Method and apparatus for implementing finite field operation, and storage medium

By using comparison and conditional operation instructions to generate flag bits in zero-knowledge proof, avoiding branch jumps, the processor inefficiency caused by modulo reduction operations in finite domain calculations is solved, and more efficient finite domain operations are achieved.

WO2025138208A1PCT designated stage expired Publication Date: 2025-07-03SUNLUNE (SINGAPORE) PTE LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2023/143544
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

The modular reduction operation of finite domain calculations in prior art in zero-knowledge proofs results in inefficient processors, ineffective branch prediction and degradation of performance.

Method used

The operation result is compared with the modulus to generate flag bits, and the branch jump is avoided through conditional operation instructions, and the operation is directly performed using 0 or modulus.

Benefits of technology

It improves the computing efficiency of the processor, reduces the execution of branch jump instructions, and improves the processing speed of finite domain operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2023143544_03072025_PF_FP_ABST
    Figure CN2023143544_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a method and apparatus for implementing a finite field operation, and a storage medium. The method comprises: respectively using two pieces of raw data participating in a finite field operation as two operands of a first operation instruction and generating a first operation result; when the operation is addition or Montgomery multiplication, using the first operation result and a modulus as two operands of a comparison instruction, and when the operation is subtraction, using the two pieces of raw data as two operands of the comparison instruction; on the basis of a comparison result, generating a first flag bit for indicating whether to enable a modulus operation; using the first operation result and the modulus as a first operand and a second operand of a conditional operation instruction; reading the first flag bit, when the first flag bit indicates enabling of the modulus operation, keeping the second operand unchanged, and when the first flag bit indicates disabling of the modulus operation, replacing the modulus with 0; and using the conditional operation instruction to perform an operation to generate a second operation result, and using the second operation result as a final result of the finite field operation.
Need to check novelty before this filing date? Find Prior Art

Description

Method, device and storage medium for implementing finite field operations Technical Field

[0001] This article relates to the field of cryptographic computing technology, and in particular to a method, device, and storage medium for implementing finite field operations. Background Art

[0002] Zero-Knowledge Proof (ZKP) is a cryptographic algorithm that can prove the correctness of a proposition without revealing any other information, thereby addressing privacy and scalability issues in communication. As a highly secure encryption technology, ZKP holds broad application prospects in future information transmission. ZKP involves a large number of finite field calculations, namely, addition, subtraction, and multiplication operations bounded by a very large prime number. However, within a finite field, after obtaining the direct calculation result, addition, subtraction, and multiplication must first determine whether the result is within a specified interval. If it is outside the specified interval, the result is adjusted to the specified interval through addition / subtraction of a modulus (the modulus is a very large prime number). This modular-based calculation process is called modular reduction.

[0003] In practical applications, since the data used in zero-knowledge proofs is relatively random, whether the modulus is added or subtracted during the modular reduction phase is random. To improve processor efficiency, computer architectures in related technologies often use past branch jump history to predict the current branch jump. However, for the modular reduction calculations in zero-knowledge proofs, this prediction is ineffective and may even be counterproductive. Therefore, given the computational characteristics of finite field zero-knowledge proofs, new solutions are needed to improve processor efficiency.

[0004] Summary of the Invention

[0005] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.

[0006] The present disclosure provides a method for implementing finite field operations, comprising:

[0007] Using two original data involved in the finite field operation as two operands of a first operation instruction, and performing an operation using the first operation instruction to generate a first operation result; wherein the operation includes: addition, subtraction, or Montgomery multiplication;

[0008] When the operation of the finite field is addition or Montgomery multiplication, the first operation result and the modulus are used as two operands of a comparison instruction; when the operation of the finite field is subtraction, the two original data are used as two operands of the comparison instruction; performing comparison using the comparison instruction, generating a first flag bit for indicating whether the modulus operation is enabled according to the comparison result, and storing the first flag bit in a first register;

[0009] The first operation result is used as the first operand of the conditional operation instruction, and the modulus is used as the second operand of the conditional operation instruction; the first flag bit is read from the first register, and when the first flag bit indicates that the modulus operation is enabled, the second operand is kept unchanged; when the first flag bit indicates that the modulus operation is not enabled, the modulus is replaced by 0 as the new second operand; the conditional operation instruction is used to perform an operation to generate a second operation result, and the second operation result is used as the final result of the finite field operation on the two original data.

[0010] The present disclosure provides a device for implementing finite field operations, comprising:

[0011] A first operation processing module is configured to use two original data involved in the finite field operation as two operands of a first operation instruction, and perform an operation using the first operation instruction to generate a first operation result; wherein the operation includes: addition, subtraction, or Montgomery multiplication;

[0012] a comparison module configured to use the first operation result and the modulus as two operands of a comparison instruction when the operation of the finite field is addition or Montgomery multiplication, and use the two original data as two operands of the comparison instruction when the operation of the finite field is subtraction; perform comparison using the comparison instruction, generate a first flag bit for indicating whether the modulus operation is enabled according to the comparison result, and store the first flag bit in a first register;

[0013] The conditional operation module is configured to use the first operation result as the first operand of the conditional operation instruction and the modulus as the second operand of the conditional operation instruction; read the first flag bit from the first register, keep the second operand unchanged when the first flag bit indicates that the modulus operation is enabled, and replace the modulus with 0 as the new second operand when the first flag bit indicates that the modulus operation is not enabled; use the conditional operation instruction to perform an operation to generate a second operation result, and use the second operation result as the final result of the finite field operation on the two original data.

[0014] The present disclosure provides a non-transitory computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-mentioned method for implementing finite field operations.

[0015] Compared with the related art, the method, device and storage medium for implementing finite field operations provided by the present disclosure implement basic operations on two original data of the finite field through a first operation instruction. By setting a first flag bit for indicating whether to enable modulus operations in a comparison instruction and introducing a conditional operation instruction, the first flag bit is read through the conditional operation instruction, and 0 or the modulus is added / subtracted according to the indication of the first flag bit, the use of if and else branch statements can be avoided, thereby eliminating the need for instruction jumps and improving the operating efficiency of the processor.

[0016] Other features and advantages of the present disclosure will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present disclosure. Other advantages of the present disclosure can be realized and obtained through the solutions described in the description and the drawings.

[0017] Still other aspects will become apparent upon reading and understanding the accompanying drawings and detailed description.

[0018] Summary of the Figures

[0019] The accompanying drawings are used to provide an understanding of the technical solution of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the technical solution of the present disclosure and do not constitute a limitation to the technical solution of the present disclosure.

[0020] FIG1 is a flow chart of a method for implementing finite field operations provided by an embodiment of the present disclosure;

[0021] FIG2 is a schematic diagram of the structure of a device for implementing finite field operations provided by an embodiment of the present disclosure;

[0022] FIG3-a is a schematic structural diagram of a comparison module provided in an embodiment of the present disclosure;

[0023] FIG3-b is a schematic diagram of the structure of a conditional comparator provided in an embodiment of the present disclosure;

[0024] FIG4-a is a schematic diagram of the structure of a conditional operation module provided in an embodiment of the present disclosure;

[0025] FIG4-b is a schematic diagram of the structure of a conditional operator provided in an embodiment of the present disclosure;

[0026] FIG5 is a schematic diagram of the structure of another device for implementing finite field operations provided by an embodiment of the present disclosure;

[0027] FIG6 is a schematic diagram of a chip provided in an embodiment of the present disclosure.

[0028] Details

[0029] The present disclosure describes a plurality of embodiments, but this description is exemplary rather than restrictive, and it will be apparent to those skilled in the art that there may be more embodiments and implementations within the scope of the embodiments described in the present disclosure. Although many possible feature combinations are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with any other feature or element in any other embodiment, or may replace any other feature or element in any other embodiment.

[0030] The present disclosure includes and contemplates combinations of features and elements known to those of ordinary skill in the art. The disclosed embodiments, features, and elements of the present disclosure may also be combined with any conventional features or elements to form a unique inventive solution defined by the claims. Any features or elements of any embodiment may also be combined with features or elements from other inventive solutions to form another unique inventive solution defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this disclosure may be implemented individually or in any appropriate combination. Therefore, the embodiments are not subject to other limitations except for the limitations set forth in the appended claims and their equivalents. In addition, various modifications and changes may be made within the scope of protection of the appended claims.

[0031] In addition, when describing representative embodiments, the specification may have presented the method and / or process as a specific sequence of steps. However, to the extent that the method or process does not rely on the specific order of the steps described herein, the method or process should not be limited to the steps in the specific order described. As will be understood by those skilled in the art, other orders of steps are also possible. Therefore, the specific order of the steps set forth in the specification should not be interpreted as limiting the claims. In addition, the claims to the method and / or process should not be limited to performing their steps in the order written, and those skilled in the art can readily understand that these orders can be changed without departing from the scope of this disclosure.

[0032] Finite field operations are widely used in zero-knowledge proofs, especially addition, subtraction, and multiplication (such as Montgomery multiplication). After direct addition / subtraction / multiplication calculations, modular reduction calculations are required to reduce the results to the range [0, p-1], where p is the modulus (a large prime number).

[0033] For the addition operation of the finite field, assuming that c_add is the result of the addition operation of operands a and b in the finite field, the logic of the addition operation of the finite field (including the modular reduction operation) is:

[0034] For the subtraction operation of the finite field, assuming that c_sub is the result of the subtraction operation of the operand a and the operand b, the logic of the subtraction operation of the finite field (including the modular reduction calculation) is:

[0035] For Montgomery multiplication, assuming that d is the multiplication result before the modular reduction of Montgomery multiplication, and c_md is the multiplication result after the modular reduction of Montgomery multiplication, the logic of the modular reduction calculation of Montgomery multiplication is:

[0036] The calculation logic of Montgomery multiplication itself is relatively complex and will not be described in detail here. The calculation result of Montgomery multiplication itself is in the range of [0, 2p), and the final calculation result after modular reduction is in the range of [0, p-1].

[0037] For zero-knowledge proof applications, generally each step of addition, subtraction and Montgomery multiplication requires modular reduction calculation.

[0038] For the addition calculation of finite fields, the code in the computer program can be expressed as:

[0039] For the subtraction calculation of finite fields, the code in the computer program can be expressed as:

[0040] For the subtraction calculation of finite fields, the code in the computer program can also be expressed as:

[0041] For the Montgomery multiplication calculation, the code in the computer program can be expressed as:

[0042] If a program design approach with branches is adopted, the addition, subtraction, and Montgomery multiplication used in zero-knowledge proof applications will be filled with conditional judgment instructions (if and else conditional judgment instructions) due to modular reduction calculations. Moreover, due to the randomness of the data, the branch prediction method that uses the branch results of the program at this location in the past history as the judgment standard for this branch prediction will not be of practical use and may even reduce processor performance.

[0043] In order to reduce the branch jump of the program, the present disclosure adopts a new design idea to implement finite field operations (addition, subtraction and multiplication).

[0044] As shown in FIG1 , an embodiment of the present disclosure provides a method for implementing operations on a finite field, including:

[0045] Step S10: using the two original data involved in the finite field operation as two operands of a first operation instruction, and performing an operation using the first operation instruction to generate a first operation result; wherein the operation includes: addition, subtraction, or Montgomery multiplication;

[0046] Step S20: When the operation of the finite field is addition or Montgomery multiplication, the first operation result and the modulus are used as two operands of a comparison instruction; when the operation of the finite field is subtraction, the two original data are used as two operands of the comparison instruction; the comparison is performed using the comparison instruction, and a first flag is generated according to the comparison result for indicating whether the modulus operation is enabled, and the first flag is stored in a first register;

[0047] Step S30, using the first operation result as the first operand of the conditional operation instruction, and using the modulus as the second operand of the conditional operation instruction; reading the first flag bit from the first register, when the first flag bit indicates that the modulus operation is enabled, keeping the second operand unchanged, when the first flag bit indicates that the modulus operation is not enabled, replacing the modulus with 0 as the new second operand; using the conditional operation instruction to perform an operation to generate a second operation result, and using the second operation result as the final result of the finite field operation on the two original data.

[0048] The method for implementing finite field operations provided by the embodiment of the present disclosure uses two original data participating in the finite field operation as two operands of a first operation instruction, and uses the first operation instruction to perform the operation to generate a first operation result; wherein, the operation includes: addition, subtraction or Montgomery multiplication; when the operation of the finite field is addition or Montgomery multiplication, the first operation result and the modulus are used as two operands of a comparison instruction; when the operation of the finite field is subtraction, the two original data are used as two operands of the comparison instruction; the comparison is performed using the comparison instruction, and an instruction for indicating whether to enable the modulus is generated according to the comparison result. The method of the present invention is to store the first flag bit of a conditional operation instruction and the modulus as the first operand of the conditional operation instruction, and store the first flag bit in the first register; use the first operation result as the first operand of the conditional operation instruction, and use the modulus as the second operand of the conditional operation instruction; read the first flag bit from the first register, and when the first flag bit indicates that the modulus operation is enabled, keep the second operand unchanged; when the first flag bit indicates that the modulus operation is not enabled, replace the modulus with 0 as the new second operand; use the conditional operation instruction to perform an operation to generate a second operation result, and use the second operation result as the final result of the finite field operation of the two original data. The method provided by the embodiment of the present disclosure can avoid executing a large number of jump instructions when implementing finite field operations, thereby improving the operation efficiency of the processor.

[0049] In an exemplary embodiment, the first operation instruction includes an addition instruction, a subtraction instruction, or a Montgomery multiplication instruction.

[0050] In an exemplary embodiment, when the first flag bit is set to 1, it is used to indicate that the modulus operation is enabled; when the first flag bit is set to 0, it is used to indicate that the modulus operation is not enabled.

[0051] In an exemplary embodiment, reading the first flag bit from the first register, and when the first flag bit indicates that the modulus operation is enabled, keeping the second operand unchanged, and when the first flag bit indicates that the modulus operation is not enabled, replacing the modulus with 0 as a new second operand, includes:

[0052] Perform a bitwise AND operation on the first flag bit and the second operand, and use the result of the operation as a new second operand;

[0053] When the first flag bit is set to 1, it is used to indicate that the modulus operation is enabled; when the first flag bit is set to 0, it is used to indicate that the modulus operation is not enabled.

[0054] In an exemplary embodiment, using two original data involved in a finite field operation as two operands of a first operation instruction, and performing an operation using the first operation instruction to generate a first operation result includes:

[0055] When the operation of the finite field is addition, the first operation instruction is an addition instruction, the two original data are used as two operands of the addition instruction respectively, and the result of the addition operation on the two operands of the addition instruction is used as the first operation result;

[0056] When the operation of the finite field is subtraction, the first operation instruction is a subtraction instruction, the minuend in the two original data is used as the first operand of the subtraction instruction, the subtrahend in the two original data is used as the second operand of the subtraction instruction, and the difference obtained by subtracting the second operand of the subtraction instruction from the first operand of the subtraction instruction is used as the first operation result;

[0057] When the operation of the finite field is Montgomery multiplication, the first operation instruction is a Montgomery multiplication instruction, the two original data are used as two operands of the Montgomery multiplication instruction respectively, and the result of Montgomery multiplication of the two operands of the Montgomery multiplication instruction is used as the first operation result.

[0058] In an exemplary embodiment, generating a first flag bit for indicating whether to enable the modulus operation according to the comparison result includes:

[0059] When the operation of the finite field is addition or Montgomery multiplication, when the comparison result is that the first operation result is greater than or equal to the modulus, the first flag bit is set to indicate that the modulus operation is enabled; when the comparison result is that the first operation result is less than the modulus, the first flag bit is set to indicate that the modulus operation is not enabled;

[0060] When the operation of the finite field is subtraction, when the comparison result is that the minuend in the two original data is smaller than the subtrahend in the two original data, the first flag is set to indicate that the modulo operation is enabled; when the comparison result is that the minuend in the two original data is greater than or equal to the subtrahend in the two original data, the first flag is set to indicate that the modulo operation is not enabled.

[0061] In an exemplary embodiment, using the first operation result as a first operand of a conditional operation instruction, using the modulus as a second operand of the conditional operation instruction, and using the conditional operation instruction to perform an operation to generate a second operation result includes:

[0062] When the operation of the finite field is addition or Montgomery multiplication, the conditional operation instruction is a conditional subtraction instruction, the first operation result is used as the first operand of the conditional subtraction instruction, the modulus is used as the second operand of the conditional subtraction instruction, and the difference obtained by subtracting the second operand of the conditional subtraction instruction from the first operand of the conditional subtraction instruction is used as the second operation result;

[0063] When the operation of the finite field is subtraction, the conditional operation instruction is a conditional addition instruction, the first operation result is used as the first operand of the conditional addition instruction, the modulus is used as the second operand of the conditional addition instruction, and the sum of the first operand of the conditional addition instruction and the second operand of the conditional addition instruction is used as the second operation result.

[0064] In an exemplary embodiment, when the operation of the finite field is addition, the first operation instruction is an addition instruction, and the two original data are respectively used as two operands of the addition instruction, and the result of the addition operation on the two operands of the addition instruction is used as the first operation result; the first operation result and the modulus are used as two operands of a comparison instruction, and the comparison is performed using the comparison instruction. When the comparison result is that the first operation result is greater than or equal to the modulus, the first flag bit is set to indicate that the modulus operation is enabled; when the comparison result is that the first operation result is less than the modulus, the first flag bit is set to indicate that the modulus operation is not enabled; the first flag bit is saved in In the first register; the conditional operation instruction is a conditional subtraction instruction, the first operation result is used as the first operand of the conditional subtraction instruction, and the modulus is used as the second operand of the conditional subtraction instruction; the first flag bit is read from the first register, when the first flag bit indicates that the modulus operation is enabled, the second operand is kept unchanged, when the first flag bit indicates that the modulus operation is not enabled, the modulus is replaced by 0 as the new second operand; the difference obtained by subtracting the second operand of the conditional subtraction instruction from the first operand of the conditional subtraction instruction is used as the second operation result, and the second operation result is used as the final result of the finite field addition operation on the two original data.

[0065] When the operation of the finite field is addition, the code in the computer program can be expressed as:

[0066] When performing addition operations on finite fields, by setting the first flag bit in the comparison instruction and introducing conditional subtraction instructions, the use of if and else branch statements can be avoided, thereby eliminating the need for instruction jumps and improving the processor's operating efficiency.

[0067] In an exemplary embodiment, when the operation of the finite field is subtraction, the first operation instruction is a subtraction instruction, the minuend in the two original data is used as the first operand of the subtraction instruction, the subtrahend in the two original data is used as the second operand of the subtraction instruction, and the difference obtained by subtracting the second operand of the subtraction instruction from the first operand of the subtraction instruction is used as the first operation result; the two original data are used as two operands of a comparison instruction, and the comparison is performed using the comparison instruction. When the comparison result is that the minuend in the two original data is less than the subtrahend in the two original data, the first flag bit is set to indicate that the modulo operation is enabled; when the comparison result is that the minuend in the two original data is greater than or equal to the subtrahend in the two original data, the first flag bit is set to indicate that the modulo operation is enabled; when the comparison result is that the minuend in the two original data is greater than or equal to the subtrahend in the two original data, the first flag bit is set to indicate that the modulo operation is enabled. When there is a subtracted number in the data, the first flag bit is set to indicate that the modulus operation is not enabled; the conditional operation instruction is a conditional addition instruction, the first operation result is used as the first operand of the conditional addition instruction, and the modulus is used as the second operand of the conditional addition instruction. The first flag bit is read from the first register. When the first flag bit indicates that the modulus operation is enabled, the second operand is kept unchanged. When the first flag bit indicates that the modulus operation is not enabled, the modulus is replaced by 0 as the new second operand; the sum of the first operand of the conditional addition instruction and the second operand of the conditional addition instruction is used as the second operation result, and the second operation result is used as the final result of the subtraction operation of the finite field on the two original data.

[0068] When the operation of the finite field is subtraction, the code in the computer program can be expressed as:

[0069] When performing subtraction operations on a finite field, by setting the first flag bit in the comparison instruction and introducing a conditional addition instruction, the use of if and else branch statements can be avoided, eliminating the need for instruction jumps and improving the processor's operating efficiency.

[0070] In an exemplary embodiment, when the operation of the finite field is Montgomery multiplication, the first operation instruction is a Montgomery multiplication instruction, and the two original data are respectively used as two operands of the Montgomery multiplication instruction, and the result of Montgomery multiplication of the two operands of the Montgomery multiplication instruction is used as the first operation result; the first operation result and the modulus are used as two operands of a comparison instruction, and the comparison is performed using the comparison instruction. When the comparison result is that the first operation result is greater than or equal to the modulus, the first flag bit is set to indicate that the modulus operation is enabled; when the comparison result is that the first operation result is less than the modulus, the first flag bit is set to indicate that the modulus operation is not enabled; and the first flag bit is set to indicate that the first operation result is greater than or equal to the modulus. A flag bit is stored in a first register; the conditional operation instruction is a conditional subtraction instruction, the first operation result is used as the first operand of the conditional subtraction instruction, and the modulus is used as the second operand of the conditional subtraction instruction; the first flag bit is read from the first register, and when the first flag bit indicates that the modulus operation is enabled, the second operand is kept unchanged; when the first flag bit indicates that the modulus operation is not enabled, the modulus is replaced by 0 as the new second operand; the difference obtained by subtracting the second operand of the conditional subtraction instruction from the first operand of the conditional subtraction instruction is used as the second operation result, and the second operation result is used as the final result of the Montgomery multiplication operation of the finite field on the two original data.

[0071] When the operation of the finite field is Montgomery multiplication, the code in the computer program can be expressed as:

[0072] When performing Montgomery multiplication operations in a finite field, by setting the first flag bit in the comparison instruction and introducing a conditional subtraction instruction, the use of if and else branch statements can be avoided, thereby eliminating the need for instruction jumps and improving the processor's operating efficiency.

[0073] In an exemplary embodiment, a method for implementing a subtraction operation in a finite field may include performing the following steps:

[0074] Step S1, using a minuend and a subtrahend in two original data participating in a subtraction operation of a finite field as two operands of a comparison instruction, performing comparison using the comparison instruction, and setting a first flag bit to indicate that a modulo operation is enabled when the comparison result shows that the minuend in the two original data is smaller than the subtrahend in the two original data; and setting the first flag bit to indicate that a modulo operation is disabled when the comparison result shows that the minuend in the two original data is greater than or equal to the subtrahend in the two original data; wherein the first flag bit is stored in a first register;

[0075] Step S2: using the minuend in the two original data as the first operand of the conditional addition instruction, using the modulus as the second operand of the conditional addition instruction, reading the first flag bit from the first register, keeping the second operand unchanged when the first flag bit indicates that the modulus operation is enabled, and replacing the modulus with 0 as the new second operand when the first flag bit indicates that the modulus operation is not enabled; and using the sum of the first operand of the conditional addition instruction and the second operand of the conditional addition instruction as the third operation result;

[0076] Step S3, using the third operation result as the first operand of the subtraction instruction, using the subtrahend in the two original data as the second operand of the subtraction instruction, using the difference obtained by subtracting the second operand of the subtraction instruction from the first operand of the subtraction instruction as the fourth operation result, and using the fourth operation result as the final result of the subtraction operation of the finite field on the two original data.

[0077] When the operation of the finite field is subtraction, the code in the computer program can be expressed as:

[0078] When performing subtraction operations on a finite field, by setting the first flag bit in the comparison instruction and introducing a conditional addition instruction, the use of if and else branch statements can be avoided, eliminating the need for instruction jumps and improving the processor's operating efficiency.

[0079] As shown in FIG2 , an embodiment of the present disclosure provides a device for implementing finite field operations, including:

[0080] A first operation processing module 10 is configured to use two original data involved in the finite field operation as two operands of a first operation instruction, and perform an operation using the first operation instruction to generate a first operation result; wherein the operation includes: addition, subtraction, or Montgomery multiplication;

[0081] The comparison module 20 is configured to use the first operation result and the modulus as two operands of a comparison instruction when the operation of the finite field is addition or Montgomery multiplication, and use the two original data as two operands of the comparison instruction when the operation of the finite field is subtraction; perform comparison using the comparison instruction, generate a first flag bit for indicating whether the modulus operation is enabled according to the comparison result, and store the first flag bit in a first register;

[0082] The conditional operation module 30 is configured to use the first operation result as the first operand of the conditional operation instruction and the modulus as the second operand of the conditional operation instruction; read the first flag bit from the first register, and when the first flag bit indicates that the modulus operation is enabled, keep the second operand unchanged; when the first flag bit indicates that the modulus operation is not enabled, replace the modulus with 0 as the new second operand; use the conditional operation instruction to perform an operation to generate a second operation result, and use the second operation result as the final result of the finite field operation on the two original data.

[0083] The device for implementing finite field operations provided by the embodiment of the present disclosure comprises a first operation processing module that uses two original data involved in the finite field operation as two operands of a first operation instruction, and uses the first operation instruction to perform an operation to generate a first operation result; wherein the operation includes: addition, subtraction or Montgomery multiplication; a comparison module that uses the first operation result and the modulus as two operands of the comparison instruction when the finite field operation is addition or Montgomery multiplication, and uses the two original data as two operands of the comparison instruction when the finite field operation is subtraction; uses the comparison instruction to compare, and generates a signal indicating whether the comparison result is correct according to the comparison result. A first flag bit for enabling a modulus operation is stored in a first register; a conditional operation module uses the first operation result as the first operand of a conditional operation instruction and the modulus as the second operand of the conditional operation instruction; the first flag bit is read from the first register, and when the first flag bit indicates that the modulus operation is enabled, the second operand is kept unchanged; when the first flag bit indicates that the modulus operation is not enabled, the modulus is replaced with 0 as the new second operand; the conditional operation instruction is used to perform an operation to generate a second operation result, and the second operation result is used as the final result of the finite field operation on the two original data. The device provided by the embodiment of the present disclosure can avoid executing a large number of jump instructions when implementing finite field operations, thereby improving the computing efficiency of the processor.

[0084] In an exemplary embodiment, the first operation instruction includes an addition instruction, a subtraction instruction, or a Montgomery multiplication instruction.

[0085] In an exemplary embodiment, when the first flag bit is set to 1, it is used to indicate that the modulus operation is enabled; when the first flag bit is set to 0, it is used to indicate that the modulus operation is not enabled.

[0086] In an exemplary embodiment, as shown in FIG3 - a , the comparison module 20 includes a condition comparator 201 ;

[0087] As shown in FIG3-b , the conditional comparator includes: a comparator 2011 , a first register 2013 and a second register 2015 ;

[0088] A comparator is configured to receive a first operand from a first input port and a second operand from a second input port, compare the first operand and the second operand, output the comparison result to a second register, generate a first flag bit for indicating whether to enable modulus operation based on the comparison result, and output the first flag bit to the first register.

[0089] The comparator is configured to use the first operation result and the modulus as the first operand and the second operand of the comparator, respectively, when the operation of the finite field is addition or Montgomery multiplication; and use the two original data as the first operand and the second operand of the comparator, respectively, when the operation of the finite field is subtraction; compare the first operand and the second operand, output the comparison result to the second register, generate a first flag bit for indicating whether the modulus operation is enabled according to the comparison result, and output the first flag bit to the first register.

[0090] In an exemplary embodiment, as shown in FIG4 - a , the conditional operation module 30 includes a conditional operator 301 ;

[0091] As shown in FIG4-b , the conditional operator includes: an operator 3011 and a bit processor 3013;

[0092] The operator includes a first input port, a second input port and a first output port; the bit processor includes a third input port, a fourth input port and a second output port;

[0093] The bit processor is configured to input a modulus from the third input port and a first flag from the fourth input port, perform a bitwise AND operation on the modulus and the first flag, and output the operation result from the second output port to the second input port of the operator;

[0094] The operator is configured to input a first operation result from a first input port and an operation result of the bit processor from a second input port, perform an operation on the first operation result and the operation result of the bit processor to generate a second operation result, and use the second operation result as the final result of the finite field operation on the two original data.

[0095] In an exemplary embodiment, the operator includes an adder or a subtractor.

[0096] In an exemplary embodiment, the first operation processing module is configured to use the two original data involved in the finite field operation as two operands of a first operation instruction, and use the first operation instruction to perform an operation to generate a first operation result in the following manner:

[0097] When the operation of the finite field is addition, the first operation instruction is an addition instruction, the two original data are used as two operands of the addition instruction respectively, and the result of the addition operation on the two operands of the addition instruction is used as the first operation result;

[0098] When the operation of the finite field is subtraction, the first operation instruction is a subtraction instruction, the minuend in the two original data is used as the first operand of the subtraction instruction, the subtrahend in the two original data is used as the second operand of the subtraction instruction, and the difference obtained by subtracting the second operand of the subtraction instruction from the first operand of the subtraction instruction is used as the first operation result;

[0099] When the operation of the finite field is Montgomery multiplication, the first operation instruction is a Montgomery multiplication instruction, the two original data are used as two operands of the Montgomery multiplication instruction respectively, and the result of Montgomery multiplication of the two operands of the Montgomery multiplication instruction is used as the first operation result.

[0100] In an exemplary embodiment, the comparison module is configured to generate a first flag bit for indicating whether the modulus operation is enabled according to the comparison result in the following manner:

[0101] When the operation of the finite field is addition or Montgomery multiplication, when the comparison result is that the first operation result is greater than or equal to the modulus, the first flag bit is set to indicate that the modulus operation is enabled; when the comparison result is that the first operation result is less than the modulus, the first flag bit is set to indicate that the modulus operation is not enabled;

[0102] When the operation of the finite field is subtraction, when the comparison result is that the minuend in the two original data is smaller than the subtrahend in the two original data, the first flag is set to indicate that the modulo operation is enabled; when the comparison result is that the minuend in the two original data is greater than or equal to the subtrahend in the two original data, the first flag is set to indicate that the modulo operation is not enabled.

[0103] In an exemplary embodiment, the conditional operation module is configured to use the first operation result as the first operand of the conditional operation instruction, use the modulus as the second operand of the conditional operation instruction, and use the conditional operation instruction to perform an operation to generate a second operation result in the following manner:

[0104] When the operation of the finite field is addition or Montgomery multiplication, the conditional operation instruction is a conditional subtraction instruction, the first operation result is used as the first operand of the conditional subtraction instruction, the modulus is used as the second operand of the conditional subtraction instruction, and the difference obtained by subtracting the second operand of the conditional subtraction instruction from the first operand of the conditional subtraction instruction is used as the second operation result;

[0105] When the operation of the finite field is subtraction, the conditional operation instruction is a conditional addition instruction, the first operation result is used as the first operand of the conditional addition instruction, the modulus is used as the second operand of the conditional addition instruction, and the sum of the first operand of the conditional addition instruction and the second operand of the conditional addition instruction is used as the second operation result.

[0106] As shown in FIG5 , an embodiment of the present disclosure provides a device for implementing operations on finite fields, comprising: a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the steps of the method for implementing operations on finite fields are implemented.

[0107] An embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the steps of the method for implementing finite field operations are implemented.

[0108] As shown in FIG6 , an embodiment of the present disclosure provides a chip including the above-mentioned device 100 for implementing finite field operations.

[0109] It will be appreciated by those skilled in the art that the functional modules / units in the apparatus disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In a hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media generally embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0110] It should be noted that the above-described embodiments or implementations are merely illustrative and not restrictive. Therefore, the present disclosure is not limited to what is specifically shown and described herein. Various modifications, substitutions, or omissions may be made to the forms and details of the implementations without departing from the scope of the present disclosure.

Claims

1. A method for implementing operations in a finite field, comprising: Taking two original data participating in the operations in the finite field as two operands of a first operation instruction respectively, and performing an operation using the first operation instruction to generate a first operation result; wherein, the operations include: addition, subtraction or Montgomery multiplication; When the operation in the finite field is addition or Montgomery multiplication, taking the first operation result and the modulus as two operands of a comparison instruction, and when the operation in the finite field is subtraction, taking the two original data as two operands of the comparison instruction; performing a comparison using the comparison instruction, generating a first flag bit for indicating whether to enable modulus operation according to the comparison result, and storing the first flag bit in a first register; Taking the first operation result as a first operand of a conditional operation instruction, and taking the modulus as a second operand of the conditional operation instruction; reading the first flag bit from the first register, when the first flag bit indicates enabling modulus operation, keeping the second operand unchanged, and when the first flag bit indicates not enabling modulus operation, replacing the modulus with 0 as a new second operand; performing an operation using the conditional operation instruction to generate a second operation result, and taking the second operation result as the final result of the operations of the two original data in the finite field.

2. The method according to claim 1, wherein: Reading the first flag bit from the first register, when the first flag bit indicates enabling modulus operation, keeping the second operand unchanged, and when the first flag bit indicates not enabling modulus operation, replacing the modulus with 0 as a new second operand, includes: Performing a bitwise AND operation on the first flag bit and the second operand, and taking the operation result as the new second operand; wherein, the first flag bit is set to 1 for indicating enabling modulus operation, and the first flag bit is set to 0 for indicating not enabling modulus operation.

3. The method according to claim 1, wherein: Taking two original data participating in the operations in the finite field as two operands of a first operation instruction respectively, and performing an operation using the first operation instruction to generate a first operation result, includes: When the operation in the finite field is addition, the first operation instruction is an addition instruction, taking the two original data as two operands of the addition instruction respectively, and taking the result of the addition operation of the two operands of the addition instruction as the first operation result; When the operation in the finite field is subtraction, the first operation instruction is a subtraction instruction, taking the minuend in the two original data as the first operand of the subtraction instruction, taking the subtrahend in the two original data as the second operand of the subtraction instruction, and taking the difference obtained by subtracting the second operand of the subtraction instruction from the first operand of the subtraction instruction as the first operation result; When the operation in the finite field is Montgomery multiplication, the first operation instruction is a Montgomery multiplication instruction, taking the two original data as two operands of the Montgomery multiplication instruction respectively, and taking the result of the Montgomery multiplication of the two operands of the Montgomery multiplication instruction as the first operation result.

4. The method according to claim 1, wherein: Generating a first flag bit for indicating whether to enable modular arithmetic according to the comparison result includes: When the operation in the finite field is addition or Montgomery multiplication, when the comparison result is that the first operation result is greater than or equal to the modulus, setting the first flag bit to indicate enabling modular arithmetic; when the comparison result is that the first operation result is less than the modulus, setting the first flag bit to indicate not enabling modular arithmetic; When the operation in the finite field is subtraction, when the comparison result is that the minuend in the two original data is less than the subtrahend in the two original data, setting the first flag bit to indicate enabling modular arithmetic; when the comparison result is that the minuend in the two original data is greater than or equal to the subtrahend in the two original data, setting the first flag bit to indicate not enabling modular arithmetic.

5. The method according to claim 1, wherein: Using the first operation result as the first operand of a conditional operation instruction and the modulus as the second operand of the conditional operation instruction, and performing an operation using the conditional operation instruction to generate a second operation result, includes: When the operation in the finite field is addition or Montgomery multiplication, the conditional operation instruction is a conditional subtraction instruction, using the first operation result as the first operand of the conditional subtraction instruction, using the modulus as the second operand of the conditional subtraction instruction, and taking the difference obtained by subtracting the second operand of the conditional subtraction instruction from the first operand of the conditional subtraction instruction as the second operation result; When the operation in the finite field is subtraction, the conditional operation instruction is a conditional addition instruction, using the first operation result as the first operand of the conditional addition instruction, using the modulus as the second operand of the conditional addition instruction, and taking the sum obtained by adding the first operand of the conditional addition instruction and the second operand of the conditional addition instruction as the second operation result.

6. A device for implementing operations in a finite field, comprising: A first operation processing module configured to use two original data participating in operations in the finite field as the two operands of a first operation instruction respectively, and perform an operation using the first operation instruction to generate a first operation result; wherein, the operations include: addition, subtraction or Montgomery multiplication; A comparison module configured to, when the operation in the finite field is addition or Montgomery multiplication, use the first operation result and the modulus as the two operands of a comparison instruction, and when the operation in the finite field is subtraction, use the two original data as the two operands of the comparison instruction; perform a comparison using the comparison instruction, generate a first flag bit for indicating whether to enable modular arithmetic according to the comparison result, and store the first flag bit in a first register; A conditional operation module, configured to use the first operation result as the first operand of a conditional operation instruction and the modulus as the second operand of the conditional operation instruction; read the first flag bit from a first register, and when the first flag bit indicates enabling modulus operation, keep the second operand unchanged, and when the first flag bit indicates disabling modulus operation, replace the modulus with 0 as the new second operand; perform an operation using the conditional operation instruction to generate a second operation result, and use the second operation result as the final result of the operation of the two original data in the finite field.

7. The apparatus according to claim 6, wherein: The comparison module includes a conditional comparator; the conditional comparator includes: a comparator, a first register, and a second register; The comparator is configured to receive a first operand from a first input port, receive a second operand from a second input port, compare the first operand and the second operand, output the comparison result to the second register, generate a first flag bit for indicating whether to enable modulus operation according to the comparison result, and output the first flag bit to the first register.

8. The apparatus according to claim 6, wherein: The conditional operation module includes a conditional arithmetic unit; the conditional arithmetic unit includes: an arithmetic unit and a bit processor; The arithmetic unit includes a first input port, a second input port, and a first output port; the bit processor includes a third input port, a fourth input port, and a second output port; The bit processor is configured to input a modulus from the third input port, input a first flag bit from the fourth input port, perform a bitwise AND operation on the modulus and the first flag bit, and output the operation result from the second output port to the second input port of the arithmetic unit; The arithmetic unit is configured to input a first operation result from the first input port and input the operation result of the bit processor from the second input port, perform an operation on the first operation result and the operation result of the bit processor to generate a second operation result, and use the second operation result as the final result of the operation of the two original data in the finite field; wherein, when the first flag bit is set to 1, it is used to indicate enabling modulus operation, and when the first flag bit is set to 0, it is used to indicate disabling modulus operation; The arithmetic unit includes an adder or a subtractor.

9. The apparatus according to claim 6, wherein: A first operation processing module, configured to use the following method to use the two original data participating in the operation in the finite field as the two operands of a first operation instruction respectively, and perform an operation using the first operation instruction to generate a first operation result: When the operation in the finite field is addition, the first operation instruction is an addition instruction, use the two original data as the two operands of the addition instruction respectively, and use the result of the addition operation of the two operands of the addition instruction as the first operation result; When the operation in the finite field is subtraction, the first operation instruction is a subtraction instruction. The minuend in the two original data is used as the first operand of the subtraction instruction, the subtrahend in the two original data is used as the second operand of the subtraction instruction, and the difference obtained by subtracting the second operand of the subtraction instruction from the first operand of the subtraction instruction is used as the first operation result; When the operation in the finite field is Montgomery multiplication, the first operation instruction is a Montgomery multiplication instruction. The two original data are respectively used as the two operands of the Montgomery multiplication instruction, and the result of performing Montgomery multiplication on the two operands of the Montgomery multiplication instruction is used as the first operation result.

10. A non-transitory computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the method for implementing the operation in the finite field described in any one of the above claims 1-5 are implemented.

Citation Information

Patent Citations

  • Hardware acceleration coprocessor for elliptic curve public key cryptosystem SM2 algorithm

    CN104579656A

  • Analog-to-digital addition instruction

    CN116069390A

  • Instruction fusion method, processor core, processor and computer system

    CN116737241A

  • Multiple algorithm cryptography system

    US8995651B1