Cell array providing non-persistent secret storage through a mutation cycle
20 claims: 20 independent, 0 dependent
- 1A method for storing and retrieving data, said method comprising:performing Mutations of a cell array (26) In a mutation cycle, until a storage phase reached;storing the data in memory regions (SR0-SR7) the cell array (26) In the storage phase by a Phase Identification Number (PIN) to the cell array (26) is provided, and wherein the PIN is used to determine the storage phase, to determine, wherein more than one possible storage phase;the Mutating the cell array (26) With additional Phases in which the cells in the assembly (26) during the Store phase data stored by mutations through the additional encrypted phases will;and the continuation of mutations as a result of a retrieval request until a retrieval phase is reached and the data is decrypted. Verfahren zum Speichern und Abrufen von Daten, wobei das Verfahren folgendes umfasst: das Ausführen von Mutationen einer Zellenanordnung (26) in einem Mutationszyklus, bis eine Speicherphase erreicht wird;das Speichern der Daten in Speicherbereichen (SR0–SR7) der Zellenanordnung (26) in der Speicherphase, indem eine Phasenidentifikationsnummer (PIN) an die Zellenanordnung (26) bereitgestellt wird, und wobei die PIN verwendet wird, um die Speicherphase zu bestimmen, wobei mehr als eine Speicherphase möglich sind;das Mutieren der Zellenanordnung (26) durch zusätzliche Phasen, in denen die in der Zellenanordnung (26) während der Speicherphase gespeicherten Daten durch Mutationen durch die zusätzlichen Phasen verschlüsselt werden;und das Fortführen der Mutationen als Folge auf eine Abrufanforderung, bis eine Abrufphase erreicht wird und die Daten entschlüsselt werden.
- 2The method of claim 1, wherein the mutation cycle has a rest phase in which the data is encrypted. Verfahren nach Anspruch 1, wobei der Mutationszyklus eine Ruhephase aufweist, in welcher die Daten verschlüsselt sind.
- 3The method of claim 1, wherein the storage phase, and the retrieval stage represent the same phase of the mutation cycle. Verfahren nach Anspruch 1, wobei die Speicherphase und die Abrufphase die gleiche Phase des Mutationszyklus darstellen.
- 4The method of claim 1, wherein at the Cell array (26) To secure against abuses binary Structural concerns. Verfahren nach Anspruch 1, wobei es sich bei der Zellenanordnung (26) um eine gegen Missbräuche sichere binäre Struktur handelt.
- 5The method of claim 1, wherein the mutation by XOR operations the cells within the cell array (26) Occurs. Verfahren nach Anspruch 1, wobei die Mutation durch XOR-Operationen der Zellen innerhalb der Zellenanordnung (26) auftritt.
- 6The method of claim 1, wherein at the PIN that while the storage phase in the cell array (26) saved is to is a first PIN, and a second PIN as part a retrieval request is received, and wherein the first and second PINs while a retrieval phase are compared. Verfahren nach Anspruch 1, wobei es sich bei der PIN, die während der Speicherphase in der Zellenanordnung (26) gespeichert wird, um eine erste PIN handelt, und wobei eine zweite PIN als Teil einer Abrufanforderung empfangen wird, und wobei die ersten und zweiten PINs während einer Abrufphase verglichen werden.
- 7The method of claim 6, wherein upon a match the first and second PINs the cell array (26) the allows retrieval of data. Verfahren nach Anspruch 6, wobei bei einer Übereinstimmung der ersten und zweiten PINs die Zellenanordnung (26) den Abruf der Daten ermöglicht.
- 8The method of claim 6, wherein when a mismatch the first and second PINs recalling data through the cell array (26) is not allowed. Verfahren nach Anspruch 6, wobei bei einer fehlenden Übereinstimmung der ersten und zweiten PINs ein Abruf der Daten durch die Zellenanordnung (26) nicht zugelassen wird.
- 9The method of claim 1, wherein when a mismatch the first and second PINs recalling data through the cell array (26) not admitted will, and the cell array (26) in a self-destruct mode enters. Verfahren nach Anspruch 1, wobei bei einer fehlenden Übereinstimmung der ersten und zweiten PINs ein Abruf der Daten durch die Zellenanordnung (26) nicht zugelassen wird, und wobei die Zellenanordnung (26) in einen Selbstzerstörungsmodus eintritt.
- 10The method of claim 1, wherein additional Storage phases are present, and wherein said additional data in the additional Storage phases are stored. Verfahren nach Anspruch 1, wobei zusätzliche Speicherphasen vorhanden sind, und wobei zusätzliche Daten in den zusätzlichen Speicherphasen gespeichert werden.
- 11A computer readable medium having contained thereon instructions, which in one embodiment cause a computer system (10performs) acts following full:providing a phase identification number (PIN) a cell array (26);performing Mutations of the cell array (26) In a mutation cycle, until a storage phase reached, the cell array (26) Using the PIN to determine the storage phase, in which the data is stored, wherein more than one storage phase possible are;storing the data in a storage region (SRi) Of the cell array (26) in the Storage phase;mutating data in a storage region (SRi) Of the cell array (26) in the Storage phase;mutating the cell array (26) Additional Phases in which data collected during the storage phase in the cell array (26) get saved, by mutations on the additional encrypted phases will;and the continuation the mutations in response to a retrieval request, until a Retrieval phase is reached and the data is decrypted. Computerlesbares Medium mit darauf enthaltenen Anweisungen, die bei einer Ausführung bewirken, dass ein Computersystem (10) Handlungen ausführt, folgendes umfassend: das Bereitstellen einer Phasenidentifikationsnummer (PIN) an eine Zellenanordnung (26);das Ausführen von Mutationen der Zellenanordnung (26) in einem Mutationszyklus, bis eine Speicherphase erreicht wird, wobei die Zellenanordnung (26) die PIN verwendet, um die Speicherphase zu bestimmen, in der die Daten gespeichert werden, wobei mehr als eine Speicherphase möglich sind;das Speichern der Daten in einem Speicherbereich (SRi) der Zellenanordnung (26) in der Speicherphase;das Mutieren von Daten in einem Speicherbereich (SRi) der Zellenanordnung (26) in der Speicherphase;das Mutieren der Zellenanordnung (26) über zusätzliche Phasen, in denen Daten, die während der Speicherphase in der Zellenanordnung (26) gespeichert werden, durch Mutationen über die zusätzlichen Phasen verschlüsselt werden;und das Fortführen der Mutationen als Reaktion auf eine Abrufanforderung, bis eine Abrufphase erreicht wird und die Daten entschlüsselt werden.
- 12Medium nach Anspruch 11, wobei die Speicherphase und die Abrufphase die gleiche Phase des Mutationszyklus darstellen. The medium of claim 11, wherein the storage phase, and the retrieval stage represent the same phase of the mutation cycle.
- 13Medium nach Anspruch 11, wobei der PIN während der Speicherphase in der Zellenanordnung (26) gespeichert wird und es sich um einen ersten PIN handelt, und wobei ein zweiter PIN als Teil einer Abrufanforderung empfangen wird, und wobei die ersten und zweiten PINs während einer Abrufphase verglichen werden. The medium of claim 11, wherein the PIN during the Storage phase in the cell array (26) Is stored and it is a first PIN, and a second PIN as part of a retrieval request is received, and wherein the first and second PINs while a retrieval phase are compared.
- 14Medium nach Anspruch 1, wobei es sich bei dem Medium um eine CD-ROM (90) handelt. The medium of claim 1, wherein the medium a CD-ROM (90) Concerns.
- 15A system for storing and retrieving Dath, where the system comprising:a memory (16) of a cell array (26) With storage areas (SR0-SR7) comprises;a processor (14), The mutations of the cell array (26) can perform in a mutation cycle, until a storage phase achieved, whereby it in several data Storage regions (SR0-SR7) of the Cell array (26) while the storage phase stores, wherein a phase identification number (PIN) is used to determine the storage phase in which the data is stored, wherein more phases as a storage phase possible are, and said he the cell array (26) In additional Phases mutated, wherein the data stored in the storage phase in the Cell array (26) Are stored by the mutation in the additional phases encoded will. System zum Speichern und Abrufen von Daten, wobei das System folgendes umfasst: einen Speicher (16), der eine Zellenanordnung (26) mit Speicherbereichen (SR0–SR7) aufweist;einen Prozessor (14), der Mutationen der Zellenanordnung (26) in einem Mutationszyklus ausführen kann, bis eine Speicherphase erreicht wird, wobei er Daten in mehreren Speicherbereichen (SR0–SR7) der Zellenanordnung (26) während der Speicherphase speichert, wobei eine Phasenidentifikationsnummer (PIN) dazu verwendet wird, die Speicherphase zu bestimmen, in der die Daten gespeichert werden, wobei mehr Phasen als eine Speicherphase möglich sind, und wobei er die Zellenanordnung (26) in zusätzliche Phasen mutiert, wobei die Daten, die in der Speicherphase in der Zellenanordnung (26) gespeichert werden, durch die Mutation in den zusätzlichen Phasen verschlüsselt werden.
- 16System according to claim 15, wherein the memory (16) and the processor (14) Are included in a DVD player. System nach Anspruch 15, wobei der Speicher (16) und der Prozessor (14) in einem DVD-Player enthalten sind.
- 17System according to claim 15, wherein the memory (16) and the processor (14included) in a personal computer are. System nach Anspruch 15, wobei der Speicher (16) und der Prozessor (14) in einem Personalcomputer enthalten sind.
- 18System according to claim 15, wherein the processor further the data determined that in a first phase in the cell array (26) Are stored, by:(I) generating a Matrix P of to be used in a mutation cycle plaintext cells in the memory, wherein the matrix P Do not Care-sections for use as having storage areas;(Ii) to be encrypted, the receiving and in the Do not Care-sections of data to process;(Iii) generating a matrix M of the partner formation in the memory, wherein the matrix Information about the having phase and cell placement;(Iv) inverting of the matrix M, so that an inverted matrix M-1 generated becomes;and (V) determining an initial phase I of the cell arrangement by a matrix multiplication I = M-1 * P. System nach Anspruch 15, wobei der Prozessor ferner die Daten bestimmt, die in einer ersten Phase in der Zellenanordnung (26) gespeichert werden, durch: (i) das Erzeugen einer Matrix P von in einem Mutationszyklus zu verwendenden Klartextzellen in dem Speicher, wobei die Matrix P Don't Care-Abschnitte zur Verwendung als Speicherbereiche aufweist;(ii) das Empfangen zu verschlüsselnder und in den Don't Care-Abschnitten zu verarbeitender Daten;(iii) das Erzeugen einer Matrix M der Partnerbildung in dem Speicher, wobei die Matrix Informationen über die Phase und Zellenplatzierung aufweist;(iv) das Invertieren der Matrix M, so dass eine invertierte Matrix M–1 erzeugt wird;und (v) das Bestimmen einer anfänglichen Phase I der Zellenanordnung durch eine Matrixmultiplikation I = M–1 * P.
- 19System nach Anspruch 18, wobei zumindest ein Teil der Don't Care-Abschnitte der Matrix P einen gleichen Versatz von den Anfängen der Klartextzellen aufweist. The system of claim 18, wherein at least a portion the Do not Care-sections the matrix P has an equal offset from the beginning of plain text cells.
- 20A computer program comprising computer program code means, to perform all the operations of claim 1 when the program run on a computer is. Computerprogramm mit einer Computerprogrammcodeeinrichtung, die alle Operationen aus Anspruch 1 ausführen kann, wenn das Programm auf einem Computer ausgeführt wird.
Independent claims20
68 paragraphs, as filed
territorially technology
The This invention relates to storage of secret data and in particular the storing secret data using a Mutation cycle of a cell array.
description of the prior art
The Most computer applications are not trying deliberately secret data while execution to protect. Rather, they store secret values, so this in memory any time are clearly legible, whereby the data for each procedure are susceptible, which can gain access to the corresponding memory. For example, an active program search a hard drive, where it searches for a particular subject, the secret a or a secret code or home has. Once the secret or the secret code or the program that secret in the holds up, it has been found, the mystery or secret code can be or the program analyzes and / or destroyed. The secret and the program may have a Modem removed for remote analysis of the hard disk or from this be copied.
More sophisticated Applications have secrets or secret data stored in the memory only during the times are clear or "plain text" readable when they actually be used. While the remaining time, the secret data in a specific encrypted Shape stored. This is associated with the problem that a further Secret or another secret code must be used to to decrypt the stored secret code. This protective secret code must be protected after are, in turn, the values are safe. The decode different Secret codes can be time-consuming shape. For example, encrypted Secret codes are stored on hard disks, the access to which takes time.
In Computers & Security, Oct. 1993, pages 565-584, the compression and encryption disclosed and the example of an XOR gate shown which can be used a random or generate random command group one by execution other XOR function can be restored.
WO97 / 48203, brought on 13 June 1996 and published on 18 December 1997, entitled "Tamper Resistant Method and Apparatus ", of Aucsmith et al, describes a secure against abuses method in the cells undergo an exclusive OR function, with other Cells produce mutations. The design pattern for this Method may include the protective constitute secret code. However, if bits are changed, mutate Cells improperly.
Thus a method and apparatus are needed to secure secret data to store such that the secret data stored quickly can be accessed and.
Summary the invention
scheduled According to a first aspect of the present invention, a method according to the subject Claim. 1
scheduled According to a second aspect of the present invention a computer readable medium in accordance with the objective Claim 11th
scheduled According to a third aspect of the present invention, a system as claimed in Claim 15th
Preferred Features of the invention are defined in the appended claims.
Short description tHE dRAWINGS
The This invention is in reference to the following detailed Description and from the accompanying Drawings of the embodiments the invention more fully understood, wherein the present invention is not specific to the Described embodiments limited is serving rather for explanation and for better understanding. In the drawings:
<figref idrefs="S28">1</figref> a Block diagram representation of a computer system according to a embodiment the present invention;
<figref idrefs="S29">2</figref> a in one embodiment, the present invention used cell array;
<figref idrefs="S30">3</figref> a Table of pairings and cells in plain text in various Phases of a simplified mutation cycle of an embodiment according to the present Invention;
<figref idrefs="S31">4A</figref> on Register and the contents of which in connection with an embodiment of the present invention is applied;
<figref idrefs="S31">4B</figref> the Cell array of <figref idrefs="S29">2</figref> and contents of storage areas therein during one <?page 3?>certain phase of execution;
<figref idrefs="S32">5</figref> a Block diagram representation of a DVD player, a cell array according to the present Invention uses;
<figref idrefs="S32">6</figref> a Block diagram representation of a computer system, the cell arrangement a according to the present Invention used to store secret data until they are needed;
<figref idrefs="S33">7A</figref> a Plan view of a disk such as a CD-ROM; and
<figref idrefs="S33">7B</figref> on A computer system as a server or as a user of a cell arrangement according to the present Invention is used.
Precise description Preferred Embodiments
In Referring to Figure <figref idrefs="S28">1</figref> has a computer system <figref>10</figref> a processor <figref>14</figref> and one memory <figref>16</figref> on. In the memory<figref>16</figref> can it to a random access memory (RAM), a hard drive and / or act to another format. processor<figref>14</figref> communicates with the memory <figref>16</figref> about the bus and associated logic <figref>20</figref>, The computer system<figref>10</figref> is not limited to a particular type of computer system. To the Example, it may be in the computer system <figref>10</figref> a trade system, which is in the processor <figref>14</figref> a Pentium<sup>®</sup> II Processor, made by Intel Corporation, is. The necessary details for implementation are of memory, bus and associated logic and processors generally known and will not be described further herein. The computer system<figref>10</figref> has numerous other well known components or components which are neither illustrated nor described, since this for the understanding of the present invention is not necessary and the invention may mask.
In The patent refers to the phrase "one embodiment" of an embodiment the invention. It should be noted that the specific components or features in relation to the respective embodiment be mentioned, in other embodiments Be the invention available. Furthermore, do not necessarily all the aforementioned various components or features in the same embodiment be the present invention exist. The various components or features in various embodiments be combined and coordinated.
Of the memory <figref>16</figref> , the or Register <figref>24</figref> and the cell array <figref>26</figref> on. At any given time can Code, data and other binary Values of the cell array <figref>26</figref> between the processor cache, the cache outside the processor (eg, L2 cache), the main memory, a hard disk be distributed or shared and / or another store. Of the Term "cell array" shall be construed as that it has a binary structure in the further Sine which having a plurality of cells, without being limited to a specific embodiment. For example, the cell array <figref>26</figref> of contiguous memory locations in the memory <figref>16</figref> are or may be distributed to non-contiguous memory locations.
In Referring to Figure <figref idrefs="S29">2</figref> has the Cell array on multiple cells. To better illustrate and explaining , cell array <figref>26</figref> only eight cells au: the cells <figref>0</figref>. <figref>1</figref>. ..., <figref>7</figref> (Collectively, the cells <figref>0</figref> to <figref>7</figref>). In practice, the cell array <figref>26</figref> alot more have cells. The cell array<figref>26</figref> mutated or passes on Another way different phases. The mutation by various Phases is an example of a mutation cycle or phase cycle.
In one embodiment, the mutations occur because processor <figref>14</figref> exclusive OR operations (XOR) passing between the cells. In one embodiment, is half the cells (eg, cells <figref>0</figref> to <figref>3</figref>) In a first portion of the cell array <figref>26</figref>, while the other half the cells (eg, cells <figref>4</figref> to <figref>7</figref>) In a second portion of the cell array <figref>26</figref> is.
In one embodiment, is an XOR operation on each of the cells of the first section the cell array <figref>26</figref> with a partner of the cells second section running. In one embodiment, is meant that a cell with another cell a performs XOR operation, that the bits of a cell corresponding through an XOR operation with bits out of the other cell will. For example, an XOR operation of bit 0 of the cell<figref>0</figref> With the bit 0 of the cell <figref>4</figref> running; for the bit 1 of the cell<figref>0</figref> is a XOR operation with the bit 1 of the cell <figref>4</figref> executed and so on, so that for bit n of cell <figref>0</figref> an XOR function with bit n of cell <figref>4</figref> is performed. In other embodiments, can not incrementally another arrangement of bits (eg, or sequentially) can be used. In certain embodiments is not for all Bits in every cell or phase executed an XOR operation. applies in the XOR function 0 XOR 0 = 0, 0 XOR 1 = 1, 1 XOR 0 = 1 and 1 XOR 1 = 0. In this regard questions Code, data and other binary values <?page 4?>only 1's and 0 represents and are suitable for XOR operations.
At least a cell has at least a certain plain text at any stage to, from which processor <figref>14</figref> (Or other circuitry) can receive commands, so that the cell array <figref>26</figref> at least mutate or otherwise proceed to the next stage can. Plain text is part of the original program (in phase 0) or generated by the compiler or compiler mutations its that run can be. Other cells can look something executable one similar code, and it being feasible in fact portions of the cells can, wherein the cells are not executed. Rather, the mutated binary Bits which have as code, data or other binary values originate, optional or randomly a certain meaning have. This is desirable, since this is the understanding cell array <figref>26</figref> for an attacker addition difficult.
In the figure of <figref idrefs="S29">2</figref> , the cells <figref>0</figref>. <figref>1</figref>. ..., <figref>7</figref> in the cell array <figref>26</figref> the corresponding Storage areas SR0, SR1 ... SR7 on. Some or all of the memory areas store data from or register (s) <figref>24</figref> out <figref idrefs="S28">1</figref>, The secret data from or register (s) <figref>24</figref> are in mutated form in most or all stages, except for one Phase. The measure the mutation of the data is a form of encryption, and the repatriation of Data in a non-mutated form is a form of decryption.
The Cell array is made safe against abuses by the Code and other binary Values are arranged so that when a bit in a different way than through XOR mutation or storage in a storage area SR0 to SR7 changed in the corresponding phase, so the content is the cell array <figref>26</figref> corrupted. Depending on factors such as of which changed bits are in which phase and cell they are changed, and the number the cells and phases, the cell array <figref>26</figref> the execution completely adjust or just not the right secret data hand back. Depending on Factors such as the code, the number of cells, the number of Phases and of which bits of an XOR operation are subjected, and at what stage they are subjected to the XOR operation, is it is possible to that one or more bits out of the memory area be given the changed can be, without preventing it, that the cell array <figref>26</figref> the correct secret data returns. In conjunction with a wide Number of phases and well-written code is the related risk or probability very low. If such bits would exist would be their number is so small that it for an attacker, who allegedly not of their position or arrangement knows draw little benefit could.
The Cells are not limited to any particular size. However, they are at least so great that they store a certain code and one of the storage areas or place for it can offer. In one embodiment, , all cells on the same size, and have all of the memory areas also the same size. The cells may certain bits other than the code or data store, do not run will. One purpose for these bits is to the content and the function of the cells to further disguise. The length the data stored in the cell codes varies depending on the particular implementation. According to one embodiment of the present invention, the cell arrangement <figref>26</figref> to the As a part of a dynamic zinc library (DLL as English abbreviation Dynamic Link Library). When called by a function call<figref>22</figref> stores the cell array <figref>26</figref> simple secret data in the or the Register (s) <figref>24</figref> or retrieves it and passes the various phases to encrypt or decrypt the data. In other embodiments may perform other functions, the cell array.
The Storage areas SR0 to SR7 can each of different sizes (Eg one byte or two bytes per sector). The memory areas SR0 to SR7 be arranged at any position within the cells. For example, the memory areas <figref>8</figref>. <figref>32</figref> or <figref>64</figref> byte or a different number of bytes (eg, so that they end up the cells be placed) start from the beginning of the cell.
In one embodiment, are secret data from or to the register (s) <figref>24</figref> during the Storage / retrieval phase in the cell array <figref>26</figref> saved and from this fetched: If the number of units (eg, bytes) the secret data is lower than the number of memory slots, so has not each location a secret data unit (eg a byte) or mutations which on at any stage. Depending on the code, the number of Phases and the number of memory locations, certain memory positions or.
where memories be that no secret data or a mutation of this during a store the phases.
A call function <figref>22</figref>Stored in the memory <figref>16</figref> saved is calling the cell array <figref>26</figref> on. In one embodiment, includes the calling function <figref>26</figref> the following arguments, not necessarily <?page 5?>must have this order or arrangement: (1) secret data, (2) an offset, (3) length, (4) Save / Recall and (5) a phase identification number (PIN) (in the envisaged can be mapped storage / retrieval phase). The secret data provide the data in the register or the (n) <figref>24</figref> , which fall in the cell array <figref>26</figref> to be saved. In one embodiment, corresponds to the offset the offset in an output cell which the storage area designated position at which stored the PIN shall be. The code in the source cell may the storage area denote a first portion (byte 0) of the secret data stores and so on. The length corresponds to the length the secret data and possibly the PIN (for example, the total number of bytes or words), stored or are retrieved. Storing / can retrieve a single Bit include. For example, a logical 1 a memory operation denote that it causes secret data from the or to the Register (s) <figref>24</figref> while Phase 0 in the cell array <figref>26</figref> to be written, and a logical 0 may designate a polling operation, which it causes in the cell array <figref>26</figref> saved from secret data the cell array <figref>26</figref> in the Register or the <figref>24</figref> or the or Register <figref>28</figref> to be written.
The PIN refers to the storage / retrieval phase either directly or indirectly by imaging. includes, in one embodiment the cell array <figref>26</figref> many possible storage / retrieval phases. The PIN can for example represent 8 bits, up to 256 objects designated. When the number of storage / retrieval phases is less as the number of possible PIN combinations, the PIN is displayed in the storage / retrieval phase (Eg, by logically ANDing the bits with a number.). The relationship between the PIN and the storage / retrieval phase may scrambled by Figure are to monitor the functioning of the cell array <figref>26</figref> continue disguise. A user may select the PIN or it may, for example, accidentally or optional for selected user will. The term described herein "random" or "optional" covers without further true random numbers and pseudo-random numbers from.
The Figure <figref idrefs="S30">3</figref> shows an illustrative For the operation of the cell array <figref>26</figref>, I hereby expressly found that the example of <figref idrefs="S30">3</figref> however illustrative only general information regarding the present invention is not necessarily complete and mathematically correct is. A commercial implementation of the invention can be much more more cells and much more other phases have to make it for one make difficult for attackers either the exact secret to make data located or a group attack on the mutation cycle make. The cell array<figref>26</figref> can different pairings exhibit. With regard to this guidance, the following description is the figure of <figref idrefs="S30">3</figref>,
The cell array <figref>26</figref> has a first or initial state or: first or initial phase, also referred to as the phase 0th If the cell array <figref>26</figref> is not in use, so the phase 0 is a rest period. While the cell array<figref>26</figref> in Phase 0 is, has only the cell <figref>0</figref> Plain text. That is, the cell <figref>0</figref> has code by the processor <figref>14</figref> is performed. cells <figref>1</figref> to <figref>7</figref> will not run in phase 0, where However, they may have content, like plain text appear. (The plain text in phase 0 can in another cell as the cell <figref>0</figref> . Are) In the cell, <figref>0</figref> can certain bits (possibly meaningless binary Values) of storage locations outside the storage region SR0 are that will not run. It is desirable but not required, that such a large part of the cell arrangement <figref>26</figref> as possible the has appearance of plain text to the functioning of cell array <figref>26</figref> disguise.
The call function <figref>22</figref> calls cell array <figref>26</figref> With a memory request on to secret data from or to Register (s) <figref>24</figref> in the cell array <figref>26</figref> to write. Some or all of the arguments of the function call <figref>22</figref> can in or the register (s) <figref>24</figref> get saved. These arguments can in the memory <figref>16</figref> stay until they are needed, or they can until they are needed the time of the call in registers or in a stack of processors <figref>14</figref> to be placed. The PIN is, for example, "202". An imaging system the PIN "202" in the phase number 3 ready.
As In response to the function call causes the code in the cell <figref>0</figref> XOR pairings certain in <figref idrefs="S30">3</figref> listed cells, causing the cell array <figref>26</figref> Phase 0 mutated in phase. 1 Storage regions SR0 to SR7 the cells are XOR operations other memory areas SR0 to SR7 according to the pairings of the cells subjected.
According to the formation, out <figref idrefs="S30">3</figref> takes place, for example, an XOR operation of the cell <figref>0</figref> with cell <figref>4</figref>, Thus, an XOR operation SR0 subjected to SR4 because SR0 within the cell <figref>0</figref> and SR4 within the cell <figref>4</figref> is. According to one embodiment the bit 0 of SR0 subjected to an XOR operation with bit 0 of SR4, wherein bit 1 of SR0 an XOR operation is subjected with bit 1 of SR4 and so forth. (However, a at<?page 6?>particular arrangement of XOR operation bits are used.) In one embodiment, be for the memory areas only XOR operations with other memory areas executed. At the end of the mutation is the cell array <figref>26</figref> in the Phase 1 and only the cell <figref>5</figref> is in plain text.
Of the Code in the cell <figref>5</figref> causes XOR pairings of certain in from Figure <figref idrefs="S30">3</figref> listed cells, which causes that the cell arrangement of Phase 1 mutated in phase. 2 At the end the mutation are only the cells <figref>2</figref> and <figref>7</figref> in the Plain text, which means that depending of a certain condition or a certain circumstance either the cell <figref>2</figref> or the cell <figref>7</figref> be executed can. For two reasons there may be more than one cell are in plain text. First, more as a cell in plaintext an attacker the project difficult shape. Second, a branch may be provided, so that dependent of a certain value more than one cell are possible.
Of the Code in the cell <figref>2</figref> or in the cell <figref>7</figref> causes a mutation of the cell array <figref>26</figref> Phase 2 Phase 3. At the end of the mutation is only the cell <figref>6</figref> in the Plaintext. As has already been noted, the PIN in combination with the code in the cell array <figref>26</figref> the processor <figref>14</figref> instructs secret data or the register <figref>24</figref> in certain areas of the storage areas SR0 to SR07 to write. In the example corresponding to the offset <figref>36</figref> Bytes, and the length is equal to 4 bytes. According to a embodiment The PIN will be in storage areas secret together with data bytes stored, and the PIN is the first of the 4 bytes. Thus exist three remaining bytes of secret data. In reference to Figure out <figref idrefs="S31">4A</figref> can or can the or Register <figref>24</figref> the arguments for the function call have (but a different memory array are selected can). In the illustration of<figref idrefs="S31">4A</figref> corresponds to the PIN one byte, and bytes B0, B1, and B2 are 3 bytes of secret Data.
The Figure <figref idrefs="S31">4B</figref> illustrated the content the cell array <figref>26</figref> in phase 3 after the call function the PIN and secret data bytes B0, B1 and B2 in the memory areas SA0, SR1, SR4 and SR5 of the cell array <figref>26</figref> writes. In one embodiment, be a part of the PIN and byte B0 in the first region of the cell array <figref>26</figref> (Ie, the cells <figref>0</figref> to <figref>3</figref>) written, and the bytes B1 and B2 are in the second region of the cell array <figref>26</figref> (Ie, the cells <figref>4</figref> to <figref>7</figref>) written as shown in Figure <figref idrefs="S31">4B</figref> illustrated is. Further, the cell pairings are given so that the PIN and the bytes of the secret data while the first transition to the next Phase be mutated, as in the example of Figures <figref>3B</figref> and <figref idrefs="S31">4B</figref>,
As In response to the XOR operations in the <figref idrefs="S30">3</figref> listed pair, mutating the cell array <figref>26</figref> Phase 3 in phase. 4 Similarly Way mutating the cell array <figref>26</figref> Phase 4 in phase 5 and from phase 5 back in phase 0, when it comes to the rest. Similarly Way mutate the PIN and the secret Datentbytes B1, B2 and B3 of Phase 3 to Phase 4 and further from phase 4 to phase 5 and more from Phase 5 to Phase 0. The cell array <figref>26</figref> remains in their resting phase (phase 0) until it is called again. mutations encode the PIN and secret data. (If the PIN and secret data in encrypted Form or in the register (s) <figref>24</figref> are present, they encrypted by the mutations on.) The call function <figref>22</figref> calls the cell array <figref>26</figref> to retrieve the secret data. to decrypt the PIN and secret data mutated cell array <figref>26</figref> from Phase 0 to Phase 1, Phase 1 in phase 2 and phase 2 in phase 3. In each phase, the storage areas with other storage areas are referred to in <figref idrefs="S30">3</figref> listed Fixtures mutates. In phase 3, the storage regions SR0, SR1, SR4 and SR5 the original IN and secret data bytes B1, B2 or B3. The call function<figref>22</figref> provides the PIN from or register (s) <figref>24</figref> or otherwise ready while the cell array <figref>26</figref> in phase 0 or phase relatively low Number is. In one embodiment, the PIN is the code of the cell array <figref>26</figref> starting in cell <figref>0</figref> Phase 0 is used. The call by the function<figref>22</figref> presented PIN is compared in phase 3 with the PIN in SR0. If a match is given, the contents of SR1, SR4 and SR5 are in an external Register (eg or register <figref>24</figref> or or register <figref>28</figref>) Written. If no match is given, leaves the cell array <figref>26</figref> reading the contents SR1, SR4 and SR5 not too. the cell arrangement Further changes<figref>26</figref> in one embodiment, in a self-destruct mode, since it is assumed that someone has attempted, or tries the cell array <figref>26</figref> to abuse. The self-destruct mode can change certain comprise bits, the effect is that the code and / or the secret Data corrupted or no longer feasible. The cell array<figref>26</figref> can allow two chances to get the correct PIN before the self-destruction is made. The self-destruction is a form of protection from abuse.
At Point of retrieving data, the call function <figref>22</figref> the cell array <figref>26</figref> call new secret data in the cell array <figref>26</figref> to write. During the storage operation in the <?page 7?>Storage areas can the bits that are not overwritten with the PIN or secret data will remain in the respective logic state or leave are, where they have been located. Alternatively, the For random numbers or only zeros or ones to This places the Storage areas are written.
Various Versions of cell array <figref>26</figref> can be generated, wherein various possible Stages are given from which the PIN can be selected. The different versions can also have other differences, including different numbers of phases and cells, different sizes of cells and storage regions, another arrangement of passing arguments and other characteristics. A provider of software invention may sell different versions to different customers. An OEM (English acronym by Original Equipment Manufacturer) may have different versions obtained and different versions on different devices to install. The presence of different versions makes it additionally difficult, the operations of the cell array <figref>26</figref> to determine.
The cell array <figref>26</figref> can be designed so that they a Error does not have behebendes self-destruct feature which is activated when the cell arrangement <figref>26</figref> Notes that certain flags or flags in the processor <figref>14</figref> set have been. For example, have Pentium<sup>®</sup> processors Intel Corporation flags, which are set when a Debugger or debugger tries breakpoints set a single-step through the program. The code cell array <figref>26</figref> may include features which the cell array <figref>26</figref> enable the self-destruct mode when it is detected that change certain bits, but also a pure natural destruction can be performed by XOR operations with the wrong code. Against abuses secure nature of the cell array <figref>26</figref> does she also resistant to troubleshooting, logging or static analysis.
A Technique to determine the contents of the cell array <figref>26</figref> in Phase 0 is as follows. A matrix P disclaims any plaintext cells on, which are used in each phase. So-called Do not Care-sections, such as storage areas have random numbers or all 1er or 0s on. The matrix P is a N × 1 matrix, where N is the number the cells with corresponding plaintext. It may be useful that N is a multiple of two. additional Cells of random numbers or only 0s or 1er can be added, to N to bring up to a multiple of two. A matrix M is a Matrix of Partners in Education, the information on the temporal (phase) and spatial (Cells) having placement. A matrix I is the first phase or output phase (Phase 0) of the cell array <figref>26</figref>, I hereby it is determined that P = MI, where * represents a matrix multiplication stands. Thus I shall = M<sup>-1</sup> * P. M, for example, by pivots and eliminations of the well known Gauss-Jordon technique be inverted.
In Referring to Figure <figref idrefs="S32">5</figref> can the present invention in conjunction with a DVD player <figref>60</figref> on Software base be used, the drive a <figref>64</figref> having, to secret data (such as the values of encryption keys) in Conjunction with a processor <figref>14</figref> and memory <figref>16</figref> and visual and audio devices <figref>68</figref> temporarily save. The PIN can optionally or randomly with each Storage process secret data in the cell array <figref>26</figref> to be chosen. This makes it more difficult that contained in the DVD decoding to determine secret data.
In Referring to Figure <figref idrefs="S32">6</figref> can the present invention in conjunction with an electronic trading system <figref>80</figref> used be that an input device <figref>84</figref> such as a keyboard and a processor <figref>14</figref> and a memory <figref>16</figref> having, to passwords or other secret data, either temporarily, or permanently to the medium save. In certain implementations, the contents of the go cell array <figref>26</figref> lost when the dominant process is interrupted. In other implementations, the cell array<figref>26</figref> on a disk memory. A long-term storage, in particular, to a disk, the cell array <figref>26</figref> for one make attack more vulnerable. secret password or other data can on ladders <figref>88</figref> to disposal made or provided. The same secret data can several times from the cell array <figref>26</figref> be retrieved. The PIN can by the user or by another means (for example accidentally be or optional) selected.
In Referring to Figures <figref idrefs="S33">7A</figref> and <figref idrefs="S33">7B</figref> can the cell array <figref>26</figref> or code that the cell array <figref>26</figref> generated, and or the Launcher <figref>22</figref>, In computer readable form, get saved. For example illustrates the Figure<figref idrefs="S33">7A</figref> a Disk <figref>90</figref>That a CD ROM (abbreviation of Compact Disk Read Only Memory), a DVD, a hard disk drive (such as in a representing PC or a server) or another disk can. A CD ROM or other disk storage can be different dealers or Endkäufern be delivered or transported. Different CD ROMs, various Versions of Zellenanord<?page 8?>Regulation <figref>26</figref> exhibit or programs, which cell array the <figref>26</figref> form.
In Referring to Figure <figref idrefs="S33">7B</figref> has a computer system <figref>92</figref> a floppy drive <figref>94</figref>, a processor <figref>14</figref>, A memory <figref>16</figref> and a modem <figref>98</figref> on. The computer system <figref>92</figref> may represent a system that the cell array <figref>26</figref> or code that the cell array <figref>26</figref> forms, from the modem <figref>98</figref> transmitting to another computer. To the For functions, the computer system <figref>92</figref> as a server that the Code, for example, about the Internet or World Wide Web or through e-mail transfers. The cell array<figref>26</figref> or the code of cell array the <figref>26</figref> generated can in the RAM of the memory <figref>16</figref> are, from where he at a remote location is provided. Different versions or remarks the cell array <figref>26</figref> can at different times to be provided. Alternatively, the computer system<figref>92</figref> a represent computer disks <figref>90</figref> on the disk drive <figref>94</figref> happening, so that the secret data in the cell array <figref>26</figref> saved will. The computer system<figref>92</figref> can also use a computer represent that performs a cell array or a cell array receives from code the over from a remote source modem <figref>98</figref> has been received.
The present invention is not mentioned in the above embodiments limited, wherein they are implemented in a rather wide range of designs can that for the Trade Mach understood in the art are the benefits of the present disclosure. In addition to the variations already described above in the text to For the following features in various embodiments to get integrated.
indeed is the code in the embodiment described above but within the cell array independently, which is alternative in a embodiment but may be a code that the in the execution Cell arrangement is used, which has no mutation, and outside the cell array. Some of the cells may be of different sizes, wherein also have some of the memory areas of different sizes can, and wherein not all cells or all parts of cells in each phase an XOR operation must be subjected, wherein while maintaining the Fluctuations complexity the code could increase in a certain way. It is not necessary to store and retrieve the secret data carried in the same phase. Furthermore, secret data can have multiple be stored and retrieved phases. For example, in each Phase of the plurality of phases of a byte of the secret data is stored. For example, in each phase of a plurality of phases of a byte the secret data is retrieved.
The Results of the XOR operations can by the XOR operations further obfuscated and encrypted are, for example, 32-bit sections of the results with the cyclic Constants.
The Storage / retrieval phase preferably corresponds to several phases Phase 0 (on either end of the mutation cycle).
indeed In the above illustrated embodiment, cells from a first Section (cells <figref>0</figref> to <figref>3</figref>) Of the cell array <figref>26</figref> just with cells from a second portion (cells <figref>4</figref> to <figref>7</figref>) of the cell array of an XOR operation subjected, in different embodiments exposed to each of the cells with each other cell an XOR operation can be.
On Advantage of the present invention over other techniques is the are speed saved with the secret data and retrieved can. A further advantage is the abuse resistant nature of the Cell arrangement, in which encrypts the secret data and decrypts will. The invention in many embodiments easily because in various embodiments relatively little storage Capacity needed is.
by virtue of the nature of XOR operations, the number of phases representing a total of multiples of six. The number of cells can be used in a commercial embodiment are in the hundreds or thousands. With others Words, there is no reasonable limit to the number the bits in the secret data.
On Center of the encryption / decryption mutation cycle occurs not necessarily in the rest phase (phase 0).
Not require it are using a PIN, length, an offset, and the Storing / retrieving the call function. These parameters can in integrates the cell array and / or partially using various call functions are achieved. The call function can additional arguments have not described herein. The storage process can be called by a different function than the polling process. The Cell array must not be called by a function.
Of the Term "as a Reaction "and related Be<?page 9?>handles mean that a signal or an event in a certain Manner is influenced by another signal or event, but not necessarily complete or directly.
The following claims define the scope of the present invention.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
49 members in 9 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 90669397 | United States of America | A | |
| 90669397 | United States of America | A | |
| 90669397 | United States of America | – | |
| 9814713 | United States of America | W | |
| 9814713 | United States of America | W | |
| 9814713 | United States of America | – | |
| 906693 | – | – | – |
| PCTUS9814713 | – | – | – |
| US19970906693 | – | – | – |
| WO1998US14713 | – | – | – |
Members49
| Document | Office | Kind | |
|---|---|---|---|
| CA2258087A1 | Canada | A1 | |
| WO9748203A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3488397A | Australia | A | |
| WO9908416A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU8658598A | Australia | A | |
| EP0900488A1 | European Patent Office (EPO) | A1 | |
| WO9913613A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9913614A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9913615A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU8412598A | Australia | A | |
| AU8412698A | Australia | A | |
| AU8495798A | Australia | A | |
| US5892899A | United States of America | A | |
| WO9908416A8 | World Intellectual Property Organization (WIPO) | A8 | |
| TW364098B | Taiwan Province of China | B | |
| US6049609A | United States of America | A | |
| EP1000482A1 | European Patent Office (EPO) | A1 | |
| EP1010291A1 | European Patent Office (EPO) | A1 | |
| EP1018236A1 | European Patent Office (EPO) | A1 | |
| EP1020049A1 | European Patent Office (EPO) | A1 | |
| AU723556B2 | Australia | B2 | |
| TW405073B | Taiwan Province of China | B | |
| EP1018236A4 | European Patent Office (EPO) | A4 | |
| EP1020049A4 | European Patent Office (EPO) | A4 | |
| EP0900488A4 | European Patent Office (EPO) | A4 | |
| CA2258087C | Canada | C | |
| US6175925B1 | United States of America | B1 | |
| US6178509B1 | United States of America | B1 | |
| US6205550B1 | United States of America | B1 | |
| KR20010023731A | Republic of Korea | A | |
| KR20010023732A | Republic of Korea | A | |
| KR20010023733A | Republic of Korea | A | |
| JP2001516908A | Japan | A | |
| EP1000482A4 | European Patent Office (EPO) | A4 | |
| EP1010291A4 | European Patent Office (EPO) | A4 | |
| KR20030085085A | Republic of Korea | A | |
| KR20030085086A | Republic of Korea | A | |
| KR100405574B1 | Republic of Korea | B1 | |
| KR100479681B1 | Republic of Korea | B1 | |
| KR100482775B1 | Republic of Korea | B1 | |
| EP0900488B1 | European Patent Office (EPO) | B1 | |
| EP1000482B1 | European Patent Office (EPO) | B1 | |
| DE69735103D1 | Germany | D1 | |
| DE69833947D1 | Germany | D1 | |
| DE69735103T2 | Germany | T2 | |
| DE69833947T2This record | Germany | T2 | |
| EP2131524A2 | European Patent Office (EPO) | A2 | |
| EP2131524A3 | European Patent Office (EPO) | A3 | |
| JP4544739B2 | Japan | B2 |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Ceased/non-payment of the annual feeCeased8339 | 8339 | |
| Change in the person/name/address of the agent8328 | 8328 | |
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 69833947
- Publication, DOCDB
- 69833947
- Publication, EPODOC
- DE69833947T
- Application
- 69833947
- Application, DOCDB
- 69833947
- Application, EPODOC
- DE1998633947T
Titles2
- German
- SPEICHERZELLENANORDNUNG ZUR ERZEUGUNG EINER GEHEIMEN NICHT DAUERHAFTEN SPEICHERUNG
- English
- MEMORY CELL ARRANGEMENT FOR GENERATING A SECRET NOT PERMANENT STORAGE
Classification
- CPC, 1
- G06F21/79
- IPC, 5
- H04L9 00
- G06F1 00
- G06F12 14
- G06F21 00
- G11C7 10
