Method and apparatus for implementing big number addition

By using multiple iterative operations in large number addition, using ADD and ADC instructions to process addition without carry and carry respectively, the problem of inefficient addition of large number in Montgomery domain multiplication is solved, and more efficient calculation is achieved.

WO2025035471A9PCT designated stage expired Publication Date: 2025-06-26SUNLUNE (SINGAPORE) PTE LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2023/113625
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-08-17
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

In Montgomery domain multiplication, implementing the addition of two larger numbers requires a lot of addition and carry addition operations, resulting in waste of hardware resources and reduced computing efficiency.

Method used

By using multiple iteration operations in large number addition, the first iteration uses the ADD instruction to perform addition without carry, and stores the carry value in the carry component; the other iterations use the ADC instruction to perform addition processing with carry value, and update the carry component.

Benefits of technology

It reduces unnecessary ADC operations, reduces the total number of overall computing instructions, improves computing efficiency, and improves the performance of large-number addition without increasing hardware resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023113625_26062025_PF_FP_ABST
    Figure CN2023113625_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a method and apparatus for implementing big number addition (ADD), applied to an ADD operation of two pieces of L-bit data. The ADD operation comprises multiple iterative operations. For ADD operations in the first iterative operation, an ADD instruction is used for each ADD operation, and carry values of the ADD operations are correspondingly stored in respective carry units, wherein the ADD operations have one-to-one correspondence to the carry units; and for ADD operations in the iterative operations other than the first iterative operation, an ADC instruction is used for each ADD operation, ADC operations implement ADD processing of carry values in carry units respectively corresponding to the ADC operations, and the carry values of the ADC operations are stored in the corresponding carry units, wherein the ADC operations have one-to-one correspondence to the ADD operations according to execution sequences in respective iterative operations.
Need to check novelty before this filing date? Find Prior Art

Description

A method and device for implementing large number addition Technical Field

[0001] The present application relates to, but is not limited to, large number arithmetic technology, and in particular to a method and device for implementing large number addition. Background Art

[0002] Zero-knowledge proofs (ZKPs) were proposed by S. Goldwasser, S. Micali, and C. Rackoff in the early 1980s. As a highly secure encryption technology, ZKPs hold broad application prospects in future information transmission. ZKPs involve a large number of finite field calculations, namely, addition, subtraction, and multiplication operations bounded by a very large prime number. To simplify the computational process and eliminate the most complex division and remainder calculations, related technologies typically convert values ​​from a finite field to a Montgomery field, where the corresponding addition, subtraction, multiplication, and squaring operations are performed. Finally, the results are transferred from the Montgomery field back to the corresponding finite field.

[0003] In practical applications, the modulus corresponding to the finite field, i.e., the prime number, is very large (more than several hundred bits). The corresponding Montgomery multiplication on a general-purpose 32-bit or 64-bit processor will truncate the multiplier and multiplicand into several 32-bit or 64-bit parts before performing decomposition calculations.

[0004] In the related art Montgomery multiplication, in order to achieve the addition of two large numbers, a large number of addition (ADD) and carry addition (ADC) operations need to be used. This will greatly increase hardware resources and the total number of overall calculation instructions, reducing calculation efficiency.

[0005] SUMMARY OF THE INVENTION

[0006] The present application provides a method and device for implementing large number addition, which can solve any of the above technical problems.

[0007] The present invention provides a method for implementing large number addition, which is applied to the addition operation of two L-bit data, wherein the addition operation includes multiple iterative operations; the method includes:

[0008] For the addition operation in the first iteration, each addition operation uses an ADD instruction, and the carry value of each ADD operation is stored in its respective carry unit; wherein, the ADD operation corresponds to the carry unit one by one; the ADD instruction implements the addition of two L-bit data without adding the carry bit;

[0009] For the addition operations in the remaining iterative operations except the first iterative operation, each addition operation adopts an ADC instruction, each ADC operation implements addition processing with a carry value in its corresponding carry component, and the carry value of each ADC operation is stored in the corresponding carry component; wherein the ADC operation and the ADD operation correspond one-to-one according to the execution order in their respective iterative operations; the ADC instruction implements the addition of two L-bit data with a carry bit.

[0010] In one exemplary embodiment, the large number addition includes an addition operation in a Montgomery field multiplication operation;

[0011] The storing the carry value of each ADD operation in the respective carry components respectively includes: in a first iteration operation of the Montgomery field multiplication operation, storing the carry value of each ADD operation in the respective carry components respectively;

[0012] The method of implementing the addition processing with the carry values ​​in the respective corresponding carry components includes: in the remaining iterative operations of the Montgomery field multiplication operation except the first iterative operation, using ADC operations to implement the addition processing with the carry values ​​in the respective corresponding carry components, and storing the carry value of each ADC operation in the corresponding carry component.

[0013] In an exemplary embodiment, the ADD operation includes an ADD0 operation, an ADD1 operation, an ADD2 operation, and an ADD3 operation in the order of execution; the ADC operation includes an ADC0 operation, an ADC1 operation, an ADC2 operation, and an ADC3 operation in the order of execution;

[0014] In the first iterative operation, the carry value of the ADD0 operation is correspondingly stored in the carry unit 0, the carry value of the ADD1 operation is correspondingly stored in the carry unit 1; the carry value of the ADD2 operation is correspondingly stored in the carry unit 2; and the carry value of the ADD3 operation is correspondingly stored in the carry unit 3;

[0015] In the remaining iterative operations except the first iterative operation, the carry value used by the ADC0 operation is the carry value stored in the carry component 0, and the carry value generated by the ADC0 operation is correspondingly stored in the carry component 0; the carry value used by the ADC1 operation is the carry value stored in the carry component 1, and the carry value generated by the ADC1 operation is correspondingly stored in the carry component 1; the carry value used by the ADC2 operation is the carry value stored in the carry component 2, and the carry value generated by the ADC2 operation is correspondingly stored in the carry component 2; the carry value used by the ADC3 operation is the carry value stored in the carry component 3, and the carry value generated by the ADC3 operation is correspondingly stored in the carry component 3.

[0016] In an exemplary embodiment, the Montgomery multiplication includes: implementing Montgomery multiplication of two M-bit data using an L-bit processor; wherein M is greater than L; and M varies according to the size of the finite field data selected by the algorithm.

[0017] An embodiment of the present application further provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute any of the above methods for implementing large number addition.

[0018] An embodiment of the present application further provides a computer device, including a memory and a processor, wherein the memory stores the following instructions that can be executed by the processor: for executing the steps of any of the above-mentioned methods for implementing large number addition.

[0019] The embodiment of the present application further provides a device for implementing large number addition, comprising: a first multiplexer, n carry components, a second multiplexer, and an ADD / ADC operation unit; n is an integer greater than 1; wherein,

[0020] An ADD / ADC operation unit is configured to perform addition operations on two L-bit data. In a first iterative operation, when performing an ADD operation, the instruction code carries out addition processing on the carry value of the value 0 from the first multiplexer, and the carry value of the ADD operation is output to the second multiplexer. In the remaining iterative operations except the first iterative operation, when performing an ADC operation, the instruction code carries out addition processing on the carry value from the first multiplexer, and the generated carry value is output to the second multiplexer. Different ADD / ADC operations are identified by corresponding instruction codes according to the order in which they are executed.

[0021] The second multiplexer is provided with an input terminal, n output terminals and a second control terminal, and is used to receive the carry value from the ADD / ADC operation unit from the input terminal, select the output terminal of the corresponding path according to the instruction code and output the carry value to the corresponding carry register under the control of the second control terminal.

[0022] a first multiplexer having n+1 input terminals, one output terminal, and a first control terminal, configured to select, according to the instruction code and under the control of the first control terminal, to output a carry value or a value 0 in a carry register connected to the input terminal of the corresponding path from the output terminal to the ADD / ADC operation unit;

[0023] Each carry component is used to store a carry value of an ADD / ADC operation corresponding to an instruction code.

[0024] In one exemplary embodiment, the large number addition includes an addition operation in a Montgomery field multiplication operation.

[0025] In an exemplary embodiment, the carry unit is a 1-bit register.

[0026] The present application also provides a device for implementing large number addition, which is used to implement an addition operation of two L-bit data, wherein the addition operation includes multiple iterative operations. The device includes: multiple ADD operation units, a carry component respectively corresponding to each ADD operation unit, and multiple ADC operation units corresponding to the ADD operation units; wherein,

[0027] An ADD operation unit is used to perform an ADD operation in a first iterative operation and store a carry value of the ADD operation in a carry component corresponding to the ADD operation unit;

[0028] The ADC operation unit is used to implement addition processing with the carry value in the carry component corresponding to the ADC operation unit in the remaining iterative operations except the first iterative operation, and store the generated carry value in the corresponding carry component.

[0029] In an exemplary embodiment, the large number addition includes an addition operation in a Montgomery field multiplication operation; the ADD operation unit includes 4, and the ADC operation unit includes 4; wherein,

[0030] The ADD operation unit is configured to perform an ADD operation in a first iteration of the Montgomery field multiplication operation, and store a carry value of the ADD operation in a carry component corresponding to the ADD operation unit;

[0031] The ADC operation unit is used to implement addition processing with a carry value in a carry component corresponding to the ADC operation unit in the remaining iterative operations except the first iterative operation of the Montgomery domain multiplication operation, and store the generated carry value in the corresponding carry component.

[0032] In an exemplary embodiment, the carry component is a 1-bit register.

[0033] In an exemplary embodiment, the ADD operation unit includes: a first ADD operation unit, a second ADD operation unit, a third ADD operation unit, and a fourth ADD operation unit identified in a sequential order of execution in the first iterative operation;

[0034] The first ADD operation unit is correspondingly provided with a first carry component, the second ADD operation unit is correspondingly provided with a second carry component, the third ADD operation unit is correspondingly provided with a third carry component, and the fourth ADD operation unit is correspondingly provided with a fourth carry component;

[0035] The ADC operation unit includes: a first ADC operation unit, a second ADC operation unit, a third ADC operation unit, and a fourth ADC operation unit, which are identified in the order of execution in the remaining iterative operations except the first iterative operation; wherein the first ADC operation unit corresponds to the first ADD operation unit, is configured to implement addition processing with a carry value in the corresponding first carry component, and store the carry value generated by itself in the corresponding carry component; the second ADC operation unit corresponds to the second ADD operation unit, is configured to implement addition processing with the carry value in the second carry component, and store the carry value generated by itself in the corresponding carry component; the third ADC operation unit corresponds to the third ADD operation unit, is configured to implement addition processing with the carry value in the third carry component, and store the carry value generated by itself in the corresponding carry component; and the fourth ADC operation unit corresponds to the fourth ADD operation unit, is configured to implement addition processing with the carry value in the fourth carry component, and store the carry value generated by itself in the corresponding carry component.

[0036] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the description, claims and drawings.

[0037] Summary of the Figures

[0038] The accompanying drawings are used to provide a further understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.

[0039] FIG1 is a schematic diagram of an implementation process of Montgomery multiplication in an embodiment of the present application;

[0040] FIG2 is a flow chart of a method for implementing large number addition in an embodiment of the present application;

[0041] FIG3 is a flow chart of a method for implementing addition in a Montgomery field multiplication operation according to an embodiment of the present application;

[0042] FIG4 is a schematic diagram of the composition structure of a first embodiment of a device for implementing large number addition in an embodiment of the present application;

[0043] FIG5 is a schematic diagram of the composition structure of a second embodiment of the apparatus for implementing large number addition in the embodiments of the present application.

[0044] Details

[0045] To make the purpose, technical solutions and advantages of this application more clear, the embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of this application can be combined with each other in any way.

[0046] To facilitate understanding of the present application, the present application will be described more fully below with reference to the accompanying drawings. The accompanying drawings provide embodiments of the present application. However, the present application may be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to make the disclosure of the present application more thorough and comprehensive.

[0047] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application pertains. The terms used herein in the specification of this application are for the purpose of describing specific embodiments only and are not intended to limit this application.

[0048] FIG1 is a schematic diagram illustrating an implementation process of a Montgomery multiplication in an embodiment of the present application. As shown in FIG1 , an L-bit processor implements Montgomery multiplication of two M-bit data, where M is greater than L. The embodiment shown in FIG1 is a 64-bit Montgomery multiplication operation on two 256-bit data. The implementation process, as shown in FIG1 , includes four iterations, each with the same structure. FIG1 only illustrates the first iteration. In FIG1 , each minimum rectangle represents a 64-bit computation unit. Thus, each 256-bit data can be represented as four 64-bit computation units combined.

[0049] In Figure 1, the variable result represents the result of the operation and is initialized to all 0s at the beginning; the variable ptr_self represents the multiplicand (256 bits); the variable other represents the multiplier, which is actually 256 bits, but is actually divided into 4 iterations, each time processing 64 bits from low to high. Figure 1 shows the first iteration, so the variable other represents the low 64 bits of the multiplier; the variable po (320 bits) is the product of the multiplicand (256 bits) and a part of the multiplier (64 bits); the variable por (320 bits) is the sum of the variable po (320 bits) and the variable result (256 bits); the low 64 bits of the variable por are taken and multiplied by the constant INV (64 bits) to obtain the variable K (128 bits); the low 64 bits of the variable K are multiplied by the constant MODU (256 bits) to obtain the variable MK (320 bits); the high 256 bits of the variable MK are added to the high 256 bits of the intermediate variable por, and the result of the addition updates the variable result. In this way, the other bits of the multiplier are processed according to the same process as shown in Figure 1, each time 64 bits are processed. In this way, after four iterative operations, the value of the variable resule is two 256-bit data, which is the result of the Montgomery multiplication in 64-bit units.

[0050] In the program implementation of the Montgomery multiplication operation, in order to save temporary memory resources, the variable ptr_self is multiplied by the variable other, and the variable K is multiplied by the constant MODU at the same time. In the implementation process of this method, many calculations similar to: d = a + b + c will appear, where a and d are logically 128 bits, and b and c are 64 bits. The implemented calculation is uint128d = uint128a + uint64b + uint64c.

[0051] In a typical 64-bit computer architecture, there is no 128-bit computing component, so it is implemented through software, such as uint128_t a will be represented as uint128_t a[2]. Later, in an architecture with more instruction optimization, the code for d=a+b+c (the following four operations) can be implemented by combining the addition instruction ADD (the ADD instruction represents the addition of two numbers without adding a carry bit) and the addition with carry instruction ADC (the ADC operation represents the addition of two numbers with a carry bit):

[0052] ADD d[0],a[0],b / / Add the lower 64 bits of b and a, assign the result to d[0], and retain the carry;

[0053] ADC d[1],a[1],0 / / Add the carry bit to the high 64 bits of a and assign the result to d[1];

[0054] ADD d[0],d[0],c / / Add the lower 64 bits of c and d, and then assign the result to d[0] while retaining the carry;

[0055] ADC d[1],d[1],0 / / Add the carry bit to the high 64 bits of d, and then assign the result to d[1].

[0056] As can be seen from the code implementing d = a + b + c, the ADC operation only stores the carry information from the previous ADD or ADC operation. In other words, the carry bit input value for the current beat cannot store more information from earlier times. Therefore, an ADC operation is required after each ADD operation to handle the carry. If the carry is 0, the ADC operation is unnecessary. The addition of half the number of zero-addition operations actually makes the entire operation inefficient.

[0057] In conjunction with the embodiment shown in FIG1 , the Montgomery multiplication fragment can be expressed as:

[0058] The above Montgomery multiplication fragment can be expressed as follows using pseudo-assembly code, where there are two calculations of the form d = a + b + c, as shown in the bold and underlined font in the following code:

[0059] In the above assembly code, in order to perform 128-bit and 64-bit addition, a carry-add operation between the upper 64 bits and 0 must be added, i.e., ADC temp[1], temp[1], 0. However, if the carry is 0, the ADC operation is unnecessary, and the added ADC operation will reduce the efficiency of the entire operation. To reduce unnecessary ADC carry-add operations and the total number of overall computational instructions, the present embodiment proposes a method for implementing addition in Montgomery field multiplication, aiming to reduce the total number of overall computational instructions without significantly increasing hardware resources, thereby improving computational efficiency.

[0060] FIG2 is a flow chart of a method for implementing large number addition in an embodiment of the present application, which includes multiple iterative operations, each of which includes an addition operation on two L-bit data. As shown in FIG2 , the method may include:

[0061] Step 200: For the addition operations in the first iterative calculation, each addition operation uses an ADD instruction, and the carry value of each ADD operation is stored in its own carry component; wherein, the ADD operation corresponds to the carry component one to one.

[0062] In an exemplary embodiment, in a large number addition operation, in the first iterative operation, the participating ADD operations can be identified according to the order of execution. For example, according to the execution order of the ADD operations, the first ADD operation is identified as ADD0, the second ADD operation is identified as ADD1, the next ADD operation is identified as ADD2..., and the last ADD operation is identified as ADDn.

[0063] In an exemplary embodiment, in a large number addition operation, in the first iterative operation, each ADD operation involved corresponds to setting a carry unit for storing the carry value generated in the addition operation, for example: ADD0 corresponds to setting a carry unit 0, ADD1 corresponds to setting a carry unit 1, ADD2 corresponds to setting a carry unit 2..., ADDn corresponds to setting a carry unit n.

[0064] Step 201: For the addition operations in the remaining iterative operations except the first iterative operation, each addition operation adopts an ADC instruction, each ADC operation implements addition processing with a carry value in the corresponding carry component, and the carry value of each ADC operation is stored in the corresponding carry component; wherein, the ADC operation and the ADD operation correspond one to one according to the execution order in the respective iterative operations.

[0065] In an exemplary embodiment, in the large number addition operation, in the remaining iterative operations except the first iterative operation, the ADC operation is used instead of the ADD operation, that is, in the remaining iterative operations except the first iterative operation, the addition operation is implemented by the ADC instruction. Moreover, the ADC operations are identified according to the order of execution, for example, according to the execution order of the ADC operations: the first ADC operation is identified as ADC0, the second ADC operation is identified as ADC1, the next ADC operation is identified as ADC2..., and the last ADC operation is identified as ADCn; and ADC0 corresponds to ADD0, that is, the carry value used in the ADC0 operation is the carry value stored in the carry unit 0 corresponding to ADD0, and the carry value generated by the ADC0 operation is stored in the carry unit 0 correspondingly; ADC1 corresponds to ADD1, that is, ADC The carry value used in the ADC1 operation is the carry value stored in the carry unit 1 corresponding to ADD1, and the carry value generated by the ADC1 operation is correspondingly stored in the carry unit 1; ADC2 corresponds to ADD2, that is, the carry value used in the ADC2 operation is the carry value stored in the carry unit 2 corresponding to ADD2, and the carry value generated by the ADC2 operation is correspondingly stored in the carry unit 2; ...ADCn corresponds to ADDn, that is, the carry value used in the ADCn operation is the carry value stored in the carry unit n corresponding to ADDn, and the carry value generated by the ADCn operation is correspondingly stored in the carry unit n.

[0066] FIG3 is a flow chart of a method for implementing addition in a Montgomery field multiplication operation according to an embodiment of the present application. FIG3 shows a typical loop calculation process. A typical loop content, corresponding to a 256-bit processor corresponding to a 64-bit processor, requires four loops, as shown in FIG3 , which may include:

[0067] Step 300: In the first iteration of the Montgomery field multiplication operation, the carry value of each ADD operation is stored in the corresponding carry unit.

[0068] In an exemplary embodiment, taking the embodiment shown in Figure 1 as an example, in the first iteration operation of the Montgomery field multiplication operation, the ADD operations are identified in the order of execution. The first ADD operation is identified as ADD0, the second ADD operation is identified as ADD1, the next ADD operation is identified as ADD2, and the last ADD operation is identified as ADD3.

[0069] Each marked ADD operation is provided with a corresponding carry unit for storing the carry value generated in the addition operation. Still taking the embodiment shown in FIG1 as an example, ADD0 is provided with a carry unit 0, ADD1 is provided with a carry unit 1, ADD2 is provided with a carry unit 2, and ADD3 is provided with a carry unit 3. In other words, in the method for implementing addition in Montgomery field multiplication provided in the embodiment of the present application, the carry value of the ADD operation does not appear in the register involved in the operation, but is stored in a separate carry unit corresponding to the ADD operation.

[0070] In an illustrative example, each carry unit may be a 1-bit register.

[0071] In an exemplary embodiment, Montgomery multiplication may be: implementing Montgomery multiplication of two M-bit data by an L-bit processor; wherein M is greater than L. In one embodiment, the L-bit processor may be a 64-bit processor or a 32-bit processor; and the M-bit data may be 256-bit data. It should be noted that in the method for implementing addition provided in the embodiment of the present application, L includes but is not limited to 32bit, 64bit, 128bit, 256bit, etc. M includes but is not limited to 256, and M will vary depending on the size of the finite field data selected by the algorithm, ranging from tens of bits to thousands of bits. In one embodiment, for example, for a 384-bit finite field calculation, if a 64-bit processor is used, then the data involved in the calculation can be divided into 6 equal parts of 64-bit data.

[0072] Still taking the above-mentioned Montgomery multiplication fragment as an example, according to step 200 of the embodiment of the present application, the first iterative operation can be represented as follows using pseudo assembly code, where each ADD operation in the first iterative operation is shown in bold and underlined font:

[0073] From the first iterative operation after step 300, the carry addition operation of the upper 64 bits and 0, which must be added to perform the addition of 128 bits and 64 bits, is omitted. Instead, the carry value of each ADD operation is directly stored in the carry component corresponding to the ADD operation.

[0074] Step 301: In the remaining iterations of the Montgomery field multiplication operation except the first iteration, an ADC operation is used to implement addition processing with carry values ​​in the corresponding carry components, and the carry value of each ADC operation is stored in the corresponding carry component; wherein the ADC operation corresponds to the ADD operation one-to-one.

[0075] In an exemplary embodiment, taking the embodiment shown in FIG1 as an example, in the remaining iterative operations of the Montgomery domain multiplication operation except the first iterative operation, the ADC operation is used to implement the addition process, and the ADC operations are identified in the order of execution. The first ADC operation is identified as ADC0, which corresponds to ADD0 in the first iterative operation, that is, the carry value used in the ADC0 operation is the carry value stored in the carry unit 0 corresponding to ADD0, and the carry value generated by the ADC0 operation is correspondingly stored in the carry unit 0; the second ADC operation is identified as ADC1, which corresponds to ADD1 in the first iterative operation, that is, the carry value used in the ADC1 operation is The carry value stored in the carry component 1 corresponding to ADD1, and the carry value generated by the ADC1 operation is stored correspondingly in the carry component 1; the ADC operation that appears next is identified as ADC2, which corresponds to ADD2 in the first iterative operation, that is, the carry value used in the ADC2 operation is the carry value stored in the carry component 2 corresponding to ADD2, and the carry value generated by the ADC2 operation is stored correspondingly in the carry component 2; the ADC operation that appears next is identified as ADC3, which corresponds to ADD3 in the first iterative operation, that is, the carry value used in the ADC3 operation is the carry value stored in the carry component 3 corresponding to ADD3, and the carry value generated by the ADC3 operation is stored correspondingly in the carry component 3.

[0076] Still taking the above-mentioned Montgomery multiplication fragment as an example, according to step 301 of the embodiment of the present application, the remaining iterative operations except the first iterative operation can be represented as follows using pseudo assembly code. Each ADC operation in the remaining iterative operations except the first iterative operation is shown in bold and underlined font:

[0077] Taking ADC0temp[0], temp[0], result[1] in the above program as an example, the low-order addition with the carry value generated in the previous iteration is implemented, that is, the carry value stored in the carry component 0 is used as the carry input of the ADC0 operation to implement the addition with carry. At the same time, the carry value of this operation, that is, the carry value of the ADC0 operation, is stored in the carry component 0 corresponding to ADC0. In other words, the value in the carry component 0 will overwrite the carry value stored in the previous iteration and become the carry value generated in this iteration.

[0078] The method for implementing addition in the Montgomery domain multiplication operation provided in the embodiment of the present application eliminates unnecessary ADC operations. For example, there is no need to add a carry addition operation between the upper 64 bits and 0 in order to perform a 128-bit and 64-bit addition. This reduces the total number of overall calculation instructions and thereby improves calculation efficiency.

[0079] An embodiment of the present application further provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute any of the above methods for implementing large number addition.

[0080] An embodiment of the present application further provides a computer device, including a memory and a processor, wherein the memory stores the following instructions that can be executed by the processor: for executing the steps of any of the above-mentioned methods for implementing large number addition.

[0081] The present application also provides a device for implementing large number addition. In this embodiment, multiple ADD\ADC instructions correspond to one ADD / ADC operation unit. Figure 4 is a schematic diagram of the composition structure of the first embodiment of the device for implementing large number addition in the present application. As shown in Figure 4, it includes: a first multiplexer, n carry components (such as the carry register in Figure 4), a second multiplexer, and an ADD / ADC operation unit; n is an integer greater than 1; wherein,

[0082] An ADD / ADC operation unit is configured to perform addition operations on two L-bit data. In a first iterative operation, when performing an ADD operation, the instruction code carries out addition processing on the carry value of the value 0 from the first multiplexer, and the carry value of the ADD operation is output to the second multiplexer. In the remaining iterative operations except the first iterative operation, when performing an ADC operation, the instruction code carries out addition processing on the carry value from the first multiplexer, and the generated carry value is output to the second multiplexer. Different ADD / ADC operations are identified by corresponding instruction codes according to the order in which they are executed.

[0083] The second multiplexer is provided with an input terminal, n output terminals and a second control terminal, and is used to input a carry value from the ADD / ADC operation unit from the input terminal, select an output terminal of a corresponding path according to the instruction code and output the carry value to the corresponding carry register under the control of the second control terminal.

[0084] a first multiplexer having n+1 input terminals, one output terminal, and a first control terminal, and configured to select, according to the instruction code and under the control of the first control terminal, to output a carry value or a value 0 in a carry register connected to the input terminal of the corresponding path from the output terminal to the ADD / ADC operation unit;

[0085] Each carry component is used to store a carry value of an ADD / ADC operation corresponding to an instruction code.

[0086] In an exemplary embodiment, the large number addition includes an addition operation in a Montgomery field multiplication operation. In an embodiment, n=4.

[0087] In an exemplary embodiment, the carry register is a 1-bit register.

[0088] For example, the instruction code of the ADD1 instruction corresponds to carry register 1, and the instruction code of the ADC1 instruction also corresponds to carry register 1; the instruction code of the ADD2 instruction corresponds to carry register 2, and the instruction code of the ADC2 instruction also corresponds to carry register 2; ... the instruction code of the ADDn instruction corresponds to carry register n, and the instruction code of the ADCn instruction also corresponds to carry register n. For example: as shown in Figure 4, when the ADD / ADC operation unit performs the ADD1 operation on input a and input b, the second multiplexer selects the corresponding value 0 according to the instruction code and outputs it to the ADD / ADC operation unit; the ADD / ADC operation unit performs the ADD1 operation, outputs the carry value of the ADD1 operation to the first multiplexer, and stores the sum value, i.e., output c, into the corresponding target register; the first multiplexer outputs the carry value to the corresponding carry register 1 according to the instruction code. For another example: when the ADD / ADC operation unit performs the ADCn operation on inputs a and b, the second multiplexer selects the carry value in the corresponding carry register n according to the instruction code and outputs it to the ADD / ADC operation unit; the ADD / ADC operation unit performs the ADCn operation, outputs the carry value of the ADDn operation to the first multiplexer, and stores the sum value, i.e., output c, into the corresponding target register; the first multiplexer outputs the carry value to the corresponding carry register n according to the instruction code.

[0089] FIG5 is a schematic diagram of the structure of a second embodiment of the apparatus for implementing large number addition in an embodiment of the present application, which is used to implement the addition operation of two L-bit data included in multiple iterative operations. In this embodiment, each ADD / ADC instruction corresponds to an ADD / ADC operation unit, as shown in FIG5 , including: multiple ADD operation units, carry components respectively corresponding to each ADD operation unit, and multiple ADC operation units corresponding to the ADD operation units; wherein,

[0090] An ADD operation unit is used to perform an ADD operation in a first iterative operation and store a carry value of the ADD operation in a carry component corresponding to the ADD operation unit;

[0091] The ADC operation unit is used to implement addition processing with the carry value in the carry component corresponding to the ADC operation unit in the remaining iterative operations except the first iterative operation, and store the generated carry value in the corresponding carry component.

[0092] In an exemplary embodiment, the carry unit may be a 1-bit register.

[0093] In an exemplary embodiment, the ADD operation unit includes: a first ADD operation unit, a second ADD operation unit, a third ADD operation unit ... an nth ADD operation unit identified in a sequential execution order in a first iteration operation of the large number addition operation;

[0094] Correspondingly, the first ADD operation unit is correspondingly provided with a first carry component, the second ADD operation unit is correspondingly provided with a second carry component, the third ADD operation unit is correspondingly provided with a third carry component, the fourth ADD operation unit is correspondingly provided with a fourth carry component…the nth ADD operation unit is correspondingly provided with a third carry component, and the fourth ADD operation unit is correspondingly provided with an nth carry component;

[0095] Accordingly, the ADC operation unit includes: a first ADC operation unit, a second ADC operation unit, a third ADC operation unit, and a fourth ADC operation unit, which are identified in order of execution in the remaining iterations of the large number addition operation except the first iteration. The first ADC operation unit corresponds to the first ADD operation unit and is configured to perform addition processing with a carry value in a first carry component of the corresponding first ADD operation unit and store the carry value generated by itself in the corresponding carry component; the second ADC operation unit corresponds to the second ADD operation unit and is configured to perform addition processing with a carry value in a second carry component of the corresponding second ADD operation unit and store the carry value generated by itself in the corresponding carry component; the third ADC operation unit corresponds to the third ADD operation unit and is configured to perform addition processing with a carry value in a third carry component of the corresponding third ADD operation unit and store the carry value generated by itself in the corresponding carry component; ... the nth ADC operation unit corresponds to the nth ADD operation unit and is configured to perform addition processing with a carry value in a fourth carry component of the corresponding nth ADD operation unit and store the carry value generated by itself in the corresponding carry component.

[0096] In an exemplary embodiment, the large number addition may be an addition operation in a Montgomery domain multiplication operation. In this embodiment, the number of ADD operation units may be 4, and the number of ADC operation units may be 4; wherein,

[0097] An ADD operation unit may be configured to perform an ADD operation in a first iteration of a Montgomery field multiplication operation and store a carry value of the ADD operation in a carry component corresponding to the ADD operation unit;

[0098] The ADC operation unit can be used to implement addition processing with a carry value in a carry component corresponding to the ADC operation unit in the remaining iterative operations except the first iterative operation of the Montgomery field multiplication operation, and store the generated carry value in the corresponding carry component.

[0099] The device for implementing large number addition provided by the embodiment of the present application eliminates unnecessary ADC operations. For example, there is no need to add a carry addition operation between the upper 64 bits and 0 in order to perform 128-bit and 64-bit addition, thereby reducing the total number of overall calculation instructions. Compared with related technologies, only a small amount of hardware resources are required, thereby improving calculation efficiency.

[0100] Although the embodiments disclosed in this application are as described above, the contents described are merely embodiments adopted to facilitate understanding of this application and are not intended to limit this application. Any person skilled in the art to which this application belongs may make any modifications and changes in the form and details of the implementation without departing from the spirit and scope disclosed in this application. However, the scope of patent protection of this application shall still be based on the scope defined by the attached claims.

Claims

1. A method for implementing large number addition, including multiple iterative operations, comprising: For the addition operations in the first iterative operation, each addition operation uses an ADD instruction, and the carry values of each ADD operation are respectively stored in their respective carry components; wherein, the ADD operations and the carry components are in one-to-one correspondence; the ADD instruction implements the addition of two L-bit data without considering the carry bit. For the addition operations in the remaining iterative operations except the first iterative operation, each addition operation uses an ADC instruction, and each ADC operation implements the addition process with the carry value in its corresponding carry component, and stores the carry value of each ADC operation in the corresponding carry component; wherein, the ADC operations and the ADD operations are in one-to-one correspondence according to the execution order in their respective iterative operations; the ADC instruction implements the addition of two L-bit data with the carry bit.

2. The method according to claim 1, wherein, The large number addition includes the addition operation in the Montgomery domain multiplication operation. The step of respectively storing the carry values of each ADD operation in their respective carry components includes: in the first iterative operation of the Montgomery domain multiplication operation, respectively storing the carry values of each ADD operation in their respective carry components. The step of implementing the addition process with the carry value in its corresponding carry component includes: in the remaining iterative operations except the first iterative operation of the Montgomery domain multiplication operation, using the ADC operation to implement the addition process with the carry value in its corresponding carry component, and storing the carry value of each ADC operation in the corresponding carry component.

3. The method according to claim 2, wherein The ADD operations include ADD0 operation, ADD1 operation, ADD2 operation and ADD3 operation in the execution order; the ADC operations include ADC0 operation, ADC1 operation, ADC2 operation and ADC3 operation in the execution order. In the first iterative operation, the carry value of the ADD0 operation is correspondingly stored in the carry component 0, the carry value of the ADD1 operation is correspondingly stored in the carry component 1; the carry value of the ADD2 operation is correspondingly stored in the carry component 2; the carry value of the ADD3 operation is correspondingly stored in the carry component 3. In the remaining iterative operations except the first iterative operation, the ADC0 operation uses the carry value stored in the carry component 0, and the carry value generated by the ADC0 operation is correspondingly stored in the carry component 0; the carry value used by the ADC1 operation is the carry value stored in the carry component 1, and the carry value generated by the ADC1 operation is correspondingly stored in the carry component 1; the carry value used by the ADC2 operation is the carry value stored in the carry component 2, and the carry value generated by the ADC2 operation is correspondingly stored in the carry component 2; the carry value used by the ADC3 operation is the carry value stored in the carry component 3, and the carry value generated by the ADC3 operation is correspondingly stored in the carry component 3.

4. The method according to claim 3, wherein The Montgomery multiplication includes: implementing the Montgomery multiplication of two M-bit data through an L-bit processor; where M is greater than L; and M varies according to the size of the finite field data selected by the algorithm.

5. A computer-readable storage medium storing computer-executable instructions for executing the method for implementing large number addition according to any one of claims 1 to 4.

6. A computer device, comprising a memory and a processor, wherein, Instructions executable by a processor are stored in a memory: for performing the steps of the method for implementing large number addition according to any one of claims 1 to 4.

7. An apparatus for implementing large number addition, comprising: A first multiplexer, n carry components, a second multiplexer, and an ADD / ADC arithmetic unit; n is an integer greater than 1; where The ADD / ADC arithmetic unit is used for the addition operation of two L-bit data; in the first iteration operation, when performing the ADD operation, according to the instruction encoding, perform the addition process of the carry value of 0 from the first multiplexer, and output the carry value of the ADD operation to the second multiplexer; in the remaining iteration operations except the first iteration operation, when performing the ADC operation, according to the instruction encoding, perform the addition process of the carry value from the first multiplexer, and output the generated carry value to the second multiplexer; different ADD / ADC operations are identified with corresponding different instruction encodings according to the execution order. The second multiplexer is provided with an input terminal, n output terminals, and a second control terminal, and is used to receive the carry value from the ADD / ADC arithmetic unit at the input terminal, and according to the instruction encoding and the control of the second control terminal, select the output terminal of the corresponding path to output the carry value to the corresponding carry register. The first multiplexer is provided with n + 1 input terminals, 1 output terminal, and a first control terminal. It is used to select and output the carry value or the value 0 in the carry register connected to the input terminal of the corresponding path from the output terminal to the ADD / ADC arithmetic unit according to the instruction encoding and the control of the first control terminal. Each carry component is used to store the carry value of the ADD / ADC operation corresponding to the instruction encoding.

8. The apparatus according to claim 7, wherein The large number addition includes the addition operation in the Montgomery domain multiplication operation.

9. The device according to claim 7 or 8, wherein The carry component is a 1-bit register.

10. An apparatus for implementing large number addition, which is used to implement the addition operation of two L-bit data included in multiple iterative operations. The apparatus includes: Multiple ADD arithmetic units, carry components respectively corresponding to each ADD arithmetic unit, and multiple ADC arithmetic units corresponding to the ADD arithmetic units; where The ADD arithmetic unit is used to perform the ADD operation in the first iteration operation, and store the carry value of the ADD operation in the carry component corresponding to the ADD arithmetic unit. The ADC arithmetic unit is used to implement the addition process with the carry value in the carry component corresponding to the ADC arithmetic unit in the remaining iteration operations except the first iteration operation, and store the generated carry value in the corresponding carry component.

11. The apparatus according to claim 10, wherein, The large number addition includes the addition operation in the Montgomery domain multiplication operation; there are 4 ADD arithmetic units and 4 ADC arithmetic units; where The ADD operation unit is configured to perform an ADD operation in the first iteration operation of the Montgomery domain multiplication operation, and store the carry value of the ADD operation in the carry component corresponding to the ADD operation unit; The ADC operation unit is configured to perform an addition process with the carry value in the carry component corresponding to the ADC operation unit in the remaining iteration operations except the first iteration operation of the Montgomery domain multiplication operation, and store the generated carry value in the corresponding carry component.

12. The device according to claim 10 or 11, wherein The carry component is a 1-bit register.

13. The apparatus according to claim 11, wherein, The ADD operation unit includes: in the first iteration operation, a first ADD operation unit, a second ADD operation unit, a third ADD operation unit, and a fourth ADD operation unit identified in the order of execution; The first ADD operation unit is correspondingly provided with a first carry component, the second ADD operation unit is correspondingly provided with a second carry component, the third ADD operation unit is correspondingly provided with a third carry component, and the fourth ADD operation unit is correspondingly provided with a fourth carry component; The ADC operation unit includes: in the remaining iteration operations except the first iteration operation, a first ADC operation unit, a second ADC operation unit, a third ADC operation unit, and a fourth ADC operation unit identified in the order of execution; wherein, the first ADC operation unit corresponds to the first ADD operation unit, and is configured to perform an addition process with the carry value in the corresponding first carry component, and store the generated carry value in the corresponding carry component; the second ADC operation unit corresponds to the second ADD operation unit, and is configured to perform an addition process with the carry value in the second carry component, and store the generated carry value in the corresponding carry component; the third ADC operation unit corresponds to the third ADD operation unit, and is configured to perform an addition process with the carry value in the third carry component, and store the generated carry value in the corresponding carry component; the fourth ADC operation unit corresponds to the fourth ADD operation unit, and is configured to perform an addition process with the carry value in the fourth carry component, and store the generated carry value in the corresponding carry component.