IP Library › Granted Patent US 12,411,996
Granted Patent B2
US 12,411,996 · App. 17/884,704 · Granted Sep 9, 2025

Hardware-based implementation of secure hash algorithms

Inventors: Manoj Kumar (Yorktown Heights, NY); Silvia Melitta Mueller (St. Ingbert, DE); Debapriya Chatterjee (Austin, TX); Niels Fricke (Herrenberg, DE); Kattamuri Ekanadham (Mohegan Lake, NY); Maarten J. Boersma (Holzgerlingen, DE); Martijn Diede Berkers (Boeblingen, DE)
Assignee: International Business Machines Corporation
G06F21/72H04L9/0643H04L2209/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,411,996
App. No.
17/884,704
Granted
Sep 9, 2025
Kind
B2
Abstract

A processor includes a register file and an execution unit. The execution unit includes a hash circuit including at least a state register, a state update circuit coupled to the state register, and a control circuit. Based on a hash instruction, the hash circuit receives from the register file and buffers within the state register a current state of a message being hashed. The state update circuit performs state update function on contents of the state register, where performing the state update function includes performing a plurality of iterative rounds of processing on contents of the state register and returning a result of each of the plurality of iterative rounds of processing to the state register. Following completion of all of the plurality of iterative rounds of processing, the execution unit stores contents of the state register to the register file as an updated state of the message.

Claims (79)

1. A processor, comprising:

an instruction fetch unit that fetches instructions to be processed in the processor;

a register file including a plurality of registers for storing source operands and destination operands; and

an execution unit for executing a hash instruction obtained from the instructions, wherein the execution unit includes a hash circuit including at least:

a state register,

a state update circuit coupled to the state register,

a control circuit, and

a single instruction multiple data (SIMD) adder, wherein the SIMD adder is a dedicated component of the hash circuit,

wherein the execution unit, based on the hash instruction, is configured to perform:

receiving from the register file and buffering within the state register a current state of a message being hashed;

performing, in the state update circuit, a state update function on contents of the state register, wherein:

the state update function comprises a Secure Hash Algorthim 2 (SHA2) block hash function;

performing the state update function includes performing a plurality of iterative rounds of processing on contents of the state register and returning a result of each of the plurality of iterative rounds of processing to the state register; and

following completion of all of the plurality of iterative rounds of processing, adding, by the SIMD adder, contents of the state register to a current state of the message being hashed and storing a resulting sum to the register file as an updated state of the message.

2. The processor of claim 1 , wherein:

the state update function comprises a Secure Hash Algorithm 3 (SHA3) state permute function; and

performing a plurality of iterative rounds of processing includes performing twenty-four rounds of processing in which each round utilizes as an input a respective one of twenty-four round indices.

3. The processor of claim 1 , wherein

the state update function comprises a Secure Hash Algorithm 3 (SHA3) state permute function; and

performing a plurality of iterative rounds of processing includes performing a number of rounds of processing in indicated by the hash instruction.

4. The processor of claim 1 , wherein the execution unit executes the hash instruction in a squeezing phase of a Secure Hash Algorithm and Keccak (SHAKE) hash algorithm.

5. The processor of claim 1 , wherein:

the execution unit further includes a message block register for buffering a message block of the message and a message schedule round circuit coupled to the message block register; and

performing a state update function includes performing, by the message schedule round circuit, a plurality of iterative rounds of processing on contents of the message block register and returning a result of each of the plurality of iterative rounds of processing to the message block register.

6. The processor of claim 1 , wherein:

the state update circuit includes a data path for data words having a first data width; and

the execution unit is configured, based on the hash instruction indicating a second data width that is narrower than the first data width, to expand data words of a message block of the message to the first data width prior to processing the data words of the message in the state update circuit.

7. A method of data processing in a processor, said method comprising:

fetching, by an instruction fetch unit, instructions to be processed by the processor, wherein the instructions include a hash instruction; and

based on receiving the hash instruction, an execution unit of the processor executing the hash instruction, wherein the execution unit includes a hash circuit including:

at least a state register,

a state update circuit coupled to the state register,

a control circuit, and

a single instruction multiple data (SIMD) adder, wherein the SIMD adder is a distinct pipeline shared by the hash circuit and at least one other hash circuit,

wherein the executing includes:

receiving from a register file and buffering within the state register a current state of a message being hashed;

performing, in the state update circuit, a state update function on contents of the state register, wherein:

the state update function comprises a Secure Hash Algorthim 2 (SHA2) block hash function;

performing the state update function includes performing a plurality of iterative rounds of processing on contents of the state register and returning a result of each of the plurality of iterative rounds of processing to the state register; and

following completion of all of the plurality of iterative rounds of processing, adding, by the SIMD adder, contents of the state register to a current state of a message being hashed and storing a resulting sum to the register file as an updated state of the message.

8. The method of claim 7 , wherein:

the state update function comprises a Secure Hash Algorithm 3 (SHA3) state permute function; and

performing a plurality of iterative rounds of processing includes performing twenty-four rounds of processing in which each round utilizes as an input a respective one of twenty-four round indices.

9. The method of claim 7 , wherein executing the hash instruction includes executing the hash instruction in a squeezing phase of a Secure Hash Algorithm and Keccak (SHAKE) hash algorithm.

10. The method of claim 7 , wherein:

the execution unit further includes a message block register for buffering a message block of the message and a message schedule round circuit coupled to the message block register; and

performing a state update function includes performing a plurality of iterative rounds of processing on contents of the message block register in the message schedule round circuit and returning a result of each of the plurality of iterative rounds of processing to the message block register.

11. The method of claim 7 , wherein:

the state update circuit includes a data path for data words having a first data width; and

the method further comprises:

based on the hash instruction indicating a second data width that is narrower than the first data width, expanding data words of a message block of the message to the first data width prior to processing the data words of the message in the state update circuit.

12. A program product, comprising:

a machine-readable storage device; and

a design structure embodied in the machine-readable storage device, wherein the design structure is for designing, manufacturing, or testing an integrated circuit, the design structure including:

a processor, including:

an instruction fetch unit that fetches instructions to be executed;

a register file including a plurality of registers for storing source and destination operands;

and

an execution unit for executing a hash instruction obtained from the instructions, wherein the execution unit includes a hash circuit including at least:

a state register,

a state update circuit coupled to the state register,

a control circuit, and

a single instruction multiple data (SIMD) an adder, wherein the SIMD adder is a distinct pipeline shared by the hash circuit and at least one other hash circuit,

wherein the execution unit, based on the hash instruction, is configured to perform:

receiving from the register file and buffering within the state register a current state of a message being hashed;

performing, in the state update circuit, a state update function on contents of the state register, wherein:

the state update function comprises a Secure Hash Algorthim 2 (SHA2) block hash function;

performing the state update function includes performing a plurality of iterative rounds of processing on contents of the state register and returning a result of each of the plurality of iterative rounds of processing to the state register; and

following completion of all of the plurality of iterative rounds of processing, adding by the SIMD adder, contents of the state register to a current state of a message being hashed and storing a resulting sum to the register file as an updated state of the message.

13. The program product of claim 12 , wherein:

the state update function comprises a Secure Hash Algorithm 3 (SHA3) state permute function; and

performing a plurality of iterative rounds of processing includes performing twenty-four rounds of processing in which each round utilizes as an input a respective one of twenty-four round indices.

14. The program product of claim 12 , wherein the execution unit executes the hash instruction in a squeezing phase of a Secure Hash Algorithm and Keccak (SHAKE) hash algorithm.

15. The program product of claim 12 , wherein:

the execution unit further includes a message block register for buffering a message block of the message and a message schedule round circuit coupled to the message block register; and

performing a state update function includes performing, by the message schedule round circuit, a plurality of iterative rounds of processing on contents of the message block register and returning a result of each of the plurality of iterative rounds of processing to the message block register.

16. The program product of claim 12 , wherein:

the state update circuit includes a data path for data words having a first data width; and

the execution unit is configured, based on the hash instruction indicating a second data width that is narrower than the first data width, to expand data words of a message block of the message to the first data width prior to processing the data words of the message in the state update circuit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2022
From: KUMAR, MANOJ; MUELLER, SILVIA MELITTA; CHATTERJEE, DEBAPRIYA; FRICKE, NIELS; EKANADHAM, KATTAMURI; BOERSMA, MAARTEN J.; BERKERS, MARTIJN DIEDE
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 060767/0210 →
Continuity (1)
Related Publication 20240061961A1 · Feb 22, 2024
References Cited (106)
US 7295671B2 · Snell · 2007 [cited by applicant]
US 7702100B2 · Han et al. · 2010 [cited by applicant]
US 7783037B1 · Bong · 2010 [cited by applicant]
US 8042025B2 · Gopal · 2011 [cited by applicant]
US 8194854B2 · Gueron · 2012 [cited by applicant]
US 8340280B2 · Gueron · 2012 [cited by applicant]
US 8913740B2 · Gueron · 2014 [cited by applicant]
US 10129018B2 · Satpathy · 2018 [cited by examiner]
US 10142098B2 · Suresh · 2018 [cited by applicant]
US 10256971B2 · Gueron · 2019 [cited by applicant]
US 10305680B2 · Gomes · 2019 [cited by applicant]
US 10313108B2 · Suresh · 2019 [cited by examiner]
US 10346343B2 · Suresh · 2019 [cited by applicant]
US 10348506B2 · Greiner · 2019 [cited by applicant]
US 10432393B2 · Gueron · 2019 [cited by applicant]
US 10581593B2 · Gomes · 2020 [cited by applicant]
US 10877753B2 · Bradbury · 2020 [cited by applicant]
US 10924282B2 · Brostrom · 2021 [cited by applicant]
US 11121856B2 · Satpathy · 2021 [cited by applicant]
US 11128443B2 · Gueron · 2021 [cited by applicant]
US 20020066014A1 · Dworkin · 2002 [cited by applicant]
US 20030135530A1 · Parthasarathy · 2003 [cited by applicant]
US 20040202317A1 · Demjanenko · 2004 [cited by applicant]
US 20040252831A1 · Uehara · 2004 [cited by applicant]
US 20040255130A1 · Henry · 2004 [cited by applicant]
US 20050089160A1 · Crispin · 2005 [cited by applicant]
US 20080240423A1 · Gueron et al. · 2008 [cited by applicant]
US 20090052659A1 · Gueron · 2009 [cited by applicant]
US 20090141887A1 · Yap et al. · 2009 [cited by applicant]
US 20100049986A1 · Watanabe · 2010 [cited by applicant]
US 20110231636A1 · Olson · 2011 [cited by applicant]
US 20110246548A1 · Yen · 2011 [cited by applicant]
US 20110255689A1 · Bolotov · 2011 [cited by applicant]
US 20150043729A1 · Gopal · 2015 [cited by applicant]
US 20150098563A1 · Gulley et al. · 2015 [cited by applicant]
US 20160119126A1 · Shay · 2016 [cited by applicant]
US 20170134163A1 · Suresh · 2017 [cited by applicant]
US 20170373836A1 · Rarick · 2017 [cited by applicant]
US 20180122271A1 · Ghosh · 2018 [cited by applicant]
US 20190197821A1 · Hutchinson-Kay et al. · 2019 [cited by applicant]
US 20190205093A1 · Suresh et al. · 2019 [cited by applicant]
US 20190286443A1 · Solomatnikov · 2019 [cited by examiner]
US 20190319782A1 · Ghosh · 2019 [cited by examiner]
US 20190386815A1 · Satpathy · 2019 [cited by applicant]
US 20200117811A1 · Ghosh · 2020 [cited by examiner]
US 20200134234A1 · Lemay · 2020 [cited by applicant]
US 20210152330A1 · Satpathy · 2021 [cited by applicant]
US 20210203504A1 · Brandt · 2021 [cited by applicant]
US 20220206958A1 · LeMay · 2022 [cited by applicant]
US 20230269076A1 · Brandt · 2023 [cited by applicant]
US 20240012811A1 · Dai · 2024 [cited by examiner]
US 20240015004A1 · Chatterjee et al. · 2024 [cited by applicant]
US 20240053963A1 · Mueller et al. · 2024 [cited by applicant]
US 20240053989A1 · Kumar et al. · 2024 [cited by applicant]
CN 1658550A · 2005 [cited by applicant]
CN 101349968A · 2009 [cited by applicant]
CN 112152785A · 2020 [cited by applicant]
CN 113485751A · 2021 [cited by applicant]
EP 14490631A · 2004 [cited by applicant]
EP 4569404A1 · 2025 [cited by applicant]
EP 4569724A1 · 2025 [cited by applicant]
EP 4569725A1 · 2025 [cited by applicant]
TW 200536331A · 2005 [cited by applicant]
TW 201135477A · 2011 [cited by applicant]
TW 201203108A · 2012 [cited by applicant]
TW 201332329A · 2013 [cited by applicant]
TW 201519623A · 2015 [cited by applicant]
TW 201636829A · 2016 [cited by applicant]
TW 201717573A · 2017 [cited by applicant]
TW 202201165A · 2022 [cited by applicant]
Taiwan IPO, P202201322TWo1 Office Action, Jun. 14, 2024, 20 pages (English Translation). [cited by applicant]
Taiwan IPO, P202201845TW01 Office Action, Jun. 12, 2024, 4 pages (English Translation). [cited by applicant]
Bertoni, Guido et al., “KangarooTwelve: fast hashing based on Keccak-p.” IACR Cryptology ePrint Archive (2018), 19 pages. [cited by applicant]
Y. Akiya et al., “SHA-3-LPHP: Hardware Acceleration of SHA-3 for Low-Power High-Performance Systems,” 2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW), Wuhan, China, 2021, pp. 393… [cited by applicant]
International Searching Authority of European Patent Office, International Search Report and Written Opinion, International Application No. PCT/EP2023/071362, Oct. 18, 2023, 13 pages. [cited by applicant]
Y. Chen et al., “A programmable Galois Field processor for the Internet of Things,” 2017 ACM/IEEE 44th Annual International Symposium on Computer Architecture (ISCA), Toronto, ON, Canada, 2017, pp. 55-68, doi: 10.1145/3… [cited by applicant]
P202201607TW01 Office Action, Jul. 1, 2024, 4 pages, TW Patent Office (English Translation). [cited by applicant]
Dworkin, M., “SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions NIST FIPS 202,” Aug. 2015, 37 pages, National Institute of Standards and Technology, Gaithersburg, MD. [cited by applicant]
Adams, A. et al., “Cryptography Acceleration in a RISC-V GPGPU,” CARRV 2021, Jun. 17, 2021, 7 pages. [cited by applicant]
Anonymous, “Method of Early Detection and Halting of Ransomware Attacks,” IPCOM000268682D, Ip.com, Feb. 15, 2022, 5 pages. [cited by applicant]
Anonymous, “A Method to Reduce Stick Table Synchronization Storm Among Load Balancer Cluster,” IPCOM000268809D, Mar. 1, 2022, 6 pages, Ip.com. [cited by applicant]
Anonymous, “Method of Flash Acceleration in Replication for Consistent Hash Ring,” Mar. 13, 2016, 9 pages, IPCOM000245503D, Ip.com. [cited by applicant]
Gulley, S. et al., “Intel SHA Extensions: New Instructions Supporting the Secure Hash Algorithm on Intel Architecture Processors,” Jul. 2013, 22 pages, Intel Corporation. [cited by applicant]
Jang, K. et al., “SSL Shader: Cheap SSL Acceleration With Commodity Processors,” 8th USENIX Symposium on Networked Systems Design and Implementation, Mar. 2011, 14 pages, USENIX Association, Boston, MA. [cited by applicant]
NIST FIPS 180-4 “Secure Hash Standard,” Aug. 2015, 37 pages, National Institute of Standards and Technology, Gaithersburg, MD. [cited by applicant]
NIST FIPS 202 “SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions,” Aug. 2015, 37 pages, National Institute of Standards and Technology, Gaithersburg, MD. [cited by applicant]
TW IPO, Notice of Allowance for P202301322TW01, Sep. 26, 2024, 6 pages (English translation). [cited by applicant]
Taiwan Intellectual Property Bureau, Notice of Allowance in P202201845TW01 (English translation), Aug. 23, 2024, 6 pages. [cited by applicant]
Advanced Encryption Standard (AES), Nov. 26, 2001, pp. 1-51, FIPS Pub 197, National Institute of Standards and Technology (NIST), US. [cited by applicant]
Anonymous, “Method and System for Prevention of Anti-Tampering of Media Content,” IPCOM000259235D, Jul. 22, 2019, 4 pages, Ip.com. [cited by applicant]
Anonymous, “Parallelizable Hashing Algorithm,” IPCOM000254123D, Jun. 4, 2018, 2 pages, Ip.com. [cited by applicant]
Bos, J.W. et al., Performance Analysis of the SHA-3 Candidates on Exotic Multi-Core Architectures, CHES 2010 12th International Workshop, Aug. 17-20, 2010, 15 pages, Santa Barbara, CA. [cited by applicant]
Dworkin, M., “Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC,” NIST Special Publication SP800-38D, Nov. 2007, 39 pages, National institute for Standards and Technology, Gaithersbu… [cited by applicant]
Ghosh, Moinak, “Optimizing Rolling Hash Computation Using SIMD Vector Registers,” IPCOM000226555D, Apr. 16, 2013, 4 pages, Ip.com. [cited by applicant]
Gueron, S. et al., “Intel Carry-Less multiplication instruction and its usage for computing GCM Mode,” May 2010, 76 pages, Intel Corporation. [cited by applicant]
IEEE standard: 1619-2018, “IEEE Standard for Cryptographic Protection of Data on Block-Oriented Storage Devices,” Oct. 23, 2018, 41 pages, IEEE, New York, NY. [cited by applicant]
International Searching Authority of European Patent Office, International Search Report and Written Opinion, International Application No. PCT/EP2023/068147, Oct. 4, 2023, 14 pages. [cited by applicant]
Keller, S. et al., “Secure Hash Algorithm 3 Validation System (SHA3VS),” Jan. 29, 2016, 33 pages, National Institute of Standards and Technology, USA. [cited by applicant]
McGrew, D. et al., “The Galois/Counter Mode of Operation,” Feb. 2004, 43 pages. [cited by applicant]
Salehani, Y. et al., “NESHA-256, New 256-BIT Secure Hash Algorithm,” Cryptology ePrint Archive, Paper 2009/033, 2009, 16 pages, https://eprint.iacr.org/2009/033. [cited by applicant]
Appendix P, List of IBM Applications and Patent Treated as Related, 2 pages. [cited by applicant]
Pittalia, P. P., A comparative study of hash algorithms in cryptography, International Journal of Computer Science and Mobile Computing, 8(6), 147-152 (2019). [cited by applicant]
Rachh, Rashmi, et al., “Implementation of AES Key Schedule Using Look-Ahead Technique,” Circuits, Systems, and Signal Processing 33.11(2014): 3663-3670. [cited by applicant]
TW IPO, Office Action for P202201845TW01, Jan. 24, 2024, 9 pages. [cited by applicant]
International Searching Authority, Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, Nov. 11, 2023, 12 pages, International Application No. … [cited by applicant]
International Searching Authority, Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, Nov. 6, 2023, 12 pages, International Application No. P… [cited by applicant]