Post quantum public key signature operation for reconfigurable circuit devices
Abstract
Embodiments are directed to post quantum public key signature operation for reconfigurable circuit devices. An embodiment of an apparatus includes one or more processors; and a reconfigurable circuit device, the reconfigurable circuit device including a dedicated cryptographic hash hardware engine, and a reconfigurable fabric including logic elements (LEs), wherein the one or more processors are to configure the reconfigurable circuit device for public key signature operation, including mapping a state machine for public key generation and verification to the reconfigurable fabric, including mapping one or more cryptographic hash engines to the reconfigurable fabric, and combining the dedicated cryptographic hash hardware engine with the one or more mapped cryptographic hash engines for cryptographic signature generation and verification.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . An apparatus comprising:
one or more processors; and a reconfigurable circuit device, the reconfigurable circuit device including:
a dedicated cryptographic hash hardware engine, and
a reconfigurable fabric including a plurality of logic elements (LEs);
wherein the one or more processors are to configure the reconfigurable circuit device for public key signature operation, including:
mapping a state machine for public key generation and verification to the reconfigurable fabric, including mapping one or more cryptographic hash engines to the reconfigurable fabric, and
combining the dedicated cryptographic hash hardware engine with the one or more mapped cryptographic hash engines for cryptographic signature generation and verification.
22 . The apparatus of claim 21 , wherein the state machine is to perform a pre-hash optimization for the public key signature operation using the one or more cryptographic hash engines.
23 . The apparatus of claim 22 , wherein performing the pre-hash optimization includes:
pre-computing a hash value and storing the pre-computed hash value in the reconfigurable fabric; and providing the pre-computed hash value as a start value for one or more hash operations.
24 . The apparatus of claim 23 , wherein the pre-hash optimization includes pre-computing the hash value for a call to a pseudo random function (PRF).
25 . The apparatus of claim 22 , wherein the public key signature operation includes XMSS (Extended Merkel Signature Scheme).
26 . The apparatus of claim 25 , wherein the dedicated cryptographic hash hardware engine and the one or more mapped cryptographic hash engines are SHA-2 (Secure Hash Algorithm 2) engines, and wherein performing the pre-hash optimization includes performing an XMSS pre-hash optimization using the one or more mapped SHA-2 engines.
27 . The apparatus of claim 21 , wherein the dedicated cryptographic hash hardware engine is a part of a secure device manager (SDM).
28 . The apparatus of claim 21 , wherein the reconfigurable circuit device is one of an FPGA (Field Programmable Gate Array) or CPLD (Complex Programmable Logic Device).
29 . One or more non-transitory computer-readable storage mediums having stored thereon executable computer program instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
configuring a reconfigurable circuit device to public key signature operation, including:
mapping a state machine for public key generation and verification to a reconfigurable fabric of the reconfigurable circuit device, including mapping one or more cryptographic hash engines to the reconfigurable fabric, and
combining a dedicated cryptographic hash hardware engine of the reconfigurable circuit device with the one or more mapped cryptographic hash engines for cryptographic signature generation and verification; and
performing a public signature generation or verification utilizing the reconfigurable circuit device.
30 . The one or more mediums of claim 29 , wherein performing the public signature generation or verification includes performing a pre-hash optimization for the public key signature operation using the one or more cryptographic hash engines.
31 . The one or more mediums of claim 30 , wherein performing the pre-hash optimization includes:
pre-computing a hash value and storing the pre-computed hash value in the reconfigurable fabric; and providing the pre-computed hash value as a start value for one or more hash operations.
32 . The one or more mediums of claim 31 , wherein the pre-hash optimization includes pre-computing the hash value for a call to a pseudo random function (PRF).
33 . The one or more mediums of claim 30 , wherein performing the public key signature generation or verification includes performing an XMSS (Extended Merkel Signature Scheme) operation.
34 . The one or more mediums of claim 33 , wherein the dedicated cryptographic hash hardware engine and the one or more mapped cryptographic hash engines are SHA-2 (Secure Hash Algorithm 2) engines, and wherein performing the pre-hash optimization includes performing an XMSS pre-hash optimization using the one or more mapped SHA-2 engines.
35 . The one or more mediums of claim 29 , wherein the dedicated cryptographic hash hardware engine is a part of a secure device manager (SDM).
36 . The one or more mediums of claim 29 , wherein the reconfigurable circuit device is one of an FPGA (Field Programmable Gate Array) or CPLD (Complex Programmable Logic Device).
37 . A computing system comprising:
one or more processors; dynamic random access memory (DRAM) for storage of data; and an FPGA (Field Programmable Gate Array), the FPGA including:
a dedicated cryptographic hash hardware engine, and
a reconfigurable fabric including a plurality of logic elements (LEs);
wherein the one or more processors are to configure the FPGA for XMSS (Extended Merkel Signature Scheme) public key signature operation, including:
mapping a state machine for XMSS public key generation and verification to the reconfigurable fabric, including mapping one or more cryptographic hash engines to the reconfigurable fabric, and
combining the dedicated cryptographic hash hardware engine with the one or more mapped cryptographic hash engines for cryptographic signature generation and verification.
38 . The computing system of claim 37 , wherein the state machine is to perform a pre-hash optimization for the public key signature operation using the one or more cryptographic hash engines.
39 . The computing system of claim 38 , wherein performing the pre-hash optimization includes:
pre-computing a hash value and storing the pre-computed hash value in the reconfigurable fabric; and providing the pre-computed hash value as a start value for one or more hash operations.
40 . The computing system of claim 39 , wherein the pre-hash optimization includes pre-computing the hash value for a call to a pseudo random function (PRF).Join the waitlist — get patent alerts
Track US2022108039A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.