EP1307993A2

Linear transformation for symmetric-key ciphers

Abstract

A method of generating a linear transformation matrix A for use in a symmetric-key cipher includes generating a binary [n,k,d] error-correcting code, where k<n<2k, and d is the minimum distance of the binary error-correcting code. The code is represented by a generator matrix GepsilonZ<SUB>2</SUB><SUP>kxn </SUP>in a standard form G=(I<SUB>k</SUB>∥B), with BepsilonZ<SUB>2</SUB><SUP>kx(n-k)</SUP>. The matrix B is extended with 2k-n columns such that a resulting matrix C is non-singular. The linear transformation matrix A is derived from matrix C. Preferably, the error correcting code is based on an XBCH code.

Term

Term ended

Projected expiry passed 20 July 2021, 5.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

8 claims: 3 independent, 5 dependent

  1. 1
    Claims of equivalent WO 0213452 A2 CLAIMS:1. A method of generating a linear transformation matrix A for use in a symmetric-key cipher, the method including: generating a binary [n,k,d] error-correcting code, represented by a generator matrix G e Z2kxn in a standard form G = (Ik || B), with B e Z2kx(n"k), where k < n <
  2. 2
    2k, and d is the minimum distance of the binary error-correcting code; extending matrix B with 2k-n columns such that a resulting matrix C is non- singular, and deriving matrix A from matrix C. 2. A method as claimed in claim 1, wherein the step of extending matrix B with 2k-n columns includes:in an iterative manner: (pseudo-)randomly generating 2k-n columns, each with k binary elements;forming a test matrix consisting of the n-k columns of B and the 2k-n generated columns;and checking whether the test matrix is non-singular, until a non-singular test matrix has been found;and using the found test matrix as matrix C.
  3. 8
    A system for cryptographically converting an input data block into an output data block; the data blocks comprising n data bits; the system including:an input for receiving the input data block;a storage for storing a linear transformation matrix A, generated according to the method of claim 1, a cryptographic processor performing a linear transformation on the input data block or a derivative of the input data block using the linear transformation matrix A;and an output for outputting the processed input data block..