Method for computer assisted encryption and decryption of data
8 claims: 6 independent, 2 dependent
- 1Verfahren zum rechnergestützten Verschlüsseln und Entschlüsseln einer Folge (DATA) von Datenelementen (DE) aus einem ersten Wertebereich, bei dem a) zum Verschlüsseln - ein jeweiliges Datenelement (DE) mit einem Schlüsselelement (KE) durch einen ersten Rechenvorgang (RV1) verknüpft wird, sowie - aus dem resultierenden Verknüpfungsergebnis (VE) durch einen auf einen vorgegebenen, zweiten Wertebereich abbildenden, zweiten Rechenvorgang (RV2) ein verschlüsseltes Datenelement (EDE) abgeleitet wird, und b) zum Entschlüsseln - das verschlüsselte Datenelement (EDE) mit dem Schlüsselelement (KE) verknüpft wird, gekennzeichnet dadurch, dass zum Entschlüsseln nach der Verknüpfung mit dem Schlüsselelement (KE) - ein zum zweiten Rechenvorgang (RV2) inverser Rechenvorgang (IRV2) iterativ so lange ausgeführt wird, bis ein Ergebnis (IDE) eines Iterationsschrittes innerhalb des ersten Wertebereichs liegt.
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass aufeinanderfolgende Datenelemente (DE) sukzessive und elementweise mit Schlüsselelementen (KE) einer vorgegebenen Folge (KEY) von Schlüsselelementen (KE) verschlüsselt werden.
- 3Verfahren nach Anspruch 2, dadurch gekennzeichnet, dass die vorgegebene Folge (KEY) von Schlüsselelementen (KE) zur Verschlüsselung längerer Datenelementfolgen (DATA) periodisch wiederholt wird.
- 4Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der erste Wertebereich auf Datenelemente (DE) eingeschränkt ist, die druckbare Zeichen repräsentieren.
- 5Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der zweite Wertebereich auf Datenelemente (DE) eingeschränkt ist, die durch ein vorgegebenes Anwendungsprogramm ohne Sonderbehandlung verarbeitbar sind.
- 6Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der zweite Wertebereich mit dem ersten Wertebereich identisch ist.
- 7Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass in die Verknüpfungen des unverschlüsselten sowie des verschlüsselten Datenelements (DE, EDE) mit dem Schlüsselelement (KE) jeweils die Position (i) des betreffenden Datenelements (DE, EDE) innerhalb der Folge von Datenelementen (DE, EDE) und/oder die Position des Schlüsselelements (KE) innerhalb einer Folge (KEY) von Schlüsselelementen (DE) eingeht.
- 8Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass der zweite Rechenvorgang (RV2) eine Modulo-Operation umfasst.
Independent claims8
39 paragraphs, as filed
In modern communication and data processing systems win process for reliable encryption and decryption data increasingly important. Encryption takes place usually based on key data, hereinafter also referred to briefly as a key, with the aim of a decryption without knowing the key possible reliably to prevent.
A well-known and very safe method for data encryption is based on a use of key pairs each have a public and include a private key. The private and public keys are insofar correlated than that with the public Key-encrypted data solely by means of the associated be decrypted private key again can. Thus, a document encrypted by a sender be transmitted to a receiver by the transmitter the recipient's public key requests, the document encrypted with the public key requested and it shall be transmitted to the receiver. Recipient the encrypted document can then by means of his private Key, and only by this, decrypt. A public impaired transmission of the public key the security of the transmission is not, because it - a sufficient key length required - virtually impossible is, from the public key to the private key derive.
Performing an on public and private keys However based encryption process is due of its complex mathematical structure computationally intensive and requires in particular at the current standard high data transfer rates considerable computing capacity.
Furthermore, requires the calculation of private and public keys a relatively high computational effort, whereby a change or a dynamic allocation is very difficult keys.
In addition, the problem of system requirements is regarding a certain range known encrypted data elements. The published patent application DE 197 07 288 A1 (Kühnl) for example describes a method of encryption by a Encryption with a symmetric key ciphertext by a Modulo operation maps to the set of ASCII characters. takes place before the decryption in this method extracts the reverse mapping.
It is an object of the present invention to provide a less expensive A method for computer-assisted encryption and decryption specify a sequence of data elements, a flexible Key specification allows.
It is a further object of the present invention, the decryption without knowledge the key element to make it more difficult.
This object is achieved by a method with the features of claim 1.
Advantageous embodiments and developments of the invention are given in the dependent claims.
The encryption and decryption of a sequence of data elements is the process of the invention in each case by a Computing device, such as a personal computer or a Microprocessor running. Too Encrypting data element can in this case as a binary-coded characters, a Character group, a number and / or another data object be. The data to be encrypted elements include a predefinable first value range to. This may indicate a definable character selection to be limited, such as printable Characters, alphanumeric characters, pure text characters Numbers or symbols, a so-called ASCII character set (ASCII: American Standard Code for Information Interchange) or a so-called Unicode character set.
The encryption and decryption carried out by means of one or more Key elements encoded example of binary may consist characters, groups of characters or numbers. to Encryption is a respective data item to be encrypted by a first calculation process with a key element linked. The resulting combination result can lie outside of the first range of values. subsequently is from the resulting combination result by imaging at a second range of values, the second Calculation process an encrypted data item derived. The second value range can eg by a single Byte-displayable characters, printable character or characters, which during further processing or onward require by an application program to any particular treatment, to be disabled. The second calculation process can preferably comprise a so-called. modulo operation, by the ready to any integer as an ASCII character becomes.
To decrypt an encrypted data element this linked to the key member, one for second arithmetic operation of inverse calculation process iteratively as long is carried out until a result of an iteration step lies within the first value range. Since the number the to be run through iterations may vary and in particular is not previously known, a decryption without knowledge of the key element at least very difficult.
The inventive method allows a simple, fast and efficient encryption and decryption of data items. The arithmetic operations to be performed can generally by few processor operations in logical form or arithmetic register links are implemented. The Method of the invention is thus particularly suitable for a hardware implementation. In addition, no costly Calculation of the key elements required so that a flexible key specification or key changes are possible. Moreover, the inventive method can very easily to system specifications regarding a range of values the data to be encrypted elements and terms a range of values of the encrypted data elements be adjusted. This adjustment is to some extent part of the Encryption method itself inventive. Thus, eg the second range of values by a corresponding configuration the second calculation process in a simple manner on those characters are limited, it travels over the Text of an e-mail is allowed. An additional recoding the e-mail, for example according to the so-called base-64 code can thus be omitted.
According to a particularly simple embodiment, successive Data elements successively and element-wise with key elements of a predetermined sequence of key elements are encrypted. Such a sequence of Key elements will hereinafter as "key" "Keyword" or "ciphertext" means.
Further, the predetermined sequence of key elements for encryption of longer data element sequences periodically be repeated. This allows a very simple manner, depending on the required security keys with different Key length used. For example, a 128-bit encryption achieved with a 27-character key text will. A key change or a dynamic Allocation of keys is possible without additional effort.
According to a further advantageous embodiment of the invention can in the links of the unencrypted and the encrypted data element with the key element in each case the position of the relevant data element within the sequence of data elements and / or the position of the Key element in a series of key elements received. The inclusion of such a position parameter complicates unauthorized decryption addition.
An embodiment of the invention is described below with reference to the drawing explained.
In each show in a schematic representation:<sl><li>1 shows a communication system with two personal computers the encrypted transmission of data,</li><li>Figure 2 is a flow chart showing the process sequence when encrypting data and</li><li>Figure 3 is a flow chart showing the process sequence in decrypting data.</li></sl>
In <b>figure 1</b> is a communication system with two one over NET network coupled personal computers PC1 and PC2 schematically shown. The personal computer PC1 has a Central processor P1 and the personal computer PC2 a central processor P2.
In the present embodiment, an unencrypted encrypt string DATA from the personal computer PC1, in encrypted form over the network NET to the personal computer PC2 to transfer and decode of this again. The string to be encrypted is DATA Here, a sequence of ASCII characters as data elements, where the term ASCII characters by a 1-byte ASCII value encoded characters to be understood.
The characters in the string DATA are on a first range with lower limit L1 and limit U1 limited. In the present embodiment, the String DATA from so-called printable ASCII characters with an ASCII value between 32 and 126. The lower limit L1 of the first range of values thus has the ASCII value 32 and its upper limit U1 the ASCII value 126. Alternatively, any other, even several disjointed intervals comprising Direction drawing area be specified as the first value range. Thus, for example also, if necessary, educated drawing area for 2-byte Unicode characters be specified as the first value range.
The string to be encrypted DATA is the central processor P1 of the personal computer PC1 based on a key KEY encrypted. The same key KEY is both in the personal computer PC1 and PC2 in the personal computer stored and is both for encrypting and decrypting used. There is thus a so-called symmetric Encryption method.
The key KEY is in the present embodiment a sequence of printable ASCII characters as the key elements. It should be noted, however, that this restriction is not absolutely necessary, but only a more comfortable Enter a key text on commercial keyboards allows. In fact, any of the central processor P1 processable characters or numbers as key elements usable.
The unencrypted text string DATA is the central processor P1 by key KEY in an encrypted String EDATA implemented via the network NET is transmitted to the personal computer PC2 to there by the Central processor P2 by key stored there KEY to be decrypted. The characters in the encrypted string EDATA are on a second Value range with lower limit L2 and U2 ceiling limited. In the present embodiment, the encrypted string EDATA of ASCII characters, which do not have control function, and thus no special treatment over the network NET, for example, in the text of an e-mail can be transferred. These ASCII characters have an ASCII value 32-255 on. The lower limit of L2 second value range thus has the ASCII value 32 and its upper limit U2 ASCII value 255th
Naturally, the method can except for encrypted Transferring data and the encrypted Storing data to be used on a mass storage device. For example, passwords can by the invention Procedures are encrypted before they are protected such are stored in a password file.
<b>figure 2</b> shows a flow diagram of the personal computer by PC1 process executed to encrypt the String DATA using the key KEY. At the beginning of Encryption is a control variable i, the position of the a date to be encrypted character within the string DATA indicating set to the value 1. This is a loop initialized in about the individual characters the string DATA is iterated. Within the Loop is first the next not yet processed Data element, ie the ith character DE = DATA [i] of the string DATA and the next to be processed key element KE = KEY [i mod key length] key KEY read. The sign DE is this - as all signs the string DATA - within the first range of values, ie it is L1 ≦ EN ≦ U1. Through the brackets is - as common in many programming languages - indexing a data field shown. 'Mod' denotes the mathematical Modulo function. By the modulo-formation with the Key length in the index for the key KEY is ensured that the index of KEY also at larger values of Control variable i does not exceed the key length. real this corresponds to a periodic repetition of the Key over the entire length of the string DATA.
The sign DE is the key elements KE and the Control variable i by a first calculation process RV1 of the central processor P1 to a combination result VE according to the Calculation rule VE = DE + i * KE linked. The calculation is performed Registered with the ASCII numerical values of the character and DE the key element KE. The current result is VE particularly due to the multiplication by the control variable i generally no longer within the first range of values or displayable by 1 byte value range lie. Thus, the combination result VE is preferably to represent by a more comprehensive bytes integer.
After the first calculation process RV1 the RLO is VE by a second to be carried out by the central processor P1 Computing operation RV2 on the second range of values (Between L2 = 32 and U2 = 255) imaged. As a result of second computing operation RV2 arises an encrypted Sign EDE according to the calculation rule EDE = L2 + VE mod (U2-L2 + 1). Obviously, the encrypted character EDE is in second range of values and it is L2 ≦ EDE ≦ U2. Due to the Modulo function forms the second computing operation RV2 all possible Values for the combination result VE, ie its entire Domain from the second range of values. The second value range again allows a 1-byte representation.
If the second value range no coherent interval forms, ie if m special characters within the interval do not belong to the second range of values, the calculation process can RV2 be replaced by the arithmetic rule EDE = L2 + VE mod (U2-L2 + 1-m) with a figure below of m characters from the interval [L2, U2-m] on the Interval [U2-m + 1, U2]. Such special characters, for example, his apostrophes or comment characters without Figure on the second range of values misinterpretations could trigger during subsequent processing.
After calculation of the encrypted character EDE is this as i-th character in the encrypted string EDATA inserted: EDATA [i] = EDE. Then, the control variable i incremented and then checked whether i is greater than the Length of string DATA is. If it does not, branches back to the beginning of the loop to the next data item read and the next key element. Otherwise is the encryption of string DATA in the encrypted string EDATA completed.
<b>figure 3</b> shows a flowchart of the procedure in based decrypting the encrypted string EDATA key KEY. At the start of decryption is the Control variable i, the one known to be decrypted, the position indicates the character within the string EDATA, initialized with a starting value. 1 Then begins a Loop in the encrypted string EDATA one character is run. Within the loop, first the next to be decrypted data element, ie, ith character EDE = EDATA [i] of the encrypted string EDATA, and the next to be processed key element KE = KEY [i mod key length] read. to encrypt the Sign EDE is on the second range of values and it is L2 ≦ EDE ≦ U2. By Modulo education with the key length the index to the key KEY ensures that the index value does not exceed the key length. real this corresponds to a periodic repetition of the Key over the entire length of the encrypted string EDATA.
After reading of a data element and EDE key element KE is a variable k as control variable for a subsequent iteration initialized to 0. furthermore is the character to be decrypted with the key element EDE KE to an interim result TMP linked according TMP = EDE - i * KE. The interim result TMP is particularly due to the multiplication by the control variable i, in Generally, neither in the first nor in the second range of values and Therefore an existing multi-byte integer represent.
Then, for further decoding of the sign EDE an iterative loop with the running variables k as iteration run through. Inside the iteration loop a second computing operation RV2 inverse calculation process IRV2 performed as iteration. The calculation process IRV2 be the interim result TMP and the iteration linked to a k Iterationsschrittergebnis IDE according IDE = TMP - L2 + k * (U2-L2 + 1). IDE is as TMP presented as a multi-byte integer comprehensive.
If the second value range no coherent interval forms and when encrypting a mapping of special characters m was made on the end of the interval, can before these special characters in EDE from the interval [U2-m + 1, U2] Calculation of the interim result TMP again in the interval [L2, U2-m] are ready to return. In this case, the arithmetic operation by the arithmetic rule IRV2 IDE = TMP - L2 + k * (U2-L2 + 1-m) to replace.
After completion of the calculation IRV2 the iteration is k increments. It is then checked whether the respective result of the IDE iteration within the first range of values; ie it is checked whether L1 ≦ IDE is ≦ U1. As long as it is not, is the beginning the iteration loop jumps back to the calculation process IRV2 rerun. In contrast, if it is determined that the result of that IDE iteration within the first range of values, the iteration is finished.
As can easily be shown, is the first Iterationsschrittergebnis IDE, which within the first range of values is exactly the original unencrypted character.
To prove this, first the from the computations and RV1 RV2 resulting total expression of the encoded characters EDE = L2 + (EN + i * KE) mod (U2-L2 + 1) is considered. Becomes this expression in the resulting expression for the Iterationszwischenergebnis IDE used arises after shortening L2: IDE = (DE + i * KE) mod (U2-L2 + 1) - i * KE + k * (U2-L2 + 1). After the general mathematical definition of the modulo operation (A mod n) exist for all integer a, n each is always an integer j with the property: a mod n = a - j * n. This yields: IDE = (DE + i * KE) - j * (U2-L2 + 1) - I * KE + k * (U2-L2 + 1). By choosing k = j (in the Iteration k all integer values through) yields finally to be shortened for i * KE: IDE = DE; ie the Iteration result IDE matches the unencrypted Mark EN agreement. contains After completion of the iteration So the IDE variable exactly decrypted mark the original string DATA.
As already mentioned above, the respective number of iterations not constant until completing the termination criterion but variable. In particular, the number of iterations without knowing the key can not be derived, whereby a unauthorized decryption much more difficult.
After completion of the iterative loop is the finally Result IDE of the last iteration of the i-th character the character string allocated in accordance DATA DATA [i] = IDE. subsequently the control variable i is incremented and the Length of string EDATA compared. As long as the control variable i still less than or equal to the length of the string EDATA is, jumps back to the beginning of the loop to the next encrypted data item and the next key element read. Otherwise, the decryption the string EDATA in the decrypted string DATA completed.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| WO0174005A | Cites | World Intellectual Property Organization (WIPO) |
| DE19630354A | Cites | Germany |
| DE19707288A | Cites | Germany |
| US5929792A | Cites | United States of America |
7 members in 3 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 10162991 | Germany | A | |
| 10162991 | Germany | – | |
| 10162991 | – | – | – |
| DE2001162991 | – | – | – |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| EP1322062A2 | European Patent Office (EPO) | A2 | |
| DE10162991A1 | Germany | A1 | |
| US2003138099A1 | United States of America | A1 | |
| EP1322062A3 | European Patent Office (EPO) | A3 | |
| EP1322062B1This record | European Patent Office (EPO) | B1 | |
| DE50201616D1 | Germany | D1 | |
| US7505586B2 | United States of America | B2 |
33 legal events, as 5 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Fr: translation filedET | ET | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Gb: translation of ep patent filed (gb section 77(6)(a)/1977)GBT | GBT | EP | |
| European patents granted designating irelandGrantedGERMANFG4D | FG4D | IE | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Designation fees paidAKX | AKX | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1322062
- Publication, DOCDB
- 1322062
- Publication, EPODOC
- EP1322062
- Application
- 2027978
- Application, DOCDB
- 02027978
- Application, EPODOC
- EP20020027978
Titles3
- German
- Verfahren zum rechnergestützten Ver- und Entschlüsseln von Daten
- English
- Method for computer assisted encryption and decryption of data
- French
- Procédé de chiffrage et de déchiffrage de données assisté par ordinateur
Classification
- CPC, 2
- H04L9/08
- H04L9/16
- IPC, 1
- H04L9 00
Designated states1
- Contracting states, 1
- Italy
