Methods and apparatus for enciphering and deciphering input messages
Abstract
This record has no abstract on file.
Term
Term ended
Expired 7 April 1995, 31.5 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
6 claims: 6 independent, 0 dependent
- 1Patentansprüche:claims: 1. Method for encrypting and securing data that comes in the form of data blocks 1. Verfahren zur Verschlüsselung und Absicherung von Daten, die in Form von Datenblöcken anfallen, wherein successive plaintext data blocks to be processed are supplied to a key device, by means of which these blocks are converted in successive block keyways under joins to a provided key bit sequencer arrangement in disguised, encrypted data blocks, wherein the encrypted data blocks can also be fed to a decrypting key device;by means of which the encrypted data blocks are decrypted in successive block key processes, again logical connections with a provided key bit sequence arrangement, and converted into the original plaintext data blocks, characterized in that, during encryption and decryption, each data block is subjected at least once to a logical combination with the key bit sequence arrangement and wobei aufeinanderfolgende zu verarbeitende Klartextdatenblöcke einer Schlüsseleinrichtung zugeführt werden, mittels derer diese Blöcke in aufeinanderfolgenden Blockschlüsselgängen unter jo logischen Verknüpfungen mit einer bereitgestellten Schlüsselbitfolgeanordnung in getarnte, verschlüsselte Datenblöcke umgewandelt werden, wobei ferner die verschlüsselten Datenblöcke einer entschlüsselnden Schlüsseleinrichtung zuführbar sind, mittels welcher die verschlüsselten Datenblökke in aufeinanderfolgenden Blockschlüsselgängen unter wiederum logischen Verknüpfungen mit einer bereitgestellten Schlüsselbitfolgeanordnung entschlüsselt bnd in die ursprünglichen Klartextdatenblöcke zunickverwandelt werden, dadurch gekennzeichnet, daß beim Ver- und Entschlüsseln jeder Datenblock mindestens einmal einer logischen Verknüpfung mit der Schlüsselbitfolgeanordnung unterzogen wird und das Ergebnis davon als abgeänderte Schlüsselbitfolgeanordnung für den nachfolgenden Blockschlüsselgang verwendet wird, the result of this being used as a modified key bit sequence arrangement for the subsequent block code transaction, wherein it is ensured that the data blocks are encrypted with a varying key bit sequence arrangement and concatenated with each other. wobei sichergestellt ist, daß die Datenblöcke mit einer variierenden Schlüsselbitfolgeanordnung und dabei untereinander verkettet verschlüsselt werden.
- 2Verfahren zur Verschlüsselung und Absicherung nach Anspruch l.dadarch ^kennzeichnet, Second Encryption and security method according to claim l.dadarch ^, daß am Beginn jeder in der kegel aus mehreren aufeinanderfolgend eingegebenen Klartextdatenblöcken bestehenden Datennachricht (B= nb) ein aus Klartextdatenbits bestehendes erstes Berechtigungsfeld und am Ende der Datennachricht ein identisches zweites Berechtigungsfeld vorgesehen werden (gemäß F i g. 3), that at the beginning of each data message (B = nb) existing in the cone of several consecutively entered plaintext data blocks, a first authorization field consisting of plaintext data bits and an identical second authorization field at the end of the data message are provided (according to FIG. daß beim Entschlüsseln oder auch beim Verschlüsseln das erste Berechtigungsfeld im Klartext gespeichert und mit dem zweiten Berechtigungsfeld im Klartext verglichen wird, wobei bei Übereinstimmung der beiden Berechtigungsfelder eine richtig und ungestört wiedergewonnene Nachricht und bei auch verschlüsselseitigem Vergleich zwei richtig eingegebene, identische Berechtigungsfelder feststellbar sind. that when decrypting or even when encrypting the first field of authorization is stored in plain text and compared with the second field of authorization in plain text, with the coincidence of the two authorization fields a correctly and undisturbed recovered message and also encrypted comparison two correctly entered, identical authorization fields can be determined.
- 3Verfahren zur Verschlüsselung und Absicherung nach einem der vorangehenden Ansprüche, dadurch gekennzeichnet, Third Encryption and security method according to one of the preceding claims, characterized in that daß sowohl beim Verschlüsseln wie auch beim Entschlüsseln der erste Blockschlüsselgang unter logischer Verknüpfung des ersten einlaufenden Blocks einer Nachricht mit einer zu Beginn eingegebenen, beim Ver- und beim Entschlüsseln übereinstimmenden Anfangsschlüsselbitfolgeanordnung durchgeführt wird und &Q in the case of both encryption and decryption, the first block code is logically linked to the first incoming block of a message with an initial key bit sequence set initially entered, matching during decryption and decryption, and & Q daß das Ergebnis des ersten und aller weiteren Blockschliisselgänge, ausgenommen das Ergebnis des letzten Blockschlüsselgangs der Nachricht, als jeweilige neue Schlüsselbitfolgeanordnung im jeweils nachfolgenden Blockschlüsselgang der Nachrieht verwendet wird. that the result of the first and all further block key transactions, except for the result of the last block code of the message, is used as the respective new key bit sequence arrangement in the subsequent block code sequence of the message.
- 4Schaltungsanordnung zur Durchführung des Verfahrens nach einem der vorangehenden Ansprüche, gekennzeichnet durch die folgenden Merkmale:ein Anfangsschlüsseleingabekanal (4, 20), über welchen eine Anfangsschlüsselbitfolgeanordnung in ein Kettenschlüsselregister (36) zu Beginn einer Schlüsselung eingebbar ist, und eine Blockschlüsseleinrichtung (40) an sich bekannter Art, deren ersten Eingängen über einen Dateneingabekanal die Blöcke mit zu verarbeitenden Datenbytes zuführbar und deren zweite Eingänge mit den Ausgängen des Kettenschlüsselregisters (36) verbunden sind, welche Blockschlüsseleinrichtung (40) unter byteweisen logischen Verknüpfungen der über ihre ersten Eingänge eingegebenen Datenbytes mit über ihre zweiten Eingänge zugeführten Schlüsselbytes vom Kettenschlüsselregister (36) an ihren Ausgängen über einen Datenausgabekanal die verarbeiteten Datenbytes jeweils eines Datenblocks abnehmbar macht, wobei des weiteren während der einzelnen Datenbyte-Arbeitsgänge der Datenausgabekanal von der Biockschlüsseleinrichtung (40) mit den ersten Eingängen antivalenter ODER-Glieder (18), die zweiten Eingänge dieser antivalenten ODER-Glieder (18) mit den Ausgängen des Kettenschlüsselregisters (36) sowie die Ausgänge der antivalenten ODER-Glieder (18) mit den Eingängen des Kettencchlüsselregisters (36) verbunden sind 4th Circuit arrangement for carrying out the method according to one of the preceding claims, characterized by the following features: an initial key input channel (4, 20), via which an initial key bit sequencer can be entered into a key chain register (36) at the beginning of a key, and a block key device (40) of known type, the first inputs of which can be supplied via a data input channel the blocks of data bytes to be processed whose second inputs are connected to the outputs of the chain key register (36), which block-key device (40) makes the processed data bytes of a respective data block removable from the chain key register (36) at its outputs via a data output channel under bytewise logic operations of the data bytes input via their first inputs;further comprising, during each byte of data operation, the data output channel from the bioskey device (40) to the first inputs of exclusive OR gates (18), the second inputs of these exclusive OR gates (18) to the outputs of the chain key register (36), and Outputs of the non-equivalent OR gates (18) are connected to the inputs of the chain key register (36) and bytewise newly formed key bytes as the basis for the byte-by-byte coding of the next data block to the inputs of the chain key register (36) are supplied with antivalence OR of the already processed data bytes with the key bytes used in the processing. und unter antivalenter ODER-Verknüpfung der bereits verarbeiteten Datenbytes mit den bei der Verarbeitung benutzten Schlüsselbytes byteweise neu gebildete Schlüsselbytes als Basis für die byteweise Schlüsselung des nächstfolgenden Datenblocks den Eingängen des Kettenschlüsselregisters (36) zuführbar sind.
- 5Schaltungsanordnung nach Anspruch 4, gekennzeichnet durch ein erstes Berechtigungsfeldregister (68), in welchem das erste Berechtigungsfeid zu Beginn einer verarbeiteten Nachricht speicherbar ist, 5th Circuit arrangement according to Claim 4, characterized by a first authorization field register (68) in which the first authorization field can be stored at the beginning of a processed message, by a second authorization field register (70), in which the second authorization field can be stored at the end of the message, and by a comparator (72), by means of which the first and the second authorization field in the authorization field registers are comparable, whereby when encrypting a check is made for correctly entered , identical authorization fields feasible durch ein zweites Berechtigungsfeldregister (70), in welchem das zweite Berechtigungsfeld am Ende der Nachricht speicherbar ist, und durch einen Vergleicher (72), mittels welchem das erste und das zweite Berechtigungsfeld in den Berechtigungsfeldregistern vergleichbar sind, womit beim Verschlüsseln eine Prüfung auf ordnungsgemäß eingegebene, identische Berechtigungsfelder durchführbar and when decrypting for proper receipt of the two authorization fields and thus the entire message contained between the two authorization fields is testable. und beim Entschlüsseln auf ordnungsgemäßen Empfang der beiden Berechtigungsfelder und somit der gesamten, zwischen den beiden Berechtigungsfeldern enthaltenen Nachricht prüfbar ist.
- 6Schaltungsanordnung nach einem der Ansprüche 4 oder 5, dadurch gekennzeichnet, 6th Circuit arrangement according to one of Claims 4 or 5, characterized daß die Kapazität und der Aufbau der Biockschlüsseleinrichtung (40) und ebenfalls die des Kettenschlüsselregisters (36) so ausgelegt sind, daß jeweils ein vollständiger Datenblock mit einer Vielzahl von Datenbytes und eine Schlüsselbitfolgeanordnung in Form eines Schlüsselblocks mit einer Vielzahl von Schlüsselbytes aufnehmbar ist. in that the capacity and the structure of the bock code device (40) and also those of the chain key register (36) are designed so that one complete data block with a plurality of data bytes and one key bit sequence device in the form of a key block with a plurality of key bytes can be received.
Independent claims6
72 paragraphs, as filed
The invention relates to a method and circuit arrangements for encryption and protection of data in the form of blocks from a transmitter to
be transmitted to a receiver, according to the preamble of claim 1.
Modern data processing systems are becoming increasingly complex and sometimes include networks with a central computer or terminals located at terminals or with widely distributed terminals; sometimes long cable connections and / or lines of public communication networks are used for connection. Furthermore, easily removable storage media are often used in the terminals and / or terminals. Because of the significant risk of unauthorized access to public network lines, private long links, and also the removable storage media, there are increasing concerns about interception and alteration of data messages during the Internet Transmission or media storage. Encryption has been recognized as a way of securing and keeping transmitted data confidential, with the data itself being protected, not just the transmitting or storing medium.
Various encryption schemes have already been developed for securing and secrecy of data transfers between a sender and a receiver. In this case, the block encryption forms a possibility in which a block encryption device, in cyclical operation, encrypts one block each of the data bus using key bits. In block-encoded data transmission equipment, the apparatus on the transmitting side encrypts one block of data each time by means of an array of key bits so as to produce an output block of unrecognizable, encrypted data bits which can not be understood without knowledge of the key. The resultant output block of encrypted data bits is then transmitted to the receiver, in which the device present there reverses the transmitted data block using the same key bits, thereby recovering the data block originally input on the transmitting side. Examples of this prior art are the subject of German Offenlegungsschriften 22 31 849 and 25 58 206.
In block encryption, the individual data bits of the transmitted block are a complex function of all the data bits of the input block and the array of key bits. In this respect, any change of an input data bit affects all data bits thus output. This property of block encryption allows the inclusion of an authorization request with the entered data bit block, which can be used to secure data transmission between the sender and a receiver. One way of doing this already is to add a password to the entered data block to be transferred. The input data block is encrypted using a key device in the transmitter and then transfer the resulting result to the receiver. In the receiver, the received encrypted data block is decrypted again with the aid of a block key device. If the connection has not been interrupted during transmission, then the decrypted file block is identical to the originally entered data block. If the recipient knows the password, it can be used to secure the data block by comparing it with the received, decrypted password.
By the essay by Feistel, Notz and Smith "Some Cryptographic Techniques for Machine-to-Machine Data Communication" published in Proceedings of the IEEE, Vol. 63, No. 11, November 197S, pages 1545 to 1554 (in particular the section Authentication on Page 1550), a block encryption method is known in which a part of the encrypted data block is added to the following data block and this is then encrypted. The key bit sequence for the encryption of the data blocks remains unchanged here.
From DE-AS 1188123 an encryptor is known in which from plain text letters and key letters encrypted letters are formed. The key letters are influenced by logical circuits through the preceding plaintext letters. In this known arrangement, the key letters δ \ are generated randomly to a key generator. The decryption on the receiving side should be done with the same key generator as on the sending side, but since the generation of the Schlüsselbuclhstaben should happen randomly, it is not recognizable how the same key letters as on the sending side can be generated here.
Examples according to the prior art can be found in the German patents 22 31 835 and 22 32 256.
According to the given technique, a plurality of data blocks are transmitted between the transmitter and the receiver and the successive input data blocks are encrypted in blocks by means of a blocking encryption of the transmitting station, which in successive keyways is always under the control of the same arrangement of key bits, thereby assigning successive encrypted data blocks produce. The result on the transmitting side is then transmitted to the receiver, where the receiver's block-key device also executes successive operations under the control of the same key bit arrangement, but in a reverse manner, and retrieves the originally input plurality before data blocks. Any manipulation of any single data bit in any block of the issued transmitted message, although affecting all other decrypted data bits of the same data block, will have no effect on any other decrypted data block of the same message. In consequence, to secure the complete message, it is necessary to send a password with each data block transmitted from the sender to the receiver. Of course, because of the need to transmit passwords with each individual data block, the transmission efficiency of the entire system is reduced.
The object of the present invention, in contrast, is a method for securing a plurality of transmitted data blocks, without substantially affecting the transmission efficiency; in this case, the encryption of the successive blocks of data in successive key transactions should be done under concatenation nit the blocks of all previous key transactions, each individual key path is always influenced by all previous key transactions and encrypted DEitenbits the aufeinanderfnlcenHpn
Blocks depend on the one hand on the data block just entered, on all previous blocks, and on the other on the input key bit arrangement; a multiplicity of variable keys should also be used, with the current key in each case being chainable with the key of preceding key operations; while it should be possible to obtain new consecutive key bits by modifying the previous key bits in dependence on the previous data block; Furthermore, a simple way to secure the transmitted data against transmission errors and to maintain the secrecy of successive transmitted data blocks without difficulty to be feasible.
The solution to this problem is characterized in claim 1. Advantageous embodiments are described in the subclaims.
According to the present invention, a method for encrypting messages having a plurality of data blocks between a sender and a receiver is described. The sender includes a key device that performs a block chaining process to improve the security and security of the messages. In this case, an input instruction, which consists of successive plain text data blocks to be entered, and an input arrangement of key bits of the key device of the transmitter is supplied. The key device encrypts the input message in successive block key transactions, during which one input plaintext data block is converted under the influence of the input key bit arrangement to obtain in turn an output block of encrypted data. One of the inputs to the J5 successive block-key operations is the result of previous block-code violations, such that each of the consecutively-issued encrypted data blocks is concatenated with all previous bio-key transitions, thus depending on the particular plaintext block entered, all previous plaintext blocks , and the originally input keybit arrangement .
A major advantage of this block chaining method is given in the transmission of stereotyped messages containing successively identical blocks of plaintext data. With the block chaining technique of the present invention, each of the consecutive stereotyped blocks is encrypted differently than its predecessor, due to the fact that the key changes from block to block, thus ensuring enhanced secrecy protection.
The receiver in turn likewise contains a key device, which performs a block chaining procedure in a comparable manner. For this purpose, the sequence of message blocks with encrypted data received by the sender and, at the beginning, a key bit arrangement are input to the key device of the receiver. This key device decrypts the incoming message in successive block-key transactions, during which a data block to be decrypted is decrypted under the control of the input key-bit arrangement, thereby resulting in a block of plain-text data, which in turn corresponds to an original plaintext data block entered in the transmitter. One of the inputs to the receive-side key device during the successive block-key operations is a function of the previous block-code transaction, again the individual consecutive plaintext data blocks are concatenated with all preceding key-thread blocks in the receiver and are thus dependent on the current block of encrypted data. from all preceding encrypted data blocks and from the initially input initial key bit arrangement.
An examination of the complete and correct transmission between the transmitter and the receiver is possible on the basis of the block chaining technique. By providing for each identical authorization field at the beginning and at the end of a message sent on the transmitting side, each modification of each data block of encrypted bits in the message issued by the transmitter affects the corresponding data block to be decrypted in the receiver and further all subsequent data bits of the receiver output message to be decrypted. By comparing the decrypted versions of the two authentication fields of the decrypted message, agreement guarantees the correctness of the message transmission, whereas mismatch identifies a corruption of the transmitted message.
An embodiment of the invention is illustrated in the drawings and will be described in more detail below.
Fig. 1 shows a block diagram with arrangement of the key devices in a data processing system;
Fig. 2 is a diagram showing the format of an input message without block chaining;
Fig. 3 is a diagram showing the format of an input message with block chaining;
Fig. 4 is a simplified diagram explaining the block chaining method of encryption:
F i g. Fig. 5 is a simplified diagram explaining the block chaining method in decryption:
Fig. 6 illustrates the relationship of Figs. 6A and 6B;
Figures 6A and 6B contain the details of the block encryption according to the present invention;
F i g. Fig. 7 is a block diagram time chart for processing a block of a multi-block message in the key device according to the present invention.
In data processing networks in which data is transmitted over interconnections between the central computer and remote controllers or remote terminals, it is expected that at any time unscrupulous individuals will attempt to intercept and corrupt the transmitted data. One way to achieve data security and secrecy in such cases is to use block key facilities at key points within the network. A message inputted via the transmitter from blocks of Kianext data can be encrypted by means of a Biockschiussieinrichtung and thus transmitted to a receiver, in which the encrypted blocks in turn by a key device for
Obtaining the originally entered Klartextdatenbits be decrypted. By reversing the key functions of the sender in the receiver, the plaintext data can be recovered and even back-encrypted in the receiver, transmitted back to the sender and in turn keyed back into the original data. In Fig. 1, the important points of interest of the arrangement of such key devices in a data processing network are represented by thick dots.
FIG. 2 shows a message of length B = nb, where η is the number of blocks and b is the block length. The blocks can have any length. For illustration, a 64-bit block length has been represented in eight bytes, with each byte having eight bits. Because every single data bit of an output block is a complex punctuation of the previous one. ". Data bits of the corresponding block plus the key bit array is affected in encrypting each change of a single data bit the entirety of the data bits of the block. Thus, the transmission of a data bit block can be checked by inserting two identical authorization fields from one or more bytes at the beginning and at the end of each data block to be entered. In the sender, the data blocks, including the authorization fields, are encrypted and transmitted to the recipient, where the decrypted versions of the authorization fields are (c). Checking the accuracy of the transmitted blocks can be compared.
While modifying a single data bit in a transmitted block affects the entirety of the data bits of the corresponding output block, such a bit change will not affect the subsequent blocks of the same message. In this type of message transfer, authorization fields must be transmitted with each individual block entered in order to be able to check the accuracy of each individual block transfer. This naturally results in a significant reduction in the effective transmission efficiency.
The throughput efficiency can be improved by the block chaining method in which the blocks are concatenated so that each output data bit block transmitted depends on the corresponding input data block, all previously inputted blocks, and the input key bit arrangement. In this case, the modification of a single data bit in any block of the message affects the corresponding output block and further all subsequent blocks of the message. Because of this block chaining property, justify permission at the beginning and at the end of the entire message according to Fig. 3 to ensure the correctness of a message transmission to guarantee and no longer in every single block of the message as in the case of transmission without block chaining. Since authorization terms are now to be provided only at the beginning and at the end of the overall message, it is well understood that under block chaining there is no significant impact on the efficiency of transmitting relatively long messages
FIGS. 4 and 5 show in simplified form the block chaining method for encrypting and decrypting. In particular, FIG. 4 shows the chaining method for encrypting in η consecutive block code lines. During each single pass, an input block X of plaintext data bits is applied using a key bit order K of key bits to produce an output block V of encrypted data bits. In the first block code, the encryption can be expressed by Y \ = f (X ,, K<sub>1</sub>where Xt is the input plaintext data block, / Ci is the input key bit arrangement, f is the block encryption function, and Vi is the outputted block of encrypted data bits.
In the block chaining, a key bit arrangement is used in each of the successive block key sequences, which is itself a function of the previous block code. In this case, a first modulo-2 addition of the first input key set K \ nvii to your cimcii entered clear text data block ΛΊ is performed and the result of the block encryption function is stored during the generation of the first output encrypted data bit block Vi. While the first encrypted block Vi is being generated, it is added to module 2 as the result of the first modulo-2 addition to form the key bit order K<sub>2</sub> for the next block code. This can be expressed by Ki = K \ X \ Vi where each © represents a modulo-2 addition. For this second block code, encryption can be used
can be expressed by Vj = f (Xi, Ki), and using the above equation for K<sub>2</sub> the encryption can now be expressed as Y<sub>2</sub> = f (X<sub>2</sub>, K, Θ ΑΙ θ V<sub>1</sub>). The issued encrypted data bit block Y<sub>2</sub> is thus a function of the associated plaintext data bit block X entered<sub>2</sub>, the preceding input block X \ and the first key bit arrangement K input<sub>1</sub>, This applies to all other subsequent block code operations; Thus, each succeeding encrypted data bit block output is effectively chained to all previous passages and is thus a function of the respective inputted plaintext data block, all previously entered plaintext data blocks, and the initially input key bit order.
In F i g. 5, the corresponding decryption is shown concatenated in η consecutive block keyways. During each block cipher, an inputted block V of encrypted data bits is decrypted under control of a current key bit arrangement K, thereby outputting a block X of plaintext data bits that can be expressed for the first decryption block code X-, = f ~<sup>x</sup>(Y \, K \), where f ~ 'signifies the decryption function and represents the inverse of the function used when encrypting.
The block chaining during decryption is similar to the chaining when encrypting, ie
using one key bit arrangement each for the individual consecutive block code operations as a function of the respective preceding block code operations. For this purpose, a modulo-2 addition of the first-to-be-input key bit arrangement K 1 is first performed with the incoming first encrypted block Yi and the result of the generation of the first plaintext data block Xi to be output is stored in addition to the output of the first plaintext data.
27 15 63!
ίο
In addition to the result of the first modulo-2 addition, it is modulo 2 added again to form the key bit arrangement K<sub>2</sub> to win for the next block code, which can be expressed K<sub>2</sub>-K<sub>1</sub> φ V, φ ΛΊ; this expression is mathematically equivalent to the / ^ expression of the encryption. The second block code can be expressed X<sub>2</sub>^ F - ^ (Y<sub>1</sub>, K<sub>1</sub>). Using the above-mentioned K<sub>1</sub> can be written for decryption X<sub>1</sub>"M (Y<sub>2</sub>, K<sub>x</sub> φ Y<sub>x</sub> φ Xi). The output plaintext data block X<sub>2</sub> is obviously a function of the associated encrypted block Y.<sub>2</sub>, the preceding encrypted block Y \ and the originally input key bit arrangement K \. As with encryption, this relationship also applies to decryption for all other block decryption runs; thus, each plaintext data block subsequently outputted is effectively concatenated with all preceding block decrypting operations, and with the associated encrypted block, all previously entered encrypted blocks, and the initially entered initial key bitmap.
Figures 6A and 6B show in detail the block-key device of the present invention for carrying out the block-chaining method; A description will be given below with reference to the time chart of FIG. 7 follow.
Various parts of the diagram are shown in simplified form, in order not to confuse the description with details that are known to those skilled in the art. Analogously, the various channel cables are shown with circled numbers indicating the numbers of individual lines, also each individually represented logic circuit J5 is a plurality of circuits whose total number corresponds to the number of connected channel lines.
The encryption
It is assumed that a message with π plaintext data blocks is to be transmitted from the sender to the receiver in blocks of 64 data bits arranged in 8-bit long bytes. It should be further assumed that according to F i g. 3 authorization bytes are provided at the beginning and at the end of the message. Prior to transmission, the message to be entered is then encrypted using an initially input key bit arrangement, which also contains 64 bits in eight bytes, each byte containing seven key bits and one parity bit. The transmitter initially receives the key bit array byte-by-byte over the key input channel, requiring a total of eight byte operations to completely accommodate the entire initial key bit array.
During the first byte operation, the transmitter enters a LASe \ n line on the key input channel, pending a valid key byte Signal Load Start Key to prepare the AND gates 4 to pass the seven key bits ω of the first key byte via the OR gates 20 to seven locations of the chain key register 36. The LAS signal is further supplied to an AND gate 6 for passing the parity bit of the first key byte via an OR gate 28 in the eighth position of the chain key register 36 addition, the .L4S signal for the purpose of switching a locking member 58 is supplied, which in the switched State to an AND gate 56, a preparatory signal for the loading of the first byte of an entered Nachrächt, namely the authorization byte, in the first byte register 68th Furthermore, the signal LAS is supplied to an inverter 8, which uses it to block AND gates 10, thereby inhibiting a feedback loop from the output of the chain key register 36 when the first key byte is entered into the chain key register 36. The LAS-S \ gna \ further passes through an OR gate 30 and an inverter 32, wherein it is reversed and delayed in a downstream delay element 34 and also immediately two control inputs below the chain key register 36 is supplied.
The chain key register 36 contains eight digits, the first of which is detailed with the details which are present in all other places. Each location of the chain key register 36 includes a shift register having eight interconnected LGB L to L 8. These locking members may be any known design, one of which z. B. in the aforementioned Offenlegungsschrift 25 58 206 is described. The incoming Schlüsselbyteleitungen are each connected to the first locking member of the individual points of the chain key register 36, while the two control lines, coming from below, are connected to all the locking members of the individual points of the chain key register 36. In all places, the output lines of all the interlocking links, except the last, are connected to the input of the next interlocking link, whereas the output of the last interlocking element is used as the output from the corresponding location of the chainkey register 36. During the first byte operation, while a valid key byte is being presented to the chain key register 36, the two control signals are alternately fed from below, causing the first eight byte key byte to be loaded into the first latches of the eight key chain register 36 locations. During the subsequent seven-byte operations, the remaining eight-byte bytes of the key are supplied byte-by-byte via the first latches of the individual locations of the chain-key register. The LKS and Z.KS lines are connected to all eight latches and cause the loading of the successive key bytes in the chain key register 36 and the displacement of the preceding byte input by one position in the individual locations, so that at the end of eight operations, the initial charge of the key bits in the chain key register 36 is completed and the first key byte at the output of the chain key register 36 is pending. The seven key bits of the pending key byte proceed to parity check circuits 38, which check for parity with the parity bit output from the eighth digit of the chain key register 36. If the parity resulting from the former seven digits differs from the parity bit of the eighth digit of the chain key register 36, then an AND gate 42 is prepared to provide an error signal. On the other hand, if the parities match, then the AND gate 42 is disabled to inhibit error signaling. With the above described
It is ensured that no parity error remains undetected during the transmission of the seven key bits of the key byte from the key chain register 36 to the block key device 40.
After the initial key bit arrangement has been loaded into the cue key register 36, the transmitter inputs a signal via the Encrypt line which tells the block cipher device 40 to set to a block key function and further prepares the AND gates 44 and 48 in front. The block-key device 40 is a circuit arrangement which can perform block-key functions in the encryption mode, wherein the generation of an output block of encrypted data bits can be carried out from an input data bit block using the input key bits. Examples of various possible block key devices at the location of the circuit block 4U according to the present invention are described in the already mentioned publications 22 31 849 and 25 58 206. As a result, no further details of the internal circuitry of block key device 40 need be described here. To explain in detail, let the block key device according to the Offenlegungsschrift 25 58 206 are used, although the use of other equally suitable circuits for performing the block key functions is nevertheless possible.
The transmitter now executes the first eight-byte block of the user message to be entered byte-by-byte via the data input channel of the key device in eight byte operations until an entire plain text data block has been entered. The timing and control unit (not shown) of the block-key device 40 performs the generation of signals on the lines LDB and LDS in the individual eight-byte processing operations; these signals are used within the block key device 40 to load successive bytes of the plaintext data block to be entered and the initial key bits into the block key device 40 in preparation for the block key function. During the first byte operation, when the first signals appear on lines LDB and LDS, eight bits of the first plaintext data byte on the data input channel and seven key bits of the first key byte are input from the output of the chain key register 36 to the block key device 40. In addition to the load of the seven key bits in the block key device 40, the signal on the line LDS the so AND gate 42 for eventual transmission of a parity error in the chain key register 36 at. The first signal on the -> line LDB is used, inter alia, to turn on the AND gates 14 for transmitting seven of the eight bits of a Nutzbytes, which arrive via the OR gates 16 'to the one inputs of antivalent OR gates 18. While no LAS signal is present at the same time, the inverter 8 passes a signal to prepare the AND gates 10 so that the seven key bits of the first key byte can pass from the output of the chain key register 36 to the other inputs of the antivalent OR gates 18. These non-equivalent OR gates 18 serve as modulo 2 adders in combining the seven key bits of the first key byte with the seven bits of the first plaintext data byte, and the resulting seven bits are input via OR gates 20 to the chain key register 36. The seven digit module 2 addition result is further supplied to a parity generator 22 for generating a parity bit for the seven bits given to the keychain register 36. The first signal except ' Furthermore, the LDB line will pass through an OR gate 24 to prepare the AND gate 26, which in turn feeds the generated parity bit to the chain key register 36 via the OR gate 28. At the same time, the first signal on the line LDB via the OR gate 30 and parallel to the inverter 32 and the delay Glie d 34 for driving the control inputs for LKS and LKS of the chain key register 36 is passed, so that the antivalent modified byte can get into the chain key register 36 ,
The first signal on the line LDB also passes through the prepared AND gate 44 and an OR gate 52 for turning on the last byte register 70. Similarly, the output signal from the AND gate 44 through the already prepared AND gate 56 and an OR Member 62 is used to turn on the first byte register 68. As a result, the first data byte, which is the permission byte, is input to the two registers 68 and 70 through the AND gates 48 prepared by the signal Encrypt and OR gates 54. The turn-on signal from the OR gate 62 also passes through the delay 64 for the purpose of resetting the latch 58 for loading the first byte; the delay time is sufficient for the register 68 to invite. When the locking member 58 is switched off again, the OR element 56 is blocked, thus preventing the switch-on signal at the register 68. As a result, only the 1st authorization byte is input to the register 68, whereas the input of the register 70, which is under the control of the signals on the scrambling line and on the LDB line, enters all the other bytes of the message consecutively into the last byte register 70 allows. If no error has been detected in entering the message into the key facility, then the last byte of the entered message should be an authorization byte that matches the very first byte of the message. Accordingly, at the end of message input to the key device, the contents of registers 68 and 70 are checked by a comparator 72 and, if no error is detected, AND gate 74 is disabled, such that an end message signal EOM at the end of the message input to the key device will not be an error signal can pass on. On the other hand, if the contents of registers 68 and 70 do not match, a signal is prepared to prepare AND gate 74 so that the EOM signal can pass an error signal at the end of the message. This error signal can be used to inform the sender that the two authorization bytes do not match and therefore the encrypted input message should not be transmitted to the receiver.
During the remaining seven-byte operations after receiving the first plaintext data byte, the remaining bytes of the input plaintext data block are supplied to the block key device 40 in byte by eight bits via the data input channel, and at the same time, the remaining bytes of the initial key bits are latched by the chain key register 36.
seven bits in parallel, supplied to the block key device 40; each time seven passed key bits are checked for parity. In addition, seven consecutive key bytes, which were initially entered, are successively selected. tnodulo 2 is added with sipben successive plaintext data bytes of the input plaintext data block and returned to the chainkey register 36. At the end of these eight byte operations considered, the chainkey register 36 now clearly holds the result of the modulo 2 addition of the initial key bitmap K \ and the first plaintext data block X \ entered first, which can be expressed as K \ ® X \.
Thereafter, the block-key device 40 performs a block-code operation in which the input plaintext data bits generate encrypted output data blocks, which can be transmitted from the sender to the receiver, using the initial key bit arrangement. The output blocks of encrypted data bits are output by the block key device 40 via the data output channel in byte by eight bits, with a total of eight byte operations are required for a complete block. The output of these successive bytes is synchronized by means of CLOCK signals from the unillustrated timer means of the block key device 40. For this purpose, the block key device 40 outputs eight CLOCK signals for outputting the individual bytes of the output block via the data output channel.
The first CLOCK signal also serves to gate the AND gates 12 for passing seven bits of the first byte of the output block of encrypted data via the OR gates 16 to the one of the inputs of the antivalent OR gates 18. Since there is no L / iS signal present, the inverter 8 gives its preparation signal for switching through the AND gates 10 for the purpose of passing the seven bits of the first byte of the already changed key bit arrangement from the output of the chain key register 36 to the other inputs of the antivalent OR gates 18 , The exclusive OR gates 18 add the seven bits of the first byte of the modified key bit array modulo 2 to the seven bits of the first byte of the encrypted output data block, with the resulting seven modulo 2 bits being returned via the OR gates 20 to the chain key register 36 , The result of this seven-bit modulo addition is further applied to the parity generator 22 to generate a parity bit for the seven bits newly input to the chain key register 36. The first signal on the CLOCK line is further given via the OR gate 24 for switching through the AND gate 26 to let the generated parity bit via the OR gate 28 to the input of the chain key register 36. At the same time, the first signal on the CLOCK line is supplied via the OR gate 30 directly and in parallel via the inverter 32 and the delay 34 as LKS and ZJCS signals from the chain key register 36 from below, bringing the modified byte into the chain key register 36 can enter. Once the now modified byte has been entered into the chain key register 36, the content of the chain key register is internally incremented by one position and the next byte from an earlier modulo 2 addition appears at the output of the chaining tick register 36. Similarly, during each of the seven remaining bytes of work, a CLOCK signal is asserted and passes the next byte of encrypted data bits via the AND gates 12 and the OR gates 16 to the exclusive OR gates 18, where they match the next modified key bit byte from the output of the chain key register 36 via the AND gates 10 modulo 2 are added, the
The resulting result is repeatedly loaded into the chain-key register 36 and is further indexed position by position, while at the same time the next modified key-byte at the output of the chain-key register 36 becomes available.
At the conclusion of the eight byte operations considered, the chain key register 36 now contains a key bit arrangement for the next block code entry of the block key device 40. This key bit arrangement can be described by the expression K<sub>2</sub>= * K<sub>x</sub> ® Xi ® Y<sub>1</sub>, The transmitter's key facility now operates in a manner similar to that described above to generate the next encrypted output block Y.<sub>2</sub> entering the next plaintext data input block Xi and the key bit arrangement K2 into the block key device 40 and corresponding processing. The entered plaintext data block X2 and the key bit arrangement K<sub>2</sub> give modulo 2 adds K<sub>2</sub> @ Xi and are entered into the chain key register 36, the supplied key bit order K<sub>2</sub> entered into the block-key device 40 Similarly as already known, at the end of the block-code entry, the output block Y2 and the content K are<sub>2</sub> Θ Xz of the chain key register 36 adds modulo 2 and thereby yield the new key bit arrangement, which is in the form K> **> K<sub>2</sub> ® X<sub>2</sub> ® Y<sub>2</sub> for the next block code. Thus, in each case a new key bit arrangement is generated for the subsequent block code in dependence on the preceding block code. Finally, each later encoded output block is chained with all previous key thread contents and thus a function of the associated input block, all previous input blocks and the initial key bit start.
When uniform messages containing identical plaintext data blocks are to be transmitted from the sender to the receiver, then the unclocked encryption results in identical encrypted blocks to be transmitted. However, when the block chaining according to the present invention is applied, each of the consecutive stereotyped message blocks to be transmitted gives encrypted different blocks because the key bit array changes from block to block; Thus, an additional measure to secure the transmission of such sterotyper messages is given. Using the present invention results in an effective block length that no longer corresponds to F i g. 3 B is equal to nb and corresponds to the total length of a message. Thus, if identical encrypted messages should result, then identical contents would have to be entered for the blocks of length B, respectively. If this should also be avoided, then one or more randomly selected, constantly changing bytes would have to be inserted in the first block of the individual messages, so that no repetition of an identical string is possible.
The decryption
Referring again to Figs. 6A and 6B, the use of the key device of the present invention for executing a block chain decryption will now be described with reference to the timing chart in Fig. 9. 7 described.
Assume that an encrypted message from the sender reaches the recipient and is to be decrypted in this again to the originally entered message. Before beginning the actual decryption, an initial key bit arrangement is input on the receiving side, which must be identical to the initial key arrangement entered in the transmitter; the key bit arrangement input is made byte by byte over the initial key input channel of the receiver, again requiring eight byte operations until complete input.
During the first operation, as described, the transmitter gave an L / 4S signal to prepare the AND gates 4 to pass the seven key bits of the first key byte via the OR gates 20 to the seven locations of the chain key register 36. Furthermore, the L / Is signal prepared the AND gate 6 to pass the parity bit of the first key byte via the OR gate 28 to the eighth position of the chain key register 36. The LAS signal was further used to turn on latch 58 for the first byte load, whereupon AND gate 60 prepares for loading the first byte of the message, namely an authorization byte, into register 68. In addition, the LAS signal has been supplied to the inverter 8 to disable the AND gates 10, and hence the feedback loop, from the output of the chain key register 36 back to the register 36 during the input of the first key byte. Next, the LAS signal via the OR gate 30 directly and in addition via the in verte r 32 and the delay element 34 as LKS and LKS signals to the control inputs of the chain key register 36 below.
The chain key register 36 of the key device on the receiving side is identical to that on the transmitting side. If, during the first operation, a key byte is to be inputted to the chain key register 36, in turn, the LKS and LKS signals obtain the input of the eight bits of the first byte into the first eight positions of the eight digits of the register 36. During the remaining seven byte operations, the further key bytes are entered byte by byte into the chain key register via desse n first positions applying the LKS and LKS signals until all the bits and bytes of the initial key array have entered register 36. During sequential inputs to the chain key register 36, the key byte just entered within the chain key register 36 is incremented one position at a time until, at the end of the eighth byte operation, the entire initial key is completely in the chain key register 36 and the first key byte is at the output of the chain key register 36. The seven key bits from the output of register 36 pass to the parity check circuits 38, which then generate a parity bit which is compared to the parity bit in the last digit of the chain key register 36, as already described in the case of encryption; if a parity error is detected in the chain-key register 36, the AND gate 42 is turned on in the manner already known and outputs an error signal.
After entering the initial key bit arrangement, the receiver sends a signal via the decrypt line to the block key device 40 to inform it of pending block decryption and to further prepare the AND gates 46 and 50. The block key device 40
It is now possible to generate output blocks of plaintext data bits from the incoming encrypted data bits using the input key bit arrangement in a manner to be reversed in an encrypted manner. The receiver inputs the first eight-byte block of the received message byte-by-byte over the data input channel, requiring eight byte operations to input an entire block of encrypted data. The timing and control unit of the block key device 40 generates signals on lines LDB and LDS during each of the eight operations required therefor, these signals now within the block key device 40 for loading the consecutive bytes of the block of encrypted data to be entered and the initial key arrangement in preparation for the now following decryption functions are used. When the first signals appear on lines LDB and LDS during the first operation, eight bits of the first encrypted data byte are input to the block key device 40 via the data input channel and seven key bits of the first key byte from the output of the chain key register 36. In addition to loading the seven key bits into the block key device 40, the signal on the Z.DS line samples the AND gate 42 for parity checking of the seven key bits output from the chain key register 36 to the block key device 40. The first signal on the LDB latch also prepares the AND gates 14 to pass seven of the eight bits of an encrypted data byte via the OR gates 16 to the one inputs of the antivalent OR gates 18. At the same time, since no L45 signal is present, the inverter 8 outputs a signal for preparing the AND gates 10, which pass the seven key bits of the first key byte from the output of the chain key register 36 to the other inputs of the antivalent OR gates 18. The exclusive OR gates 18 add modulo 2 the seven key bits of the first key byte to the seven bits of the first encrypted data byte, with the seven resulting bits being returned to the key chain register 36 via the OR gates 20. The result of this two-seven bit ModuIo-2 addition is also supplied to the parity generator 22 to generate a parity bit for the seven bits now supplied to the chain-key register 36. The first signal via the LDÖ line is also supplied to the OR gate 24 so as to allow the AND gate 26 to pass the parity bit via the OR gate 28 to the chain circuit register 36. The first signal on the LDB line is simultaneously passed through the OR gate 30 and in parallel via the inverter 32 and the delay 34 to the lower control inputs of the chain key register 36, whereby the modified key byte is now keyed into the chain key register 36.
During the remaining seven-byte operations, the remaining bytes of the incoming encrypted data block are byte-inputted to the block key device 40 via the data input channel and at the same time the remaining seven bytes of the initial key bit arrangement are passed from the chain-stop register 36 byte-by-byte to the block-key device 40, checking each transmitted group of seven key-bits for parity becomes. All of the successive key bit groups of the initial key array are modulo 2 added to the bits of each input encrypted data byte and fed to the chain-end register 36. At the end of these eight byte operations considered, the chain-stop register 36 now contains the results of the modulo-2 additions of the first key-bit array K \ and of the first input encrypted data block Yi, for which K, Y can be written<sub>1</sub>.
Hereinafter, the block key means 40c performs a block closure, during which the input encrypted data bit block, using the initial key bit arrangement, inversely for encrypting at the transmitting side, yields a plaintext data bit block which in turn should be identical to that supplied to the transmitter. The plaintext data output block is output byte-by-byte through the data output channel from the block-key device 40, for which a total of eight byte operations are required for complete transmission. The transmission of the consecutive bytes is synchronized by means of the CLOCK-signal from the timer unit of the block-key device 40.
The first CLOCK signal prepares the AND gates 12 and passes seven bits of the first byte of the block to be output via the OVER gates 16 to the one inputs of the antivalent OR gates 18. Since there is no LAS signal, the inverter 8 outputs a signal to prepare the AND gates 10 and causes the seven bits of the first byte of the modified key bit array to go from the output of the chain key register 36 to the other inputs of the antivalent OR gates 18. These non-equivalent OR gates 18 add the seven bits of the first byte of the modified key bit arrangement with the seven bits of the first byte of the plaintext data block to be output, and the seven newly resulting bits are again supplied via the links 20 to the chain circuit register 36. Furthermore, the result of this modulo-2 addition is supplied to the parity generator 22 in order to generate the parity bit for the seven key bits now entering the chain-stop register 36. The first CLOCK signal is further given via the OR gate 24 to prepare the AND gate 26 for the purpose of passing the parity bit via the ODSR gate 28 to the chain circuit register 36. Also, the first CLOCK signal passes via the OR gate 30 directly and in parallel via the inverter 32 and the delay element 34 to the lower control inputs of the chain key register 36, whereby the modified key byte can enter into the chain circuit. While a modified byte in each case enters the chain-of-circuit register 36, its content is shifted by one position at a time, so that the next following modulo-2-addition result can be entered into the chain-of-circuit register 36. During the seven remaining operations, a CLOCK signal each time passes the next plaintext data byte via the AND gates 12 and the OR gates 16 to the exclusive OR gates 18, where it modulo 2 with the next modified key byte from the output of the chain key register 36 is added via the AND gates 10, wherein the result is in turn input to the chain-stop register 36 to provide the next-following key-byte at the output of the chain-key register 36 for the next operation.
After completion of the considered eight operations, the chain-end register 36 now contains the key-bit arrangement for the next operation of the block-key device 40. The key-bit order now present may be referred to as K<sub>2</sub> = Ki © Y<sub>1</sub> ® Xi; this expression is the expression K<sub>1</sub> Equivalent to Encryption The recipient's decryption facility will now continue to operate as described above and generate the next Kjartextdata output block X.<sub>2</sub> Enter the next encrypted data bit block Y<sub>2</sub> and the aforementioned key bit arrangement K<sub>2</sub> in the block key device 40 for the purpose of carrying out another key path. The entered block Y<sub>2</sub> and the input key bit arrangement K<sub>2</sub> give modulo 2 adds K<sub>2</sub> © Y<sub>2</sub>, similar to the previous K<sub>t</sub> © V, and are input to the chain-of-circuit register 36 while the supplied encrypted block Y<sub>2</sub> and the input key bit arrangement K<sub>2</sub> the block key device 40 are supplied. Again, the plaintext data block X to be output is X<sub>2</sub> and the content K<sub>2</sub> © Y<sub>2</sub> of the chain key register 36 modulo 2 adds to generate another key bit arrangement Kz = K<sub>2</sub> ©<sub>2</sub>© X<sub>2</sub> for the next keyway. The linking ratios from block to block are again given in the same way as on the transmitting side.
The transmission test
It will now be described how to secure the message transmission between transmitter and receiver. While the block key device 40 completes the first key transaction with the first recorded block of encrypted data, the first generated TAKT signal passes through the already prepared AND gate 46 and the OR gate 52 to the turn-on input of the last byte register 70. The signal output by the AND gate 46 also passes through the AND gate 60, which is already prepared by the latch 58, and the OR gate 62 to the turn-on output of the first byte register 68. In this case, the first decrypted byte, which is the authorization byte is supplied to the inputs of the two registers 68 and 70 via the AND gates 50 prepared by the decryption signal and the OR gates 54. The turn-on signal via the OR gate 62 is further supplied via the delay element 64 to the reset input of the latch member 58. Thus, the disabled locking member 58 blocks from now on the AND gate 56 and thus inhibits another turn-on signal to the register 68th Thus, only the first authorization byte is entered into the register 68, whereas the switch-on input of the register 70, under the control of the decrypt signal and the CLOCK signals, inputs all subsequent plaintext data of the decrypted message to the last one consecutively.
Bytes register 70 permits If no error has occurred within the transmission between sender and receiver, then the last byte of the message is an authorization byte which is identical to the first recorded decrypted authorization byte. At the end of the encrypted night, therefore, a comparison of the contents of registers 68 and 70 is made performed by means of the comparator 72; if no error has occurred remains at Gleichbedingimg behind the comparator, the AND gate 74 locked and the
At the end of the night, the scanning signal EOM delivered can not trigger an error signal. If, on the other hand, the contents of registers 68 and 70 are unequal then AND gate 74 is prepared so that the OM OM signal generates an error signal. This error signal can be used to indicate in the receiver that the authorization fields do not match and that an error within the transmission between transmitter and receiver is present
For this 5 sheets of drawings
9 members in 6 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 68040476 | United States of America | A | |
| 68040476 | United States of America | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| JPS52130504A | Japan | A | |
| DE2715631A1 | Germany | A1 | |
| FR2350011A1 | France | A1 | |
| US4074066A | United States of America | A | |
| GB1524767A | United Kingdom | A | |
| CA1100588A | Canada | A | |
| FR2350011B1 | France | B1 | |
| DE2715631C2This record | Germany | C2 | |
| JPS5925411B2 | Japan | B2 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Ceased/non-payment of the annual feeCeased8339 | 8339 | |
| No opposition during term of oppositionOpposition8364 | 8364 | |
| Grant after examinationD2 | D2 | |
| Request for examination paragraph 448110 | 8110 |
Numbers
- Publication
- 2715631
- Application
- 2715631
Titles2
- German
- Verschlüsselung und Absicherung von Daten
- English
- Encryption and security of data
Classification
- CPC, 1
- H04L9/0637
- IPC, 5
- G09C1 00
- G06F21 12
- G06F21 14
- H04L9 06
- H04L12 22