Cryptographic method modifiable during run time
3 claims: 3 independent, 0 dependent
- 1Method for generation of a pseudo random number for cryptographic purposes with the steps:- repeatable translation, generation and assembling of a limited number of cryptographic program fragments (12) by a compiler (4),- wheras the source code is being generated using a source code pseudorandom number generator (2) with dependance on an alterable source code password (1) and being stored in a source code data memory (3), and- whereas the program fragments (12) are being assembled as generic machine code (5), and- whereas this machine code (5) executes permutations, division modulo computations, bit shifts and/or permutations of bit groups in a data memory (6)characterized by- the initialization of this data memory (6) by a pseudo random number sequence that is generated by another pseudorandom number generator (10), which is controlled by another password (11)- one time or repeated execution of this compiler (4) generated machine code (5) in the central processing unit of a computer for the generation of a pseudorandom number for cryptographic purposes Methode zur Erzeugung einer Pseudozufallszahl für kryptographische Zwecke mit den Schritten: - wiederholbares Übersetzen, Generieren und Aneinanderreihen einer begrenzten Zahl von kryptographischen Programmfragmenten (12) durch einen Compiler (4),- wobei der Quellkode mittels eines Quellkode-Pseudozufallszahlengenerators (2) in Abhängigkeit eines änderbaren Quellkode-Paßworts (1) generiert und in einem Quellkode-Datenspeicher (3) gespeichert wird, und- wobei die Programmfragmente (12) als generierter Maschinenkode (5) aneinandergereiht werden, und- wobei dieser Maschinenkode (5) Permutationen, Divisionsrestberechnungen, Bitverschiebungen und/oder Vertauschungen von Bitgruppen in einem Datenspeicher (6) durchführtgekennzeichnet durch- die Initialisierung dieses Datenspeichers (6) mit einer durch ein weiteres Paßwort (11) gesteuerten und in einem weiteren Pseudozufallszahlengenerator (10) erzeugten Pseudozufallszahlenfolge- ein- oder mehrmaliges Ausführen dieses vom Compiler (4) erzeugten Maschinenkodes (5) in der Zentraleinheit eines Rechners zur Erzeugung einer Pseudozufallszahl für kryptographische Zwecke Méthode de génération de nombres pseudo aléatoires pour des buts cryptographiques suivant les étapes décrites ci-dessous: - traduction, génération et assemblage répétable d'un nombre limité de fragments de programme (12) cryptographiques par un compilateur (4),- où le code source étant générer en utilisant le code source de générateur de nombres pseudo aléatoires (2) dépendamment d'un mot de passe de code source stocké dans la mémoire de données de code source(3), et- dont les fragments de programme (12) sont réunis comme code machine générique (5), et- Où ce code machine (5) exécute des permutations, des calculs de reste de divisions, des décalages de bits et/ou permutation de groupe de bits dans la mémoire de données (6).caractérisé en ce que- l'initialisation de cette mémoire de données (6) par une séquence de nombres pseudo aléatoires produite par un autre générateur de nombre pseudo aléatoires (10) qui est contrôlé par un autre mot de passe (11).- une ou plusieurs exécutions de ce code machine (5) généré par le compilateur (4) dans le processeur central d'un calculateur pour produire des nombres pseudo aléatoires à des buts cryptographiques.
- 2Method for generation of a pseudo random number for cryptographic purposes as recited in claim 1 wherein execution of the machine code (5) can be carried out by an interpreter. Méthode de génération de nombres pseudo aléatoires pour des buts cryptographiques selon la revendication 1 caractérisé en ce que l'exécution du code machine peut être effectuée par un interpréteur. Während der Laufzeit veränderbare kryptographische Methode (20) nach Anspruch 1, dadurch gekennzeichnet, daß die Ausführung des Maschinenkodes (5) durch einen Interpretierer durchgeführt werden kann.
- 3Method for generation of a pseudo random number for cryptographic purposes as recited in claim 1 or 2, wherein the limited number of cryptographic program fragments (12), which are assembled by the compiler (4), can as well execute other cryptographic operations than permutations, division modulo computations, bit shifts and/or permutations of bit groups in a data memory (6);in particular CRC code calculations, computation of non-linear mathematic formulas and linear congruential random number calculations. Méthode de génération de nombres pseudo aléatoires pour des buts cryptographiques selon les revendications 1 et 2 caractérisé en ce que le nombre limité de fragments de programme cryptographique (12) qui sont assemblés par le compilateur (4) peut aussi bien exécuter des opérations cryptographiques autre que des permutations, des calculs de reste de divisions, des décalages de bits et/ou échanges des groupes de bits dans la mémoire (6);en particulier les calculs de codes CRC, calculs de formules mathématiques non linéaires et calculs linéaires congruents de nombre aléatoire. Während der Laufzeit veränderbare kryptographische Methode (20) nach einem der Ansprüche 1 bis 2, die dadurch gekennzeichnet, daß begrenzte Zahl kryptographischer Programmfragmente (12), die vom Compiler (4) aneinandergereiht werden, auch andere kryptographische Operationen als Permutationen, Divisionsrestberechnungen, Bitverschiebungen und/oder Vertauschungen von Bitgruppen im Datenspeicher (6) durchführen können, insbesondere CRC-Kodeberechnungen, die Berechnung nichtlinearer mathematischer Formeln und linear kongruente Zufallszahlenberechnungen.
Independent claims3
19 paragraphs, as filed
The invention relates to a cryptographic method that at the beginning of their term on a Computer or microcontroller is undetermined. The compilation process of Key is a program piece generated in machine language, which the cryptographic specifies method during the term of a cryptographic program. By changing the key and recompile the program piece can in modified machine language during the term of a cryptographic program will.
Cryptographic methods are known since ancient times and are widely used before particularly in computer networks, in smart card and communications systems, messages a group of receivers make available, information on their to protect transmission and to authenticate data. International Banking and telecommunications industries require fast and secure data encryption methods, to which are imposed secrecy comply.
Known are methods that make use of the simple substitution of letters, and block ciphers with permutations, additions and substitutions of Bit groups of a linked with a key message. Furthermore, methods that perform arithmetic operations with large numbers, however, in which the reversal of Arithmetic operation for lack of suitable mathematical methods involve high Time is determined, known, and are widely used. Besides exist Methods that perform a large number of shift operations long key or use random number generators to the above bitwise EXOR operation resulting key to perform a message whose encryption and decryption. Virtually any known method for calculation of a bit pattern, which is the Bit pattern is different of the original message, is used in cryptography. For this reason, today there is a flood of algorithms that a more or less large cryptographic security offer.
With mixing of messages to be encrypted and a staggered implementation of various cryptographic methods is attempted usually single known to conceal weaknesses of the known cryptographic methods. An acquaintance Weakness of a cryptographic method, for example, the transparency of the be key in the encrypted data or too short a key, so that by Try a number of possible keys, the encrypted data is decrypted can.
Many well-known cryptographic methods have in common that at the beginning of the execution of the Methods on a computer system, the arrangement of the machine instructions in the program memory the computer system is determined. When trying a known cryptographic breaking method for the purpose of decrypting data, sampling a will large number of possible key in on one or more specialized computers finite time lead to success. Thus, by the extension of the key used higher security can be achieved as a rule, does not render the data encryption time required in the best case linear, however, usually quadratically with the number Key bits grows. For the case that a method is found in the future, with the the number of required to break the cryptographic method attempts substantially is reduced, there is a significant security risk for all already with the procedure encrypted data. however Läge the sequence of interdependent cryptographic processes not in advance firmly, so would the Try different key every possible combination apart nonlinear cryptographic processes are additionally tested. at the same key length and execution time would therefore be the tasting of a factor possible combinations of cryptographic processes larger numtrials required.
"Sequential Test Generator: Past, Present and Future" (Integration, The VLSI Joumal, Dec. 1998) by Yong Chang Kim and Kewal K. Saluja describes a method for Generating random numbers for use as a test pattern by algorithms in turn are generated pseudo-randomly.
US5222139 describes a method for encrypting that of the features The preamble of claim 1 comprises.
The rates in the characterizing part of patent claim 1 solve the Task, an alternative method for generating pseudo-random numbers for cryptographic purposes to create.
Through a compilation process of a key is a piece of program generated in machine language, which the cryptographic method during the term or part of the term of a cryptographic program specifies. By changing the key and recompilation of the cryptographic method, the program fragment in machine language during the term of a cryptographic program be changed, whereby the disadvantages described above do not occur.
This problem is solved by the features listed in claim 1st
An inventive cryptographic method consists of a limited number of cryptographic Program fragments that are executed sequentially in any order can and the contents of a data memory by permutations, remainder calculations, Bit shifts permutations of bit groups and other non-linear change operations often. The order in which the cryptographic Program fragments can be selected, in an advantageous embodiment, a with a password initialized pseudo-random number generator, which controls a compiler, with the cryptographic program fragments finally translated into machine code will. During execution of the machine code of the contents of the data memory is quasi randomly scrambled. carried out the transfer of the data to be encrypted in the encrypted data for example, by logical EXOR operation on the data to be encrypted with the content of the data memory.
The big advantage of a cryptographic method of the invention is to increase the breaking of a comparable known cryptographic method whose Machine code is already set at the beginning of the term, the effort required. The Number of contributory attempts grows exponentially with the number of aligned cryptographic program fragments from which the machine code is constructed. The cryptographic program fragments must be interchangeable, non-linear and have a comparable cryptographic security. Moreover, can in an advantageous embodiment of cryptographic program fragments from where the machine code is constructed on almost any known microprocessor be performed within a few instruction cycles. It can thus in smart card applications, to the use of a special circuit block for encryption operations be waived. The program executed by the processor core of the fragments Machine code offer exponentially by using the code length of the machine code growing number of possible combinations a well expontentiell growing Attack security. The processing time of the machine code, however only increases linearly with the code length to.
The limited number of cryptographic program fragments strung together by the compiler are, other cryptographic operations than permutations, Remainder calculations, bit shifts and / or permutations of bit groups in Data storage perform. In particular, CRC Kodeberechnungen, the calculation of non-linear mathematical formulas and linear congruent random number calculations conceivable. The the compiler available cryptographic program fragments are limited by controlled by the input assignment of constants and by adjusting the operation of variable in your function.
It is also conceivable that the execution of the machine code for better portability the cryptographic method on computer different internal structure with is accomplished an interpreter. The execution speed of machine code is thereby reduced, but can in an advantageous embodiment of a according to the invention cryptographic method from the differences in the Central units of different computer independent interpretation of the machine code be considered.
It is further contemplated that the cryptographic method in a cryptographic Program can also be used as a generator for pseudo-random numbers. The overpass the data to be encrypted in the encrypted data by logical EXOR operation on the data to be encrypted with the content of the data memory on the other hand does not take place here, the contents of the data memory as a quasi random number in a cryptographic program used.
Further features, details and advantages of the invention will be apparent from the accompanying drawing and the following description of an invention cryptographic method. In the drawings:<dl tsize="7" compact="compact"><dt>figure 1</dt><dd>a schematic representation of an embodiment of an inventive cryptographic method</dd></dl>
In the schematic diagram of Figure 1 is designated by the numeral 20 cryptographic Method shown. It consists of a source code by entering the password- 1 controlled source code pseudo-random number generator 2, which has a generated pseudorandom number sequence, which is latched in Quellkodespeicher 3 and is converted by the compiler 4 in machine code fifth The machine code 5 accesses during the execution of the data memory indicated by the reference numeral 6 by frequent read / write operations to. The data memory 6 is a by the password 11 influenced and generated in the pseudo-random number generator 10 Pseudorandom number sequence initialized. Repeated execution of the machine code 5, when executed in a central processing unit of a computer, a large number of bits in Data storage 6 reversed, permuted and data words in the data memory 6 by Division remainder calculations other data words is replaced from the data memory 6, the full contents of the data memory 6 scrambled quasi random. With the aid of EXOR function 8, the data to be encrypted 7 by linking with the Content of the data memory 6 transferred in the encrypted data. 9 The logical EXOR function 8 can both blocks, as well as in smaller data packets as bytes, words, or double words are applied to the data to be encrypted. 7
When decrypting the encrypted data, the encrypted data 9 9 are in reverse direction with the contents of the data memory 6 by the EXOR function 8 logically linked to the data store for data to be encrypted the decrypted 7 to obtain data. The source code password 1, and the password 11 have both the Encryption process and the decryption be identical. Otherwise results upon execution of the machine code 5 in a central processing unit of a computer with high Security is not the same content data in the data memory 6, and there is a faulty transfer of the encrypted data 9 on the reverse applied EXOR function 8 in the decrypted data in the data store for to be encrypted Data. 7
Due to the fact that only after recognition of the password 1 conclusions about the cryptographic algorithm can be drawn, the security of increased order encrypted data by a factor by the number of non-linear combinations cryptographic program fragments 12 which are strung together by the compiler 4, is determined. Forming in an advantageous embodiment, permutations, remainder calculations, Bit shifts and permutations of bit groups the set of possible Program fragments 12, as each of the four program fragments 12 each of the four Program fragments follow 12th The number of possible combinations is calculated accordingly potential from the supply of program fragments 12 to the number of joined Program fragments 12. For example, if n = 16 program fragments 12 from a compiled set of four possible code fragments 12 with the compiler and 4 in the converted machine code 5, a 4<sup>n</sup> = 4<sup>16</sup> = 2<sup>32</sup> = 4294967296 possibilities determined without the running time of the machine code 5 when executed in a central processing unit a computer influence. It is demanding, however, that a minimum number program fragments 12 joined to the bits in Datenspei cher 7 sufficient to scramble. In an advantageous embodiment, more than 512 fragments of a program 12 joined. There are obtained in this case 4<sup>512</sup> = 2<sup>1024</sup> = 1.7977 * 10<sup>308</sup> possible Combinations for the machine code. 5
1 sheet
Sheet 1
Every citation, both waysCites: the store holds 6 of 7
| Document | Relation | Office | Cited during |
|---|---|---|---|
| DE102009050493A1 | Cited by | Germany | Applicant |
| US5222139A | Cites | United States of America | Examiner |
| DE19735922A | Cites | Germany | – |
| US4316055A | Cites | United States of America | – |
| US5222139A | Cites | United States of America | – |
| US5425103A | Cites | United States of America | – |
| US5675652A | Cites | United States of America | – |
7 members in 3 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19932769 | Germany | A | |
| 19932769 | Germany | A | |
| 19932769 | Germany | – | |
| 19932769 | – | – | – |
| DE1999132769 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| EP1069508A2 | European Patent Office (EPO) | A2 | |
| DE19932769A1 | Germany | A1 | |
| EP1069508A3 | European Patent Office (EPO) | A3 | |
| EP1069508B1This record | European Patent Office (EPO) | B1 | |
| AT298107T | Austria | T | |
| ATE298107T1 | Austria | T1 | |
| DE50010548D1 | Germany | D1 |
60 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Fr: translation not filedEN | EN | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Gb: ep patent (uk) treated as always having been void in accordance with gb section 77(7)/1977 [no translation filed]GBV | GBV | EP | |
| Nl: lapsed or annulled due to failure to fulfill the requirements of art. 29p and 29m of the patents actLapsedNLV1 | NLV1 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Corresponds to:REF | REF | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Designation fees paidAKX | AKX | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAL;LT;LV;MK;RO;SIAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1069508
- Publication, DOCDB
- 1069508
- Publication, EPODOC
- EP1069508
- Application
- 114018
- Application, DOCDB
- 00114018
- Application, EPODOC
- EP20000114018
Titles3
- German
- Während der Laufzeit veränderbare kryptographische Methode
- English
- Cryptographic method modifiable during run time
- French
- Procédé cryptographique modifiable pendant l'exécution
Classification
- CPC, 3
- H04L9/34
- H04L2209/12
- H04L2209/34
- IPC, 3
- G06F1 00
- G06F12 14
- H04L9 18
Designated states19
- Contracting states, 19
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
