IP Library › Granted Patent US 12,288,064
Granted Patent B2
US 12,288,064 · App. 17/884,739 · Granted Apr 29, 2025

Hardware-based message block padding for hash algorithms

Inventors: Manoj Kumar (Yorktown Heights, NY); Silvia Melitta Mueller (St. Ingbert, DE); Debapriya Chatterjee (Austin, TX); Niels Fricke (Herrenberg, DE); Martijn Diede Berkers (Boeblingen, DE)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F9/30101G06F9/3802H04L9/0643G09C1/00H04L2209/12H04L2209/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,288,064
App. No.
17/884,739
Granted
Apr 29, 2025
Kind
B2
Abstract

A processor includes an execution unit for executing a message padding instruction including an operand field indicating a register buffering a message block segment of a message block to be padded and a mode field indicating which hash functions is to be applied to the message block. The execution unit includes a padding circuit configured to receive a message block segment from a register indicated by the operand field, where the message block spans multiple registers in a register file. Based on which hash function is indicated by the mode field, the padding circuit selects a byte location in the message block segment at which to insert at least one padding byte and inserts the at least one padding byte at the byte location within the message block segment. The message block segment as padded by the at least one padding byte is written back to the register file.

Claims (68)

1. A processor, comprising:

an instruction fetch unit that fetches instructions to be executed;

a register file including a plurality of registers for storing source and destination operands; and

an execution unit for executing a message padding instruction among the instructions, wherein the message padding instruction includes an operand field indicating one of the plurality of registers buffering a message block segment of a message block to be padded and a mode field indicating which one of a plurality of different hash functions is to be applied to the message block, wherein the execution unit includes a padding circuit configured, based on execution of the message padding instruction by the execution unit, to perform:

receiving the message block segment from one of the plurality of registers indicated by the operand field of the message padding instruction, wherein the message block spans multiple registers in the register file;

based on which one of the plurality of different hash functions is indicated by the mode field of the message padding instruction, determining whether at least one padding byte is to be inserted within the message block segment;

based on determining that the at least one padding byte is to be inserted within the message block segment, selecting a byte location among multiple byte locations in the message block segment at which to insert the at least one padding byte based on which one of the plurality of different hash function is indicated by the mode field and inserting the at least one padding byte at the selected byte location within the message block segment;

based on determining that the at least one padding byte is not to be inserted within the message block segment, refraining from inserting any padding byte within the message block segment; and

writing the message block segment as processed by the padding circuit back to the register file;

wherein the padding circuit includes at least one enable circuit configured to generate an enable vector to select the byte location and an OR circuit coupled to receive the enable vector and the message block segment and configured to insert, based on the enable vector, the at least one padding byte at the selected byte location in the message block segment.

2. The processor of claim 1 , wherein the plurality of different hash functions includes SHA3, SHAKE, and SHA2 hash functions.

3. The processor of claim 1 , wherein:

the message block includes multiple message block segments; and

the padding circuit is configured to detect, based on an indication in an extension field of the message padding instruction, which of the multiple message block segments the message block segment is.

4. The processor of claim 1 , wherein:

the plurality of different hash functions includes a first hash function and a second hash function; and

the padding circuit is configured to insert both end-of-message (EOM) padding and end-of-block (EOB) padding in the message block segment based on the mode field indicating the first hash function and is configured to insert EOM padding but not EOB padding in the message block segment based on the mode field indicating the second hash function.

5. The processor of claim 1 , wherein: the plurality of hash functions includes a first hash function and a second hash function;

the selecting includes selecting the byte location based on a length parameter stored in the register indicated by the operand mode field of the message padding instruction; and

the padding circuit is configured to insert the at least one padding byte at a first byte location based on the length parameter given the mode field indicating the first hash function and to insert the at least one padding byte at a different second byte location based on the length parameter given the mode field indicating the second hash function.

6. The processor of claim 1 , wherein:

the padding circuit includes a select circuit configured to select a value of the at least one padding byte among multiple different values based on which one of the plurality of different hash functions is indicated by the mode field of the padding instruction.

7. The processor of claim 1 , wherein:

the register file is a first register file;

the plurality of registers is a first plurality of registers;

the processor includes a second register file including a second plurality of registers each having a length less than that of the first plurality of registers;

the execution unit is further configured to assemble multiple chunks of the message block segment in multiple registers among the second plurality of registers and transfer all of the multiple chunks into one of the first plurality of registers to form the message block segment.

8. The processor of claim 7 , wherein the processor is further configured to insert end-of-block (EOB) padding into one of the multiple registers among the second plurality of registers prior to transfer of the multiple chunks to said one of the first plurality of registers.

9. The processor of claim 1 , wherein:

the enable vector has a length in bits corresponding to a length of the message block segment in bytes; and

inserting the at least one padding byte includes inserting the at least one padding byte at the byte location in the message block segment identified by the enable vector.

10. The processor of claim 1 , wherein:

inserting the at least one padding byte includes logically combining an end-of-block (EOB) padding byte with an end-of-message (EOM) padding byte utilizing a Boolean operation to obtain a combined padding byte and inserting the combined padding byte.

11. The processor of claim 1 , wherein:

the execution unit includes a hash circuit that is configured, based on a hash instruction among the instructions, to apply a hash function among the SHA family of hash functions to a padded message block including the message block segment as padded.

12. The processor of claim 1 , wherein:

the message block segment is a portion of a message comprising a plurality of message blocks having an identical length of r bits;

the message block, as padded, includes r bits; and

each of the plurality of registers has a length of less than r bits.

13. A method of data processing in a processor including a register file, said method comprising:

fetching, by an instruction fetch unit of the processor, instructions to be executed by the processor, wherein the instructions include a message padding instruction including an operand field indicating one of the plurality of registers buffering a message block segment of a message block to be padded and a mode field indicating which one of a plurality of different hash functions is to be applied to the message block; and

based on receiving the message padding instruction, an execution unit of the processor executing the message padding instruction, wherein executing the message padding instruction includes:

receiving, from the register file, the message block segment from one of the plurality of registers indicated by the operand field of the message padding instruction, wherein the message block spans multiple registers in the register file;

based on which one of the plurality of different hash functions is indicated by the mode field of the message padding instruction, determining whether at least one padding byte is to be inserted within the message block segment;

based on determining that the at least one padding byte is to be inserted within the message block segment, selecting a byte location among multiple byte locations in the message block segment at which to insert the at least one padding byte based on which one of the plurality of different hash function is indicated by the mode field and inserting the at least one padding byte at the selected byte location within the message block segment, wherein:

the selecting includes generating by an enable circuit an enable vector specifying the byte location; and

the inserting includes merging by an OR circuit, coupled to receive the enable vector and the message block segment, the at least one padding byte and the message block vector;

based on determining that the at least one padding byte is not to be inserted within the message block segment, refraining from inserting any padding byte within the message block segment; and

writing the message block segment as processed by the padding circuit back to the register file.

14. The method of claim 13 , wherein:

the message block includes multiple message block segments; and

the method further comprising detecting, based on an indication in an extension field of the message padding instruction, which of the multiple message block segments the message block segment is.

15. The method of claim 13 , wherein:

the plurality of different hash functions includes a first hash function and a second hash function; and

the executing includes inserting both end-of-message (EOM) padding and end-of-block (EOB) padding in the message block segment based on the mode field indicating the first hash function and is configured to insert EOM padding but not EOB padding in the message block segment based on the mode field indicating the second hash function.

16. The method of claim 13 , wherein: the plurality of hash functions includes a first hash function and a second hash function;

the selecting includes selecting the byte location based on a length parameter stored in the register indicated by the mode field of the message padding instruction; and

the inserting includes inserting the at least one padding byte at a first byte location based on the length parameter given the mode field indicating the first hash function and inserting the at least one padding byte at a different second byte location based on the length parameter given the mode field indicating the second hash function.

17. The method of claim 13 , further comprising:

selecting, by the execution unit, a value of the at least one padding byte among multiple different values based on which one of a plurality of different hash functions is indicated by the mode field of the padding instruction.

18. The method of claim 13 , wherein:

the register file of the processor is a first register file;

the plurality of registers is a first plurality of registers;

the processor includes a second register file including a second plurality of registers each having a length less than that of the first plurality of registers;

the method further comprises assembling multiple chunks of the message block segment in multiple registers among the second plurality of registers and transferring all of the multiple chunks into one of the first plurality of registers to form the message block segment.

19. The method of claim 18 , further comprising inserting end-of-block (EOB) padding into one of the multiple registers among the second plurality of registers prior to transfer of the multiple chunks to said one of the first plurality of registers.

20. The method of claim 13 , further comprising:

based on a hash instruction among the instructions, applying, by hash circuit of the processor, a hash function among the SHA family of hash functions to a padded message block including the message block segment as padded.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2022
From: KUMAR, MANOJ; MUELLER, SILVIA MELITTA; CHATTERJEE, DEBAPRIYA; FRICKE, NIELS; BERKERS, MARTIJN D.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 060767/0707 →
Continuity (1)
Related Publication 20240053989A1 · Feb 15, 2024
References Cited (89)
US 7295671B2 · Snell · 2007 [cited by applicant]
US 7702100B2 · Han · 2010 [cited by applicant]
US 7783037B1 · Bong · 2010 [cited by applicant]
US 8042025B2 · Gopal · 2011 [cited by applicant]
US 8194854B2 · Gueron · 2012 [cited by applicant]
US 8340280B2 · Gueron · 2012 [cited by applicant]
US 8913740B2 · Gueron · 2014 [cited by applicant]
US 10129018B2 · Satpathy · 2018 [cited by applicant]
US 10142098B2 · Suresh · 2018 [cited by applicant]
US 10256971B2 · Gueron · 2019 [cited by applicant]
US 10305680B2 · Gomes · 2019 [cited by applicant]
US 10313108B2 · Suresh · 2019 [cited by applicant]
US 10346343B2 · Suresh · 2019 [cited by applicant]
US 10348506B2 · Greiner · 2019 [cited by applicant]
US 10432393B2 · Gueron · 2019 [cited by applicant]
US 10581593B2 · Gomes · 2020 [cited by applicant]
US 10877753B2 · Bradbury · 2020 [cited by applicant]
US 10924282B2 · Brostrom · 2021 [cited by applicant]
US 11121856B2 · Satpathy · 2021 [cited by applicant]
US 11128443B2 · Gueron · 2021 [cited by applicant]
US 20020066014A1 · Dworkin · 2002 [cited by examiner]
US 20030135530A1 · Parthasarathy · 2003 [cited by applicant]
US 20040202317A1 · Demjanenko · 2004 [cited by applicant]
US 20040252831A1 · Uehara · 2004 [cited by applicant]
US 20040255130A1 · Henry · 2004 [cited by applicant]
US 20050089160A1 · Crispin · 2005 [cited by examiner]
US 20080240423A1 · Gueron · 2008 [cited by applicant]
US 20090052659A1 · Gueron · 2009 [cited by applicant]
US 20090141887A1 · Yap · 2009 [cited by applicant]
US 20100049986A1 · Watanabe · 2010 [cited by examiner]
US 20110231636A1 · Olson · 2011 [cited by applicant]
US 20110246548A1 · Yen · 2011 [cited by applicant]
US 20110255689A1 · Bolotov · 2011 [cited by applicant]
US 20150043729A1 · Gopal · 2015 [cited by applicant]
US 20150098563A1 · Gulley · 2015 [cited by applicant]
US 20160119126A1 · Shay · 2016 [cited by applicant]
US 20170134163A1 · Suresh · 2017 [cited by applicant]
US 20170373836A1 · Rarick · 2017 [cited by applicant]
US 20180122271A1 · Ghosh · 2018 [cited by applicant]
US 20190205093A1 · Suresh · 2019 [cited by applicant]
US 20190286443A1 · Solomatnikov et al. · 2019 [cited by applicant]
US 20190319782A1 · Ghosh · 2019 [cited by applicant]
US 20190386815A1 · Satpathy · 2019 [cited by applicant]
US 20200134234A1 · Lemay · 2020 [cited by applicant]
US 20210152330A1 · Satpathy · 2021 [cited by applicant]
US 20210203504A1 · Brandt · 2021 [cited by applicant]
US 20220206958A1 · LeMay · 2022 [cited by applicant]
US 20230269076A1 · Brandt · 2023 [cited by applicant]
CN 1658550A · 2005 [cited by applicant]
CN 112152785A · 2020 [cited by applicant]
CN 113485751A · 2021 [cited by applicant]
EP 1449063B1 · 2004 [cited by applicant]
TW 200536331A · 2005 [cited by applicant]
TW 201135477A · 2011 [cited by applicant]
TW 201203108A · 2012 [cited by applicant]
TW 201519623A · 2015 [cited by applicant]
TW 201717573A · 2017 [cited by applicant]
Pittalia, P. P. (2019), A comparative study of hash algorithms in cryptography, International Journal of Computer Science and Mobile Computing, 8(6), 147-152 (Year: 2019). [cited by examiner]
National Institute of Standards and Technology (NIST) (2015), SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions, FIPS PUB 202, 1-37 (Year: 2015). [cited by examiner]
Bertoni, Guido et al., “KangarooTwelve: fast hashing based on Keccak-p.” IACR Cryptology ePrint Archive (2018), 19 pages. [cited by applicant]
Dworkin, M., “SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions NIST FIPS 202,” Aug. 2015, 37 pages, National Institute of Standards and Technology, Gaithersburg, MD. [cited by applicant]
Y. Akiya et al., “SHA-3-LPHP: Hardware Acceleration of SHA-3 for Low-Power High-Performance Systems,” 2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW), Wuhan, China, 2021, pp. 393… [cited by applicant]
Adams, A. et al., “Cryptography Acceleration in a RISC-V GPGPU,” CARRV 2021, Jun. 17, 2021, 7 pages. [cited by applicant]
Advanced Encryption Standard (AES), Nov. 26, 2001, pp. 1-51, FIPS PUB 197, National Institute of Standards and Technology (NIST), US. [cited by applicant]
Anonymous, “Method of Early Detection and Halting of Ransomware Attacks,” IPCOM000268682D, IP.com, Feb. 15, 2022, 5 pages. [cited by applicant]
Anonymous, “A Method to Reduce Stick Table Synchronization Storm Among Load Balancer Cluster,” IPCOM000268809D, Mar. 1, 2022, 6 pages, IP.com. [cited by applicant]
Anonymous, “Method of Flash Acceleration in Replication for Consistent Hash Ring,” Mar. 13, 2016, 9 pages, IPCOM000245503D, IP.com. [cited by applicant]
Dworkin, M., “Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC,” NIST Special Publication SP800-38D, Nov. 2007, 39 pages, National institute for Standards and Technology, Gaithersbu… [cited by applicant]
Gueron, S. et al., “Intel Carry-Less multiplication instruction and its usage for computing GCM Mode,” May 2010, 76 pages, Intel Corporation. [cited by applicant]
Gulley, S. et al., “Intel SHA Extensions: New Instructions Supporting the Secure Hash Algorithm on Intel Architecture Processors,” Jul. 2013, 22 pages, Intel Corporation. [cited by applicant]
IEEE standard: 1619-2018, “IEEE Standard for Cryptographic Protection of Data on Block-Oriented Storage Devices,” Oct. 23, 2018, 41 pages, IEEE, New York, NY. [cited by applicant]
Jang, K. et al., “SSL Shader: Cheap SSL Acceleration With Commodity Processors,” 8th USENIX Symposium on Networked Systems Design and Implementation, Mar. 2011, 14 pages, USENIX Association, Boston, MA. [cited by applicant]
McGrew, D. et al., “The Galois/Counter Mode of Operation,” Feb. 2004, 43 pages. [cited by applicant]
NIST FIPS 180-4 “Secure Hash Standard,” Aug. 2015, 37 pages, National Institute of Standards and Technology, Gaithersburg, MD. [cited by applicant]
NIST FIPS 202 “SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions,” Aug. 2015, 37 pages, National Institute of Standards and Technology, Gaithersburg, MD. [cited by applicant]
Appendix P, List of IBM Patents or Patent Applications Treated as Related, 2 pages. [cited by applicant]
International Searching Authority of European Patent Office, International Search Report and Written Opinion, International Application No. PCT/EP2023/068147, Oct. 4, 2023, 14 pages. [cited by applicant]
International Searching Authority of European Patent Office, International Search Report and Written Opinion, International Application No. PCT/EP2023/071362, Oct. 18, 2023, 13 pages. [cited by applicant]
Y. Chen et al., “A programmable Galois Field processor for the Internet of Things,” 2017 ACM/IEEE 44th Annual International Symposium on Computer Architecture (ISCA), Toronto, ON, Canada, 2017, pp. 55-68, doi: 10.1145/3… [cited by applicant]
Anonymous, “Method and System for Prevention of Anti-Tampering of Media Content,” IPCOM000259235D, Jul. 22, 2019, 4 pages, IP.com. [cited by applicant]
Anonymous, “Parallelizable Hashing Algorithm,” IPCOM000254123D, Jun. 4, 2018, 2 pages, IP.com. [cited by applicant]
Bos, J.W. et al., Performance Analysis of the SHA-3 Candidates on Exotic Multi-Core Architectures, CHES 2010 12th International Workshop, Aug. 17-20, 2010, 15 pages, Santa Barbara, CA. [cited by applicant]
Ghosh, Moinak, “Optimizing Rolling Hash Computation Using Simd Vector Registers,” IPCOM000226555D, Apr. 16, 2013, 4 pages, IP.com. [cited by applicant]
Keller, S. et al., “Secure Hash Algorithm 3 Validation System (SHA3VS),” Jan. 29, 2016, 33 pages, National Institute of Standards and Technology, USA. [cited by applicant]
Salehani, Y. et al., “NESHA-256, New 256-BIT Secure Hash Algorithm,” Cryptology ePrint Archive, Paper 2009/033, 2009, 16 pages, https://eprint.iacr.org/2009/033. [cited by applicant]
TW IPO, Notice of Allowance for P202301322TW01, Sep. 26, 2024, 6 pages (English translation). [cited by applicant]
P202201607TW01 Office Action, Jul. 1, 2024, 4 pages, TW Patent Office (English Translation). [cited by applicant]
International Searching Authority, Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, Nov. 11, 2023, 12 pages, International Application No. … [cited by applicant]
International Searching Authority, Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, Nov. 6, 2023, 12 pages, International Application No. P… [cited by applicant]