Nova Patents
EP0676876A1

Encryption method and system.

Abstract

The present invention provides a simple encryption method and system for encrypting data into a plurality of control and encrypted data blocks. The data to be encrypted is divided into data segments which can be of varying length. Each control block comprises the information necessary to decrypt the data contained in the encrypted data block, such as the encryption function and associated key used to encrypt a data segment, the start position of an encrypted data segment within the encrypted data block and the length of the encrypted data block. Both the control block and the encrypted data block are padded with random numbers and the start position of the encrypted data with the encrypted data block can vary.

EP0676876A1, drawing sheet 1
Sheet 1 of 10

Term

Term ended

Projected expiry passed 3 April 2015, 11.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

15 claims: 12 independent, 3 dependent

  1. 1
    A method for encrypting data comprising a plurality of data segments (DS₁ to DS n ) into a plurality of encrypted data blocks (EDB₁ to EDB n ) and associated control blocks (CB₁ to CB n ), the method comprising the steps of, for each data segment,    selecting one of a plurality of encryption functions (F₁ to F i ),    encrypting the data segment using the selected encryption function to form an encrypted data segment,    producing an encrypted data block comprising the encrypted data segment,    producing for the encrypted data block an associated control block comprising an indication of the encryption function used to encrypt the data.
  2. 3
    A method as claimed in either of claims 1 or 2, further comprising the step of selecting the length of each encrypted data segment (L₂) within each encrypted data block.
  3. 4
    A method as claimed in any preceding claim, further comprising the step of selecting the starting position (S) of the encrypted data segment within the encrypted data block.
  4. 5
    A method as claimed in any of claims 2, 3 or 4, wherein the control block further comprises an indication of the total length L₁ of the encrypted data block, the length L₂ of the data encrypted segment or the starting position (S) of the encrypted data segment within the encrypted data block, as appropriate.
  5. 6
    A method as claimed in any of claims 2 to 5, wherein the total length (L₁) of the encrypted data block, the length (L₂) of the encrypted data segment, or the starting position (S) of the encrypted data segment within the encrypted data block is selected randomly.
  6. 7
    A method as claimed in any preceding claim, further comprising the step of filling the fields of the encrypted data block which do not contain the encrypted data segment with random numbers (X).
  7. 8
    A method as claimed in any preceding claim, further comprising the step of selecting an encryption key from a plurality of encryption keys (K₁ to K j ) for use with the selected encryption function.
  8. 10
    A method as claimed in any preceding claim, wherein the control block further comprises random numbers (X) in the fields not occupied by other information.
  9. 11
    A method as claimed in any preceding claim, further comprising the step of selecting one of a plurality of predetermined control block formats (CB₁ to CB₁) and wherein a predetermined position of each control block further contains an indication (C) of the predetermined format of the control block.
  10. 12
    A system for encrypting data comprising a plurality of data segments (DS₁ to DS n ) into a plurality of encrypted data blocks (EDB₁ to EDB n ) and associated control blocks (CB₁ to CB n ), comprising:means for selecting for each data segment one of a plurality of encryption functions (F₁ to F i );means for encrypting for each data segment the data segment using the selected encryption function to form an encrypted data segment;means for producing for each data segment an encrypted data block comprising the encrypted data segment;and means for producing for each data segment a control block associated with the encrypted data block comprising an indication of the encryption function used to encrypt the data.
  11. 13
    A method for decrypting data encrypted from a plurality of data segments (DS₁ to DS n ) into a plurality of encrypted data blocks (EDB₁ to EDB n ) and associated control blocks (CB₁ to CB n ) using a plurality of encryption functions (F₁ to F i ), the method comprising the steps of:reading a control block and an associated encrypted data block;determining an encryption function from the information in the control block used with the associated encrypted data block;and decrypting a data segment from the encrypted data block based on the determined encryption function.
  12. 15
    A system for decrypting data encrypted from a plurality of data segments (DS₁ to DS n ) into a plurality of encrypted data blocks (EDB₁ to EDB n ) and associated control blocks (CB₁ to CB n ) using a plurality of encryption functions (F₁ to F i ), the system comprising:means for reading a control block and an associated encrypted data block;means for determining an encryption function from the information in the control block used with the associated encrypted data block;and means for decrypting a data segment from the encrypted data block based on the determined encryption function.