EP0802653B1

Multi-cycle non-parallel data encryption engine

Abstract

This record has no abstract on file.

EP0802653B1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Expired 15 April 2017, 9.4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

13 claims: 13 independent, 0 dependent

  1. 1
    A method for safeguarding data transmissions, characterised in that it comprises the steps of:inputting data to a first cipher stage (520) of a plurality of cipher stages (520, 525, 530) that are coupled in series, wherein the data is encrypted by each of the cipher stages (520, 525, 530) and encrypted data generated by one of the cipher stages (520, 525, or 530, respectively) is input to a following stage (525, 530, or 520, respectively);feeding back an output from a last cipher stage (530) of the plurality of cipher stages (520, 525, 530) to the first cipher stage (520);cycling through the plurality of cipher stages (520, 525, 530) N times;selecting from one (520) of the plurality of cipher stages (520, 525, 530) as a final encrypted data for output. Procédé pour sauvegarder des transmissions de données, caractérisé en ce qu'il comprend les étapes suivantes : l'entrée de données dans un premier étage chiffré (520) d'une pluralité d'étages chiffrés (520, 525, 530) reliés en série, les données étant chiffrées par chacun des étages chiffrés (520, 525, 530) et les données chiffrées générées par l'un des étages chiffrés (respectivement 520, 525 ou 530) étant appliquées à un étage suivant (respectivement 525, 530 ou 520);rétroaction d'une sortie provenant du dernier étage chiffré (530) de la pluralité d'étages chiffrés (520, 525, 530) vers le premier étage chiffré (520);cyclage de N fois à travers la pluralité d'étages chiffrés (520, 525, 530) , etsélection de l'un (520) de la pluralité des étages chiffrés (520, 525, 530) en tant que données chiffrées finales pour la sortie. Verfahren zum Schützen von Datenübertragungen, dadurch gekennzeichnet, dass es die folgenden Schritte umfasst: das Eingeben von Daten in eine erste Chiffrierstufe (520) von einer Vielzahl von Chiffrierstufen (520, 525, 530), die in Reihe geschaltet sind, wobei die Daten durch jede der Chiffrierstufen (520, 525, 530) verschlüsselt werden und die verschlüsselten Daten von einer der Chiffrierstufen (520, 525, 530) an eine folgende Stufe (525, 530 bzw. 520) weitergegeben werden;das Rückkoppeln einer Ausgabe von einer letzten Chiffrierstufe (530) der Vielzahl von Chiffrierstufen (520, 525, 530) an die erste Chiffrierstufe (520);das N-malige Durchlaufen der Vielzahl von Chiffrierstufen (520, 525, 530);das Auswählen von einer Chiffrierstufe (520) aus der Vielzahl von Chiffrierstufen (520, 525, 530) als endgültig verschlüsselte Daten für die Ausgabe.
  2. 2
    A method as claimed in claim 1 for encrypting and decrypting data, characterised in that it comprises the steps of:a) inputting the data to an XOR gate (505);b) XORing the data with an output from a first cipher stage (520);c) multiplexing an output from the XOR gate (505) with an output from a third cipher stage (530);d) storing an output signal from the multiplexer (510) in a register (515);e) encrypting data stored in the register (515) by the first cipher stage (520) to generate a first encrypted block of data;f) generating a second encrypted block of data by a second cipher stage (525) processing the first encrypted block of data;g) generating a third encrypted block of data by the third cipher stage (530) processing the second encrypted block of data;h) repeating steps e-g five times;i) inputting a signal from the third cipher stage (530) to the multiplexer (510) after the firth time and taking the output signal from the first cipher stage (520) as an encrypted output such that the data is encrypted through sixteen cycles. Procédé suivant la revendication 1 pour chiffrer et déchiffrer des données, caractérisé en ce qu'il comprend les étapes suivantes : a) entrée des données dans une porte OU EXCLUSIF (505);b) traitement OU EXCLUSIF des données avec une sortie du premier étage chiffré (520);c) multiplexage d'une sortie de la porte OU EXCLUSIF (505) avec une sortie d'un troisième étage chiffré (530);d) stockage d'un signal de sortie du multiplexeur (510) dans un registre (515);e) chiffrement de données stockées dans le registre (515) par le premier étage chiffré (520) pour générer un premier bloc chiffré de données;f) génération d'un deuxième bloc chiffré de données par un deuxième étage chiffré (525) traitant le premier bloc chiffré de données;g) génération d'un troisième bloc chiffré de données par le troisième étage chiffré (530) traitant le deuxième bloc chiffré de données;h) répétition des étapes e à g cinq fois, eti) entrée d'un signal du troisième étage chiffré (530) dans le multiplexeur (510) après la cinquième fois et adoption du signal de sortie du premier étage chiffré (520) comme sortie chiffrée, de sorte que les données sont chiffrées à travers seize cycles. Verfahren nach Anspruch 1 zum Verschlüsseln und Entschlüsseln von Daten, dadurch gekennzeichnet, dass es die folgenden Schritte umfasst: a) Eingeben der Daten in ein EXKLUSIV-ODER-Gatter (505);b) EXKLUSIV-ODER-Verknüpfen der Daten mit der Ausgabe von einer ersten Chiffrierstufe (520);c) Multiplexieren einer Ausgabe von dem EXKLUSIV-ODER-Gatter (505) mit einer Ausgabe von einer dritten Chiffrierstufe (530);d) Speichern eines Ausgabesignals vom Multiplexer (510) in einem Register (515);e) Verschlüsseln der in dem Register (515) gespeicherten Daten durch die erste Chiffrierstufe (520), um einen ersten verschlüsselten Datenblock zu erzeugen;f) Erzeugen eines zweiten verschlüsselten Datenblocks durch eine zweite Chiffrierstufe (525), die den ersten verschlüsselten Datenblock verarbeitet;g) Erzeugen eines dritten verschlüsselten Datenblocks durch die dritte Chiffrierstufe (530), die den zweiten verschlüsselten Datenblock verarbeitet;h) 5-maliges Wiederholen der Schritte e - g;i) Eingeben eines Signals von der dritten Chiffrierstufe (530) in den Multiplexer (510) nach der fünften Wiederholung und Nehmen des Ausgabesignals aus der ersten Chiffrierstufe (520) als verschlüsselte Ausgabe, so dass die Daten durch sechzehn Zyklen verschlüsselt werden.
  3. 3
    Procédé suivant la revendication 1, comprenant en outre l'étape de traitement OU EXCLUSIF des données avec un vecteur initial avant l'entrée des données dans le premier étage chiffré (520). The method of Claim 1 further comprising the step of XORing the data with an initial vector before the data is input to the first cipher stage (520). Verfahren nach Anspruch 1, das weiterhin den Schritt der EXKLUSIV-ODER-Verknüpfung der Daten mit einem Anfangsvektor enthält, bevor die Daten in die erste Chiffrierstufe (520) eingegeben werden.
  4. 4
    Procédé suivant la revendication 3, comprenant en outre l'étape de multiplexage entre la sortie de la porte OU EXCLUSIF (505) et la sortie du dernier étage chiffré (530), en sachant que la sortie du multiplexeur (510) est entrée dans un registre (515) relié à une entrée du premier étage chiffré (520). The method of Claim 3 further comprising the step of multiplexing between the output from the XOR gate (505) and the output from the last cipher stage (530), wherein the output from the multiplexer (510) is input to a register (515) coupled to an input of the first cipher stage (520). Verfahren nach Anspruch 3, das weiterhin den Schritt des Multiplexierens zwischen der Ausgabe von dem EXKLUSIV-ODER-Gatter (505) und der Ausgabe von der letzten Chiffrierstufe (530) enthält, wobei die Ausgabe von dem Multiplexer (510) in ein Register (515) eingegeben wird, das mit einem Eingang der ersten Chiffrierstufe (520) verbunden ist.
  5. 5
    Procédé suivant l'une quelconque des revendications précédentes, dans lequel les étages chiffrés (520, 525, 530) chiffrent les données suivant une pluralité de clés qui sont différentes pour chaque étage chiffré (respectivement 520, 525 ou 530) de chaque cycle du processus de chiffrement. The method of any one of the preceding claims wherein the cipher stages (520, 525, 530) encrypt the data according to a plurality of keys which are different for each cipher stage (520, 525, or 530, repectively) of each cycle of the encryption process. Verfahren nach einem der vorhergehenden Ansprüche, wobei die Chiffrierstufen (520, 525, 530) die Daten entsprechend einer Vielzahl von Schlüsseln verschlüssetn, die für jede Chiffrierstufe (520, 525 bzw. 530) jedes Zyklus des Verschlüsselungsprozesses unterschiedlich sind.
  6. 6
    Procédé suivant l'une quelconque des revendications précédentes, dans lequel il y a trois étages chiffrés (520, 525, 530), N est égal à 5, et la sortie finale est tirée de la sortie du dernier étage chiffré (520), de sorte que les données sont chiffrées seize fois. The method of any one of the preceding claims wherein there are three cipher stages (520, 525, 530), N equals 5, and the final output is taken from the output from the first cipher stage (520), such that the data is encrypted sixteen times. Verfahren nach einem der vorhergehenden Ansprüche, wobei es drei Chiffrierstufen (520, 525, 530) gibt, N gleich 5 ist und die endgültige Ausgabe von dem Ausgang der ersten Chiffrierstufe (520) genommen wird, so dass die Daten sechzehn Mal verschlüsselt werden.
  7. 7
    Procédé suivant la revendication 1, dans lequel les étages chiffrés (520, 525, 530) correspondent à :1) un mode de fonctionnement par chiffrement progressif;et/ou 2) un mode de fonctionnement par rétroaction de sortie;et/ou un mode de fonctionnement par rétroaction chiffrée;et/ou un mode de fonctionnement par dictionnaire de codes électronique. The method of Claim 1, wherein the cipher stages (520, 525, 530) correspond to: 1) a cipher block chaining mode of operation;and/or 2) an output feedback mode of operation;and/or 3) a cipher feedback mode of operation;and/or 4) an electronic codebook mode of operation. Verfahren nach Anspruch 1, wobei die Chiffrierstufen (520, 525, 530) Folgendem entsprechen: 1) einem Cipher-Block-Chaining-Betriebsmodus;und/oder 2) einem Output-Feedback-Betriebsmodus;und/oder 3) einem Cipher-Feedback-Betriebsmodus;und/oder 4) einem Electronic-Codebook-Betriebsmodus.
  8. 8
    Procédé suivant la revendication 1, dans lequel les données sont chiffrées et déchiffrées suivant 16 opérations de chiffrement. The method of Claim 1, wherein the data is encrypted and decrypted according to 16 cipher operations. Verfahren nach Anspruch 1, wobei die Daten entsprechend 16 Chiffrieroperationen verschlüsselt und entschlüsselt werden.
  9. 9
    An apparatus for encoding or decoding data, characterised by:an XOR gate (505) for XORing the data with previously encrypted data;a multiplexer (510) coupled to the XOR gate (505), wherein the multiplexer (510) selects between an output from the XOR gate (505) and an output from a last cipher stage (530) as an input to a first cipher stage (520);a plurality of cipher stages (520, 525, 530) coupled in series to the multiplexer (510), wherein the data is encrypted by each of the cipher stages (520, 525, 530) and encrypted data processes by one cipher stage (520, 525, or 530, respectively) is input to a following cipher stage (525, 530, or 520, respectively);a feedback path coupled from an output of the last cipher stage (530) to an input of the first cipher stage (520), wherein the data is encrypted N cycles through the plurality of cipher stages (520, 525, 530);an output register (535) coupled to one (520) of the plurality of cipher stages (520, 525, 530) for storing the encrypted data. Appareil pour coder ou décoder des données, caractérisé par : une porte OU EXCLUSIF (505) pour un traitement OU EXCLUSIF des données avec des données chiffrées auparavant;un multiplexeur (510) relié à la porte OU EXCLUSIF (505), le multiplexeur (510) effectuant une sélection entre une sortie de la porte OU EXCLUSIF (505) et une sortie d'un dernier étage chiffré (530) comme entrée pour un premier étage chiffré (520);une pluralité d'étages chiffrés (520, 525, 530) reliés en série au multiplexeur (510), les données étant chiffrées par chacun des étages chiffrés (520, 525, 530) et les données chiffrées traitées par un étage chiffré (respectivement 520, 525 ou 530) sont entrées dans un étage chiffré suivant (respectivement 525, 530 ou 520);un chemin de rétroaction relié entre une sortie du dernier étage chiffré (530) et une entrée du premier étage chiffré (520), les données étant chiffrées sur N cycles à travers la pluralité d'étages chiffrés (520, 525, 530), etun registre de sortie (535) relié à l'un (520) de la pluralité d'étages chiffrés (520, 525, 530) pour stocker les données chiffrées. Gerät zum Codieren und Decodieren von Daten, gekennzeichnet durch:ein EXKLUSIV-ODER-Gatter (505) zum EXKLUSIV-ODER-Verknüpfung der Daten mit zuvor verschlüsselten Daten;einen Multiplexer (510), der mit dem EXKLUSIV-ODER-Gatter (505) verbunden ist, wobei der Multiplexer (510) zwischen einer Ausgabe des EX-KLUSIV-ODER-Gatters (505) und einer Ausgabe der letzten Chiffrierstufe (530) als Eingabe für eine erste Chiffrierstufe (520) wählt;eine Vielzahl von Chiffrierstufen (520, 525, 530), die mit dem Multiplexer (510) in Reihe geschaltet sind, wobei die Daten durch jede der Chiflrierstufen (520, 525, 530) verschlüsselt werden und die durch eine Chiffrierstufe (520, 525 bzw. 530) verarbeiteten verschlüsselten Daten in eine folgende Chiffrierstufe (525, 530 bzw. 520) eingegeben werden;einen Rückkopplungspfad von einem Ausgang der letzten Chiffrierstufe (530) zu einem Eingang der ersten Chiffrierstufe (520), wobei die Daten in N Zyklen durch die Vielzahl von Chiffrierstufen (520, 525, 530) verschlüsselt werden;ein Ausgangsregister (535), das mit einer Chiffrierstufe (520) der Vielzahl von Chiffrierstufen (520, 525, 530) verbunden ist, um die verschlüsselten Daten zu speichern.
  10. 10
    Appareil suivant la revendication 9, dans lequel les données chiffrées auparavant sont formées d'un vecteur initial avant que les données sont introduites dans le premier étage chiffré (520). Gerät nach Anspruch 9, wobei die zuvor verschlüsselten Daten einen Anfangsvektor umfassen, bevor die Daten in die erste Chiffrierstufe (520) eingegeben werden. The apparatus of Claim 9, wherein the previously encrypted data is comprised of an initial vector before the data is input to the first cipher stage (520).
  11. 11
    Appareil suivant la revendication 9 ou 10, dans lequel les étages chiffrés (520, 525, 530) chiffrent les données conformément à une pluralité de clés qui sont différentes pour chaque étage chiffré (520, 525, 530) de chaque cycle du processus de chiffrement. Gerät nach Anspruch 9 oder 10, wobei die Chiffrierstufen (520, 525, 530) die Daten entsprechend einer Vielzahl von Schlüsseln verschlüsseln, die für jede Chiffrierstufe (520, 525, 530) jedes Zyklus des Verschlüsselungsprozesses unterschiedlich sind. The apparatus of Claims 9 or 10, wherein the cipher stages (520, 525, 530) encrypt the data according to a plurality of keys which are different for each cipher stage (520, 525, 530) of each cycle of the encryption process.
  12. 12
    Appareil suivant la revendication 9, 10 ou 11, dans lequel il y a trois étages chiffrés (520, 525, 530), N est égal à 5, et la sortie finale est prise sur la sortie du premier étage chiffré (520), de sorte que le nombre de cycles de chiffrement est de seize.. Gerät nach Anspruch 9, 10 oder 11, wobei es drei Chiffrierstufen (520, 525, 530) gibt, N gleich 5 ist und die endgültige Ausgabe von dem Ausgang der ersten Chiffrierstufe (520) genommen wird, so dass es sechzehn Chiffrierzyklen gibt. The apparatus of Claims 9, 10 or 11, wherein there are three cipher stages (520, 525, 530), N equals 5, and the final output is taken from the output from the first cipher stage (520), such that there are sixteen cipher cycles.
  13. 13
    Appareil suivant la revendication 9, 10, 11 ou 12, dans lequel les étages chiffrés (520, 525, 530) comprennent des modes de fonctionnement basés sur la norme de chiffrement de données et reposant sur un chiffrement progressif, une rétroaction de sortie, une rétroaction chiffrée et un dictionnaire de codes électronique. Gerät nach Anspruch 9, 10, 11 oder 12, wobei die Chiffrierstufen (520, 525, 530) den Cipher-Block-Chaining-Betriebsmodus, den Output-Feedback-Betriebsmodus, den Cipher-Feedback-Betriebsmodus und den Electronic-Codebook-Betriebsmodus des Data Encryption Standard (DES) umfassen. The apparatus of Claims 9, 10, 11 or 12, wherein the cipher stages (520, 525, 530) include data encryption standard cipher block chaining, output feedback, cipher feedback, and electronic codebook modes of operation.