d2d1d0)2 In this case, the binary representation of y1 (y1 7 y1 6 y1 5 y1 4 y1 3 y1 2 y1 1 y1 0 Each bit of y1 can be expressed as follows: 0 is the least significant bit.
[0061]
number
[0062] Let i be the number of rounds and j be the number of bytes. Let the round key (8 bits) be RK. j i (i=1, ,9, j=0, ,15). The binary representation of the round key to be XORed with y1 is expressed as follows:
[0063] RK0 i :(rk7rk6rk5rk4rk3rk2rk1rk0)2 In this case, if the XOR operation to obtain y1 (that is, the MixColumns operation) and the XOR operation between y1 and the round key are performed simultaneously, the following can be expressed:
[0064]
number
[0065] Therefore, three implementation examples of 6-bit XOR operation and 8-bit XOR operation using optical processing are described below. As an example, in the 6-bit XOR operation, y1 0 and rk0, and y1 in 8-bit XOR operation. 1 This section explains the case where an XOR operation is performed between y1 and rk1. However, by using a multi-wavelength light source, it is possible to perform other 6-bit XOR operations (y1 2 XOR operation with rk2, y1 5 XOR operation with rk5, y1 6 XOR operation with rk6, y1 7 and rk7) or other 8-bit XOR operation (y1 3 XOR operation with rk3, y1 4and rk4) can be realized.
[0066] Implementation example (A): An implementation method that expresses bits by the amplitude (or intensity) of light This section explains an implementation example in which the amplitude (or intensity) of an optical signal is coded as a bit 1 or a bit 0. In this implementation example, a Y-gate circuit is used to superimpose the optical amplitudes, thereby achieving a 6-bit XOR operation or an 8-bit XOR operation.
[0067] An example of implementation of the optical arithmetic circuit 101 when performing a 6-bit XOR operation is shown in Fig. 13. Also, an example of implementation of the optical arithmetic circuit 101 when performing an 8-bit XOR operation is shown in Fig. 14.
[0068] 13, when performing a 6-bit XOR operation, optical operation circuit 101 is implemented with Y gate circuit 204 consisting of three stages using five Y gate circuits 301 to 305, and optical signals a7, b0, b7, c0, d0, and rk0 of equal amplitude are superimposed in phase (in-phase) by this Y gate circuit 204. Note that optical signals a7, b0, b7, c0, d0, and rk0 are output from light source 121.
[0069] At this time, the amplitude (or intensity) of the optical signal output from the Y gate circuit 204 increases by the amount of the optical signal corresponding to bit 1 that is superimposed. Note that, in order to superimpose two optical signals in phase, an adjustment phase shifter may be used on one of the paths of the Y gate circuit.
[0070] Therefore, the amplitude (or intensity) of the optical signal output from the Y gate circuit 204 is detected by the photodetector 103's photodetector unit 131, and the photoelectric converter 132 performs threshold processing on the detection result to output an electrical signal corresponding to bit 0 or 1. Homodyne detection can be used to detect the amplitude of the optical signal, and direct detection can be used to detect the intensity.
[0071] In the threshold processing of the photoelectric conversion unit 132, an electrical signal corresponding to bit 0 or 1 is output depending on how many times the amplitude (or intensity) of the optical signal detected by the photodetection unit 131 corresponds to the amplitude (or intensity) when a single optical signal corresponding to bit 1 is detected by the photodetection unit 131. That is, for example, the photoelectric conversion unit 132 stores in advance in the memory 104 information that associates the following multiples with bit values (that is, information that associates 0 with an even multiple (including 0) and 1 with an odd multiple).
[0072] 6 times → 0 5 times → 1 4x → 0 3x → 1 2x → 0 1x → 1 0 times → 0 The photoelectric conversion unit 132 then determines how many times the amplitude (or intensity) of the optical signal detected by the optical detection unit 131 is multiplied by the amplitude (or intensity) of a single optical signal corresponding to bit 1, and outputs a bit value corresponding to that multiple. 0 and rk0 (the result of a 6-bit XOR operation), and is stored in the memory 104. Note that in this implementation example, unlike implementation examples (B) and (C) described later, there is no need to perform photoelectric conversion when calculating the bit value represented by the optical signal output from the Y gate circuit 204.
[0073] 14, when performing an 8-bit XOR operation, optical operation circuit 101 is implemented by Y gate circuit 205 consisting of three stages using seven Y gate circuits 401 to 407, and optical signals a0, a7, b0, b1, b7, c1, d1, and rk1 of equal amplitude are superimposed in phase (in-phase) by this Y gate circuit 205. Note that optical signals a0, a7, b0, b1, b7, c1, d1, and rk1 are output from light source 121.
[0074] At this time, similar to the 6-bit XOR operation, the amplitude (or intensity) of the optical signal output from the Y gate circuit 205 increases by the amount of the optical signal corresponding to bit 1 that is superimposed. Therefore, similar to the 6-bit XOR operation, the amplitude (or intensity) of the optical signal output from the Y gate circuit 205 is detected by the photodetector 131 of the photodetector 103, and the photoelectric conversion unit 132 performs threshold processing on the detection result to output an electrical signal corresponding to bit 0 or 1. Note that in the threshold processing, similar to the 6-bit XOR operation, it is determined that an even multiple (including 0) is 0 and an odd multiple is 1. This bit value is y1 1 and rk1 (the result of an 8-bit XOR operation), and is stored in the memory 104.
[0075] Implementation example (B): Implementation method that expresses bits by the phase difference of light (using a phase modulator) We will explain an implementation example in which a phase modulator (PM) is used to encode bits 1 and 0 based on the phase difference between two lights.
[0076] FIG. 15 shows an example of an implementation of the optical arithmetic circuit 101 for performing a 6-bit XOR operation. As shown in FIG. 15, six PMs 206-1 to 206-6 are connected in series, and the optical arithmetic circuit 101 is implemented so that the optical signal from the light source 121 is split and output to PM 206-1 and the optical detection unit 131. Because the inputs to PMs 206-1 to 206-6 are electrical signals, the optical arithmetic circuit 101 also implements an opto-electrical converter 207 for converting the optical signals a7, b0, b7, c0, d0, and rk0 into electrical signals. Furthermore, an electronic circuit 105 is implemented that receives an electrical signal from the optical detector 103 and performs bit determination. The optical signal output to PM 206-1 (the optical signal at the top of the figure) is called the input light, and the optical signal directly output to the optical detection unit 131 (the optical signal at the bottom of the figure) is called the reference light.
[0077] At this time, each of PMs 206-1 to 206-6 shifts the phase of the input light by π when the value of the electrical signal input to it is 1, and outputs the input light as is when the value of the electrical signal input to it is 0. As a result, if an even number (including 0) of a7, b0, b7, c0, d0, and rk0 are 1, the phase difference between the input light and the reference light is 0, and if an odd number are 1, the phase difference between the input light and the reference light is π. For example, if there are two 1 bits among a7, b0, b7, c0, d0, and rk0, the phase of the input light is 2π, and the phase difference with the reference light is 0. On the other hand, if there are three 1 bits, for example, the phase of the input light is 3π, and the phase difference with the reference light is π.
[0078] Therefore, the photodetector 103 detects the phase difference between the input light and the reference light by homodyne detection (or heterodyne detection), and outputs a voltage -V from the photoelectric conversion unit 132 when the phase difference is detected to be 0, or a voltage V when the phase difference is detected to be π. The electronic circuit 105 then performs a bit decision to output 0 when the voltage -V is input, or 1 when the voltage V is input, and outputs an electrical signal representing the decision result. The value represented by this electrical signal is y1 0 and rk0 (6-bit XOR result), and is stored in the memory 104. Note that the optical detection unit 131 can also detect the optical signal by heterodyne detection, but in that case, it is necessary to use reference light that is slightly shifted in phase from the input light.
[0079] 16, it is also possible to implement an optical arithmetic circuit 101 that performs a 6-bit XOR operation without using reference light. In this implementation example, PMs 208-1 to 208-3 are arranged on the upper side and PMs 208-4 to 208-6 are arranged on the lower side, and input light from a light source 121 is split into two. Also, a photoelectric converter 209-1 for converting optical signals a7, b0, and b7 into electrical signals, and a photoelectric converter 209-2 for converting optical signals c0, d0, and rk0 into electrical signals are implemented. In this implementation example, similar to the implementation example shown in FIG. 15, each of PMs 208-1 to 208-6 shifts the phase of the input light by π when the value of the electrical signal input to it is 1, and outputs the input light as is when the value of the electrical signal input to it is 0. As a result, similar to the implementation example shown in FIG. 15, the photodetector 103 detects whether the phase difference is 0 or π, and adjusts y1 according to the detection result. 0 and rk0 (the result of a 6-bit XOR operation), an electrical signal representing the result of the XOR operation is output from the electronic circuit 105. Note that the implementation example shown in Fig. 16 has an advantage of shorter signal delay compared to the implementation example shown in Fig. 15.
[0080] 17 shows an example of the implementation of the optical arithmetic circuit 101 when performing an 8-bit XOR operation. The implementation example shown in FIG. 17 is an extension of the implementation example shown in FIG. 15 to an 8-bit XOR operation, in which eight PMs 210-1 to 210-8 are connected in series, and a photoelectric converter 211 for converting optical signals a0, a7, b0, b1, b7, c1, d1, and rk1 into electrical signals is implemented in the optical arithmetic circuit 101. Other points are the same as the implementation example shown in FIG. 15. As a result, in the implementation example shown in FIG. 17, the photodetector 103 detects whether the phase difference is 0 or π, and y1 is calculated according to the detection result. 1 An electrical signal representing the result of the XOR operation between rk1 and rk2 (the result of the 8-bit XOR operation) is output from the electronic circuit 105.
[0081] 18, it is also possible to implement an optical arithmetic circuit 101 that performs an 8-bit XOR operation without using reference light. This implementation example is an extension of the implementation example shown in FIG. 16 to an 8-bit XOR operation, with PMs 212-1 to 212-4 arranged on the upper side and PMs 212-5 to 212-8 arranged on the lower side, and includes a photoelectric converter 213-1 for converting optical signals a0, a7, b0, and b1 into electrical signals, and a photoelectric converter 213-2 for converting optical signals b7, c1, d1, and rk1 into electrical signals. Other points are the same as in the implementation example shown in FIG. 16. As a result, in the implementation example shown in FIG. 18 as well, the photodetector 103 detects whether the phase difference is 0 or π, and y1 is calculated according to the detection result. 1 An electrical signal representing the result of the XOR operation between rk1 and rk2 (the result of the 8-bit XOR operation) is output from the electronic circuit 105.
[0082] 16, a 6-bit XOR operation may be realized by the implementation example shown in FIG. 19. In the implementation example shown in FIG. 19, compared to the implementation example shown in FIG. 16, PM 208-7 that inputs an electrical signal representing bit 1 and a Y-gate circuit 214 that receives optical signal A output from PM 208-3 and optical signal B output from PM 208-7 as inputs are added. Furthermore, the optical detection unit 131 of the optical detector 103 detects the optical signal output from the Y-gate circuit 214 by direct detection, and the photoelectric conversion unit 132 outputs a voltage V when the intensity of the optical signal is equal to or greater than a certain threshold, and outputs a voltage 0 when the intensity is less than the threshold. The electronic circuit 105 performs a bit determination: 0 when a voltage 0 is input, and 1 when a voltage V is input, and outputs an electrical signal representing the determination result. The value represented by this electrical signal is y1 0 and rk0 (the result of a 6-bit XOR operation), and is stored in the memory 104.
[0083] In this implementation example, the input light passing through the lower path always has a phase shift of π at PM 208-7. Therefore, the intensity of the input light obtained by superimposing input light A and input light B at Y gate circuit 214 corresponds to the result of the 6-bit XOR operation of a7, b0, b7, c0, d0, and rk0.
[0084] For example, when (a7, b0, b7, c0, d0, rk0) = (1, 1, 1, 1, 1, 1), the phase difference between input light A and input light B is π. Therefore, when input light A and input light B are superimposed in Y gate circuit 214, the intensity of the optical signal output from Y gate circuit 214 becomes 0. Therefore, a voltage of 0 is output from photodetector 103, and finally, an electrical signal representing bit 0 is output from electronic circuit 105.
[0085] As another example, if (a7, b0, b7, c0, d0, rk0) = (1, 0, 0, 1, 1, 0), the phase difference between input light A and input light B is 0. Therefore, when input light A and input light B are superimposed in Y gate circuit 214, the intensity of the optical signal output from Y gate circuit 214 is twice that of the original input light. Therefore, voltage V is output from photodetector 103, and finally, an electrical signal representing bit 1 is output from electronic circuit 105.
[0086] 18, an 8-bit XOR operation may be realized by the implementation example shown in FIG. 20. In the implementation example shown in FIG. 20, compared to the implementation example shown in FIG. 18, PM212-9 that inputs an electrical signal representing bit 1 and Y-gate circuit 215 that receives optical signal A output from PM212-4 and optical signal B output from PM212-9 are added. As in the implementation example shown in FIG. 19, the optical detection unit 131 of the optical detector 103 detects the optical signal output from the Y-gate circuit 214 by direct detection, and the photoelectric conversion unit 132 outputs a voltage V when the intensity of the optical signal is equal to or greater than a certain threshold, and outputs a voltage 0 when the intensity is less than the threshold. The electronic circuit 105 performs a bit determination: 0 when a voltage 0 is input, and 1 when a voltage V is input, and outputs an electrical signal representing the determination result. The value represented by this electrical signal is y1 1 and rk1 (the result of an 8-bit XOR operation), and is stored in the memory 104.
[0087] In this way, even with the method of using direct detection in the photodetector 103, it is possible to realize 6-bit XOR operations and 8-bit XOR operations.
[0088] Implementation example (C): Implementation method to express bits by optical paths (using MZI circuits) This section explains how to express bits 1 and 0 using MZI circuits.
[0089] 21 shows an example of implementation of the optical arithmetic circuit 101 when performing a 6-bit XOR operation. As shown in Fig. 21, six MZI circuits 216-1 to 216-6 are connected in series, and the optical arithmetic circuit 101 is implemented so that an optical signal from the light source 121 is input to the upper optical signal port of the MZI circuit 216-1. Furthermore, because the input to the path control port of each of the MZI circuits 216-1 to 216-6 is an electrical signal, the optical arithmetic circuit 101 also implements an opto-electrical converter 217 for converting the optical signals a7, b0, b7, c0, d0, and rk0 into electrical signals. Furthermore, the optical signal output from the lower optical signal port of the MZI circuit 216-6 is implemented so that it is input to the photodetector 103.
[0090] In this case, if an even number (including 0) of a7, b0, b7, c0, d0, and rk0 are bit 1, the optical signal from the light source 121 is output from the upper optical signal port of the MZI circuit 216-6. On the other hand, if an odd number are bit 1, the optical signal from the light source 121 is output from the lower optical signal port of the MZI circuit 216-6. Therefore, when the optical detection unit 131 detects an optical signal, the optical detector 103 outputs an electrical signal representing bit 1 from the photoelectric conversion unit 132, and when the optical detection unit 131 does not detect an optical signal, the optical detector 103 outputs an electrical signal representing bit 0 from the photoelectric conversion unit 132. The value represented by this electrical signal is y1 0 and rk0 (the result of a 6-bit XOR operation), and is stored in the memory 104.
[0091] An example implementation of the optical arithmetic circuit 101 for performing an 8-bit XOR operation is shown in Fig. 22. As shown in Fig. 22, eight MZI circuits 218-1 to 218-8 are connected in series, and the optical arithmetic circuit 101 is implemented so that an optical signal from the light source 121 is input to the upper optical signal port of the MZI circuit 218-1. Furthermore, because the input to the path control port of each of the MZI circuits 218-1 to 218-8 is an electrical signal, the optical arithmetic circuit 101 also implements an opto-electrical converter 219 for converting the optical signals a0, a7, b0, b1, b7, c1, d1, and rk1 into electrical signals. Furthermore, the optical signal output from the lower optical signal port of the MZI circuit 218-8 is implemented so that it is input to the photodetector 103.
[0092] 21, if an even number (including 0) of a0, a7, b0, b1, b7, c1, d1, and rk1 are 1 bits, the optical signal from the light source 121 is output from the upper optical signal port of the MZI circuit 218-8. On the other hand, if an odd number are 1 bits, the optical signal from the light source 121 is output from the lower optical signal port of the MZI circuit 218-8. Therefore, if the optical detection unit 131 detects an optical signal, the optical detector 103 outputs an electrical signal representing 1 bit from the photoelectric conversion unit 132, and if the optical detection unit 131 does not detect an optical signal, the optical detector 103 outputs an electrical signal representing 0 bit from the photoelectric conversion unit 132. If the value represented by this electrical signal is y1 1 and rk1 (the result of an 8-bit XOR operation), and is stored in the memory 104.
[0093] Moreover, as an example of implementation of the optical arithmetic circuit 101 when performing a 6-bit XOR operation, it is also possible to use the implementation example shown in Fig. 23. The implementation example shown in Fig. 23 is an implementation example when realizing a 6-bit XOR operation using a two-input port MZI circuit.
[0094] 23, three two-input port MZI circuits 220-1 to 220-3 are connected in series, and the optical arithmetic circuit 101 is implemented so that an optical signal from the light source 121 is input to the lower optical signal port of the two-input port MZI circuit 220-1. Furthermore, since the input to the route control port of each of the two-input port MZI circuits 220-1 to 220-3 is an electrical signal, an opto-electrical converter 221-1 for converting the optical signals a7, b7, and d0 into an electrical signal, and an opto-electrical converter 221-2 for converting the optical signals b0, c0, and rk0 into electrical signals are implemented in the optical arithmetic circuit 101. Furthermore, the optical signal output from the lower optical signal port of the two-input port MZI circuit 220-3 is implemented so that it is input to the photodetector 103.
[0095] In this case, if an even number (including 0) of a7, b0, b7, c0, d0, and rk0 are 1 bits, the optical signal from the light source 121 is output from the upper optical signal port of the two-input port MZI circuit 220-3. On the other hand, if an odd number are 1 bits, the optical signal from the light source 121 is output from the lower optical signal port of the two-input port MZI circuit 220-3. Therefore, as in the implementation example shown in FIG. 21, y1 0 and rk0 (6-bit XOR operation). In this implementation example, the number of MZI circuits can be reduced compared to the implementation example shown in Fig. 21, which has the advantage of reducing the operation delay and the circuit area.
[0096] Similarly, an example of implementation of the optical arithmetic circuit 101 when performing an 8-bit XOR operation can be the implementation example shown in Fig. 24. The implementation example shown in Fig. 24 is an example of implementation when an 8-bit XOR operation is realized using a two-input port MZI circuit.
[0097] 24, four two-input port MZI circuits 222-1 to 222-4 are connected in series, and the optical arithmetic circuit 101 is implemented so that an optical signal from the light source 121 is input to the upper optical signal port of the two-input port MZI circuit 222-1. Furthermore, since the input to the path control port of each of the two-input port MZI circuits 222-1 to 222-4 is an electrical signal, an opto-electrical converter 223-1 for converting the optical signals a0, b0, b7, and d1 into an electrical signal, and an opto-electrical converter 223-2 for converting the optical signals a7, b1, c1, and rk1 into electrical signals are implemented in the optical arithmetic circuit 101. Furthermore, the optical signal output from the lower optical signal port of the two-input port MZI circuit 222-4 is implemented so that it is input to the photodetector 103.
[0098] 22, if an even number of a0, a7, b0, b1, b7, c1, d1, and rk1 are 1 bits, the optical signal from the light source 121 is output from the upper optical signal port of the two-input port MZI circuit 222-4. On the other hand, if an odd number of bits are 1 bits, the optical signal from the light source 121 is output from the lower optical signal port of the two-input port MZI circuit 222-4. Therefore, if the optical detection unit 131 detects an optical signal, the optical detector 103 outputs an electrical signal representing a 1 bit from the photoelectric conversion unit 132, and if the optical detection unit 131 does not detect an optical signal, the optical detector 103 outputs an electrical signal representing a 0 bit from the photoelectric conversion unit 132. If the value represented by this electrical signal is y1 1 and rk1 (the result of an 8-bit XOR operation), and is stored in the memory 104. This implementation also has the advantage that the number of MZI circuits can be reduced compared to the implementation example shown in Fig. 22, and therefore the operation delay can be reduced and the circuit area can also be reduced.
[0099] The above implementation examples (A), (B), and (C) are summarized in Figure 25. As shown in Figure 25, implementation example (A) uses a Y-gate circuit, implementation example (B) uses a PM, and implementation example (C) uses an MZI circuit, and all of them use optical signals as input, but implementation example (A) does not require photoelectric conversion.
[0100] <<Example of the entire implementation of the data calculation section>> Above, we have explained an example of an implementation that uses optical processing to achieve one round of the AES data calculation unit. An example of the implementation of the entire AES data calculation unit is shown in Figure 26. In this case, the switching of the calculation timing of the data calculation unit (i.e., determining the timing to enter the next round processing) is managed by a clock, and the length of one clock is set to be sufficiently longer than the calculation time for all 128-bit optical paths. Note that in the figure, R represents the number of rounds.
[0101] As shown in Figure 26, AddRoundKey (XOR operation with the initial key) when R=1 is implemented using one of implementation examples (A), (B)-1, or (B)-2. In implementation example (A), the plaintext and initial key are input as optical signals, and an XOR operation with the initial key is performed. In implementation example (B)-1, the plaintext is input as an optical signal and the initial key is input as an electrical signal, and an XOR operation with the initial key is performed. In implementation example (B)-2, the plaintext and initial key are input as electrical signals, and an XOR operation with the initial key is performed. SubBytes is implemented using an MZI circuit (an optical pass gate logic circuit in which MZI circuits are connected in multiple stages), and ShiftRows is implemented using a hardwired connection (changing the wiring connections). AddRoundKey with MixColumns and a round key is implemented using one of implementation examples (A), (B), or (C).
[0102] SubBytes and ShiftRows are repeated 10 times for R = 1 to 10. Meanwhile, AddRoundKey using MixColumns and the round key is repeated 9 times for R = 1 to 9. Because MixCoulumns is not calculated at R = 10 (the final round), AddRoundKey when R = 10 is implemented using either implementation example (A) or (B)-1. This performs an XOR operation on the round key for the final round and the intermediate data. Note that implementation example (A) or (B)-1 can be used depending on whether the round key is stored in an optical state or electrically. The calculation result using AddRoundKey when R = 10 becomes the encryption result (electrical signal).
[0103] <Key schedule part> The following describes a method for implementing the operations of the key schedule section using optical arithmetic processing when the secret key is 128 bits. Note that the same method can be used to implement the cases where the secret key is 192 bits or 256 bits.
[0104] In the key schedule section, the secret key (128 bits) is divided into four blocks of 32 bits each, and operations are performed. This arithmetic processing is composed of RotWord, SubWord, Rcon, and the XOR operation with intermediate values (Reference 1). At this time, it does not matter whether the secret key (initial key) is held electrically or in the state of light.
[0105] The following describes the method regarding determining the bit value by the amplitude of light.
[0106] ·RotWord This process divides four 32-bit blocks into 8 bits each and performs a left 8-bit rotation. Therefore, similar to ShiftRows, when the secret key or the round key of the previous stage is held in the state of light, it is implemented by changing the connection of the wiring (optical signal line). When the secret key or the round key of the previous stage is held electrically, it is implemented by changing the connection of the electrical wiring.
[0107] ·SubWord This process applies SubBytes used when encrypting each block by 8 bits. Therefore, it is possible to use the optical path gate logic circuit of SubBytes using the MZI circuit. When the initial key is held electrically and the output of RotWord is an electrical signal, the input of SubBytes is also an electrical signal as it is. On the other hand, when the initial key is held in the state of light and the output of RotWord is an optical signal, it needs to be converted into an electrical signal by photoelectric conversion and then input to SubBytes.
[0108] ·XOR operation between Rcon and intermediate value Let the j-th (0 < j < 12) Rcon be Rcon j Each Rcon jis a fixed 32-bit value with four blocks of 8 bits each. Here, let w3' be the SubWord output of the initial round of the key schedule. Note that w3' is 32 bits.
[0109] In this case, an implementation example for realizing 1-bit XOR operation in the initial round is shown in Figure 27. Note that i (0≦i≦31) represents the bit position, for example, w 3,i 'is the bit value of bit position i of w3', Rcon 1,i Let w denote the bit value at bit position i of Rcon1. 4,i Yay 5,i The same applies to the following:
[0110] 27, the optical operational circuit 101 is implemented by serially connected MZI circuits 224-1 to 224-5, directional couplers 225-1 to 225-4, an opto-electric converter 226, and amplifiers 227-1 to 227-5. 3,i If '=0, the upper optical signal port of the MZI circuit 224-1, 3,i If w′=1, the light source 121 emits light so that an optical signal is input to the lower optical signal port of the MZI circuit 224-1. 3,i When w ′=0, no optical signal is input to the lower optical signal port of the MZI circuit 224-1, and 3,i When '=1, no optical signal is input to the upper optical signal port of the MZI circuit 224-1.
[0111] In addition, the routing control ports of the MZI circuits 224-1 to 224-5 are 1,i , w 0,i , w 1,i , w 2,i , w 3,i are input respectively.
[0112] The directional coupler 225-1 splits the optical signal output from the lower optical signal port of the MZI circuit 224-2, and outputs one of the split optical signals to the photoelectric converter 226. Similarly, the directional coupler 225-2 splits the optical signal output from the upper optical signal port of the MZI circuit 224-3, the directional coupler 225-3 splits the optical signal output from the lower optical signal port of the MZI circuit 224-4, and the directional coupler 225-4 splits the optical signal output from the upper optical signal port of the MZI circuit 224-5, and outputs one of the split optical signals to the photoelectric converter 226. That is, the directional couplers are arranged alternately, such as the lower optical signal port, the upper optical signal port, and the lower optical signal port. The split ratio when splitting the optical signal may be set arbitrarily.
[0113] Furthermore, the amplitude is amplified by amplifiers 227-1 to 227-4 to generate an electrical signal that can control the path of the MZI circuit in the next round. Furthermore, because the amplitude attenuates due to the division of the optical signal, the amplitude is amplified by amplifier 227-5. However, amplifiers 227-1 to 227-5 are not essential, and if the decrease in amplitude can be ignored, all or some of amplifiers 227-1 to 227-5 may be omitted.
[0114] At this time, the output from the upper optical signal port of the MZI circuit 224-1 is w 3,i ' and Rcon 1,i The electric signal w output from the photoelectric converter 226 and passed through the amplifiers 227-1 to 227-4 corresponds to an XOR operation. 4,i , w 5,i , w 6,i , w 7,i becomes the input to the routing control port of the MZI circuit of the next round. On the other hand, the optical signal w 7,i becomes the input to the next round, and this optical signal w 7,i Depending on whether the value of is 0 or 1, the optical signal from the light source 121 in the next round is input to either the upper or lower optical signal port of the first MZI circuit connected in series.
[0115] It is also possible to implement an optical signal output from the light source 121 using input light having five wavelengths (λ1, λ2, λ3, λ4, λ5). An example of this implementation is shown in Fig. 28. As shown in Fig. 28, the optical arithmetic circuit 101 is implemented by serially connected MZI circuits 228-1 to 228-5, filters 229-1 to 229-4, photoelectric converter 230, and amplifiers 231-1 to 231-4. In this case, w 3,i If '=0, the upper optical signal port of the MZI circuit 228-1, 3,i If w′=1, the light source 121 is caused to emit light so that an optical signal is input to the lower optical signal port of the MZI circuit 228-1. 3,i When '=0, no optical signal is input to the lower optical signal port of the MZI circuit 228-1, and w 3,i When '=1, no optical signal is input to the upper optical signal port of the MZI circuit 228-1.
[0116] In addition, the routing control ports of the MZI circuits 228-1 to 228-5 are 1,i , w 0,i , w 1,i , w 2,i , w 3,i are input respectively.
[0117] Filter 229-1 is a filter that uses a ring resonator or the like of wavelength λ1, and extracts only the optical signal of wavelength λ1 from the optical signal output from the lower optical signal port of MZI circuit 228-2, and outputs it to photoelectric conversion 230. Similarly, filter 229-2 is a filter that uses a ring resonator or the like of wavelength λ2, and extracts only the optical signal of wavelength λ2 from the optical signal output from the upper optical signal port of MZI circuit 228-3, and outputs it to photoelectric conversion 230. The same is true for filters 229-3 to 229-4, with filter 229-3 extracting only the optical signal of wavelength λ3 from the optical signal output from the lower optical signal port of MZI circuit 228-4, and filter 229-4 extracting only the optical signal of wavelength λ4 from the optical signal output from the upper optical signal port of MZI circuit 228-5, and outputting them to photoelectric conversion 230. Note that the filters are alternately arranged, such as the lower optical signal port, the upper optical signal port, and the lower optical signal port.
[0118] Furthermore, the amplitude is amplified by amplifiers 231-1 to 231-4 to generate electrical signals that can control the path of the MZI circuit in the next round. However, amplifiers 231-1 to 231-5 are not essential, and if the decrease in amplitude can be ignored, all or some of amplifiers 231-1 to 231-5 may be omitted. Note that in the implementation example shown in Fig. 28, the optical signal is not split, so there is almost no attenuation of the optical signal, and it is possible to eliminate the need for amplifiers to amplify the amplitude of the optical signal.
[0119] At this time, the output from the upper optical signal port of the MZI circuit 228-1 is w 3,i ' and Rcon 1,i The electric signal w output from the photoelectric converter 230 and passed through the amplifiers 231-1 to 231-4 corresponds to an XOR operation. 4,i , w 5,i , w 6,i , w 7,i becomes the input to the routing control port of the MZI circuit in the next round. On the other hand, the final output optical signal w 7,i becomes the input to the next round, and this optical signal w 7,i Depending on whether the value of is 0 or 1, the optical signal from the light source 121 in the next round is input to either the upper or lower optical signal port of the first MZI circuit connected in series.
[0120] By repeatedly executing the calculations according to the implementation example shown in FIG. 27 or FIG. 28 for i=0, . . . , 31, 128-bit (w4, w5, w6, w7) is calculated. Also, the implementation example shown in FIG. 27 or FIG. 28 may be implemented in parallel to calculate 128-bit (w4, w5, w6, w7) by repeating it less than 32 times. In the next round, (w8, w9, w 10 ,w 11 ) is calculated, and in the next round (w 12 ,w 13 ,w 14 ,w 15 ) is calculated, and so on for subsequent rounds.
[0121] The key schedule part can be calculated by repeating the XOR operation of RotWord, SubWord, Rcon and the intermediate value for 10 rounds.
[0122] Above, we have explained an implementation example that realizes one round of the key schedule part of AES using optical computation processing. An implementation example of the entire key schedule part of AES is shown in Figure 29. As shown in Figure 29, when generating round keys, either (1) or (2) is performed. In (1), the private key or the round key of the previous round is held in an optical state, and opto-electrical conversion from an optical signal to an electrical signal is required between RotWord and SubWord. On the other hand, in (2), the private key or the round key of the previous round is held electrically.
[0123] <Summary> As described above, the optical operation circuit 101 of the encryption device 10 according to this embodiment is implemented using a Y-gate circuit, an optical switching circuit, etc., and can realize XOR operations, multi-stage XOR operations, and nonlinear operations through optical operation processing (particularly, multi-stage XOR operations and nonlinear operations that have been difficult to perform in the past). Therefore, the optical encryption operation unit 111 and the optical operation control unit 112 of the encryption device 10 according to this embodiment can realize cryptographic operations (encryption / decryption processes, authentication / verification processes, etc.) used in various encryption methods and authentication methods through optical operation processing. While the above embodiment has described a case where AES cryptographic operations are realized through optical operation processing by realizing XOR operations, multi-stage XOR operations, and nonlinear operations through optical operation processing, it goes without saying that the encryption device 10 according to this embodiment can also realize XOR operations, multi-stage XOR operations, and nonlinear operations of cryptographic operations of other encryption methods and authentication methods through optical operation processing.
[0124] The present invention is not limited to the above-described specifically disclosed embodiments, and various modifications, changes, and combinations with known technologies are possible without departing from the scope of the claims.
[0125] [References] Reference 1: Federal Information Processing Standards Publication 197 November 26, 2001 Announcing the ADVANCED ENCRYPTION STANDARD (AES) Reference 2: Shota Kita, Kengo Nozaki, Kenta Takata, Akihiko Shinya, Masaya Notomi, Ultrashort low-loss Ψ gates for linear optical logic on Si photonics platform, Communications Physics, volume 3, Article number: 33 (2020), 8pages. Reference 3: JP 2018-5825 A [Explanation of symbols]
[0126] 10 Cryptographic device 101 Optical calculation circuit 102 Optical transmitter 103 Photodetector 104 memory 111 Optical cryptographic calculation unit 112 Optical calculation control unit 121 Laser transmitter 122 Light source control unit 131 Light detection unit 132 Photoelectric conversion unit
Claims
1. The photonics-electronics convergence processor, which is made up of Y-gate circuits that superimpose optical signals, performing a cryptographic operation including a multi-stage exclusive OR operation on two or more bit values and a nonlinear operation on two or more bit values by optical operation processing; The photonics-electronics integrated processor is composed of a multi-stage Y gate circuit, The optical calculation process includes: An encryption system in which optical signals corresponding to each of the two or more bit values are input to the multi-stage Y gate circuit, and the intensity of the optical signals output from the multi-stage Y gate circuit is detected, thereby obtaining a bit value corresponding to the intensity as the result of a multi-stage exclusive OR operation on the two or more bit values.
2. A photonics-electronics convergence processor comprising a phase modulator that modulates the phase of an optical signal, performing a cryptographic operation including a multi-stage exclusive OR operation on two or more bit values and a nonlinear operation on two or more bit values by optical operation processing; the photonics-electronics convergence processor is configured with a plurality of phase modulators that π-modulate the phase of an optical signal according to a bit value; The optical calculation process includes: An encryption system in which an electrical signal corresponding to each of the two or more bit values and an optical signal are input to each of the plurality of phase modulators, and the phase of the optical signal output from the plurality of phase modulators is detected, thereby obtaining a bit value corresponding to the phase shift as the result of multi-stage exclusive OR operations on the two or more bit values.
3. A photonics-electronics convergence processor comprising an optical switching circuit that controls the path of an optical signal by an electrical signal, performing a cryptographic operation including a multi-stage exclusive OR operation on two or more bit values and a nonlinear operation on two or more bit values by optical operation processing; the photonics-electronics convergence processor is composed of a plurality of optical switching circuits connected in series, The optical calculation process includes: An encryption system in which an electrical signal corresponding to each of the two or more bit values and an optical signal are input to the plurality of optical switching circuits, and the optical signal output from a predetermined port of the plurality of optical switching circuits is detected, thereby obtaining a bit value corresponding to the intensity of the optical signal as the result of multi-stage exclusive OR operations on the two or more bit values.
4. The photonics-electronics convergence processor is composed of multi-stage optical switching circuits, The optical calculation process includes:
4. The cryptographic system according to claim 1, wherein an electrical signal corresponding to each of the two or more bit values and an optical signal representing each bit value constituting a bit string representing a predetermined conversion are input to the multi-stage optical switching circuit, and the bit value corresponding to the optical signal output from a predetermined port of the multi-stage optical switching circuit is the result of a nonlinear operation on a predetermined bit value included in the two or more bit values.
5. The photonics-electronics convergence processor, which is made up of Y-gate circuits that superimpose optical signals, performing a cryptographic operation including a multi-stage exclusive OR operation on two or more bit values and a nonlinear operation on two or more bit values by optical operation processing; The photonics-electronics integrated processor is composed of a multi-stage Y gate circuit, The optical calculation process includes: An encryption device that inputs optical signals corresponding to each of the two or more bit values into the multi-stage Y gate circuit, detects the intensity of the optical signals output from the multi-stage Y gate circuit, and determines the bit value corresponding to the intensity as the result of a multi-stage exclusive OR operation on the two or more bit values.
6. The photonics-electronics convergence processor, which is made up of Y-gate circuits that superimpose optical signals, performing a cryptographic operation including a multi-stage exclusive OR operation on two or more bit values and a nonlinear operation on two or more bit values by optical operation processing; The photonics-electronics integrated processor is composed of a multi-stage Y gate circuit, The optical calculation process includes: An encryption method comprising: inputting optical signals corresponding to each of the two or more bit values into the multi-stage Y gate circuit; detecting the intensity of the optical signals output from the multi-stage Y gate circuit; and determining the bit value corresponding to the intensity as the result of a multi-stage exclusive OR operation on the two or more bit values.
7. The photonics-electronics convergence processor is composed of a Y-gate circuit that superimposes optical signals. performing a cryptographic operation including a multi-stage exclusive OR operation on two or more bit values and a nonlinear operation on two or more bit values by optical operation processing; The photonics-electronics integrated processor is composed of a multi-stage Y gate circuit, The optical calculation process includes: A program that inputs optical signals corresponding to each of the two or more bit values to the multi-stage Y gate circuit, detects the intensity of the optical signal output from the multi-stage Y gate circuit, and sets the bit value corresponding to the intensity as a result of a multi-stage exclusive OR operation on the two or more bit values.
Citation Information
Patent Citations
Method and device for optical computing
JP1988113527A
Optical computing method
JP1988229436A
Nonlinear random series generator
JP1988294115A
Optical device and optical computer
JP2002098931A