IP Library Granted Patent US 12,493,450
Granted Patent B2
US 12,493,450 · App. 17/562,490 · Granted Dec 9, 2025

System and method for big number hardware multiplication for cryptography

Inventors: Itzchak Harel (Jerusalem, IL); Roy Naor (Tel Aviv, IL); Ishai Ilani (Dolev, IL)
Assignee: Sandisk Technologies, Inc.
G06F7/722G06F17/17G06F7/724G06F7/728
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,493,450
App. No.
17/562,490
Granted
Dec 9, 2025
Kind
B2
Abstract

A system performs big number multiplication during a cryptographic process. This can occur, for example, when a controller in a storage system encrypts data for storage in its memory or decrypts data read from its memory. To perform the multiplication of these big input numbers quickly, the system uses a modified Toom-Cook algorithm comprising a plurality of levels of coefficient vectors for each of the input numbers. This involves performing a sample extraction process, a point multiplication process, and an interpolation (synthesis) process.

Claims (50)

1 . A storage system comprising:

a memory; and

a controller comprising a processor and a plurality of hardware multipliers, wherein the controller is configured to:

receive data from a host to store in the memory;

transform the data received from the host to encrypted data by performing a cryptographic process to encrypt the data by:

using the processor to:

receive input numbers x and y for multiplication; and

generate a plurality of levels of coefficient vectors for x and for y; and

using the plurality of hardware multipliers to:

perform a sample extraction process by multiplying the plurality of levels of coefficient vectors for x by a first decomposition matrix to yield a first result vector and by multiplying the plurality of levels of coefficient vectors for y by a second decomposition matrix to yield a second result vector;

perform a point multiplication process by multiplying the first and second result vectors to yield a third result vector; and

perform an interpolation process by multiplying the third result vector by a synthesis matrix to yield a result and dividing the result by a constant to yield a final result by accessing small, fast memory at algorithm concatenations with iterations done in a single clock cycle; and

store the encrypted data in the memory.

2 . The storage system of claim 1 , wherein the processor is configured to retrieve the constant from a look-up table.

3 . The storage system of claim 1 , wherein the plurality of hardware multipliers is configured to perform the dividing from multiple starting points and make corrections according to remainders of the division.

4 . The storage system of claim 1 , wherein the cryptographic process is based on a Toom-Cook algorithm comprising the plurality of levels of coefficient vectors.

5 . The storage system of claim 1 , wherein the plurality of hardware multipliers is configured to use a modified Montgomery multiplier to perform the multiplying from a most-significant bit to a least-significant bit.

6 . The storage system of claim 1 , wherein the first decomposition matrix comprises a product of decomposition matrices of each of the plurality of levels of coefficient vectors for x, and wherein the second decomposition matrix comprises a product of decomposition matrices of each of the plurality of levels of coefficient vectors for y.

7 . The storage system of claim 6 , wherein the plurality of hardware multipliers is configured to compute the first decomposition matrix offline and then perform the point multiplication process.

8 . The storage system of claim 1 , wherein the plurality of hardware multipliers is configured to perform the point multiplication process before the sample extraction process ends.

9 . The storage system of claim 1 , wherein the memory comprises a three-dimensional memory.

10 . In a data storage device comprising a memory and a controller comprising a processor and a plurality of hardware multipliers, a method comprising:

receiving data from a host to store in the memory;

transforming the data received from the host to encrypted data by performing a cryptographic process to encrypt the data by:

using the processor to:

receive input numbers x and y for multiplication; and

generate a plurality of levels of coefficient vectors for x and for y; and

using the plurality of hardware multipliers to:

perform a sample extraction process by multiplying the plurality of levels of coefficient vectors for x by a first decomposition matrix to yield a first result vector and by multiplying the plurality of levels of coefficient vectors for y by a second decomposition matrix to yield a second result vector;

perform a point multiplication process by multiplying the first and second result vectors to yield a third result vector; and

perform an interpolation process by multiplying the third result vector by a synthesis matrix to yield a result and dividing the result by a constant to yield a final result by accessing small, fast memory at algorithm concatenations with iterations done in a single clock cycle; and

storing the encrypted data in the memory.

11 . The method of claim 10 , further comprising using the processor to retrieve the constant from a look-up table.

12 . The method of claim 10 , further comprising using a Toom-Cook algorithm comprising the plurality of levels of coefficient vectors, wherein the plurality of levels of coefficient vectors comprises two levels, each of the two levels comprising four parts.

13 . The method of claim 10 , further comprising using a modified Montgomery multiplier to perform the multiplying from a most-significant bit to a least-significant bit.

14 . The method of claim 10 , wherein the first decomposition matrix comprises a product of decomposition matrices of each of the plurality of levels of coefficient vectors for the first number, and wherein the second decomposition matrix comprises a product of decomposition matrices of each of the plurality of levels of coefficient vectors for the second number.

15 . The method of claim 10 , further comprising using a plurality of hardware multipliers to perform a point multiplication process before a sample extraction process ends.

16 . The method of claim 10 , wherein the method is performed in a controller of a storage system.

17 . The method of claim 11 , wherein the method is performed in a host in communication with a storage system.

18 . A data storage device comprising:

a memory; and

means for transforming data received from a host to store in the memory to encrypted data by performing a cryptographic process to encrypt the data by:

using a processor to:

receive input numbers x and y for multiplication; and

generate a plurality of levels of coefficient vectors for x and for y; and

using the plurality of hardware multipliers to:

perform a sample extraction process by multiplying the plurality of levels of coefficient vectors for x by a first decomposition matrix to yield a first result vector and by multiplying the plurality of levels of coefficient vectors for y by a second decomposition matrix to yield a second result vector;

perform a point multiplication process by multiplying the first and second result vectors to yield a third result vector; and

perform an interpolation process by multiplying the third result vector by a synthesis matrix to yield a result and dividing the result by a constant to yield a final result by accessing small, fast memory at algorithm concatenations with iterations done in a single clock cycle; and

means for storing the encrypted data in the memory.

Assignments (8)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 27, 2021
From: HAREL, ITZCHAK; NAOR, ROY; ILANI, ISHAI
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 058482/0988 →
Continuity (1)
Related Publication 20230205491A1 · Jun 29, 2023
References Cited (5)
US 20110106872A1 · Hasenplaugh et al. · 2011 [cited by applicant]
US 20190310828A1 · Langhammer et al. · 2019 [cited by applicant]
N. E. Mrabet et al., Efficient Multiplication in Finite Field Extensions of Degree 5, Progress in Cryptology—ACRICACRYPT 2011, LNCS6737, 2011 (Year: 2011). [cited by examiner]
J. Ding et al., High-Speed ECC Processor Over NIST Prime Fields Applied with Toom-Cook Multiplication, IEEE Transactions on Circuits and Systems—I: Regular Papers, vol. 66, No. 3, 2019 (Year: 2019). [cited by examiner]
C.H. Liu et al., Efficient Digit-Serial KA-Based Multiplier Over Binary Extension Fields Using Block Recombination Approach, IEEE Transactions on Circuits and Systems—I: Regular Papers, vol. 62, No. 8, 2015 (Year: 2015). [cited by examiner]