Apparatus and method for reducing sequential bit correlation in a random number generator
Abstract
An apparatus and method for reducing sequential bit correlation in a random number generator. The method includes generating a stream of random bits and selecting every Nth bit from the stream for accumulation and delivery to the requesting software application rather than delivering all the bits in the stream, where N is a programmable value. In one embodiment, the apparatus for carrying out the method includes a microprocessor that includes elements such as an arithmetic and logic unit, store unit, branching circuitry, and registers that execute instructions specified in microcode stored in a microcode memory. In another embodiment, the apparatus includes a plurality of multiplexers that selectevery Nth bit. In one embodiment, N is specified as an input parameter to a microprocessor instruction that stores the random bits selected.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
32 claims: 29 independent, 3 dependent
- 1一種用於改善由一隨機亂數產生器所產生資料之隨機性的方法,包括以下步驟:由一隨機位元產生器產生複數個位元;從該複數個位元中選出每第N個位元,其中,N為大於1的整數;以及累積所選出的每第N個位元。
- 2如申請專利範圍第1項所述之方法,更包括有以下步驟:捨棄未被選定的複數個位元。
- 3如申請專利範圍第1項所述之方法,其中該累積步驟包括將該每第N個位元累積到一微處理器之一暫存器中。
- 4如申請專利範圍第3項所述之方法,更包括:儲存已累積的該每第N個位元。
- 5如申請專利範圍第4項所述之方法,其中該儲存步驟包括將已累積的該每第N個位元儲存到連接該微處理器之一記憶體。
- 6如申請專利範圍第4項所述之方法,其中該儲存步驟包括將已累積的該每第N個位元儲存到在該微處理器之一第二暫存器。
- 7如申請專利範圍第4項所述之方法,其中儲存已累積的該每第N個位元被執行,以回應該微處理器執行用來儲存一部份該複數個位元的一指令。
- 8如申請專利範圍第3項所述之方法,其中在該微處理器中該N值是可程式化的。
- 9如申請專利範圍第1項所述之方法,其中該N值是由2的冪次所組成。
- 10如申請專利範圍第1項所述之方法,更包括:設定一值到一暫存器中;及在選出該每第N個位元之前,根據設定到該暫存器中的該值計算出該N值。
- 11一種微處理器,包括:一隨機位元產生器,用以產生一串隨機位元;以及一算數邏輯單元,連接該隨機位元產生器,用以選擇在該串隨機位元的每第N個位元,其中,N為大於1的整數,並用以累積被選定的每第N個位元到連接該算數邏輯單元之一暫存器。
- 12如申請專利範圍第11項所述之該微處理器,更包括:一可程式化暫存器,連接到該算數邏輯單元,用以儲存計算該N值的一值。
- 13如申請專利範圍第12項所述之該微處理器,其中,該N值可為2的x次方,x為儲存在可程式化暫存器的該值。
- 14如申請專利範圍第12項所述之該微處理器,其中該N值可為儲存在可程式化暫存器的該值。
- 15如申請專利範圍第11項所述之該微處理器,更包括:一指令轉譯器,用以將在該微處理器中一指令集之一指令轉譯,該指令指示該微處理器儲存已選出及累積之該每第N個位元。
- 16如申請專利範圍第15項所述之該微處理器,其中該指令將已選出及累積之該每第N個位元,儲存到連接該處理器之一記憶體。
- 17如申請專利範圍第15項所述之該微處理器,其中該指令將已選出之該每第N個位元,儲存到連接該算數邏輯單元之一第二暫存器。
- 18如申請專利範圍第15項所述之該微處理器,其中該N為該指令之一輸入參數。
- 19如申請專利範圍第18項所述之該微處理器,其中該N值為一指令之輸入參數,被儲存在該微處理器之一通用暫存器中。
- 20如申請專利範圍第15項所述之該微處理器,更包括:一記憶體,連接到該算數邏輯單元,用以儲存複數個微碼指令,該微碼指令包括用以執行該指令的複數個指令。
- 21如申請專利範圍第20項所述之該微處理器,其中該複數個指令包括有一或多個指令,以指示該算數邏輯單元將該串隨機位元移動N個位元。
- 22如申請專利範圍第21項所述之該微處理器,其中該複數個指令包括有一或多個指令,以指示該算數邏輯單元執行邏輯運算以取出被移動的該串隨機位元之一。
- 23如申請專利範圍第22項所述之該微處理器,其中取出被移動該串隨機位元之一的邏輯運算包括一邏輯及(AND)運算。
- 24如申請專利範圍第22項所述之該微處理器,該複數個指令包括有一或多個指令以指示該算數邏輯單元執行算數或邏輯運算以累積被移動的該串隨機位元之一到該暫存器。
- 25如申請專利範圍第24項所述之該微處理器,其中該算數或邏輯運算以累積被移動的該串隨機位元之一到的該暫存器包括一加法運算。
- 26如申請專利範圍第24項所述之該微處理器,其中該算數或邏輯運算以累積被移動的該串隨機位元之一到的該暫存器包括一移位(shift)運算。
- 27如申請專利範圍第11項所述之該微處理器,其中該N值大於0。
- 28一種用以減低連續隨機位元間的相關性之裝置,包括:一隨機位元產生器,用以產生一組隨機位元;一第一暫存器,連接到該隨機位元產生器,用以儲存該組隨機位元;複數個多工器,連接到該第一暫存器,用以選擇在該組隨機位元的每第N個位元,該複數個多工器藉由一控制值選擇每第N個位元;以及一第二暫存器,連接到該複數個多工器,用以儲存該複數個多工器所選擇之該組隨機位元的每第N個位元。
- 29如申請專利範圍第28項所述之該裝置,其中該N值始可程式化的。
- 30如申請專利範圍第28項所述之該裝置,其中該N值可為2的x次方,該x值由該控制信號所指定。
- 31如申請專利範圍第28項所述之該裝置,其中該N值為大於0的整數。
- 32如申請專利範圍第28項所述之該裝置,其中該N值為大於1的整數。
Independent claims32
273 paragraphs, as filed
Apparatus and method for reducing continuous bit correlation in random random number generator
[0001] The present invention is related to the field of random random number generation methods, and particularly refers to a random random number generation method without random correlation between consecutive bits.
[0002] From a historical point of view, many computer applications need to provide random numbers. For example, Monte Carlo simulations of physical phenomena, such as large-scale weather simulations, need to provide random numbers to simulate physical phenomena. Other examples that require random numbers are casino games and online gambling to simulate card shuffling, rolling dice, etc.; the generation of lottery numbers; the generation of statistical analysis data, such as psychological tests; and computer games.
[0003] In these types of applications, the required randomness and the performance requirements for generating random numbers are different. Many application software, such as computer games, have low requirements for randomness. The application of psychology tests has stricter requirements for randomness, but the performance requirements are quite low. However, large-scale use of Monte Carlo simulations will have very high performance requirements and require good random number statistics characteristics, although unpredictability is not particularly important. Other applications, such as online gambling, have very strict requirements for randomness and unpredictability.
[0004] Although the above-mentioned applications are still important, in the field of computer security, there is the greatest demand for high-quality random numbers. Recently, the explosive growth of personal computer networks and Internet transactions has significantly increased the demand for various security mechanisms.
[0005] For all the main components of computer security, high-quality random numbers are necessary. These elements include confidentiality, identification and data integrity.
[0006] Data encryption is the main mechanism for providing confidentiality. There are many different encryption algorithms, such as symmetric encryption, public keys, and one-time pads, but these algorithms all have a key feature, that is, the encryption/decryption key cannot be simply predicted. The cipher strength of an encryption system is basically the strength of the key it uses, that is, how difficult it is to predict, guess, or calculate the decryption key. The best key is a long enough real random number, and in all applications that strictly require security, the random number generator is the basis for generating cryptographic keys.
[0007] Many successful attacks on cryptographic algorithms have not focused on encryption algorithms, but have focused on the sources of random numbers. A well-known example is the early version of Netscapes Secure Sockets Layer (SSL), which collects data from the system clock and program ID table to generate the initial value of the software-based quasi-random number generator. . The random number generated is used to generate a symmetric key to encrypt communication data. Two graduate students came up with a program that can accurately guess random numbers. Within a minute, they guessed the communication key, destroying this mechanism.
[0008] Similar to the decryption key, the strength of the password used to confirm the identity of the user accessing the information is actually how difficult it is to predict or guess the password. The best password is a long enough real random number. In addition, in an authentication protocol that uses a challenge protocol, the key factor is that the password cannot be predicted by the confirming party. Random numbers are used to generate secret codes to confirm identity.
[0009] Digital signatures and message digests are used to ensure the integrity of communications on the Internet. Random numbers are used in most digital signature algorithms to make it difficult for malicious parties to forge signatures. The quality of the random number will directly affect the validity of the signature. All in all, good security requires good random numbers.
[0010] The value itself is not random. The definition of randomness must include not only the characteristics of the generated value, but also the characteristics of the generator used to generate the value. Random number generators using software are common and sufficient for many applications. However, for some applications, software-based generators are insufficient. These applications require a hardware generator that can generate values with the same characteristics as those generated by random physical procedures. Here, the important characteristics are the degree of unbiased statistical distribution of the generated values, and the degree of unpredictability and non-reproducibility.
[0011] Having an unbiased statistical distribution means that all values have an equal probability of occurrence, regardless of the sample size. Almost all applications require a good statistical distribution of random numbers, and high-quality software random number generators can usually meet this demand. A generator that only satisfies the demand for unbiased statistical distribution is called a quasi random number generator.
[0012] Unpredictability means that in a bit sequence, the probability of correctly guessing the next bit should be exactly half, regardless of the bit value previously generated. Some applications do not need this feature of unpredictability; however, it is important for random numbers used in security applications. If a software generator is used, the software algorithm and its initial value must be hidden in order to effectively meet the unpredictable demand. From a security point of view, the practice of hiding the algorithm is very unsafe. For application software that uses predictable hidden algorithm random number generators, there are many well-known examples of security breaches. The generator that satisfies the first two requirements at the same time is called a cryptographic security quasi random number generator.
[0013] If the generator is not reproducible, two identical generators with the same initial conditions must produce different outputs. Software algorithms cannot meet this demand. Only a hardware generator based on a random physical program can generate a value that meets the strict non-reproducibility required for security. A generator that meets all three requirements is called a true random number generator.
[0014] Software algorithms are used to generate most of the random numbers required by computer applications. These are called quasi random number generators, because these generators cannot meet the requirements of unpredictability and non-reproducibility. Furthermore, some cannot meet the demand for unbiased statistical distribution.
[0015] Generally, the software generator starts with an initial value or seed (seed), and the initial value is sometimes provided by the user. The generator performs arithmetic operations with the initial value to generate a first random result, which serves as a seed for generating the second result, and so on. The software generator must be cyclic, and eventually it will repeat the same output sequence. Guessing the seed is equivalent to predicting the entire generated sequence of values. Its non-reproducibility is only the same as the confidentiality of the algorithm and the initial seed, which may be an undesirable feature for security applications. Furthermore, the software algorithm is reproducible, because starting with the same input, it will produce the same result. Finally, the software algorithm does not necessarily generate every possible value within the range of the output data size, which may not fully meet the demand for unbiased statistical distribution.
[0016] There is a random number generator, which is a mixture of a software generator and a pure hardware generator, and is called an entropy generator. Entropy is another term for unpredictability. The more unpredictable the value produced by the generator, the more entropy the generator has. The entropy generator applies software algorithms to seeds produced by physical phenomena. For example, a commonly used PC encryption program records the characteristics of mouse movements and keyboard strokes for a few seconds to obtain the seeds it needs. These actions do not necessarily produce undesirable entropy numbers, and usually require some degree of involvement from the user. For most entropy generators, the most undesirable feature is that it takes a lot of time to achieve sufficient entropy.
[0017] So it is obvious that the baking generator cannot be used in some of the aforementioned applications, including security applications. These applications require that real random random numbers can only be generated by random physical programs. The random physical procedure can be through the thermal noise of semiconductor diodes or resistors, the frequency instability generated by a free-run ocsiliator, or the amount of charge of a semiconductor capacitor in a special period of time. One method of generating random random numbers is to use one or more of the aforementioned physical processes to generate a series of bits, and these bits form a byte or word for use by an application program. However, under some environmental conditions, the slight correlation between successively generated bits can be observed. These correlations will reduce the randomness of random random numbers.
[0018] Therefore, a device and method are needed to reduce the correlation between consecutive bits generated by a random number generator.
[0019] The present invention provides a microprocessor, including a device and a method, by providing a selected part of a series of random bits, so as to reduce the amount generated by a hardware random number generator. Correlation between consecutive bits. Therefore, in order to achieve the above objective, the present invention provides a method to improve the randomness of the data generated by the random number generator. The method includes generating a plurality of bits by a random number generator, selecting every Nth bit from the plurality of bits, and accumulating every Nth bit selected. N is an integer greater than 1.
[0020] Another object of the present invention is to provide a microprocessor. The processor includes a random bit generator, which generates a series of random bits; an arithmetic logic unit (ALU), connected to the random bit generator, is used to select each random bit in a series of random bits. N bits, and each Nth bit accumulated is sent to a register connected to the operation logic unit, where N is an integer greater than 1.
[0021] Another object of the present invention is to provide a device for reducing the correlation between consecutive random bits. The device includes: a random bit generator for generating a group of random bits; the device also includes a first register connected to the random bit generator for storing the group of random bits; The device also includes a plurality of multiplexers (multiplexers) connected to the first register for selecting every Nth bit in the set of random bits; the device also includes a second register , Connect the multiple multiplexers to store every Nth bit selected by the multiplexer in the group of random bits.
[0022] An advantage of the present invention is that when the user makes a tradeoff between a higher random number generation rate and better randomness, the present invention can reduce the correlation between consecutive bits.
[0023] Other advantages and features of the present invention can be understood later from this specification and drawings.
[0046] Please refer to FIG. 1, which shows a block diagram of the microprocessor 100 of the present invention. The microprocessor 100 in FIG. 1 is a pipelined microprocessor including multiple stages, where each stage is responsible for a part of the entire program instruction execution process, as described below.
[0047] The microprocessor 100 includes a random number generator (RNG) unit 136. The operating system and application programs executed by the microprocessor 100 may use random numbers to perform various functions, such as data encryption, physical phenomenon simulation, statistical analysis, numerical analysis, or others. The RNG unit 136 generates random numbers for these functions. The RNG unit 136 will be described in more detail below.
[0048] The microprocessor 100 also includes an instruction cache 102. The instruction cache 102 caches the program instructions retrieved from the system memory coupled to the microprocessor 100.
[0049] The microprocessor 100 also includes an instruction fetcher 104, which is coupled to the instruction cache 102. The instruction fetcher 104 controls the action of fetching instructions from the system memory and/or the instruction cache 102. The instruction fetcher 104 selects a value for the instruction pointer maintained by the microprocessor 100. The instruction pointer will specify the next memory address to fetch instructions from there. Generally speaking, the instruction pointer will increase sequentially and point to the next instruction. However, flow control instructions (such as branch, jump, subroutine call, and return) update the command pointer to the non-sequential memory address specified by the flow control instruction. In addition, the interrupt may drive the instruction fetcher 104 to update the instruction pointer to a non-sequential address.
[0050] The microprocessor 100 also includes an interrupt unit 146, which is coupled to the instruction fetcher 104. The interrupt unit 146 receives an interrupt signal 148 and an interrupt vector 152. Components outside the microprocessor 100 may enable the interrupt signal 148 and provide an interrupt vector 152 to enable the microprocessor 100 to execute the interrupt service routine. The interrupt unit 146 determines the memory address of the interrupt service routine according to the interrupt vector 152, and sends the memory address of the interrupt service routine to the instruction fetcher 104 to update the instruction pointer to the address of the interrupt service routine . The interrupt unit 146 also selectively disables and enables interrupt services according to specific instructions executed by the microprocessor 100. That is, if the interrupt is disabled, even if the interrupt line 148 is enabled, the content of the instruction pointer will not change until the interrupt is enabled.
[0051] The microprocessor 100 also includes an instruction translator 106, which is coupled to the instruction fetcher 104, the interrupt unit 146, and the RNG unit 136. The instruction translator 106 translates instructions received from the instruction cache 102 and/or system memory. The instruction translator 106 translates the instruction, and takes appropriate actions according to the type of the translated instruction. The instruction translator 106 translates instructions defined in the instruction set of the microprocessor 100. If the instruction translator 106 wants to translate instructions that are not defined in the instruction set of the microprocessor 100, an illegal instruction exception will be generated.
[0052] In a specific embodiment, the instruction set of the microprocessor 100 is substantially similar to the instruction set of the Intel Pentium III or Pentium IV microprocessor. However, it is advantageous that the microprocessor 100 of the present invention includes additional instructions related to the random number generation function of the RNG unit 136. An additional instruction is the XSTORE instruction, which can store the random number generated by the RNG unit 136. Another additional command is the XLOAD command, which can load the control value from the system memory into the control and status register (CSR) 226 and the Streaming SIMD Extensions (SSE) in the RNG unit 136. ) Register XMM0 372. This part will be explained in conjunction with Figure 2 and Figure 3 below. The XSTORE and XLOAD instructions will also be explained in more detail below.
[0053] In addition, the instruction translator 106 sends relevant information about the translation instruction to the interrupt unit 146 so that the interrupt unit 146 can appropriately enable and disable interrupts. Furthermore, the instruction translator 106 sends relevant information about the translation instruction to the RNG unit 136. For example, the instruction translator 106 sends information about the translated XSTORE and XLOAD instructions to the RNG unit 136. In addition, when an instruction that loads a value into the SSE register XMM0 372 is translated, the instruction translator 106 will notify the RNG unit 136 so that the RNG unit 136 can take certain actions, such as setting a flag to indicate that the operating system may There will be a job switch, as described below.
[0054] In a specific embodiment, the instruction translator 106 translates giant instructions, such as Pentium III or IV instructions, into one or more micro instructions to be executed by the pipeline of the microprocessor 100.
[0055] The microprocessor 100 also includes a microprogram code ROM 132, which is coupled to the instruction translator 106. The microprogram code ROM 132 stores the microprogram code instructions and sends them to the instruction translator 106 for execution by the microprocessor 100. Some instructions in the instruction set of the microprocessor 100 are implemented by microprogram codes. That is, when the instruction translator 106 translates one of these instructions, the instruction translator 106 causes a micro instruction routine in the micro program code ROM 132 to be executed, thereby executing the translated giant instruction. In a specific embodiment, the XSTORE and/or XLOAD instructions are implemented by microprogram code. In addition, in a specific embodiment, the XSTORE and XLOAD instructions are executed continuously because they are not interruptible. That is, during the execution of the XSTORE and XLOAD instructions, the interrupt will be disabled.
[0056] The microprocessor 100 also includes a register file 108, which is coupled to the instruction translator 106. The register file 108 includes a user-visible register of the microprocessor 100 and a user-invisible register. In a specific embodiment, the register file 108 includes eight 32-bit registers that are not visible to general-purpose users, labeled r0 to r7. In another specific embodiment, the user-visible register in the register file 108 includes a Pentium III or IV user-visible register set. The SSE register 352 of FIG. 3 is included in the register file 108. The SSE register 352 is used by the SSE unit 134 and the RNG unit 136 included in the microprocessor 100, as described below. In particular, the register file 108 includes a register that is well-known in the current operating system. Therefore, when the operating system switches from the first task to the second task, the operating system stores the contents of the first task in the register of the register file 108 (including the SSE register 352) into the system memory, And restore the contents of the second task in the register (including the SSE register 352) of the register file 108 from the system memory.
[0057] The microprocessor 100 also includes an address generator 112, which is coupled to the register file 108. The address generator 112 generates a memory address based on the operands stored in the register file 108 and the operands provided by the instructions translated by the instruction translator 106. In particular, the address generator 112 generates a memory address to designate a location in the system memory, and the XSTORE command stores multiple bytes of random data therein. In addition, the address generator 112 also generates a memory address specifying a location in the system memory, and the control value loaded therein by the XLOAD command is stored in the CSR 226 of FIG. 2 via a data bus 142.
[0058] The microprocessor 100 also includes a loading unit 114, which is coupled to the address generator 112. The loading unit 114 loads data from the system memory to the microprocessor 100. The loading unit 114 also includes a data cache to cache the data read from the system memory. The loading unit 114 sends the loaded data to the execution units in the microprocessor 100 via the data bus 142, such as the SSE unit 134, the RNG unit 136, and the execution units included in the execution stage 116. In particular, the loading unit 114 loads the control value from the system memory and stores it in the CSR 226 in FIG. 2 to execute the XLOAD instruction.
[0059] The microprocessor 100 also includes an execution stage 116, which is coupled to the loading unit 114 via the data bus 142. The execution stage 116 includes an execution unit, such as an arithmetic logic unit, which is used to perform arithmetic and logic operations, such as addition, subtraction, multiplication, division, and Bollinger operations. In a specific embodiment, the execution stage 116 includes an integer unit for performing integer operations, and a floating point unit for performing floating point operations.
[0060] The microprocessor 100 also includes an SSE unit 134, which is coupled to the load unit 114 and the instruction translator 106. The SSE unit 134 includes arithmetic and logic units for executing SSE instructions, such as those included in the SSE or SSE2 instruction sets of Pentium III and IV. In a specific embodiment, although the SSE register 352 of FIG. 3 is conceptually included in the register file 108, it is actually located in the SSE unit 134 for storing the operands used by the SSE unit 134.
[0061] The microprocessor 100 also includes an RNG unit 136, which is coupled to the instruction translator 106 and the load unit 114 via the data bus 142. The RNG unit 136 provides random data bytes and a count value on the data bus 144, where the count value represents the number of random data bytes provided to an XSTORE command. The RNG unit 136 will be described in more detail below with the rest of the drawings.
[0062] The microprocessor 100 also includes a storage unit 118, which is coupled to the execution unit 116, the SSE unit 134, and the RNG unit 136. The storage unit 118 stores the data in the system memory and the data cache memory in the loading unit 114. The storage unit 118 stores the results generated by the execution unit 116, the SSE unit 134, and the RNG unit 136 to the system memory. In particular, the storage unit 118 stores the XSTORE command count and random data bytes provided by the RNG unit 136 on the data bus 144 to the system memory.
[0063] The microprocessor 100 also includes a write-back unit 122, which is coupled to the execution unit 116 and the register file 108. The write-back unit 122 writes the command result back to the register file 108.
[0064] The microprocessor 100 also includes a write buffer 124, which is coupled to the write back unit 122. The write buffer 124 will hold data waiting to be written to the system memory, such as XSTORE command count and data.
The microprocessor 100 also includes a bus interface unit (BIU) 128, which is coupled to the write buffer 124. The BIU 128 serves as the interface between the microprocessor 100 and a processor bus 138. The processor bus 138 couples the microprocessor 100 to the system memory. The BIU 128 also performs bus operations on the processor bus 138 to transfer data between the microprocessor 100 and the system memory. In particular, the BIU 128 executes one or more bus operations on the processor bus 138 to store the XSTORE instruction count and data to the system memory. In addition, the BIU 128 executes one or more bus operations on the processor bus 138 to load the XLOAD command control value from the system memory.
[0066] The microprocessor 100 also includes a read buffer 126, which is coupled to the BIU 128 and the register file 108. For the data received from the system memory by the BIU 128, while it is waiting to be sent to the load unit 114 or the register file 108, the read buffer 126 saves it. In particular, when the XLOAD command data received from the system memory is waiting to be sent to the load unit 114 and the RNG unit 136 thereafter, the read buffer 126 will store the data.
[0067] Please refer to FIG. 2, which is a block diagram of the RNG unit 136 in the microprocessor 100 of FIG. 1 of the present invention.
[0068] The RNG unit 136 includes control logic 244. The control logic 244 includes a large number of combination and sequential logics for controlling various elements in the RNG unit 136. The control logic 244 receives the xload signal 272 and the xstore signal 268, which respectively indicate that the XLOAD or XSTORE command is being executed. The control logic 244 also receives a reset signal 248, which indicates that the RNG unit 136 is being reset. The control logic 244 will be described in more detail below in conjunction with the rest of the RNG unit 136.
[0069] The RNG unit 136 also includes a self-test unit 202, which is coupled to the control logic 244. The self-test unit 202 receives the self-test enable signal 292 from a control and status register, called the machine specific register (MSR) 212. The MSR 212 will be described in more detail in conjunction with FIG. 3 below. The MSR 212 is also coupled to the control logic 244. The self-test unit 202 sends a self-test failure signal 288 to the control logic 244. If the self-test unit 202 is enabled by the self-test enable signal 292, the self-test unit 202 will perform various self-tests of the RNG unit 136. If the self-test fails, the self-test unit 202 generates a true self-test failure signal 288 and sends it to the MSR 212. In a specific embodiment, the self-test unit 202 performs a random number generator statistical test, as defined in Federal Information Processing Standards (FIPS) Publication No. 140-2, pages 35-36, which are incorporated herein by reference .
[0070] In a specific embodiment, the self-test unit 202 performs a self-test at the request of the user. In a specific embodiment, after the microprocessor 100 is reset, the self-test unit 202 performs a self-test. If the self-test fails, whether it is requested by the user or done after reset, the self-test unit 202 will generate a true self-test failure signal 288, which is reflected in the self-test failure bit of MSR 212 in Figure 3 318. When the control logic 244 is reset, it checks the self-test failure bit 318. If the self-test failure bit 318 is true, the control logic 244 will set a false value of the RNG presence signal 286 and send it to the MSR 212 to update the RNG presence bit 314 in FIG. 3.
[0071] The RNG presence signal 286 is also sent to a CPUID register 204, which includes the RNG presence bit 302 in FIG. 3, and the RNG presence bit 302 is also updated by the RNG presence signal 286. That is, the RNG existence bit 302 of the CPUID register 204 is a copy of the RNG existence bit 314 of the MSR 212. In a specific embodiment, the application program can read the CPUID register 204 by executing the CPUID instruction in the IA-32 instruction set. If the RNG presence bit 302 is false, it means that the RNG unit 136 does not exist in the microprocessor 100, and the microprocessor 100 does not have the feature of random number generation. Advantageously, applications that require random numbers can use the RNG presence bit 302 to detect the presence of the RNG unit 136 in the microprocessor 100, and if the RNG unit 136 does not exist, select another one with lower performance. Source to get random numbers.
[0072] The RNG unit 136 also includes two random bit generators, which are coupled to the control logic 244, called random bit generator 0 206 and random bit generator 1 208. The random bit generators 206 and 208 both generate a string of random bits, which are accumulated by the RNG unit 136 into a byte group of random data. Both the random bit generators 206 and 208 receive a power control (power_cntrl) signal 231, which is used to specify whether to turn off the power of the random bit generators 206 and 208. In a specific embodiment, the action of turning off the power of the random bit generators 206 and 208 includes not sending a clock signal to them. The random bit generators 206 and 208 both generate a series of random data bits according to the random electrical characteristics of the microprocessor 100 (such as thermal noise).
[0073] The random bit generator 0 206 receives the DC bias signal 296 from the MSR 212. The DC bias signal 296 transmits the value stored in the DC bias bit 322 of the MSR 212 in FIG. 3. The value of the DC bias signal 296 specifies the DC bias voltage to partially control the operating voltage of the spontaneous ringing oscillator in the random bit generator 0 206.
[0074] Following the US patents in the following applications, the application numbers are 10/046055, 10/046054, and 10/046057, and the titles are "Device for Generating Random Numbers", "Oscillator Bias Voltage Variation Mechanism" and " "Oscillator Frequency Variation Mechanism" (document number CNTR.2113, CNTR.2155, and CNTR.2156), in which the random bit generator 0 206 is described in detail, all of which are incorporated by reference here.
[0075] The RNG unit 136 also includes a multiplexer 214 with two input terminals, the input terminals of which are coupled to the output terminals of the random bit generators 206 and 208. The multiplexer 214 selects one of the two input terminals according to the generator selection signal 252 provided by the CSR 226. The generator selection signal 252 transmits the value stored in the generator selection bit 336 of the CSR 226 in FIG. 3.
[0076] The RNG unit 136 also includes a Van Neumann whitener 216, or compressor, which is coupled to the output end of the multiplexer 214. The whitener 216 is selectively enabled/disabled by the original bit signal 254 received from the MSR 212. The original bit signal 254 transmits the value stored in the original bit field 324 of the MSR 212 in FIG. 3. If the original bit signal 254 is true, the whitener 216 allows the bits received by the multiplexer 214 to pass through and output directly, and does not perform the whitening function. The whitener 216 receives a pair of bits from the multiplexer 214 and outputs either or neither of them according to a predetermined input/output function, thereby significantly reducing the possibility of being present in the random bit generator 206 And the residual bias voltage of 208. The input/output functions of the whitener 216 are shown in Table 1 below.
<tables><img file="TWI227439B_D0001.tif" /></tables>
[0077] The RNG unit 136 also includes an 8-bit shift register 218, which is coupled to the whitener 216. The shift register 218 temporarily stores the random data bits received from the whitener 216, accumulates them into 8-bit bytes, and outputs the accumulated random data bytes. The shift register 218 sets a byte generating signal 282 sent to the control logic 244 as true to indicate that it has accumulated and output a random data byte 298.
[0078] The RNG unit 136 also includes a continuous count test (CNT) unit 222, which is coupled to the output terminal of the shift register 218. The CNT unit 222 receives the random byte 298 from the shift register 218, and performs a continuous random number generator test on the random byte 298. The CNT unit 222 is selectively enabled/disabled based on the CNT enabling signal 284 received from the CSR 226. The CNT enable signal 284 transmits the value stored in the CNT enable bit 342 of the CSR 226 in FIG. 3. If the continuous random number generator test fails, the CNT unit 222 sets a CNT failure signal 294 sent to the CSR 226 as true and stores it in the CNT failure bit 344 of the CSR 226 in FIG. 3.
[0079] In a specific embodiment, the continuous random number generator test performed by the CNT unit 222 substantially conforms to the continuous random number generator test described on page 37 of FIPS Issue 140-2, which is referred to here. Incorporated. In a specific embodiment, the CNT unit 222 uses two 8-byte buffers (referred to as "old" and "new") to perform the test. After reset and self-test (if enabled), the first eight bytes transmitted by the shift register 218 will be accumulated in the old buffer. The next eight bytes are accumulated in the new buffer. When the XSTORE instruction is executed, the 8 bytes in the old buffer will be compared with the 8 bytes in the new buffer. If the bytes are not equal, the test passes and the 8 bytes in the new buffer will be moved to the old buffer. The new buffer is cleared to wait for the accumulation of new 8 bytes. However, if the bytes are equal, the CNT unit 222 sets the CNT failure signal 294 to true to indicate that the continuous random number generator test failed.
[0080] In a specific embodiment, as long as the CNT enable bit 342 and the CNT failure bit 344 in FIG. 3 are set, the available byte count value returned by the XSTORE command is 0. In a specific embodiment, the microprocessor 100 stores the available byte count and random data bytes to the system memory when a specific XSTORE instruction is executed, where the execution of the specific XSTORE instruction activates the failure. Continuous random number generator test.
[0081] In a specific embodiment, the continuous random number generator test does not span several tasks that do not all enable the test. That is, when the CNT enable bit 342 is set, both the new and old buffers will be updated, and the continuous random number generator test will only be performed by executing the XSTORE command. Therefore, it can be ensured that a specific job will never receive two consecutive groups of 8 bytes with the same value. However, if two tasks are being executed, and one of them sets the CNT enable bit 342 and the other is not set, the RNG unit 136 may use the XSTORE command to store 8 bytes into one of the tasks and generate The job is switched, and the RNG unit 136 uses the XSTORE command to store 8 bytes equal to the previous 8 bytes in another job; however, in this case, the continuous random number generator test will not fail .
[0082] The RNG unit 136 also includes a string filter 224, which is coupled to the output terminal of the shift register 218. The string filtering device 224 receives random bytes 298 from the shift register 218, and selectively discards some random bytes, as described below, and outputs undiscarded random bytes. The string filtering device 224 ensures that the RNG unit 136 does not generate consecutive similar bits (ie, a continuous 0-bit string or a continuous 1-bit string) that is longer than a specified value. The specified value is specified by the maximum count (max_cnt) signal 258 received from the CSR 226. The max_cnt signal 258 transmits the value specified by the maximum count field 346 of the string filter device of CSR 226 in FIG. 3. In a specific embodiment, the default value of max_cnt 346 is 26 bits. In a specific embodiment, the value of the maximum count field 346 of the string filter device must be at least 8. If the string filtering device 224 detects that the length of a continuous similar bit string exceeds max_cnt 258, the string filtering device 224 sets a filter failure signal 256 to true. This signal is stored in the string filtering device of CSR 226 in Figure 3 and failed. Bit 338. The string filter device 224 will be described in more detail in conjunction with FIGS. 10 to 12 below.
[0083] The RNG unit 136 also includes a second multiplexer 228 with two input terminals. One of the input terminals is coupled to the output terminal of the string filter device 224, and the other input terminal is coupled to the output terminal of the shift register 218. The multiplexer 228 selects one of the input terminals according to the filter enable signal 262 provided by the CSR 226 to transmit the value stored in the string filter enable bit 334 of the CSR 226 in FIG. 3.
[0084] The RNG unit 136 also includes a demultiplexer 232 having an input terminal and two output terminals, the input terminal of which is coupled to the output of the multiplexer 228. The demultiplexer circuit includes a single data input terminal and a plurality of data output terminals. The demultiplexer also includes a control input. The demultiplexer selects one of a plurality of data output terminals according to the signal of the control input terminal, and sends the data received by the data input terminal to the selected output terminal. Here, the demultiplexer 232 selectively sends the random data bytes received by the input terminal to one of the output terminals according to the fill_select signal 264 provided by the control logic 244.
[0085] The RNG unit 136 also includes two data buffers, labeled as buffer 0242 and buffer 1246, both of which are coupled to the output end of the demultiplexer 232. The buffer 0242 and the buffer 1246 use the XSTORE command to accumulate random data bytes to be stored in the system memory. In a specific embodiment, buffer 0 242 and buffer 1 246 can each store 15 bytes of random data. In a specific embodiment, buffer 0 242 and buffer 1 246 can each store 16 bytes of random data.
[0086] The RNG unit 136 also includes a third multiplexer 236 with two input terminals, the input terminals of which are coupled to the output terminals of the buffer 0 242 and the buffer 1 246. The multiplexer 236 selects one of the random data bytes at its input terminal according to the store_select signal 266 provided by the control logic 244 to output to a data bus 278.
[0087] The RNG unit 136 also includes a TSPO flag register 274, which is coupled to the control logic 244. The TSPO flag register 274 stores a flag to indicate whether the task switching performed by the operating system may occur. The use of the TSPO flag register 274 will be explained in more detail below.
[0088] The RNG unit 136 also includes a second demultiplexer 215 with two input terminals, which is connected to the control logic 244. The input terminal of the second demultiplexer 215 receives an increment signal 221 generated by the control logic 244. Each time a random data byte is stored in buf0 242 or buf1 246, the control logic 244 declares the increment signal 221. The demultiplexer 215 provides the received increment signal 221 to the output terminal selected according to the fill_Select signal 264.
[0089] The RNG unit 136 also includes a third demultiplexer 217 with two input terminals, which is coupled to the control logic 244. The input terminal of the demultiplexer 217 is coupled to the control logic 244 to receive the clear signal 223 generated by it. Whenever an XSTORE command is executed, the control logic 244 sets the clear signal 223 to true, so that valid random data bytes are removed from the buffer 0 242 or the buffer 1 246. The demultiplexer 217 selectively sends the clear signal 223 received at its input terminal to one of its output terminals according to the store_select signal 266.
[0090] The RNG unit 136 also includes two counters, denoted as counter 0 211 and counter 1 213, which are coupled to the demultiplexer 215 and the demultiplexer 217. Counter 0 211 and counter 1 213 each have an increment (or count) input terminal. The counting input terminal is coupled to the output terminal of the demultiplexer 215. Therefore, when the control logic 244 sets the increment signal 221 to be true, one of the counter 0 211 and the counter 1 213 specified by the fill_select signal 264 will be incremented. Counter 0 211 and counter 1 213 also each have a clear input terminal. The clear input terminal is coupled to the output terminal of the demultiplexer 217. Therefore, when the control logic 244 sets the clear signal 223 to true, one of the counter 0 211 and the counter 1 213 specified by the store_select signal 266 will be cleared to 0.
[0091] The RNG unit 136 also includes two comparators 225, which are coupled to the output terminals of the counter 0 211 and the counter 1 213. The comparator 225 compares the count value output by the counter 0 211 and the counter 1 213 with the number of bytes that can be stored in the counter 0 211 and the counter 1 213 to determine whether the counter 0 211 and the counter 1 213 are full, and generate The full0 signal 229 and the full1 signal 227 are used to inform the control logic 244 of the comparison result.
[0092] The RNG unit 136 also includes a fourth multiplexer 219 with two input terminals, the input terminals of which are coupled to the output terminals of the counter 0 211 and the counter 1 213. The multiplexer 219 selects one of the count values of its input terminal according to the store_select signal 266, and outputs it as the available byte count 234. The available byte count 234 is also sent to CSR226.
[0093] The RNG unit 136 also includes a register, labeled RNG R5238, or R5 238. The R5 238 has an input terminal, which is coupled to the output terminal of the multiplexer 236 to receive the data byte 278. R5238 has another input terminal, which is coupled to the output terminal of the multiplexer 219 to receive the available byte count 234. The output terminal of R5 238 is coupled to the data bus 144 in FIG. 1. R5 238 will keep the count value and data of the XSTORE instruction. In a specific embodiment, the count value is stored in the least significant byte of R5 238, and the effective data byte is stored in the position of the effective byte connected to the count value. In a specific embodiment, R5 238 can store a count byte, plus the random data bytes that buffer 0 242 and buffer 1 246 can store.
[0094] In a specific embodiment, the RNG unit 136 includes four buffers instead of two. Each buffer can store up to eight bytes of random data. In this embodiment, the demultiplexers 215, 217, and 232 include demultiplexers with four output terminals; the multiplexers 219 and 236 include multiplexers with four input terminals; and the comparator 225 includes four comparators. , To generate four full outputs; and the fill_select signal 264 and store_select signal 266 include two bits for selecting one of the four counters and buffers.
[0095] Please refer to FIG. 3, which is a block diagram of various registers related to the RNG unit 136 of FIG. 1 in the microprocessor 100 of FIG. 1 of the present invention.
[0096] FIG. 3 shows the CPUID register 204 in FIG. 2. The CPUID register 204 includes an RNG presence bit 302. The RNG presence bit 302 is a read-only feature flag unit. If the RNG presence bit 302 is 1, it means that the RNG unit 136 exists and is enabled by the microprocessor 100. If the RNG presence bit 302 is 0, the RNG unit 136 does not exist, and the XLOAD and XSTORE instructions are invalid. When the instruction translator 106 encounters these instructions, an invalid instruction exception will be generated. In addition, reading the bits in MSR 212 will result in undefined results, and attempting to write will not produce any effect. The RNG presence bit 302 is a copy of the RNG presence bit 314 of the MSR 212.
[0097] FIG. 3 also shows the MSR 212 in FIG. The MSR 212 includes an RNG enable bit 312. The RNG enable bit 312 is writable. Writing 1 to the RNG enable bit 312 enables the RNG unit 136 to be enabled. Writing 0 to the RNG enable bit 312 disables the RNG unit 136. If the RNG enable bit 312 is 0, the XLOAD and XSTORE instructions are invalid, and if the instruction translator 106 encounters these instructions, an invalid instruction exception will be generated. In addition, reading the bits in MSR 212 will result in undefined results, and attempting to write will not produce any effect. The value of the RNG enable bit 312 becomes 0 after being reset.
[0098] The MSR 212 also includes a read-only RNG presence bit 314. The RNG presence bit 314 indicates whether the RNG unit 136 exists in the microprocessor 100. If the RNG presence bit 314 is 0, the RNG unit 136 cannot be enabled by setting the RNG enable bit 312, and the bit in the MSR 212 is read, but the result is undefined. If you try to write, it will not Will have any effect. In addition, if the self-test of the RNG unit 136 fails, the RNG presence bit 314 will be cleared, as described in the previous part of Figure 2.
[0099] The MSR 212 also includes a read-only statistical self-test enable bit 316. The self-test enable bit 316 indicates whether the self-test after reset in the above-mentioned part of Figure 2 is currently enabled. If the self-test enable bit 316 is 0, the self-test will not be executed after resetting. If the self-test enable bit 316 is 1, the self-test will be executed after resetting. In a specific embodiment, after the warm reset and power-on reset of the microprocessor 100, a self-test is performed.
[0100] The MSR 212 also includes a read-only statistical self-test failure bit 318. The self-test failure bit 318 indicates whether the self-test after the most recent reset in the aforementioned Figure 2 has failed. In a specific embodiment, if the self-test failure bit 318 is 1, the RNG unit 136 cannot be enabled.
[0101] The MSR 212 also includes a writable DC bias bit 322. In a specific embodiment, the DC bias bit 322 includes three bits. The DC bias bit 322 is used to control the DC bias sent to the random bit generator 0 206, which affects the operating speed and possible randomness of the random bit generator 0 206. In a specific embodiment, if the statistical self-test is performed during reset, the self-test unit 202 will determine the correct value or the optimal value of the DC bias bit 322 and set it to this value. After the reset, the value of the DC bias bit 322 becomes 000.
[0102] The MSR 212 also includes original bits 324 that can be written. If the original bit bit 324 is set to 0, the whitener 216 in FIG. 2 will perform the whitening function described in the previous part of the second part, and transfer the whitened bit to the shift register 218. If the original bit bit 324 is set to 1, the whitener 216 will not perform the whitening function, and the original bit from the multiplexer 214 is transferred to the shift register 218. After the reset, the value of the original bit bit 324 becomes 0.
[0103] Figure 3 also shows the CSR 226 in Figure 2. In a specific embodiment, CSR 226 is a 128-bit register. The CSR 226 includes a read-only available byte count field 332. The available byte count field 332 indicates how many bytes of random data in the buffer 0242 or the buffer 1246 selected by the Store_select signal 266 can be stored by the XSTORE command. If necessary, software can be used to read the available byte count field 332 to determine how many random data bytes can be stored by the XSTORE command. Since the RNG unit 136 will simultaneously accumulate bytes in the buffer 0242 and the buffer 1246, the actual number of bytes that can be stored may be greater than the available byte count previously read by XLOAD when XSTORE is executed. 332. After the RNG unit 136 is enabled, the value of the available byte count field 332 becomes 0.
[0104] The CSR 226 also includes a writable string filter enable bit 334. If the string filter device enable bit 334 is 1, the string filter device 224 is enabled; otherwise, the string filter device 224 is disabled. The operation of the string filter device 224 will be described in more detail below in conjunction with Figures 10 to 12. After the RNG unit 136 is enabled, the value of the string filter device enable bit 334 becomes 0.
[0105] The CSR 226 also includes a generator selection bit 336 that can be written. If the generator selection bit 336 is set to 0, the random bit generator 0206 is selected to provide a random bit stream through the multiplexer 214 of FIG. 2 for accumulation; otherwise, the random bit generator 1208 is selected. After the RNG unit 136 is enabled, the value of the generator selection bit 336 becomes 0.
[0106] The CSR 226 also includes a string filter device failure bit 338. If the string filter device failed bit 338 is set to 1, it means that the string filter device 224 has detected a continuous similar bit string longer than the value specified in the string filter device max_cnt field 346, as shown in Figure 2 and Figures 10 to 10 above. In part two. Only the RNG unit 136 can set the string filter device failure bit 338 to 1. However, the software can clear the string filter device failure bit 338 by writing 0 into it. In a specific embodiment, the filter failure bit 338 can be set to 1 by the pulse of the filter failure signal 256, and remains at 1 until the software clears it. After the RNG unit 136 is enabled, the value of the string filter device failure bit 338 becomes 0.
[0107] The CSR 226 also includes a writable count (CNT) enable bit 342. If the CNT enable bit 342 is set to 1, the CNT unit 222 will perform a continuous random number generator test, as described in the second part of FIG. After the RNG unit 136 is enabled, the value of the CNT enable bit 342 becomes 0.
[0108] The CSR 226 also includes a read-only CNT failure bit 344. If the CNT enable bit 342 is 1 and the continuous random number generator test fails, the RNG unit 136 sets the CNT failure bit 344 to 1. In a specific embodiment, when the CNT enable bit 342 and the CNT fail bit 344 are both 1, the execution of the XSTORE command will store the available byte count value 0 in the system memory, instead of the data bits The group is stored in the system memory. Therefore, if the CNT enable bit 342 is set for a job and a failure occurs during the execution of the job, the RNG unit 136 will be effectively disabled for the job. However, the RNG unit 136 will not disable other tasks for which the CNT enable bit 342 is not set. After the RNG unit 136 is enabled, the value of the CNT failure bit 344 becomes 0.
[0109] The CSR 226 also includes a writable string filtering device max_cnt field 346. The software writes the value into the max_cnt field 346 of the string filter device to specify the maximum number of allowable consecutive similar bits, as described in the ten to twelfth parts of the figure below. In a specific embodiment, the string filter device max_cnt field 346 includes 5 bits. In a specific embodiment, the default value of the max_cnt field 346 of the string filtering device is 26.
[0110] In a specific embodiment, each field of MSR 212 is included in CSR 226 instead of MSR 212. Therefore, the value of MSR 212 will be stored and restored with CSR 226, which is suitable for multi-tasking operations, as described here, especially the parts of Figures 4-9.
[0111] FIG. 3 also shows the RNG R5 register 238 of FIG. R5 238 includes two fields: the available byte count field 362, and another field 364 for storing random data bytes, as described above. In a specific embodiment, the valid random data bytes are adjusted to the right next to the available byte count field 362.
[0112] Figure 3 also shows the SSE register 352. The SSE register 352 includes eight 128-bit registers, labeled XMM0 to XMM7. In Figure 3, XMM0 is called XMM0 372, XMM3 is called XMM3 376, and XMM5 is called XMM5 374. In a specific embodiment, the SSE register 352 is substantially similar to the SSE register included in the Pentium III or IV, such as the IA-32 Intel Architecture Software Developers Manual Volume One: Basic Architecture (2002). It is described on pages 10-14, which are incorporated herein by reference. RNG CSR 226 will shadow XMM0 372, and RNG R5 238 will shadow XMM5 374, as described below.
[0113] In a specific embodiment, the microprocessor 100 includes various fuses, which are temporarily or permanently set during the manufacturing process of the microprocessor 100, so that the CSR 226 and MSR can be selected during resetting. The value of each bit in 212 replaces the aforementioned reset value.
[0114] Please refer to FIG. 4, which shows a flowchart of the operation of the microprocessor 100 of FIG. 1 to load a value into the XMM0 register 372 of FIG. 3 according to the present invention. The instruction loaded into XMM0 372 is executed by the microprocessor 100, which loads the value from the system memory into the XMM0 register 372, such as the MOVAPS instruction. The MOVAPS instruction moves the data from the system memory to the specified XMM register, and vice versa. This part is described in the second volume of the IA-32 Intel Architecture Software Developer's Manual: Instruction Set Reference (2001) No. 3 -443 to page 3-444, which are incorporated by reference here. Other commands that load XMM0 372 from system memory are MOVAPD and MOVDQA. Since the XMM0 372 operating system is stored in the memory and restored from the register when the task is switched, when the task is switched, the operating system will execute commands such as MOVAPS to restore from the memory In the work after switching, the previous value of XMM0 372. The flow starts at block 402.
[0115] In block 402, the microprocessor 100 executes the instruction by fetching the value of an instruction (such as MOVAPS) at the specified location in the system memory, and loads the value into XMM0 372. Therefore, any time XMM0 372 is loaded from memory, job switching may occur. The flow continues to block 404.
[0116] In block 404, the instruction translator 106 informs the RNG unit 136 that the MOVAPS instruction (or other similar instructions loaded into the XMM0 372 from the memory) has been translated. Once this value has been loaded into XMM0 372, the control logic 244 of the RNG unit 136 will set the TSPO flag 274 to indicate that a work switch may occur. The process will end at block 404.
[0117] Please refer now to FIG. 5, which shows a block diagram of the operation of the microprocessor 100 in FIG. 1 when the XLOAD instruction is executed according to the present invention. The XLOAD command is a tool used by software to load values into the CSR 226 in Figure 2 to specify the control values required for the operation of the RNG unit 136. Because CSR 226 does not exist in Pentium III or IV, new instructions outside the Pentium III or IV instruction set are needed to load CSR 226. Advantageously, the XLOAD instruction also loads the control value into XMM0 372, which facilitates multiplexing operations with the RNG unit 136, as described herein.
[0118] FIG. 5 shows the format of the XLOAD command specifying XMM0 372, which is: XLOAD XMM0, memaddr where memaddr specifies a memory address in the system memory 502. The operation of the XLOAD instruction is similar to that of the MOVAPS instruction, but in addition to XMM0 372, the former also loads the value of the system memory into CSR 226. In a specific embodiment, XLOAD moves the 16-byte data 504 from memaddr to CSR 226 and XMM0 372, as shown in the figure. In a specific embodiment, the opcode value of the XLOAD instruction is 0x0F 0x5A, followed by the standard mod R/M register and address format bytes specified by the x86 instruction. In another specific embodiment, the operation code value of the XLOAD instruction is 0x0F 0xA6 0xC0. If the XLOAD instruction specifies one of the SSE registers 352 instead of XMM0 372, the specified SSE register 352 will be loaded; however, the CSR 226 will not be loaded.
[0119] Please refer to FIG. 6, which shows the operation flow chart of the XLOAD instruction executed by the microprocessor 100 of FIG. 1 to load the value into the XMM0 register 372 of FIG. 3 according to the present invention. The flow starts at block 602.
[0120] In block 602, the microprocessor 100 loads the value of the memory address specified by the XLOAD instruction in the system memory 502 into the CSR 226 in FIG. 2 and the XMM 0372 in FIG. 3, as shown in FIG. 5. The flow continues to block 604.
[0121] In block 604, since the random data bytes accumulated in buffer 0 242 and buffer 1246 are not generated with the control values in CSR 226, these control values are being loaded into CSR 226. The new work is required, so the RNG unit 136 will respond to the loading action of the CSR 226, and discard the contents of the buffer 0242 and the buffer 1 246. The flow continues to block 606.
[0122] In block 606, since the random data bytes in buffer 0 242 and buffer 1 246 are discarded in block 604, the RNG unit 136 adjusts the available bits in counter 0 211 and counter 1 213 The group count is cleared to 0. The flow continues to block 608.
[0123] In block 608, the RNG unit 136 restarts accumulating random numbers. That is, the random bit generator 206 or 208 selected by the generator selection signal 252, in the case of the random bit generator 0206, will generate random bits based on the DC bias signal 296; the whitener 216 based on the original The bit signal 254 selectively whitens these bits; the CNT unit 222 selectively executes the continuous random number generator test according to the CNT enable signal 284; the string filter device 224 selects according to the filter enable signal 262 and max_cnt signal 258 Buffer 0 242 and buffer 1 246 accumulate random data bytes according to the fill_select signal 264; and counter 0 211 and counter 1 213 according to the fill_select signal 264 Calculate the number of bytes accumulated in buffer 0 242 and buffer 1 246.
[0124] In block 612, since the CSR 226 has been updated to the control value required for the current operation, the control logic 244 clears the TSPO flag 274. The process will end at block 612.
[0125] Please refer now to FIG. 7, which shows a block diagram of the operation of the microprocessor 100 in FIG. 1 when the XSTORE instruction is executed according to the present invention. XSTORE command is a tool used by software to store the count value of available random data bytes and itself from R5 238 to system memory. Because RNG R5 238 does not exist in Pentium III or IV, new instructions outside the Pentium III or IV instruction set are required to store RNG R5 238. Advantageously, the XSTORE command writes the count value and data bytes into the memory in an integral and indivisible manner, so that the RNG unit 136 can be used for multiplexing operations, as described herein. That is, the XSTORE instruction is not interruptible. Therefore, when a job executes the XSTORE instruction, another job cannot be interrupted by the XSTORE instruction to modify the available byte count or random data bytes to be written into the system memory by the XSTORE instruction. Therefore, by writing data and count values in an integral and indivisible manner, the XSTORE command provides a variable number of random data bytes, which is inherently beneficial to facilitate multiplexing.
[0126] Figure 7 shows the format of the XSTORE command, which is: XSTORE memaddr, XMM5 Memaddr will specify the memory address in the system memory 502. The operation of the XSTORE command is similar to the MOVAPS command, except that the specified XMM register will not be stored in the system memory; instead, if XMM5 374 is specified, R5 238 will be stored in the system memory. That is, R5 238 will obscure XMM5 374. XSTORE will move the count value of available valid random data byte 362 in Figure 3 from R5 238 to position 702 of memaddr in system memory 502, as shown in the figure. In addition, XSTORE moves the valid random byte data 364 specified by the count value 362 to the position 704 in the system memory 502 next to the available byte count 702, as shown in the figure.
[0127] In a specific embodiment, the operation code value of the XSTORE instruction is 0x0F 0x5B, followed by the standard mod R/M register and address format bytes specified by the x86 instruction. In another specific embodiment, the operation code value of the XSTORE instruction is 0x0F 0xA7 0xC0. In a specific embodiment, the XSTORE command requires the ES:EDI register in the register file 108 to specify the memaddr, that is, the starting memory address to store the count and random data bytes. In a specific embodiment, XSTORE does not allow sections to overlap. If the XSTORE instruction specifies one of the SSE registers 352 instead of XMM5 374, the result will be in an undetermined state.
[0128] In a specific embodiment, the number of random data bytes 704 stored in the system memory by the microprocessor 100 is equal to the available byte count 702 also written into the system memory.
[0129] In another specific embodiment, the number of random data bytes 704 stored in the system memory of the microprocessor 100 is equal to a number less than the number of bytes in the RNG R5 238. That is, if RNG R5 238 is a 16-byte register that can store up to 15 random data bytes 364 and one byte available byte count 362, the microprocessor 100 will 16 bytes are stored in the system memory 502: 15 bytes of random data are stored in the random data byte 704 position, and one count byte is stored in the available byte count 702 position. However, some of the 15 bytes written into the system memory 502 may not be valid. In a specific embodiment, the number of bytes written into the memory is all a power of two. Only the first N bytes are valid, where N is the available byte count 702.
[0130] In this specific embodiment, the RNG unit 136 clears the buffer referred to by the XSTORE operation (that is, the buffer 0242 or the buffer 1 246 in FIG. 2). By clearing the buffer, the microprocessor 100 can avoid the problem that each task sees each other's random data, thereby improving security. For example, suppose the first job executes the first XSTORE operation, stores 15 bytes of random data from the buffer 0 242 to the system memory, and executes the second XSTORE operation to remove 15 bytes of random data from the buffer The device 1 246 is stored in the system memory; then the operating system switches to the second task, which will immediately execute the XSTORE operation before the RNG unit 136 accumulates any random data bytes in the buffer 0 242. If after the first XSTORE operation, the RNG unit 136 does not clear the buffer 0 242, the random data received by the first job will also be stored in the memory location of the second job, so that the second job will see the first job. Random information of the job.
[0131] In a specific embodiment, the XSTORE instruction specifies the maximum number of random data bytes to be stored in the system memory. In this embodiment, the maximum number is specified in one of the general-purpose registers of the register file 108, such as ECX. In this specific embodiment, if the available bytes in the buffer 0242 or the buffer 1246 selected by the store_select signal 266 are more than the maximum number specified in ECX, the microprocessor 100 will only store the number specified in ECX The maximum number of bytes; otherwise, the XSTORE instruction will store the available number of valid bytes. In any of the foregoing cases, the XSTORE command will store the number of valid random data bytes stored in the data byte position 704 of the system memory 502 to the available byte count position 702.
[0132] In a specific embodiment, the XSTORE instruction specifies the required number of random data bytes to be stored in the system memory. In this embodiment, the required number is specified in one of the general-purpose registers of the register file 108, such as ECX. In this specific embodiment, an x86 REP prefix is added to the XSTORE instruction. In this specific embodiment, the REP XSTORE instruction does not need to be executed continuously. That is, because the number of random bytes required may be very large, REP XSTORE is interruptible. However, since the number of stored random data bytes is immutable (that is, the software knows the number of random data bytes to be stored in the memory), the command does not have to be executed continuously.
[0133] Please refer to FIG. 8, which shows the operation flow chart of the microprocessor 100 of FIG. 1 executing the XSTORE instruction from the XMM5 register of FIG. 3 according to the present invention. The flow starts at block 802.
[0134] In block 802, for the instruction translator 106 of FIG. 1 to notify that the XSTORE instruction has been translated, the interrupt unit 146 will respond to disable the interrupt. The flow continues to decision block 804.
[0135] In the decision block 804, the control logic 244 of FIG. 2 checks the TSPO flag 274 to determine whether the flag is set. If it is set, the process continues to block 806. Otherwise, the process continues to block 816.
[0136] In block 806, the RNG unit 136 copies the content of the XMM0 372 to the CSR 226, and clears the TSPO flag 274. Since the TSPO flag 274 indicates that since the last XSTORE or XLOAD was executed, job switching may have occurred, as indicated by loading XMM0 372 from the system memory in step 402 of Figure 4, so CSR 226 may not have the current execution The correct control value required for the operation of the XSTORE instruction. Therefore, the XSTORE instruction must update CSR 226 with the correct control value. The correct value is stored in XMM0 372, because when the job is initial, the correct control value is loaded into XMM0 372 and CSR 226 by executing XLOAD, and then when the operating system is switched back to the current job, the correct control value is It has also been restored to XMM0 372. The process will continue to block 808.
[0137] In block 808, because the random data bytes accumulated in buffer 0 242 and buffer 1246 will not be generated with the new control values required by the new job in the CSR, where these new control values are The block 806 is copied to the CSR 226, so the RNG unit 136 will respond to the loading of the CSR 226 and discard the contents of the buffer 0 242 and the buffer 1 246. The process continues to block 812.
[0138] In block 812, because in block 808, random data bytes in buffer 0 242 and buffer 1 246 are discarded, in counter 0 211 and counter 1 213, the RNG unit 136 will be available The byte count is cleared to 0. The flow continues to block 814.
[0139] In block 814, the RNG unit 136 restarts the accumulation of random numbers, as described in block 608 of Figure 6. The flow will continue to block 816.
[0140] In block 816, the RNG unit 136 will continuously store R5 238 in the system memory 502 at the memory address specified by the XSTORE instruction, which will hold the counter 0 211 or counter 1 specified by the store_select signal 266 The value of 213 and the valid random data bytes in the buffer 0 242 or the buffer 1 246 designated by the store_select signal 266 are shown in FIG. 7. The process will continue to block 818.
[0141] In block 818, because in block 816, the effective random data bytes have been consumed by the action of storing to the memory, the control logic 244 sets the clear signal 223 to true to clear the specified by the store_select signal 266 The counter 0 211 or counter 1 213. The process will continue to block 822.
[0142] In block 822, the control logic 244 updates the store_select signal 266. That is, if the store_select signal 266 is 0, the control logic 244 will update the store_select signal 266 to 1. Conversely, if the store_select signal 266 is 1, the control logic 244 will update the store_select signal 266 to 0. The flow continues to block 824.
[0143] In block 824, because the execution of the XSTORE instruction has been completed, the interrupt unit 146 enables the interrupt. The process will end at block 824.
[0144] Referring now to FIG. 9, it is a flow chart of the operation example of the microprocessor 100 in FIG. 1 performing the multi-tasking operation of random number generation according to the present invention. Figure IX is a flowchart shows a typical system condition, wherein the two are working First initialize RNG unit 136 and execute XSTORE instructions to store random data bytes to memory. Figure 9 illustrates how the present invention advantageously supports multiple tasks between two jobs (job A and job B), even if the operating system does not support storing and restoring the state of the RNG unit 136 (ie, CSR 226). The flow starts at block 902.
[0145] In block 902, a reset occurs, which causes the control logic 244 to clear the TSPO flag 274. The flow continues to block 904.
[0146] In block 904, the operating system will start job A, and the initial code of job A will execute the instruction from XLOAD to XMM0 372 to initialize CSR 226 and XMM0 372 with the desired control value (represented as value A). The flow continues to block 906.
[0147] In block 906, according to blocks 604, 606, 608, and 612 of FIG. 6, RNG unit 136 responds to XLOAD, discards the contents of buffer 0242 and buffer 1246, clears counter 0 211 and counter 1213, and restarts Random number generation and accumulation and TSPO flag 274 is cleared. The flow will continue to block 908.
[0148] In block 908, task A executes the XSTORE command to store the random data generated according to the control value A loaded into the CSR 226 in block 904. The flow continues to block 912.
[0149] In block 912, in order to execute the XSTORE of the previous block, the RNG unit 136 continuously stores the count value and data accumulated after block 906 restarts in the system memory, as shown in FIGS. 7 and 8. Show. The flow continues to block 914.
[0150] In block 914, the operating system will perform a job switch from job A to job B. Among them, the operating system will store the value of XMM0 372 (which includes the control value A) into the system memory to retain the status of job A. However, the operating system does not know the status of CSR 226, so the operating system does not store CSR 226 in the system memory to retain its status. The flow continues to block 916.
[0151] In block 916, according to step 404 of FIG. 4, the RNG unit 136 responds to the loading of XMM0 372 in block 914 and sets the TSPO flag 274. The process will continue to block 918.
[0152] In block 918, the operating system starts job B, and the initial code of job B executes the instruction from XLOAD to XMM0 372 to initialize CSR 226 and XMM0 372 with the desired control value (represented as value B). The flow continues to block 922.
[0153] In block 922, according to blocks 604, 606, 608, and 612 of FIG. 6, RNG unit 136 responds to XLOAD, discards the contents of buffer 0242 and buffer 1 246, clears counter 0 211 and counter 1 213, The generation and accumulation of random numbers are restarted, and the TSPO flag 274 is cleared. The flow continues to block 924.
[0154] In block 924, task B executes the XSTORE command to store random data generated according to the control value B loaded into CSR 226 in block 918. The flow continues to block 924.
[0155] In block 926, in order to execute the XSTORE of the previous block, the RNG unit 136 continuously stores the count value and data accumulated after block 922 restarts in the system memory, as shown in FIGS. 7 and 8. Show. The flow continues to block 928.
[0156] In block 928, the operating system will perform a job switch from job B to job A. Among them, the operating system will store the value of XMM0 372 (which includes the control value B) into the system memory to retain the status of job B. However, the operating system does not know the status of CSR 226, so the operating system does not store CSR 226 in the system memory to retain its status. In addition, the operating system restores the status of task A, which includes loading the value A previously reserved in block 914 from system memory to XMM0 372. The process will continue to block 932.
[0157] In block 932, according to step 404 of FIG. 4, the RNG unit 136 responds to the loading of XMM0 372 in block 928 and sets the TSPO flag 274. The flow continues to block 934.
[0158] In block 934, task A executes the XSTORE command to store random data generated according to the control value A loaded into CSR 226 in block 904. However, in block 918, the value A in CSR 226 is overwritten. Therefore, the random data bytes currently accumulated in the buffer 0 242 and the buffer 1 246 are not generated based on the value A, but generated based on the value B. The flow continues to block 936.
[0159] In block 936, the RNG unit 136 determines that the TSPO flag 274 has been set according to block 804 in FIG. 8, and then copies the content of XMM0 372 to CSR 226 according to block 806 in FIG. Save to CSR 226. In addition, since the CSR 226 has been restored, the RNG unit 136 clears the TSPO flag 274 according to block 806. The flow will continue to block 938.
[0160] In block 938, according to blocks 808, 812, and 814 in FIG. 8, RNG unit 136 responds to the action copied to CSR 226 in block 936, discards the contents of buffer 0 242 and buffer 1 246, and clears the counter. 0 211 and counter 1 213 and restart random number generation and accumulation. The process continues to block 942.
[0161] In block 942, to execute the XSTORE of block 934, the RNG unit 136 will continuously store the accumulated count value and data after the previous block restarts to the system memory, as shown in FIGS. 7 and 8. Show. In this case, since in the previous block, counter 0 211 and counter 1 213 have been cleared, and the contents of buffer 0 242 and buffer 1 246 are discarded, the count value is 0 and there is no valid random data byte Stored in the system memory. The flow continues to block 944.
[0162] In block 944, task A executes the XSTORE command to store the random data generated according to the control value A loaded into the CSR 226 in block 904, where the CSR 226 has been restored to the value A in block 936. The flow will continue to block 946.
[0163] In block 946, in order to execute the XSTORE of the previous block, the RNG unit 136 continuously stores the count value and data accumulated after block 938 is restarted in the system memory, as shown in FIGS. 7 and 8 . The process will continue to block 948.
[0164] In block 948, task A executes the XSTORE command to store the random data generated according to the control value A loaded into the CSR 226 in block 904, where the CSR 226 has been restored to the value A in block 936. The flow continues to block 952.
[0165] In block 952, in order to execute the XSTORE of the previous block, the RNG unit 136 will deduct the bytes stored in the previous XSTORE in block 944 from the count value and data accumulated after the restart of block 938. Then the results are continuously stored in the system memory, as shown in Figure 7 and Figure 8. The process ends at block 952.
[0166] Referring now to FIG. 10, it is a block diagram of the string filtering device 224 of the RNG unit 136 of FIG. 2 in the microprocessor 100 of FIG. 1 according to the present invention.
[0167] For the purpose of the present invention, the leading 1 bit is defined as the continuous 1 bit at the beginning of a byte. A byte may contain 0 to 8 leading 1 bit. For example, byte 000111111 has 5 leading 1 bit; byte 11111110 has 0 leading 1 bit; and byte 11111111 has 8 leading 1 bit.
[0168] For the purpose of the present invention, the leading 0 bit is defined as the continuous 0 bit at the beginning of a byte. A byte may contain 0 to 8 leading 0 bits. For example, byte 11100000 has 5 leading 0 bits; byte 00000001 has 0 leading 0 bits; and byte 00000000 has 8 leading 0 bits.
[0169] For the purpose of the present invention, the trailing 1 bit is defined as a continuous 1 bit at the end of a byte; however, a byte with all 1s is defined as a 1 bit without a trailing end. A byte may contain 0 to 7 trailing 1 bits. For example, byte 11110000 has 4 tails and 1 bit; byte 11111110 has 7 tails and 1 bit; byte 01111111 has 0 tails and 1 bit; and byte 11111111 has 0 bits. 1 bit at the end.
[0170] For the purpose of the present invention, the trailing 0 bit is defined as the consecutive 0 bits at the end of a byte; however, a byte with all 0s is defined as the 0 bit without the trailing end. A byte may contain 0 to 7 trailing 0 bits. For example, byte 00001111 has 4 trailing 0 bits; byte 00000001 has 7 trailing 0 bits; byte 10000000 has 0 trailing 0 bits; and byte 00000000 has 0 bits. 1 bit at the end.
[0171] The string filtering device 224 includes a comparison logic 1002. The comparison logic 1002 receives a random data byte 298 from the shift register 218 in FIG. 2. The comparison logic 1002 checks the bit value in the random data byte group 298, and generates various signals for detecting consecutive bit strings of 1 and 0, as described below.
[0172] The comparison logic 1002 generates a num_leading_ones signal 1022A to specify the number of leading 1 bits in the random data byte group 298.
[0173] The comparison logic 1002 generates a num_trailing_ones signal 1028A to specify the number of trailing 1 bits in the random data byte 298.
[0174] The comparison logic 1002 also generates the a11_ones signal 1048A. If the random data byte 298 contains bits that are all 1, this signal is true.
[0175] The comparison logic 1002 also generates a leading_ones signal 1036A. If the random data byte 298 contains a leading 1 bit, this signal is true.
[0176] The comparison logic 1002 also generates a trailing_ones signal 1038A. If the random data byte 298 includes a trailing one bit, this signal is true.
[0177] The string filtering device 224 also includes a first counter 1016A to store a continuous 1-bit current count. In a specific embodiment, the counter 1016A includes a 6-bit register. The output of the counter 1016A is the ones_cnt signal 1024A.
[0178] The string filtering device 224 also includes a first adder 1012A, which adds the num_leading_ones signal 1022A and the ones_cnt signal 1024A to generate a new_ones_cnt signal 1026A.
[0179] The string filtering device 224 also includes a four-input first multiplexer 1014A. The multiplexer 1014A receives the ones_cnt signal 1024A, the new_ones_cnt signal 1026A, the num_trailing_ones signal 1028A, and the hard-coded zero value 1032A at its input. The multiplexer 1014A selects one of the input terminals according to the one_select signal 1042A, and outputs it to the counter 1016A.
[0180] The comparison logic 1002 generates a num_leading_zeros signal 1022B to specify the number of leading zero bits in the random data byte group 298.
[0181] The comparison logic 1002 generates a num_trailing_zeros signal 1028B to specify the number of trailing 0 bits in the random data byte 298.
[0182] The comparison logic 1002 also generates an all_zeros signal 1048B. If the random data byte group 298 contains all 0 bits, this signal is true.
[0183] The comparison logic 1002 also generates a leading_zeros signal 1036B. If the random data byte 298 contains a leading zero bit, this signal is true.
[0184] The comparison logic 1002 also generates a trailing_zeros signal 1038B. If the random data byte 298 includes a trailing zero bit, this signal is true.
[0185] The string filtering device 224 also includes a second counter 1016B to store a current count of consecutive 0 bits. In a specific embodiment, the counter 1016B includes a 6-bit register. The output of the counter 1016B is the zeros_cnt signal 1024B.
[0186] The string filtering device 224 also includes a second adder 1012B, which adds the num_leading_zeros signal 1022B and the zeros_cnt signal 1024B to generate a new_zeros_cnt signal 1026B.
[0187] The string filtering device 224 also includes a four-input second multiplexer 1014B. The multiplexer 1014B receives a zeros_cnt signal 1024B, a new_zeros_cnt signal 1026B, a num_trailing_zeros signal 1028B, and a fixed zero value 1032B at its input terminals. The multiplexer 1014B selects one of the input terminals according to the zero_select signal 1042B, and outputs it to the counter 1016B.
[0188] The string filtering device 224 also includes a first comparator 1046A, which compares the new_ones_cnt signal 1026A with the max_cnt signal 258 in FIG. 2. If the new_ones_cnt signal 1026A is greater than the max_cnt signal 258, the comparator 1046A will generate a true ones_exceeded signal 1034A; otherwise, the comparator 1046A will generate a false ones-exceeded signal 1034A.
[0189] The string filtering device 224 also includes a second comparator 1046B, which compares the new_zeros_cnt signal 1026B with the max_cnt signal 258 in FIG. If the new_zeros_cnt signal 1026B is greater than the max_cnt signal 258, the comparator 1046B will generate a true zeros_exceeded signal 1034B; otherwise, the comparator 1046B will generate a false zeros_exceeded signal 1034B.
[0190] The string filter device 224 also includes an OR gate 1004 with two input terminals, the input terminals of which are coupled to the output terminals of the comparator 1046A and the comparator 1046B. The OR gate 1004 receives the ones_exceeded signal 1034A and the zeros_exceeded signal 1034B at its input terminal. The OR gate 1004 generates a max_cnt_exceeded signal 1044 as the input of the selection logic 1006.
[0191] The string filter device 224 also includes a two-input AND gate 1008, which is coupled to the OR gate 1004. One input terminal of the AND gate 1008 receives the max_cnt_exceeded signal 1044 from the OR gate 1004, and the other input terminal receives the filter enable signal 262 in FIG. 2. The output of the gate 1008 is the filter failure signal 256 in FIG. 2.
[0192] The string filtering device 224 also includes a selection logic 1006 that receives the all_ones signal 1048A, the leading_ones signal 1036A, the trailing_ones signal 1038A, the max_cnt_exceeded signal 1044, the leading_zeros signal 1036B, the trailing_zeros signal 1038B, and the all_zeros signal 1048B. The selection logic 1006 generates the one_select signal 1042A and the zero_select signal 1042B according to the following code.
<img file="TWI227439B_D0002.tif" />
[0193] Reference is now made to FIG. 11, which shows a flow chart of the operation of the string filtering device 224 of FIG. 10 according to the present invention. The flow starts at block 1102.
[0194] In block 1102, counters 1016A and 1016B are initialized to zero. The process will continue to block 1104.
[0195] In block 1104, the RNG unit 136 of FIG. 1 generates 1-byte random data in the random byte signal 298 of FIG. 2, and the comparison logic 1002 generates according to the check result of the random data byte Its signal. The process will continue to block 1106.
[0196] In block 1106, the adder 1012A adds num_leading_ones 1022A and ones_cnt 1024A to generate new_ones_cnt 1026A, and the adder 1012B adds num_leading_zeros 1022B and zeros_cnt 1024B to generate new_zeros_cnt 1024B. The process continues to decision block 1112.
[0197] In decision block 1112, the selection logic 1006 checks max_cnt_exceeded 1044 to determine whether the number of consecutive 0s or 1s has exceeded max_cnt 258. If so, the process will continue to decision block 1114. Otherwise, the process continues to decision block 1124.
[0198] In the determination block 1114, the gate 1008 checks the filter enable signal 262 to determine whether the string filter device 224 is enabled. If so, the gate 1008 will generate the filter failure signal 256 of the true value in FIG. 2. The process will continue to block 1118.
[0199] In block 1118, the control logic 244 responds to the filter failure signal 256 with a true value, and does not set the increment signal 221 in FIG. 2 to true, and does not cause the random byte 298 to be loaded into the buffer 0 242 or The buffer 1246, even if the shift register 218 has generated a true byte generating signal 282. Therefore, since the random byte 298 has caused the number of consecutive 1s or 0s to exceed max_cnt258, the RNG unit 136 discards the random byte 298. The process will continue to block 1122.
[0200] In block 1122, the selection logic 1006 generates a value of 3 in the one_select signal 1042A and the zero_select signal 1042B, so that the multiplexers 1014A and 1014B retain the current ones_cnt 1024A and zeros_cnt 1024B, respectively. The flow then returns to block 1104.
[0201] In the decision block 1124, the selection logic 1006 checks the all_zeros signal 1048B to determine whether the random data bytes 298 are all zeros. If so, the process continues to block 1126. Otherwise, the process continues to decision block 1128.
[0202] In block 1126, the selection logic 1006 generates a value of 2 in the zero_select signal 1042B, so that the multiplexer 1014B selects the new_zeros_cnt signal 1026B, and generates a value of 0 in the one_select signal 1042A, so that the multiplexer 1014A selects A fixed value of 0 is entered in 1032A. The process will continue to block 1148.
[0203] In the decision block 1128, the selection logic 1006 checks the trailing_zeros signal 1038B to determine whether the random data byte 298 contains any trailing zeros. If so, the process continues to block 1132. Otherwise, the process continues to block 1134.
[0204] In block 1132, the selection logic 1006 generates a value of 1 in the zero_select signal 1042B, so that the multiplexer 1014B selects the num_trailing_zeros signal 1028B, and generates a value of 0 in the one_select signal 1042A, so that the multiplexer 1014A selects A fixed value of 0 is entered in 1032A. The process will continue to block 1148.
[0205] In block 1134, the selection logic 1006 generates a value of 0 in the zero_select signal 1042B, so that the multiplexer 1014B selects the fixed 0 value input 1032B. The process will continue to decision block 1136.
[0206] In the decision block 1136, the selection logic 1006 checks the all_ones signal 1048A to determine whether the random data bytes 298 are all ones. If so, the process continues to block 1138. Otherwise, the process continues to the decision block 1142.
[0207] In block 1138, the selection logic 1006 generates a value of 2 in the one_select signal 1042A, so that the multiplexer 1014A selects the new_ones_cnt signal 1026A. The process will continue to block 1148.
[0208] In the decision block 1142, the selection logic 1006 checks the trailing_ones signal 1038A to determine whether the random data byte 298 contains any trailing 1s. If so, the process continues to block 1144. Otherwise, the process continues to block 1146.
[0209] In block 1144, the selection logic 1006 generates a value of 1 in the one_select signal 1042A so that the multiplexer 1014A selects the num_trailing_ones signal 1028A. The process will continue to block 1148.
[0210] In block 1146, the selection logic 1006 generates a value of 0 in the one_select signal 1042A, so that the multiplexer 1014A selects the fixed 0 value input 1032A. The process will continue to block 1148.
[0211] In block 1148, the control logic 244 causes the random data byte 298 to be loaded into the buffer 0 242 or the buffer 1 246 selected by the fill_select signal 264, and sets the increment signal 221 to true to increment The counter 0 211 or the counter 1 213 selected by the fill_select signal 264. The flow then returns to block 1104.
[0212] Referring now to FIG. 12, which illustrates another specific embodiment of the present invention, FIG. 1 is a block diagram of the operation of the microprocessor 100 executing the XSTORE instruction. The XSTORE instruction in FIG. 12 is similar to the XSTORE instruction in FIG. 7, but in this specific embodiment, the count value of the valid random data byte is loaded into one of the general-purpose registers in the register file 108 , Such as the EAX 1202 register, and will not be stored in the system memory. Advantageously, similar to the XSTORE instruction in Figure 7, the XSTORE instruction in Figure 12 will continuously load the count value into EAX and store random data bytes into the memory to facilitate multiplexing with the RNG unit 136. . That is, the XSTORE instruction in Figure 12 is also uninterruptible.
[0213] Referring now to FIG. 13, which is a flow chart of the multi-buffering operation of the RNG unit 136 of FIG. 2 according to the present invention. The process starts at block 1302.
[0214] In block 1302, the reset signal 248 is set to true. The process will continue to block 1304.
[0215] In block 1304, the control logic 244 of FIG. 2 initializes the fill_select signal 264 and the store_select signal 266 to 0, and clears the counter 0 211 and the counter 1 213 in response to the reset action of the block 1302. The process will continue with decision block 1306.
[0216] In the decision block 1306, the control logic 244 checks the xstore signal 268 to determine whether the XSTORE command has been executed. If yes, the process will continue to decision block 1308. Otherwise, the process continues to the decision block 1322.
[0217] In the determination block 1308, the control logic 244 determines whether the power of the random bit generator 0 206 or the random bit generator 1 208 selected by the generator selection signal 252 is turned off. If so, the process will continue to block 1312. Otherwise, the process continues to block 1314.
[0218] In block 1312, the control logic 244 uses the power_cntrl signal 231 to turn on the power of the selected random bit generator. The flow will continue to block 1314.
[0219] In block 1314, according to block 816 of FIG. 8 and as shown in FIG. Buffer 0 242 or Buffer 1 246<img file="TWI227439B_D0003.tif" />The effective data bytes of is continuously stored in the system memory. The flow will continue to block 1316.
[0220] In block 1316, the control logic 244 sets the clear signal 223 to true to clear the counter 0 211 or the counter 1 213 selected by the store_select signal 266. The flow will continue to block 1318.
[0221] In block 1318, the control logic 244 updates the store_select signal 266 to select another buffer and counter. In an embodiment where the RNG unit 136 includes more than two buffers, the store_select signal 266 includes more than one bit, and the action of updating the store_select signal 266 includes incrementing the store_select signal 266, and when the increment exceeds the number of buffers, Will return to 0. The flow will continue to block 1322.
[0222] In the decision block 1322, the control logic 244 checks whether the byte generating signal 282 is true and the filtering failure signal 256 is false to determine whether a good random data byte is generated. If it has been generated, the process continues to block 1324. Otherwise, the process will continue to decision block 1306.
[0223] In block 1324, the control logic 244 loads good random data bytes into the buffer 0242 or the buffer 1 246 selected by the fill_select signal 264, and increments the counter 0 211 selected by the fill_select signal 264 Or counter 1 213. The process will continue with decision block 1326.
[0224] In the decision block 1326, the control logic 244 checks the fu110 signal 229 or the fu111 signal 227 specified by the fill_select signal 264 to determine whether the buffer 0 242 or the buffer 1 246 selected by the fill_select signal 264 is full. If so, the process continues to block 1328. Otherwise, the process returns to block 1306.
[0225] In block 1328, the control logic 244 updates the fill_select signal 264. In the embodiment where the RNG unit 136 includes two buffers, the action of updating the fill_select signal 264 includes switching the fill_select signal 264. In an embodiment where the RNG unit 136 includes more than two buffers, the fill_select signal 264 includes more than one bit, and the action of updating the fill_select signal 264 includes incrementing the fill_select signal 264, and when the increment exceeds the number of buffers, Will return to 0. The process will continue to decision block 1332.
[0226] In the decision block 1332, the control logic 244 checks the full0 signal 229 or the full1 signal 227 specified by the fill_select signal 264 updated by the block 1328 to determine the buffer 0 242 or the buffer 1 246 selected by the fill_select signal 264 Whether it is full (that is, determine whether all buffers are full). If so, the process continues to block 1334. Otherwise, the process returns to block 1306.
[0227] In block 1334, since all the buffers are full, the control logic 244 uses the power_cntrl signal 231 to turn off the power of the random bit generator 0 206 and the random bit generator 1 208. The process returns to decision block 1306.
[0228] Referring now to FIG. 14, it is a flow chart of the operation of the microprocessor 100 of FIG. 1 to execute the XLOAD instruction of FIG. 3 according to another embodiment of the present invention. The flowchart in FIG. 14 is the same as the flowchart in FIG. 6, and the blocks with the same number are the same, except that FIG. 14 includes an additional determination block 1403. The flow proceeds from block 602 to decision block 1403. In the determination block 1403, the control logic 244 of FIG. 2 determines whether the relevant bits of the CSR 226 have been changed due to the loading of the CSR 226 in the block 602. If so, the process will continue to block 604 in Figure 6. Otherwise, the flow continues to block 612, as shown in the figure. The advantage of this embodiment is that it is not necessary to discard the accumulated random bytes and restart the accumulation of random bytes. That is, if the loading of CSR 226 does not change the value that will affect the random number generation function of the RNG unit 136, since the random byte is generated by using the desired control value, there is no need to discard the accumulated value. Random bytes and restart the accumulation of random bytes. In a specific embodiment, the relevant CSR 226 bits are the string filter enable bit 334, the generator select bit 336, the CNT enable bit 342, and the string filter max_cnt 346.
[0229] Referring now to FIG. 15, it shows a flowchart of the operation of the microprocessor 100 of FIG. 1 to execute the XSTORE instruction of FIG. 3 according to another specific embodiment of the present invention. The flowchart of FIG. 15 is the same as the flowchart of FIG. 8, and the blocks with the same number are the same, except that FIG. 15 includes an additional judgment block 1507. The flow proceeds from block 806 to decision block 1507. In the determination block 1507, the control logic 244 of FIG. 2 determines whether the relevant bits of the CSR 226 have been changed due to the copying to the CSR 226 in the block 806. If so, the process will continue to block 808 in Figure 8. Otherwise, the flow continues to block 816, as shown. The advantage of this embodiment is that it is not necessary to discard the accumulated random bytes and restart the accumulation of random bytes. That is, if the action copied to the CSR 226 does not change the value that will affect the random number generation function of the RNG unit 136, since the random byte is generated by using the desired control value, there is no need to discard the accumulated value. And restart the accumulation of random bytes. In a specific embodiment, the relevant CSR 226 bits are string filter enable bit 334, generator select bit 336, CNT enable bit 342, and string filter max_cnt 346.
[0230] Referring now to FIG. 16, it is a block diagram of the operation of the microprocessor 100 in FIG. 1 to execute the XSTORE instruction according to another embodiment of the present invention. The XSTORE instruction of FIG. 16 is similar to the XSTORE instruction of FIG. 12. However, in the embodiment of FIG. 16, the destination operand of the XSTORE instruction specifies a register of the microprocessor 100, such as XMM register, floating Point register, MMX register or integer unit register (such as EBX) instead of specifying the address in system memory. That is, the effective random data bytes are continuously written into one of the user-visible registers of the register file 108, and are not stored in the system memory. In the example of FIG. 16, the XSTORE instruction will specify the XMM3 register 376 in the SSE register 352 of FIG. 3 to write valid random data bytes, as shown in the figure. Advantageously, similar to the XSTORE command in Figure 12, the XSTORE command in Figure 16 will continuously write random data bytes into the user-visible register and load the count value into EAX 1202 to facilitate communication with Multiplexing operation of RNG unit 136. That is, the XSTORE instruction in Figure 16 is also uninterruptible.
[0231] Referring now to FIG. 17, it is a block diagram of the operation of the microprocessor 100 executing the XSTORE instruction in FIG. 1 according to another specific embodiment of the present invention. The XSTORE instruction of FIG. 17 is similar to the XSTORE instruction of FIG. 12. However, in the embodiment of FIG. 17, the XSTORE instruction includes an x86 architecture REP preamble. With the REP XSTORE command, the number of random data bytes to be stored in the system memory will be designated as the input parameter of the ECX register 1702 of the register file 108, as shown in the figure. Before executing the REP XSTORE command, the software loads the ideal count value of the random data bytes to be stored in the system memory into the ECX 1702.
[0232] In a specific embodiment, the REP XSTORE command can be interrupted during the storage operation of storing random data bytes into the system memory. The memory address is initially specified in the general-purpose register of the register file 108. In the example of FIG. 17, the memory address is specified in ES:EDI 1704 of the register file 108, as shown in the figure. Whenever one or more random data bytes are written into the system memory, ES:EDI1702 is updated as the next location in the system memory for storing random data bytes. In addition, whenever one or more random data bytes are stored in the system memory, the ECX 1702 is updated to reflect the number of random bytes that are yet to be stored. For example, suppose the REP XSTORE instruction specifies a byte count of 28 and a memory address of 0x12345678 in ECX 1702. Suppose that in one of buffer 0 242 and buffer 1 246, the RNG unit 136 has 8 available bytes, and when more random data bytes are accumulated, 8 bytes are written into System memory. When 8 bytes are written to memory, ECX 1702 will be updated to 20 to indicate that there are 20 random data bytes that must be written into the system memory. In addition, the address will be updated to the position 0x12345680 in the system memory where a large number of random data bytes will be written next. Interruptions may occur at this time, and the software will check for updated values. When the interrupt has been executed and control returns to the REP XSTORE instruction, the REP XSTORE instruction will use the updated values in ECX 1702 and ES:EDI 1704 to resume execution. In addition, when the REP XSTORE command is completed, the current value of the CSR 226 in Figure 2 will be copied to the EAX register 1202 of the register file 108.
[0233] Please refer to FIG. 18. FIG. 18 is a block diagram of the XSTORE instruction executed by the processor 100 in FIG. 1 according to a specific embodiment of the present invention. The XSTORE instruction in Figure 18 is very similar to the XSTORE instruction in Figure 12. However, in the specific embodiment of FIG. 18, only part of the random data bytes temporarily stored in R5238 are stored in the system memory 502. Define N as a power of 2 (exponential factor). An N is provided to select every Nth bit in R5238 to be stored in the system memory 502. In other words, N is equal to the power of 2 (exponential factor) as a reference. The exponential factor specified by the EDX 1802 register is an input parameter of the XSTORE instruction as shown in Figure 18. EDX 1802 is a user-visible general register in the register file 108.
[0234] In an embodiment, the length of the random data byte temporarily stored in R5 238 is 8 bits or 64 bits, so the allowable value of the exponent factor specified in EDX 1802 can be 0, 1, 2, 3, The possible values of N are 1, 2, 4, 8. Therefore, in the XSTORE instruction embodiment shown in Figure 18, the effective random data byte length stored in the system memory is 8/N, that is, 8, 4, 2, 1. In another embodiment, the allowable values of factor exponents specified in EDX 1802 are 1, 2, 3, and the possible N values are 1, 2, 4, and 8. After the execution of the XSTORE command is completed, the effective random data byte length of the system memory 502 and the command status are determined and placed in the EAX 1202 at the same time.
[0235] The XSTORE instruction shown in FIG. 18 also includes the features of other XSTORE instruction embodiments described in the previous figure. For example, the XSTORE instruction shown in Figure 18 can store every Nth accumulated and selected bit in a register in the microprocessor, instead of as described in the specific embodiment of Figure 16 Stored to the memory; or the valid bit count value can be stored in the memory instead of the EAX register as described in the specific embodiment of Figure 7; or a REP preamble can be included in the figure In the specific embodiment described in 17.
[0236] Please refer to FIG. 19, FIG. 19 is an example of an operation executed when the XSTORE instruction is performed as shown in FIG. 18 according to the present invention. A practical example of binary random data bit value in R5 238. In the figure, each bit in R5 238 is represented in octal. The figure also shows that random data bytes are stored in the system memory 502 according to one of the four allowable values given in Figure 18. If EDX is 0, all 64 bits from R 5 238 will be stored in system memory 502. If EDX is 1, then only the 32 bits composed of two selected by R5 238 will be stored in the system memory 502. If EDX is 2, only 16 bits consisting of one of the four selected by R5 238 will be stored in the system memory 502. If the EDX is 3, only 8 bits consisting of one out of eight selected by R5 238 will be stored in the system memory 502.
[0237] The advantage of the present invention is that, as shown in Figure 18, the XSTORE instruction reduces the correlation between consecutive bits generated by the RNG unit 136, where the RNG unit 136 is enabled by the user and specifies the exponential factor stored in the EDX 1802 , The exponential factor is used to select every N bits in R5 238, and the relationship between the exponential factor and N can be expressed as: N=2<sup>^</sup>(Exponential factor).
[0238] Please refer to FIG. 20. FIG. 20 is an operation flowchart of the RNG unit 136 of FIG. 1 to reduce the correlation between consecutive bits according to a specific embodiment of the present invention. In the specific embodiment of FIG. 20, the device used to perform the function of reducing the correlation between consecutive bits includes multiple components as shown in the microprocessor 100, such as the file register 108, the address generator 112, and the load The input unit 114, the execution unit 116 (including the ALU 162), the RNG unit 136, the storage unit 118, the write-back unit 122, the write buffer 124, and the bus interface unit 128. The microcode instructions stored in the microcode memory 132 as shown in FIG. 1 control the components of the microprocessor 100 according to the program listing as shown in FIG. 21. The flowchart of FIG. 20 describes the microcode instructions of the program list shown in FIG. 21. The process starts at block 2002.
[0239] In block 2002, the RNG unit 136 shown in FIG. 2 generates a series of random data bits through the random bit generator 206 or 208, the multiplexer 214, and the whitener 216, and by means of FIG. 2 and The shift register 218, the string filter device 224, the multiplexer 228, the demultiplexer 232, the buffer 0 242 and the buffer 1 246 described in the previous figure are two data buffers, the multiplexer 236, R5 238 and The control logic 244 accumulates the bits into bytes. The next step of the flow is to the decision block 2004.
[0240] In the determination block 2004, the microprocessor 100 determines whether eight random data bytes have been accumulated in buf0 242 or buf1 246 by using the available bit count 332 from the CSR 226 in FIG. 3. If yes, the process proceeds to block 2012; otherwise, the process proceeds to block 2006.
[0241] In block 2006, since eight random data bytes have not been accumulated, the microprocessor 100 sets the length of the effective random data bytes to zero. The flow goes to block 2008 next.
[0242] In block 2008, the microprocessor 100 loads the status obtained by the EAX 1202 from the CSR 226 and the length of the valid random data byte stored in the memory. If the block 2008 is from the block 2006, the length of the effective random data byte is zero. If the block 2008 is from the block 2018, the length of the effective random data byte is 8. If block 2008 comes from block 2044, the length of the effective random data byte is the relational function of the exponential factor specified in EDX, such as: 2<sup>^</sup>(3-Exponential factor). The process ends at block 2008.
[0243] In block 2012, the microprocessor 100 loads the contents of R5 238 into a temporary storage location, such as temp1 in FIG. 20. In one embodiment, only the random data bytes from R5 238 are loaded into templ, not the effective byte count. In the embodiment of the microcode list shown in Figure 21, two 32-bit registers r4 and r5 are commonly used as templ. The next step of the process is to the decision block 2014.
[0244] In the determination block 2014, the microprocessor 100 determines whether the exponential factor specified in the EDX 1802 is 0, that is, whether all the bytes from R5 will be stored in the memory. If yes, the process goes to block 2016, otherwise, the process goes to block 2022.
[0245] In the decision block 2016, the microprocessor 100 stores all eight valid random data bytes accumulated in R5 238 into the system memory in FIG. 18. The next step of the process is to block 2018.
[0246] In block 2018, since all eight bytes are stored in the system memory 502 in block 2016, the microprocessor 100 sets the length of the effective random data byte to 8. The flow goes to block 2008 next.
[0247] In block 2022, the microprocessor 100 stores an input parameter of the XSTORE instruction in the EDX 1802, and calculates the value of N by the power of two. The flow next goes to block 2024.
[0248] In block 2024, the microprocessor 100 obtains a lap count by dividing 64 by N. The loop count is the length to be stored in the system memory 502. The flow next goes to block 2026.
[0249] In block 2026, the microprocessor 100 clears EAX1202 to zero. The flow next goes to block 2028.
[0250] In block 2028, the microprocessor 100 shifts the EAX 1202 by one bit to the left to clear an EAX space for the next bit selected and accumulated from the original data obtained from the R5 238. The flow next goes to block 2032.
[0251] In block 2032, the microprocessor 100 obtains the last bit from temp1 (that is, discards all but the last bit) and adds the last bit to EAX 1202 to achieve selection and selection. Accumulate the next Nth bit. The flow next goes to block 2034.
[0252] In block 2034, the microprocessor 100 shifts temp1 to the right by N bits, and therefore puts the next selected N bits in the position of temp1, and shifts temp1 to the right by N bits to shift the previous The second selected and accumulated bits in block 2032 are discarded. The flow next goes to block 2036.
[0253] In block 2036, the microprocessor 100 decrements the loop count value by one. The flow next goes to block 2038.
[0254] In block 2038, the microprocessor 100 determines whether the loop count value has reached zero. If yes, the process goes to block 2042, otherwise, the process goes to block 2028.
[0255] In block 2042, the microprocessor 100 stores the EAX 1202 in the system memory 502. EAX 1202 includes every Nth bit selected from R5 238 and accumulated. In one embodiment, the entire contents of EAX 1202 are stored in system memory 502, even though some bits in EAX 1202 may not contain valid random data bytes. However, in the 2008 block, the XSTORE instruction is completed every time. The length of the effective random data bytes stored in the system memory 502 will be reflected in EAX 1202. Therefore, the enabling program determines the length of the effective random data bytes to be stored in the system memory 502. For example, if EAX 1202 is 2, only two of the four bytes are stored in the system memory 502, and the length of the effective random data byte is set to 2 according to the state of EAX1202.
[0256] In block 2044, since N is 2, 4, or 8, and all (8/N) bits are stored in the system memory 502 in block 2042, the microprocessor 100 sets valid random data bits The length of the group is set to 8 divided by N. The flow goes to block 2008.
[0257] Please refer to FIG. 21. FIG. 21 is a microcode instruction list for reducing the correlation between consecutive bits in the processor 100 as shown in FIG. 1 according to the present invention. The following discussion will help understand the microcode list.
[0258] This microcode list includes branch instructions called jump instructions, such as je. 32, je1.32, loop instructions, such as loopn. 32, return Instruction (return instruction). All instruction positions following the branch instruction are called a delay slot, and all instructions in the delay slot will be executed regardless of whether the branch has been selected. In this way, if the branch has not been selected, the instruction in the delay slot and the next instruction will be executed. If the branch has been selected, the instruction in the slot during the delay and the instruction at the branch target address will be executed next.
[0259] The microcode instructions use eight 32-bit general registers in the register file 108, which are represented as r0 to r7 in the list. In one embodiment, r0 to r7 are not user-visible registers. The stored value of r0 is 0 at all times. In one embodiment, the arithmetic and logical operations specified by the microcode instructions, such as and, add, and shift instructions are mainly executed by the ALU 162 in FIG. 1.
[0260] Except for branch instructions, the format of these three operand instructions is: <opcode> <purpose> <source one> <source two>
[0261] The command mfxd.64 XMM5 in the 7th line followed by the command dmtid r4, r5 in the 8th line causes the contents of the 64-bit R5 238 in Figure 2 to be copied to two 32-bit register r4, r5. According to the dmtid r2, r3 instruction on the first line, the part of the microcode is branched to get_random_data including an mfxd.64 instruction (that is, CSR 226) in the delay time slot after the branch. Therefore, combining the two instructions causes the contents of the 64-bit CSR 226 to be copied to the two 32-bit registers r2 and r3.
[0262] Please refer to FIG. 22. FIG. 22 is a specific embodiment according to the present invention. The part of the RNG unit 136 shown in FIG. 1 includes a bit selector 2202 to reduce the correlation between consecutive bits. Block diagram of sexual time. The RNG unit 136 shown in Figure 22 is very similar to the RNG unit 136 shown in Figure 2. However, only the register R5 238 shown in Fig. 2 is shown in Fig. 22. However, unlike Figure 2, R5 238 is not directly connected to data bus 144 in Figure 22. Instead, the output of R5 238 is connected to an intermediate data bus 2206. The RNG unit 136 shown in FIG. 22 also includes a bit selector 2202. The input of the bit selector 2202 is connected to the intermediate data bus 2206. The output of the bit selector 2202 is connected to the data bus 144 as shown in FIG. 1, and is represented as the DB 144 in FIG. 22. In the embodiment shown in Figure 22, both the intermediate data bus 2206 and the data bus 144 are 64 bits, and R5 238 includes 64 bits for storing random data bytes, that is, storing 8 random data bytes. The bit selector 2202 also includes a control input for receiving an exponential factor signal 2204. The value of the exponential factor signal 2204 is used as an input parameter of an XSTORE command in FIG. 18. In one embodiment, the bit selector 2202 selects every bit, every two bits, every four bits, or every eight bits from the intermediate data bus 2206 according to the value of the exponent factor 2204, respectively Provide 8, 4, 2 or 1 random data bytes to the data bus 144, as described above and as shown in the embodiment of FIG. 19.
[0263] Please refer to FIG. 23. FIG. 23 is a detailed block diagram of the bit selector 2202 as shown in FIG. 22 according to the present invention. The bit selector 2202 includes 64 4-to-1 multiplexers, denoted as 2302-0 to 2302-63, and these 64 multiplexers are denoted as a multiplexer set 2302. Each multiplexer of the multiplexer set 2302 includes four inputs, denoted as 0, 1, 2, and 3. Each multiplexer of the multiplexer set 2302 also includes a control input connected to the exponential factor signal 2204 as shown in FIG. 22. If the exponent factor 2204 is equal to 0, the multiplexer 2302 selects the 0th input and provides it to the output. If the exponent factor 2204 is equal to 1, the multiplexer 2302 selects No. 1 input and provides it to the output. If the exponent factor 2204 is equal to 2, the multiplexer 2302 selects the No. 2 input and provides it to the output. If the exponent factor 2204 is equal to 3, the multiplexer 2302 selects the No. 3 input and provides it to the output.
[0264] FIG. 23 shows multiplexers 2302-0, 2302-1, 2302-2, 2302-3, 2302-n, and 2302-63. In Fig. 23, n corresponds to the bit length of DB 144, and 2302-n is generally represented as the output of multiplexer 2303 connected to DB 144[n]. The output of the multiplexer 2302-0 is connected to DB 144[0], which is the 0th bit of DB 144, as shown in Figure 22. In the same way, the output of the multiplexer 2302-1 is connected to DB 144[1]. The output of the multiplexer 2302-2 is connected to DB 144[2]. The output of the multiplexer 2302-3 is connected to DB 144 [3]. The output of the multiplexer 2302-n is connected to DB 144[n]. The output of the multiplexer 2302-63 is connected to DB 144 [63].
[0265] Each multiplexer 2302-n receives intermediate data bus 2206 signal n at its 0 input; receives intermediate data bus 2206 signal 2n at its 1 input; receives intermediate data bus 2206 at its 2 input Signal 4n; Receive intermediate data bus 2206 signal 8n at its 3 inputs. Therefore, the multiplexer 2302-0 receives the intermediate data bus 2206 signal 0 at its 0 input; receives the intermediate data bus 2206 signal 0 at its 1 input; receives the intermediate data bus 2206 signal 0 at its 2 input; At its 3 inputs, it receives the intermediate data bus 2206 signal 0. The multiplexer 2302-1 receives the intermediate data bus 2206 signal at its 0 input, 1 receives the intermediate data bus 2206 signal at its 1 input, receives the intermediate data bus 2206 signal at its 2 inputs, and receives the signal 4 at its 3 input Intermediate data bus 2206 signal 8. The multiplexer 2302-2 receives intermediate data bus 2206 signal 2 at its 0 input; receives intermediate data bus 2206 signal 4 at its 1 input; receives intermediate data bus 2206 signal 8 at its 2 input; 3 Input and receive the intermediate data bus 2206 signal 16. The multiplexer 2302-3 receives the intermediate data bus 2206 signal 3 at its 0 input; receives the intermediate data bus 2206 signal 6 at its 1 input; receives the intermediate data bus 2206 signal 12 at its 2 input; The 3 inputs receive the intermediate data bus 2206 signal 24. The multiplexer 2302-63 receives the intermediate data bus 2206 signal 63 at its 0 input, as shown. Any value input to the multiplexer 2303 greater than 63 will be ignored.
[0266] As described above, the present invention can be observed that, under some environmental conditions, the smallest correlation between consecutively generated bits that will reduce the randomness of the generated random numbers is achieved. The advantage is that by selecting a bit in every N bits by the random bit generator, the present invention can be observed to increase the Shannon entropy and the corresponding minimum random data bit generator rate is as follows:
<tables><img file="TWI227439B_D0004.tif" /></tables>
[0267] Although the present invention and its objectives, features and advantages have been described in detail, other embodiments should also be included in the scope of the present invention. For example, in some embodiments, the exponential factor is based on 2. Of course, the present invention can also be applied to other base values. In addition, although in some embodiments the factor is used to calculate the power of 2 and stored in the register, the factor can also be specified in other ways. For example, when the value is divided into a register, the factor can be directly specified by the value.
[0268] In short, the above are only preferred embodiments of the present invention, and should not be used to limit the scope of implementation of the present invention. Most of the equal changes and modifications made in accordance with the scope of the patent application for this invention should still fall within the scope of the patent for this invention.
<p>100. . . microprocessor</p><p>102. . . Command cache</p><p>104. . . Instruction extractor</p><p>106. . . Instruction translator</p><p>108. . . Scratchpad file</p><p>112. . . Address generator</p><p>114. . . Loading unit</p><p>116. . . Execution phase</p><p>118. . . Storage unit</p><p>122. . . Write-back unit</p><p>124. . . Write buffer</p><p>126. . . Read buffer</p><p>128. . . Bus Interface Unit (BIU)</p><p>132. . . Microcode ROM</p><p>134. . . SSE unit</p><p>136. . . Random number generator (RNG) unit</p><p>138. . . Processor bus</p><p>142,144. . . Data bus</p><p>146. . . Interrupt unit</p><p>148. . . Interrupt signal</p><p>152. . . Interrupt vector</p><p>202. . . Self-test unit</p><p>204. . . CPUID register</p><p>206. . . Random bit generator 0</p><p>208. . . Random bit generator 1</p><p>211. . . Counter 0</p><p>212. . . Machine Specific Register (MSR)</p><p>213. . . Counter 1</p><p>214. . . Multiplexer</p><p>215. . . Second demultiplexer</p><p>216. . . Albino</p><p>217. . . Third demultiplexer</p><p>218. . . Shift register</p><p>219. . . Fourth multiplexer</p><p>221. . . Increment signal</p><p>222. . . Continuous number test (CNT) unit</p><p>223. . . Clear signal</p><p>224. . . String filter</p><p>225. . . Comparators</p><p>226. . . Control and Status Register (CSR)</p><p>227. . . full1 signal</p><p>228. . . Second multiplexer</p><p>229. . . full0 signal</p><p>231. . . power_cntrl signal</p><p>232. . . Demultiplexer</p><p>234. . . Available byte count</p><p>236. . . Third multiplexer</p><p>238. . . Register R5</p><p>242. . . Buffer 0</p><p>244. . . Control logic</p><p>246. . . Buffer 1</p><p>248. . . Reset signal</p><p>252. . . Generator selection signal</p><p>254. . . Raw bit signal</p><p>256. . . Filter failure signal</p><p>258. . . max_cnt signal</p><p>262. . . Filter enabling signal</p><p>264. . . fill_select signal</p><p>266. . . store_select signal</p><p>268. . . xstore signal</p><p>272. . . xload signal</p><p>274. . . TSPO flag register</p><p>278. . . Data bus</p><p>282. . . Byte generates signal</p><p>284. . . CNT enabling signal</p><p>286. . . RNG presence signal</p><p>288. . . Self-test failure signal</p><p>292. . . Self-test enabling signal</p><p>294. . . CNT failure signal</p><p>296. . . DC bias signal</p><p>298. . . Random data bytes</p><p>302, 314. . . RNG presence bit</p><p>312. . . RNG enable bit</p><p>316. . . Self-test enable bit</p><p>318. . . Self-test failure bit</p><p>322. . . DC bias bit</p><p>324. . . Original bit</p><p>332, 362. . . Available byte count field</p><p>334. . . String filter enable bit</p><p>336. . . Generator selection bit</p><p>338. . . String filter device failure bit</p><p>342. . . CNT enable bit</p><p>344. . . CNT failure bit</p><p>346. . . String filter device max_cnt field</p><p>352. . . SSE register</p><p>364. . . Random data byte field</p><p>372. . . XMM0</p><p>374. . . XMM5</p><p>376. . . XMM3</p><p>402-404. . . The operation flow of the microprocessor executing the instruction to load the value into the XMM0 register</p><p>502. . . System memory</p><p>504. . . 16 bytes of data</p><p>602-612. . . The operation flow of the microprocessor executing the XLOAD instruction</p><p>702. . . Available byte count</p><p>704. . . Random data bytes</p><p>802-824. . . The operation flow of the microprocessor executing the XSTORE instruction</p><p>902-952. . . The microprocessor performs the action flow of the multitasking operation example of random number generation</p><p>1002. . . Comparison logic</p><p>1004. . . Or gate</p><p>1006. . . Choice logic</p><p>1008. . . And gate</p><p>1012A. . . First adder</p><p>1012B. . . Second adder</p><p>1014A. . . First multiplexer</p><p>1014B. . . Second multiplexer</p><p>1016A. . . First counter</p><p>1016B. . . Second counter</p><p>1022A. . . num_leading_ones signal</p><p>1022B. . . num_leading_zeros signal</p><p>1024A. . . ones_cnt signal</p><p>1024B. . . zeros_cnt signal</p><p>1026A. . . new_ones_cnt signal</p><p>1026B. . . new_zeros_cnt signal</p><p>1028A. . . num_trailing_ones signal</p><p>1028B. . . num_trailing_zeros signal</p><p>1032A, 1032B. . . Fixed zero</p><p>1034. . . Aones_exceeded signal</p><p>1034B. . . zeros_exceeded signal</p><p>1036A. . . leading_ones signal</p><p>1036B leading_zeros signal</p><p>1038A. . . trailing_ones signal</p><p>1038B. . . trailing_zeros signal</p><p>1042A. . . one_select signal</p><p>1042B. . . zero_select signal</p><p>1044. . . max_cnt_exceeded signal</p><p>1046A. . . First comparator</p><p>1046B. . . Second comparator</p><p>1048A. . . all_ones signal</p><p>1048B. . . all_zeros signal</p><p>1102-1148. . . Operation process of string filter device</p><p>1202. . . EAX register</p><p>1302-1334. . . The flow of multiple buffer operation of RNG unit</p><p>1702. . . ECX register</p><p>1704. . . ESEDI</p><p>1802. . . EDX</p><p>2002-2044. . . Operation flow to reduce the correlation between consecutive bits</p><p>2202. . . Bit selector</p>
[0024] FIG. 1 shows a block diagram of the microprocessor of the present invention.
[0025] FIG. 2 is a block diagram of the RNG unit in the microprocessor of FIG. 1 of the present invention.
[0026] FIG. 3 shows a block diagram of various registers related to the RNG unit of FIG. 1 in the microprocessor of FIG. 1 of the present invention.
[0027] FIG. 4 is a flowchart showing the operation of the microprocessor of FIG. 1 to load the value into the XMM0 register of FIG. 3 according to the present invention.
[0028] FIG. 5 shows a block diagram of the operation of the microprocessor in FIG. 1 when the XLOAD instruction is executed according to the present invention.
[0029] FIG. 6 shows a flowchart of the operation of the microprocessor in FIG. 1 to execute the XLOAD instruction according to the present invention.
[0030] FIG. 7 shows a block diagram of the operation of the microprocessor in FIG. 1 when the XSTORE instruction is executed according to the present invention.
[0031] FIG. 8 is a flowchart showing the operation of the microprocessor of FIG. 1 to execute the XSTORE instruction according to the present invention.
[0032] FIG. 9 is a flow chart showing an example of a multitasking operation performed by the microprocessor in FIG. 1 for generating random numbers according to the present invention.
[0033] FIG. 10 shows a block diagram of the string filtering device of the RNG unit of FIG. 2 in the microprocessor of FIG. 1 according to the present invention.
[0034] FIG. 11 is a flow chart showing the operation of the filter device in FIG. 10 according to the present invention.
[0035] FIG. 12 shows a block diagram of the operation of a microprocessor executing the XSTORE instruction according to another specific embodiment of the present invention.
[0036] FIG. 13 shows a flowchart of the multiple buffering operation of the RNG unit of FIG. 2 according to the present invention.
[0037] FIG. 14 shows a flowchart of the operation of the microprocessor executing the XLOAD instruction in FIG. 1 according to another specific embodiment of the present invention.
[0038] FIG. 15 shows a flowchart of the operation of the microprocessor 100 executing the XSTORE instruction in FIG. 1 according to another specific embodiment of the present invention.
[0039] FIGS. 16 and 17 show a block diagram of the operation of the microprocessor executing the XSTORE instruction according to another specific embodiment of the present invention.
[0040] FIG. 18 is a block diagram of the XSTORE instruction executed by the processor as shown in FIG. 1 according to a specific embodiment of the present invention.
[0041] FIG. 19 According to the present invention, an example of an operation is executed when the XSTORE instruction is shown in FIG. 18.
[0042] FIG. 20 is a flow chart of the operation of reducing the correlation between consecutive bits in the RNG unit shown in FIG. 1 according to a specific embodiment of the present invention.
[0043] FIG. 21 is a microcode instruction list that enables the processor 100 of FIG. 1 to reduce the correlation between consecutive bits according to the present invention.
[0044] FIG. 22 is a block diagram according to a specific embodiment of the present invention, such as the part of the RNG unit shown in FIG. 1, which includes a bit selector to reduce the correlation between consecutive bits.
[0045] FIG. 23 is a detailed block diagram of the bit selector in FIG. 22 according to the present invention.
152 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47 Sheet 48 Sheet 49 Sheet 50 Sheet 51 Sheet 52 Sheet 53 Sheet 54 Sheet 55 Sheet 56 Sheet 57 Sheet 58 Sheet 59 Sheet 60 Sheet 61 Sheet 62 Sheet 63 Sheet 64 Sheet 65 Sheet 66 Sheet 67 Sheet 68 Sheet 69 Sheet 70 Sheet 71 Sheet 72 Sheet 73 Sheet 74 Sheet 75 Sheet 76 Sheet 77 Sheet 78 Sheet 79 Sheet 80 Sheet 81 Sheet 82 Sheet 83 Sheet 84 Sheet 85 Sheet 86 Sheet 87 Sheet 88 Sheet 89 Sheet 90 Sheet 91 Sheet 92 Sheet 93 Sheet 94 Sheet 95 Sheet 96 Sheet 97 Sheet 98 Sheet 99 Sheet 100 Sheet 101 Sheet 102 Sheet 103 Sheet 104 Sheet 105 Sheet 106 Sheet 107 Sheet 108 Sheet 109 Sheet 110 Sheet 111 Sheet 112 Sheet 113 Sheet 114 Sheet 115 Sheet 116 Sheet 117 Sheet 118 Sheet 119 Sheet 120 Sheet 121 Sheet 122 Sheet 123 Sheet 124 Sheet 125 Sheet 126 Sheet 127 Sheet 128 Sheet 129 Sheet 130 Sheet 131 Sheet 132 Sheet 133 Sheet 134 Sheet 135 Sheet 136 Sheet 137 Sheet 138 Sheet 139 Sheet 140 Sheet 141 Sheet 142 Sheet 143 Sheet 144 Sheet 145 Sheet 146 Sheet 147 Sheet 148 Sheet 149 Sheet 150 Sheet 151 Sheet 152
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8019802B2 | Cited by | United States of America | Applicant |
11 members in 5 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 10365600 | United States of America | – | |
| 36560003 | United States of America | A |
Members11
| Document | Office | Kind | |
|---|---|---|---|
| CN1514345A | China | A | |
| US2004158591A1 | United States of America | A1 | |
| EP1450251A2 | European Patent Office (EPO) | A2 | |
| TW200416592A | Taiwan Province of China | A | |
| EP1450251A3 | European Patent Office (EPO) | A3 | |
| TWI227439BThis record | Taiwan Province of China | B | |
| EP1450251B1 | European Patent Office (EPO) | B1 | |
| US7139785B2 | United States of America | B2 | |
| DE60309282D1 | Germany | D1 | |
| DE60309282T2 | Germany | T2 | |
| CN100454235C | China | C |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Expiration of patent term of an invention patentMK4A | MK4A |
Numbers
- Publication
- I227439
- Application
- 92118544
Titles4
- Chinese
- 用以減低在隨機亂數產生器中連續位元相關性的裝置與方法
- English
- APPARATUS AND METHOD FOR REDUCING SEQUENTIAL BIT CORRELATION IN A RANDOM NUMBER GENERATOR
- Unlabeled
- 用以減低在隨機亂數產生器中連續位元相關性的裝置與方法
- Unlabeled
- Apparatus and method for reducing continuous bit correlation in random random number generator
Classification
- CPC, 1
- G06F7/588
- IPC, 1
- G06F7 58