IP Library Granted Patent US 11,456,877
Granted Patent B2
US 11,456,877 · App. 16/456,187 · Granted Sep 27, 2022

Unified accelerator for classical and post-quantum digital signature schemes in computing environments

Inventors: Sanu Mathew (Portland, OR); Manoj Sastry (Portland, OR); Santosh Ghosh (Hillsboro, OR); Vikram Suresh (Portland, OR); Andrew H. Reinders (Portland, OR); Raghavan Kumar (Hillsboro, OR); Rafael Misoczki (Hillsboro, OR)
Assignee: INTEL CORPORATION
H04L9/3247G06F21/76H04L9/0869H04L9/3239H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,456,877
App. No.
16/456,187
Granted
Sep 27, 2022
Kind
B2
Abstract

A mechanism is described for facilitating unified accelerator for classical and post-quantum digital signature schemes in computing environments. A method includes unifying classical cryptography and post-quantum cryptography through a unified hardware accelerator hosted by a trusted platform of the computing device. The method may further include facilitating unification of a first finite state machine associated with the classical cryptography and a second finite state machine associated with the post-quantum cryptography though one or more of a single the hash engine, a set of register file banks, and a modular exponentiation engine.

Claims (39)

1. At least one non-transitory machine-readable medium comprising instructions which, when executed by a computing device, cause the computing device to perform operations comprising:

unifying classical cryptography and post-quantum cryptography through a unified hardware accelerator hosted by a trusted platform of the computing device;

facilitating unification of a first finite state machine associated with the classical cryptography and a second finite state machine associated with the post-quantum cryptography using one or more of a hash engine, a set of register file banks, and a modular exponentiation engine, wherein the hash engine, the set of register file banks, and the module exponentiation engine are allowed direct memory access;

computing a bitmask based on an address and a seed and writing the bitmask to a first bank of the set of register file banks using the hash engine;

computing a key based on the address and the seed and writing the key to a second bank of the set of register file banks using the hash engine;

fetching a first hash function from a third bank of the set of register file banks and adding the first hash function to the bitmask in the first bank; and

appending results of the addition of the first hash function to the bitmask to the key.

2. The non-transitory machine-readable medium of claim 1 , wherein the first finite state machine comprises a classical public key cryptography signatures (PKCS) finite state machine, and wherein the second finite state machine comprises an extended Merkel signature scheme (XMSS) finite state machine, wherein the trusted platform includes a field-programmable gate array (FPGA) platform coupled to one or more processors including a central processing unit, wherein the hash engine comprises a secure hash algorithm (SHA) engine.

3. The non-transitory machine-readable medium of claim 1 , wherein the operations further comprise:

computing a second hash function based on the results using the hash engine;

writing the results to the third bank; and

upon completing a signature and verification loop, fetching the results from the third bank through direct memory access.

4. The non-transitory machine-readable medium of claim 1 , wherein the computing device comprises one or more processors including one or more of an application processor and a graphics processor, wherein the one or more processors are co-located on a common semiconductor package.

5. A method comprising:

unifying classical cryptography and post-quantum cryptography through a unified hardware accelerator hosted by a trusted platform of the computing device;

facilitating unification of a first finite state machine associated with the classical cryptography and a second finite state machine associated with the post-quantum cryptography using one or more of a hash engine, a set of register file banks, and a modular exponentiation engine, wherein the hash engine, the set of register file banks, and the module exponentiation engine are allowed direct memory access;

computing a bitmask based on an address and a seed and writing the bitmask to a first bank of the set of register file banks using the hash engine;

computing a key based on the address and the seed and writing the key to a second bank of the set of register file banks using the hash engine;

fetching a first hash function from a third bank of the set of register file banks and adding the first hash function to the bitmask in the first bank; and

appending results of the addition of the first hash function to the bitmask to the key.

6. The method of claim 5 , wherein the first finite state machine comprises a classical public key cryptography signatures (PKCS) finite state machine, and wherein the second finite state machine comprises an extended Merkel signature scheme (XMSS) finite state machine, wherein the trusted platform includes a field-programmable gate array (FPGA) platform coupled to one or more processors including a central processing unit, wherein the hash engine comprises a secure hash algorithm (SHA) engine.

7. The method of claim 5 , further comprising:

computing a second hash function based on the results using the hash engine;

writing the results to the third bank; and

upon completing a signature and verification loop, fetching the results from the third bank through direct memory access.

8. The method of claim 5 , wherein the method is facilitated by a computing device having one or more processors including one or more of an application processor or a graphics processor, wherein the one or more processors are co-located on a common semiconductor package.

9. An apparatus comprising:

one or more processors to:

unify classical cryptography and post-quantum cryptography through a unified hardware accelerator hosted by a trusted platform of the computing device;

facilitate unification of a first finite state machine associated with the classical cryptography and a second finite state machine associated with the post-quantum cryptography using one or more of a hash engine, a set of register file banks, and a modular exponentiation engine, wherein the hash engine, the set of register file banks, and the module exponentiation engine are allowed direct memory access;

compute a bitmask based on an address and a seed and writing the bitmask to a first bank of the set of register file banks using the hash engine;

compute a key based on the address and the seed and writing the key to a second bank of the set of register file banks using the hash engine;

fetch a first hash function from a third bank of the set of register file banks and adding the first hash function to the bitmask in the first bank; and

append results of the addition of the first hash function to the bitmask to the key.

10. The apparatus of claim 9 , wherein the first finite state machine comprises a classical public key cryptography signatures (PKCS) finite state machine, and wherein the second finite state machine comprises an extended Merkel signature scheme (XMSS) finite state machine, wherein the trusted platform includes a field-programmable gate array (FPGA) platform coupled to one or more processors including a central processing unit, wherein the hash engine comprises a secure hash algorithm (SHA) engine.

11. The apparatus of claim 9 , wherein the one or more processors are further to:

compute a second hash function based on the results using the hash engine;

write the results to the third bank; and

upon completing a signature and verification loop, fetch the results from the third bank through direct memory access, wherein the one or more processors include one or more of the central processing unit and a graphics processing unit, wherein the one or more processors are co-located on a common semiconductor package.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2019
From: MATHEW, SANU; SASTRY, MANOJ; GHOSH, SANTOSH; SURESH, VIKRAM; REINDERS, ANDREW H.; KUMAR, RAGHAVAN; MISOCZKI, RAFAEL
To: INTEL CORPORATION
Reel/Frame 051221/0467 →
Continuity (1)
Related Publication 20190319804A1 · Oct 17, 2019
Cited By (1)
US 12,445,303