EP0792041A2

Method and apparatus for block encryption

Abstract

A system for encrypting a plaintext block using a block encryption algorithm having a block size smaller than that of the plaintext block. The plaintext block is transformed into a masked plaintext block using an invertible transformation optionally dependent on additional data and defined such that each bit of the masked plaintext block depends on every bit of the original plaintext block. A subportion of the masked plaintext block is encrypted using the encryption algorithm to generate an encrypted portion of the masked plaintext block. A ciphertext block is generated from the thus encrypted portion of the masked plaintext block and the remaining portion of the masked plaintext block. The ciphertext block is transmitted to a data recipient, who reverses the procedure to recover the original plaintext block. Since the entire masked plaintext block is necessary to reconstruct the original plaintext block and since the encrypted portion cannot be derived from the remaining portion, the remaining portion of the masked plaintext block may be transmitted to the recipient in unencrypted form. To thwart certain cryptanalytic attacks, either the plaintext block or the optional additional data is uniquely modified for each encryption of a plaintext block, using an incrementing counter, time stamp, random number or other mechanism. In an exemplary embodiment, an elliptic curve algorithm having a block size on the order of 160 bits is used to encrypt a 512-bit block containing a symmetric encryption key.

EP0792041A2, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 6 February 2017, 9.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

18 claims: 9 independent, 9 dependent

  1. 1
    A method of encrypting a plaintext block using a block encryption procedure, said method comprising the steps of:generating a masked plaintext block as a function of said plaintext block and additional data using a predetermined invertible transformation defined such that the original plaintext block is recoverable from said masked plaintext block and optional additional data;andencrypting at least a subportion of said masked plaintext block using said encryption procedure to generate a ciphertext block.
  2. 2
    A method of encrypting a plaintext data block using a block encryption procedure having a block size smaller than that of said plaintext block, said method comprising the steps of:transforming said plaintext block into a masked plaintext block using a predetermined invertible transformation defined such that each bit of said masked plaintext block depends on every bit of the original plaintext block;encrypting a subportion of said masked plaintext block having said block size using said encryption procedure to generate an encrypted portion of said masked plaintext block;andgenerating a ciphertext block from said encrypted portion of said masked plaintext block and the remaining portion of said masked plaintext block.
  3. 11
    The method of any of Claims 2 to 7 wherein said plaintext block comprises first and second parts, said transforming step comprising the steps of:generating a first mask value from said second part using a first transformation;combining said first mask value with said first part to generate an intermediate-stage first part;generating a second mask value from said intermediate-stage first part using a second transformation;combining said second mask value with said second part to generate a masked second part;generating a third mask value from said masked second part using a third transformation;andcombining said third mask value with said intermediate-stage first part to generate a masked first part, one of said masked parts being used to generate a first part of said masked plaintext block, the other of said masked parts being used to generate a second part of said masked plaintext block.
  4. 12
    The method of any of Claims 2 to 11 wherein said masked plaintext block is generated as a function of said plaintext block and optional additional data, said method comprising the further step of uniquely modifying at least one of said plaintext block and optional additional data for each encryption of a plaintext block, said transforming step being performed on said modified plaintext block.
  5. 13
    A method of encrypting a plaintext block using a block encryption procedure, said method comprising the steps of:generating a masked plaintext block as a function of said plaintext block and optional additional data using a predetermined invertible transformation defined such that the original plaintext block is recoverable from said masked plaintext block and optional additional data;encrypting at least a subportion of said masked plaintext block using said encryption procedure to generate a ciphertext block;anduniquely modifying at least one of said plaintext block and said optional additional data prior to generation of said masked plaintext block for each encryption of a plaintext block.
  6. 15
    Apparatus for encrypting a plaintext data block using a block encryption procedure having a block size smaller than that of said plaintext block, said apparatus comprising:means for transforming said plaintext block into a masked plaintext block using a predetermined invertible transformation defined such that each bit of said masked plaintext block depends on every bit of the original plaintext block;means for encrypting a subportion of said masked plaintext block having said block size using said encryption procedure to generate an encrypted portion of said masked plaintext block;andmeans for generating a ciphertext block from said encrypted portion of said masked plaintext block and the remaining portion of said masked plaintext block.
  7. 16
    Apparatus for encrypting a plaintext block using a block encryption procedure, said apparatus comprising:means for generating a masked plaintext block as a function of said plaintext block and optional additional data using a predetermined invertible transformation defined such that the original plaintext block is recoverable from said masked plaintext block and optional additional data;andmeans for encrypting at least a subportion of said masked plaintext block using said encryption procedure to generate a ciphertext block;andmeans for uniquely modifying at least one of said plaintext block and said optional additional data prior to generation of said masked plaintext block for each encryption of a plaintext block.
  8. 17
    A program storage device readable by a machine, tangibly embodying a program of instructions executable by the machine to perform method steps for encrypting a plaintext data block using a block encryption procedure having a block size smaller than that of said plaintext block, said method steps comprising:transforming said plaintext block into a masked plaintext block using a predetermined invertible transformation defined such that each bit of said masked plaintext block depends on every bit of the original plaintext block;encrypting a subportion of said masked plaintext block having said block size using said encryption procedure to generate an encrypted portion of said masked plaintext block;andgenerating a ciphertext block from said encrypted portion of said masked plaintext block and the remaining portion of said masked plaintext block.
  9. 18
    A program storage device readable by a machine, tangibly embodying a program of instructions executable by the machine to perform method steps for encrypting a plaintext block using a block encryption procedure, said method steps comprising:generating a masked plaintext block as a function of said plaintext block and optional additional data using a predetermined invertible transformation defined such that the original plaintext block is recoverable from said masked plaintext block and optional additional data;andencrypting at least a subportion of said masked plaintext block using said encryption procedure to generate a ciphertext block;anduniquely modifying at least one of said plaintext block and said optional additional data prior to generation of said masked plaintext block for each encryption of a plaintext block.