IP Library › Granted Patent US 11,917,053
Granted Patent B2
US 11,917,053 · App. 17/707,629 · Granted Feb 27, 2024

Combined SHA2 and SHA3 based XMSS hardware accelerator

Inventors: Santosh Ghosh (Hillsboro, OR); Vikram Suresh (Portland, OR); Sanu Mathew (Portland, OR); Manoj Sastry (Portland, OR); Andrew H. Reinders (Portland, OR); Raghavan Kumar (Hillsboro, OR); Rafael Misoczki (Hillsboro, OR)
Assignee: Intel Corporation
H04L9/0643G06F7/503G06F9/3012H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,917,053
App. No.
17/707,629
Granted
Feb 27, 2024
Kind
B2
Abstract

In one example an apparatus comprises a computer readable memory, an XMSS operations logic to manage XMSS functions, a chain function controller to manage chain function algorithms, a secure hash algorithm-2 (SHA2) accelerator, a secure hash algorithm-3 (SHA3) accelerator, and a register bank shared between the SHA2 accelerator and the SHA3 accelerator. Other examples may be described.

Claims (62)

1. An apparatus, comprising:

a secure hash algorithm-2 (SHA2) accelerator;

a secure hash algorithm-3 (SHA3) accelerator configurable to perform at least one of a SHAKE-128 function or to perform a SHAKE-256 operation and comprising:

a bit state register to receive a first set of inputs for a plurality of chain functions, a second set of inputs for hashes involved in an L-Tree computation, and a third set of inputs for a Merkle tree root node computation;

a processor to:

receive a 256 bit message input;

perform a set of 24 SHA3 rounds; and

generate a 128 bit output; and

a register bank shared between the SHA2 accelerator and the SHA3 accelerator.

2. The apparatus of claim 1 , the processor to:

receive, in computer readable memory, a set of XMSS inputs for an XMSS operation;

determine a selected accelerator from at least one of the SHA2 accelerator or the SHA3 accelerator; and

apply the set of inputs to the selected accelerator.

3. The apparatus of claim 2 , the processor to:

assert a busy signal on a communication bus; and

switch to a protected mode in which external read/write operations are disregarded.

4. The apparatus of claim 3 , the processor to:

determine whether the XMSS operation utilizes a one-time signature function, and in response to a determination that the XMSS operation requires a one-time signature function, to:

apply a one-time signature function process to the set of XMSS inputs; and

invoke a chain function controller to apply a chain function to facilitate the one-time signature function.

5. The apparatus of claim 1 , the SHA2 accelerator comprising a 64 bit datapath that is configurable to perform a single SHA2-512 round of operations or to perform two SHA2-256 rounds of operation in parallel.

6. The apparatus of claim 5 , the SHA2 accelerator comprising a conditional carry propagation circuitry to selectively apply a carry operation when the SHA2 accelerator is configured to perform the two SHA2-256 rounds of operation in parallel.

7. The apparatus of claim 5 , the SHA2 accelerator comprising a conditional carry propagation circuitry to selectively terminate a carry operation when the SHA2 accelerator is configured to the single SHA2-512 round of operation.

8. The apparatus of claim 1 , wherein the SHA3 accelerator is configurable to perform the SHAKE-128 function or to perform the SHAKE-256 operation.

9. The apparatus of claim 8 , the SHA3 accelerator comprising:

a computer readable memory; and

an XMSS operations processing circuitry to manage XMSS functions.

10. The apparatus of claim 8 , the SHA3 accelerator comprising:

a chain function controller to manage chain function algorithms.

11. An electronic device, comprising:

a computer-readable memory;

a secure hash algorithm-2 (SHA2) accelerator;

a secure hash algorithm-3 (SHA3) accelerator configurable to perform at least one of a SHAKE-128 function or to perform a SHAKE-256 operation and comprising:

a bit state register to receive a first set of inputs for a plurality of chain functions, a second set of inputs for hashes involved in an L-Tree computation, and a third set of inputs for a Merkle tree root node computation;

processing circuitry to:

receive a 256 bit message input;

perform a set of 24 SHA3 rounds; and

generate a 128 bit output; and

a register bank shared between the SHA2 accelerator and the SHA3 accelerator.

12. The electronic device of claim 11 , the processing circuitry to:

receive, in a computer readable memory, a set of XMSS inputs for an XMSS operation;

determine a selected accelerator from at least one of the SHA2 accelerator or the SHA3 accelerator; and

apply the set of inputs to the selected accelerator.

13. The electronic device of claim 12 , the processing circuitry to:

assert a busy signal on a communication bus; and

switch to a protected mode in which external read/write operations are disregarded.

14. The electronic device of claim 13 , the processing circuitry to:

determine whether the XMSS operation utilizes a one-time signature function, and in response to a determination that the XMSS operation requires a one-time signature function, to:

apply a one-time signature function process to the set of XMSS inputs; and

invoke a chain function controller to apply a chain function to facilitate the one-time signature function.

15. The electronic device of claim 11 , the SHA2 accelerator comprising a 64 bit datapath that is configurable to perform a single SHA2-512 round of operations or to perform two SHA2-256 rounds of operation in parallel.

16. The electronic device of claim 15 , the SHA2 accelerator comprising a conditional carry propagation circuitry to selectively apply a carry operation when the SHA2 accelerator is configured to perform the two SHA2-256 rounds of operation in parallel.

17. The electronic device of claim 15 , the SHA2 accelerator comprising a conditional carry propagation circuitry to selectively terminate a carry operation when the SHA2 accelerator is configured to the single SHA2-512 round of operation.

18. The electronic device of claim 11 , wherein the SHA3 accelerator is configurable to perform the SHAKE-128 function or to perform the SHAKE-256 operation.

19. The electronic device of claim 18 , the SHA3 accelerator comprising:

an XMSS operations processing circuitry to manage XMSS functions.

20. The electronic device of claim 18 , the SHA3 accelerator comprising:

a 1600 bit state register to receive a first set of inputs for each WOTS chain function, a second set of inputs for hashes involved in an L-Tree computation, and a third set of inputs for a Merkle tree root node computation; and

processing circuitry to:

receive a 512 bit message input;

perform two sets of 24 SHA3 rounds; and

generate a 256 bit output.

Continuity (2)
Continuation 16455950 · Jun 28, 2019
Related Publication 20220224514A1 · Jul 14, 2022