Secure encryption method and component using same
17 claims: 4 independent, 13 dependent
- 1Procédé de calcul cryptographique sécurisé comprenant N rondes de calcul réalisées successivement pour obtenir une donnée de sortie à partir d'une donnée d'entrée et d'une clé secrète, procédé au cours duquel :- on réalise un premier niveau de masquage, pour masquer la donnée d'entrée, de sorte que chaque donnée intermédiaire utilisée ou produite par une ronde de calcul soit masquée, caractérisé en ce que - on réalise un deuxième niveau de masquage, pour masquer des données manipulées à l'intérieur de chaque ronde de calcul, en réalisant successivement les étapes suivantes : - une deuxième étape (ET3) de masquage d'un résultat d'une étape précédente (ET2) de la ronde de calcul de rang i, - une étape (ET6) de substitution du résultat masqué obtenu par la deuxième étape (ET3) à l'aide d'un opérateur non linéaire masqué (SBOX'), - une deuxième étape (ET9) de démasquage du résultat de l'étape (ET6) de substitution. les résultats intermédiaires à l'intérieur de chaque ronde de calcul étant tous masqués.
- 2Procédé selon la revendication 1, caractérisé en ce qu' il comprend :- une première étape de masquage (ET01) de la donnée d'entrée (ME), réalisée avant une première ronde de calcul, et - une première étape de démasquage (ET10) du résultat de la N ème ronde de calcul pour produire la donnée de sortie, les étapes (ET01) et (ET10) réalisant le premier niveau de masquage.
- 3Procédé selon la revendication 2, caractérisé en ce que :- lors de la première étape de masquage (ET01), un premier paramètre de masquage (X 1 ) est mélangé à la donnée d'entrée (ME), pour fournir une donnée d'entrée masquée (ME';L' 0 , R' 0 ) à la première ronde de calcul, le mélange étant réalisé par l'utilisation d'un premier opérateur de mélange ("&") linéaire, - lors de la première étape de démasquage (ET10), la contribution apportée par le premier paramètre de masquage (X 1 ) au résultat de la N ème ronde de calcul est soustraite du résultat'de la N ème ronde de calcul.
- 4Procédé selon l'une des revendications 2 à 3, caractérisé en ce qu' il comprend également :- une troisième étape de masquage (ET03), réalisée avant la première ronde de calcul, pour fournir l'opérateur non linéaire masqué (SBOX') vérifiant la relation suivante, pour toute donnée A : SBOXʹ A@ X 3 = SBOX A # X 2 , où X 2 est un deuxième paramètre de masquage, X 3 est un troisième paramètre de masquage, SBOX est un opérateur non linéaire connu, " # " est un deuxième opérateur de mélange, et "@ " est un troisième opérateur de mélange.
- 5Procédé selon la revendication 4, caractérisé en ce que , au cours de l'étape (ET9) de démasquage de la ronde de calcul de rang i, on enlève la contribution apportée par le deuxième paramètre de masquage (X 2 ) au résultat produit par l'opérateur non linéaire masqué (SBOX').
- 6Procédé selon l'une des revendications 2 à 5, caractérisé en ce que la ronde de calcul de rang i comprend les étapes suivantes, exécutées dans l'ordre :- une étape (ET2) d'expansion d'une partie droite (R' i-1 ) d'une donnée intermédiaire masquée calculée par une précédente ronde de calcul, - la deuxième étape de masquage (ET3), au cours de laquelle on masque le résultat de l'étape (ET2) précédente par le troisième paramètre de masquage (X 3 ) en utilisant le troisième opérateur de masquage ("@"), - une étape (ET4) au cours de laquelle on supprime la contribution apportée par le premier paramètre de masquage au résultat de l'étape (ET3) précédente, - une étape (ET5) de mélange du résultat de l'étape précédente ET4 avec une clé dérivée actualisée (M i ), - l'étape (ET6) de substitution du résultat de l'étape (ET5) précédente par l'opérateur non linéaire masqué (SBOX), et fourniture d'un résultat masqué par le deuxième paramètre de masquage (X 2 ), - une étape (ET7) de permutation du résultat de l'étape ET6 précédente, - une étape (ET8) d'addition, par l'intermédiaire d'un OU-Exclusif, d'une partie gauche (L' i-1 ) de la donnée intermédiaire précédemment calculée au résultat de l'étape précédente, - la deuxième étape (ET9) au cours de laquelle on supprime la contribution apportée par le deuxième paramètre de masquage au résultat de l'étape précédente, pour fournir une partie droite (R' i ) de la donnée intermédiaire (L' i , R' i ) actualisée dont une partie gauche (L' i ) est égale à la partie droite (R' i-1 ) de la donnée intermédiaire (L' i-1 , R' i-1 ) précédemment calculée.
- 7Procédé selon l'une des revendications 2 à 6, caractérisé en ce que au moins l'un des paramètres (X 1 , X 2 , X 3 ) de masquage est choisi aléatoirement à chaque mise en oeuvre du procédé.
- 8Procédé selon l'une des revendications 2 à 6, caractérisé en ce que au moins l'un des paramètres de masquage (X 1 , X 2 , X 3 ) est choisi aléatoirement toutes les M mises en oeuvres du procédé.
- 9Procédé selon l'une des revendications 2 à 8, caractérisé en ce que le premier opérateur de mélange ("&") et/ou le deuxième opérateur de mélange ("#") et/ou le troisième opérateur de mélange ("@") est (sont) un (des) opérateur(s) de type OU-Exclusif.
- 10Procédé selon l'une des revendications 2 à 9, comprenant une étape de calcul de clé dérivée (ET1), pour fournir une clé dérivée actualisée à partir de la clé secrète (K 0 ) selon une loi de calcul de clé connue, le procédé étant caractérisé en ce qu' il comprend également une quatrième étape de masquage (ET06), effectuée avant l'étape de calcul de clé dérivée (ET1), pour masquer la clé secrète (K 0 ) par un paramètre de mélange (Y 0 ), de sorte que la clé dérivée actualisée (M' 1 , M' i ) soit différente à chaque mise en oeuvre du procédé.
- 11Procédé selon la revendication 10, caractérisé en ce qu' il comprend N étapes de calcul de clé dérivée (ET1) exécutées successivement, l'étape de calcul de clé dérivée de rang i fournissant une clé dérivée actualisée masquée (M' i ) à la ronde de calcul (ronde i) de même rang i et une clé secrète masquée actualisée (K' i ) à partir d'une clé (K' i-1 ) secrète masquée précédemment calculée, et en ce que la ronde de calcul de rang i comprend notamment les étapes (ET5) et (ET12) suivantes, réalisées entre l'étape (ET3) et l'étape (ET6) :(ET5) : mélange d'un résultat de l'étape précédente avec la clé dérivée actualisée masquée (M' i ) de rang i, (ET12) : suppression de la contribution (C i ) apportée par le paramètre de mélange (Y 0 ) au résultat de l'étape (ET5).
- 12Procédé selon la revendication 11, caractérisé en ce que la quatrième étape de masquage (ET06) est réalisée avant la première étape de calcul de clé dérivée.
- 13Procédé selon la revendication 11, caractérisé en ce que la quatrième étape de masquage (ET06) est réalisée'avant chaque étape de calcul de clé (ET1).
- 14Procédé selon l'une des revendications 10 à 13, caractérisé en ce que , lors de la quatrième étape de masquage (ET06), le paramètre de mélange (Y 0 ) choisi aléatoirement est mélangé à la clé secrète (K 0 ) par l'intermédiaire d'un quatrième opérateur de masquage (" | "), pour fournir une clé secrète masquée (K' 0 ), la clé dérivée (M' 1 , M' i ) masquée étant calculée à partir de la clé secrète masquée (K' 0 ).
- 15Procédé selon la revendication 14, caractérisé en ce que , au cours de la quatrième étape de masquage (ET06), l'opération suivante est réalisée :Kʹ 0 = K 0 | Y 0 , K' 0 étant la clé secrète masquée, K 0 étant la clé secrète Y 0 étant le quatrième paramètre de masquage, et " | " étant le quatrième opérateur de mélange.
- 16Procédé selon l'une des revendications 14 à 15, caractérisé en ce que le quatrième opérateur de mélange (" |") est un opérateur OU-Exclusif.
- 17Composant électronique, caractérisé en ce qu' il comprend des moyens adaptés pour mettre en oeuvre le procédé de calcul cryptographique selon l'une des revendications 1 à 16.
Independent claims17
127 paragraphs, as filed
0001The present invention relates to a secure method of cryptographic calculation with a secret or private key. The present invention also relates to a component implementing such a secure method. More particularly, the invention aims to protect such components against a physical attack aimed at obtaining information on the secret or private key from the energy consumption or from the electromagnetic radiation of the component when it implements the encryption process.
0002The components concerned by the invention are used in particular for applications where access to services and / or data is severely controlled. These components most often have an architecture formed around a microprocessor and a program memory comprising in particular the secret key.
0003Such components are for example used in smart cards, in particular for banking type applications, via a command terminal or remotely.
0004Such components use one or more secret or private key encryption methods to calculate an output data item from an input data item. Such a method is for example used to encrypt, decrypt, sign an input message or else verify the signature of said input message.
0005To ensure the security of the transactions, the secret or private key encryption methods are constructed so that it is not possible to determine the secret key used from knowledge of the input data and / or of the data output from the algorithm. However, the security of a component rests on its ability to keep the secret key it uses hidden.
0006A frequently used process is the DES type process (for <i>Data Encryption Standard</i>). It allows for example to provide an encrypted message MS (or output data) coded on 64 bits, from a clear message ME (or input data) also coded on 64 bits and a secret key K<sub>0</sub> 56 bits.
0007The main stages of the DES process are detailed on the <figref idref="f0001">figure 1</figref>. After an initial IP permutation, the block formed by the bits of the permuted input data, is separated into a left part L<sub>0</sub> and a straight part R<sub>0</sub>.
0008After that, 16 rounds of identical operations are performed. During each round of operations, the right part (R<sub>0</sub>, ..., R<sub>15</sub>) of an intermediate data calculated during the previous round of operations is mixed with a derived key (M<sub>1</sub>, ..., M<sub>16</sub>) of the secret key. The mixing is done during a transformation called transformation F. The result of the transformation F is then added (by an OR-Exclusive operator) to the left part (L<sub>0</sub>, ..., L<sub>15</sub>) of the intermediate data calculated during the previous round of operations.
0009After the 16<sup>th</sup> round of operations, left parts L<sub>16</sub> and right R<sub>16</sub> from the 16<sup>th</sup> intermediate data are assembled and a final IP permutation<sup>-1</sup>, inverse of the initial IP permutation, ends the process.
0010A round of rank i operations between 1 and 16 is detailed on the <figref idref="f0001">figure 2</figref>. During an AND key calculation step, the 56 bits of an intermediate key K<sub>i-1</sub> calculated during the previous round are shifted (operation S<sub>i</sub>) to provide a new updated intermediate key K<sub>i</sub>, then 48 bits out of 56 are selected by a PC permutation / compression operation to provide a derived key M<sub>i</sub> : M<sub>i</sub> = PC (K<sub>i</sub>) = PC (S<sub>i</sub> (K<sub>i-1</sub>)).
0011In parallel, the transformation F is carried out. The right part R<sub>i-1</sub> of an intermediate data calculated during the previous round, is extended to 48 bits by an expansion (operator E), combined with the derived key M<sub>i</sub> by an OR-Exclusive type operation, replaced by 32 new bits by a non-linear substitution operation (represented by the SBOX operator) then permuted once more (simple permutation P).
0012The result of the transformation F is then combined by an OU-Exclusive on the left part L<sub>i-1</sub> of the intermediate data (L<sub>i-1</sub>, R<sub>i-1</sub>) calculated in the previous round. The combination provides the right part R<sub>i</sub> an updated intermediate data. The left part L<sub>i</sub> of the updated intermediate data is equal to R<sub>i-1</sub>.
0013The operators F, P, E, PC, SBOX are identical for all the rounds. On the other hand, operators S<sub>1</sub> at S<sub>16</sub> used when calculating K derived keys<sub>1</sub> at K<sub>16</sub> may be different from round to round.
0014All the characteristics of the operators IP, IP<sup>-1</sup>, P, PC, E, SBOX, S<sub>i</sub> used during the implementation of a DES process are known: calculations performed, parameters used, etc. These characteristics are for example described in detail in the application for<patcit id="pcit0001" dnum="WO0046953A"><text>WO 00/46953</text></patcit> or in the "Data Encryption Standard, FIPS PUB 46" published on January 15, 1977.
0015The security of a component using a secret or private key encryption method lies in its ability to keep the key it uses secret.
0016To be sure, a component must in particular be able to keep hidden the secret key which it uses when it undergoes a DPA type analysis (for <i>Differential Power Analysis</i>).
0017A DPA analysis consists in making a statistical analysis of the consumption of the component, that is to say of the trace left by the component as a function of time. For this, a sample of around 1000 trace measurements is used, each trace corresponding to ME input data [i = 1 to 1000] which are different and independent of each other. The statistical study makes it possible to validate one or more hypotheses made on the value of the bits of the secret key used.
0018A concrete example of implementing a DPA analysis on a component using a DES-type encryption method is detailed in the <patcit id="pcit0002" dnum="WO0046953A"><text>publication WO 00/46953</text></patcit>, especially on pages 3, 4 of this publication.
0019The DES type encryption process is particularly sensitive to DPA type attacks at the exit of SBOX operators. More generally, an encryption process is sensitive to a DPA type analysis at any point where the secret key appears in combination either with the input data or with the output data.
0020Thus, in practice, a DES type process is sensitive at the output of all operators (Exclusive-OU, P, E, PC, SBOX, etc.) from all rounds of operations because the secret key is mixed with the input from the first round of operations.
0021For example, by knowing the input data ME, and by making hypotheses on the secret key K<sub>0</sub>, we can predict the value of at least one bit of the intermediate data (L<sub>1</sub>, R<sub>1</sub>) provided at the end of the first round of operations. If the prediction is verified, then the hypothesis made on the secret key is verified.
0022To be sure, a component must also be able to keep the secret key it uses hidden when it undergoes a SPA type analysis (for <i>Simple Power Analysis</i>).
0023A SPA analysis consists in having the component execute the encryption process it uses several times by applying the same input data ME to it, and in measuring, for each execution of the process, the trace left by this execution according to the time. The trace represents for example the energy consumption of the component or the electromagnetic energy radiated as a function of time. The set of measurements is then averaged to filter the noise of the measurement and obtain the actual trace of the circuit for a fixed input data ME. As an indication, a set of 10 to 100 identical measurements may be sufficient to filter the noise of the measurement and obtain the actual trace of the component for a fixed input data item ME.
0024After filtering, the different stages of the DES process are clearly distinguished on the actual trace of the component: initial permutation IP, 16 rounds of operations, then final permutation IP<sup>-1</sup>.
0025A DES type process is sensitive to SPA type analyzes, in particular at the points where the secret key appears, in its initial form K<sub>0</sub> or in another form (intermediate keys K<sub>1</sub>, ..., K<sub>16</sub>, derived keys M<sub>1</sub>, ..., M<sub>16</sub>). Indeed, by a SPA type analysis, it is possible, for each round i of operations, to determine an image of the derived key M<sub>i</sub>. For example, it is possible to identify the time interval during which the transfer of the derived key M<sub>i</sub> is performed before the execution of the Exclusive OR operation. All M derived keys<sub>1</sub> at M<sub>16</sub> being obtained from the secret key K<sub>0</sub> by known operations, the knowledge of simple images of the derived keys gives information on the secret key K<sub>0</sub>.
0026In general, all encryption methods are more or less sensitive to DPA type attacks, especially in places where a predictable intermediate result appears, which is a combination of the input data (or a data derived from the input data) and the secret or private key (or a key obtained from the secret or private key) or else which is a combination of the output data (or a data derived from the input data) and the secret key (or a key obtained from the secret key) Such an intermediate result is indeed predictable, from the input data and / or the output data and from assumptions about the key used, because the encryption methods used are known (operators used, order of use of these operators, etc.) . A DPA attack then makes it possible to obtain information on the key used, by validating the assumptions made.
0027In practice, all the processes are sensitive at the output of all the operators of all their stages (or sub-stages) using the input data (or a data derived from the input data), as soon as the input data was mixed with the secret key for the first time. In the same way, all the methods are equally sensitive at the output of all the operators providing a result dependent on the output data and on the secret or private key, and this, as soon as the input data has been mixed for the first time. secret or private key.
0028The document <patcit id="pcit0003" dnum="WO0041356A"><text>WO 00/41356</text></patcit> describes a countermeasure method against such an attack comprising a single level of masking of the input data.
0029Also, all encryption methods using secret or private keys are more or less sensitive to SPA type analyzes. Their sensitivity is particularly important in places where the key appears alone, in its initial form or in its derived form. In practice, all the methods are sensitive at the end of a so-called critical step, during which the secret key is used either directly or in a derived form obtained by a known derivative key calculation law. Such a critical step is, for example, a step of calculating an intermediate or derived key, from the secret or private key or else from a previously calculated intermediate key.
0030An object of the invention is to implement a secure method of cryptographic calculation with a secret or private key which is immune to any physical attack of the DPA type, that is to say a secure method of cryptographic calculation, the trace of which, during the implementation of the method, does not give any information on the key that it uses, regardless of the input data used by the method, regardless of the number of uses of the method, and even if a statistical study of the trace is carried out.
0031Another object of the invention is to implement a secure method of cryptographic calculation with a secret or private key which is also protected against any SPA type attack.
0032With these objectives in view, the invention relates to a method of cryptographic calculation comprising N rounds of calculation carried out successively to obtain an output data item from an input data item and a secret key.
0033According to the invention, during the process:<ul id="ul0001" list-style="dash" compact="compact"><li>a first masking level is produced, to mask the input data, so that each intermediate data used or produced by a round of calculation is masked, and</li><li>a second level of masking is carried out, to mask the data manipulated within each round of calculation.</li></ul>
0034The invention also relates to an electronic component comprising means suitable for implementing a method such as that described above, and detailed below.
0035The word "masked" (or "mixed") should be understood here, and in everything that follows, in the following sense. In a method according to the invention, a datum, a result, an operand are said to be masked if they have a different value during two executions of the method, in particular during two executions of the method using the same input data and the same secret or private key.
0036Thus, with the invention, data produced by a round of calculation is masked because the input data is masked (first level of masking) before the round of calculation. Data produced by a round of calculation is therefore different at each execution of the method, even if the input data and the secret key used are identical.
0037Furthermore, the second level of masking used in a method according to the invention makes it possible to mask any data manipulated within a round of calculation.
0038The two masking levels used in the invention therefore make it possible to mask any data manipulated during the execution of the method, outside and inside the calculation rounds.
0039A statistical study of the consumption of the component (or of its electromagnetic radiation) using a method according to the invention is therefore doomed to failure: it does not make it possible to obtain information on the secret key used since the consumption of the component is decorrelated from the value of the key used.
0040To carry out the first level of masking, it is preferably carried out:<ul id="ul0002" list-style="dash" compact="compact"><li>a first step of masking ET01 of the input data, carried out before a first round of calculation,</li><li>a first step of unmasking ET10 of the result of an Nth round of calculation, to produce the output data.</li></ul>
0041To carry out the second level of masking, it is preferably carried out, in a round of calculation of rank i of the process:<ul id="ul0003" list-style="dash" compact="compact"><li>a second step of masking ET3 of a result of a previous step of the round of calculation of rank i,</li><li>a step ET6 of substitution of the masked result obtained by the second step (ET3), using a masked non-linear operator SBOX ',</li><li>a second step ET9 of unmasking the result of step ET6.</li></ul>
0042During the first masking step ET01, a first masking parameter is mixed with the input data ME, to supply a masked input data to the first round of calculation, the mixing being carried out by the use of a first operator of linear mixing.
0043For maximum security of the process, the first masking parameter is preferably chosen randomly at each implementation of the process during the masking step. The first masking parameter can also be chosen randomly only all the M implementations of the method. In this case, the same masking parameter is used for the following M implementations.
0044The first masking step thus makes it possible, by mixing the input data with a random parameter, to remove any correlation between the input data ME and an intermediate data obtained from the input data ME, and used or produced by a round of calculation.
0045During the first unmasking step, at the end of the process, the contribution made by the first masking parameter to the result of the N<sup>th</sup> round of calculation is subtracted from the result of the N<sup>th</sup> calculation round. The unmasking step thus makes it possible to find, at the end of the process, the expected output data. In particular, if the method is executed twice with the same input data and the same secret key, then the output data MS obtained is the same in both cases. However, the intermediate data are different.
0046For the implementation of the second masking level, the method also preferably comprises a third masking step ET03, carried out before the first calculation round, to provide the non-linear operator SBOX '. SBOX 'checks the following relation, for all data A:<maths id="math0001"><math display="block"><mi mathvariant="normal">SBOXʹ</mi><mfenced><mi>AT@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo mathvariant="normal">=</mo><mi>SBOX</mi><mfenced><mi mathvariant="normal">AT</mi></mfenced><mo></mo><mi mathvariant="normal">#</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub><mo mathvariant="normal">,</mo></math><img file="EP1358732B2_D0001.tif" /></maths> or X<sub>2</sub> is a second masking parameter and X<sub>3</sub> is a third masking parameter, SBOX is a known nonlinear operator, "#" Is a second mixing operator and @ is a third mixing operator.
0047Preferably, at least one of the three masking parameters used is chosen randomly at each implementation of the method, to obtain maximum security.
0048According to a variant, one of the masking parameters can be chosen randomly all the M implementations of the method.
0049More preferably, the mixing operators are linear operators. In an example, we can choose the OR - Exclusive operator for one of the mixing operators.
0050If the method according to the invention comprises a step of calculating a derived key, to supply a key derived from the secret key according to a known key calculation law, then the method is advantageously supplemented by the addition of a fourth masking step, performed before the derivative key calculation step, to mask the secret key so that the calculated derived key is different each time the method is implemented.
0051Thus, the derived key (s) and / or the calculated intermediate key (s) are all masked, by adding a random parameter, so that a consumption analysis of the component, of the SPA type for example, cannot provide any indication of the secret key used.
0052According to an embodiment, during the fourth masking step, a randomly chosen mixing parameter is mixed with the secret key by means of a fourth masking operator, to provide a secret masked key, the key hidden derivative being calculated from the hidden secret key.
0053The invention will be better understood and other characteristics and advantages will appear on reading the following description of an example of implementation of a protected cryptographic calculation method according to the invention. The description should be read with reference to the accompanying drawings in which:<ul id="ul0004" list-style="dash" compact="compact"><li>the <figref idref="f0001">figure 1</figref>, already described, is a diagram of a known DES type encryption method using a secret key,</li><li>the <figref idref="f0001">figure 2</figref>, already described, is a diagram detailing a step in the process of <figref idref="f0001">figure 1</figref>,</li><li>the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref> are a flow diagram of the <figref idref="f0001">figure 1</figref>, secure according to the invention,</li><li>the <figref idref="f0004">figure 4</figref> is a diagram of an improvement in the process of <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>.</li></ul>
0054The <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref> show how the DES process <figref idref="f0001">figures 1, 2</figref> is secure according to the invention.
0055For the sake of clarity and simplification, only the 1<sup>time</sup> and the i<sup>th</sup> rounds of operations, were represented on the <figref idref="f0004">Figures 4a, 4b</figref>, with the characteristic steps of the present invention, i being an integer between 1 and 16.
0056As seen above, a DES method calculates an output data item MS from a secret key K<sub>0</sub> and an input data item ME; The DES process includes 16 rounds of calculation, preceded by an IP input permutation (<figref idref="f0002">figure 3a</figref>) and followed by an IP output swap<sup>-1</sup> (<figref idref="f0003">figure 3b</figref>), inverse of the input permutation. Each round of operations includes (<figref idref="f0001">figure 2</figref>) a step of calculating derived key ET1, a step F 'of transformation and a step of combination by an Exclusive-OR ET8.
0057The DES process is secured according to the invention by the addition of two masking levels. The first masking level is carried out by a masking step ET01 (<figref idref="f0002">figure 3a</figref>) and an ET10 unmasking step (<figref idref="f0003">figure 3b</figref>). The second masking level is carried out, at each round of calculation, by an ET3 masking step, an ET6 substitution step by a masked non-linear operator SBOX 'and an ET9 unmasking step.
0058In the example of <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>, the method comprises an initialization step ET0 which is broken down into four substeps ET00 to ET03. The purpose of the initialization step is to carry out the first masking level (step ET01: masking of the input data ME), and to prepare the second masking level (calculation of the non-linear operator SBOX ') which is then performed for each round of calculation.
0059During step ET00, three masking parameters X<sub>1</sub>, X<sub>2</sub>, X<sub>3</sub> are chosen randomly; they are modified for example, at each implementation of the method. They can also be modified only every M implemented.
0060During step ET01, the left and right parts of the input data are separated then masked by the parameter X<sub>1</sub>, thus providing a hidden left part L '<sub>0</sub> = L<sub>0</sub> & X<sub>1</sub> and a straight part R '<sub>0</sub> = R<sub>0</sub> & X<sub>1</sub>. The masking is carried out by means of the first masking operator "&".
0061The operator "&" is chosen linear with respect to the two variables it mixes. In one embodiment, the operator "&" is an Exclusive-OR. The "&" operator can also be any type of linear operator. Generally, the operator "&" has the following properties, whatever the data A, B, C:<ul id="ul0005" list-style="none" compact="compact"><li>* "&" is arity two: it takes two arguments as parameters,</li><li>* "&" checks: E (A & B) = E (A) & E (B), E being a linear operator,</li><li>* "&" checks (A ⊕ B) & C = A ⊕ (B&C), ⊕ being the OR-Exclusive operator,</li><li>* there is an operator "&<sup>-1</sup> ", inverse of" & ", such as (A & B) &<sup>-1</sup> A = B, possibly "&" and "&<sup>-1</sup> " are the same.</li></ul>
0062During step ET02, variables VX1 = E (X<sub>1</sub>), VX2 = P (X<sub>2</sub>) are calculated. The operators E, P are respectively an expansion and a simple permutation, as defined in the known DES type method.
0063During step ET03, a new non-linear operator SBOX 'is calculated by the relation: <maths id="math0002"><math display="block"><mi mathvariant="normal">SBOXʹ</mi><mo mathvariant="normal">=</mo><mi>FCT</mi><mfenced><mi>SBOX</mi><mo mathvariant="normal">,</mo><mspace width="1em" /><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub><mo mathvariant="normal">,</mo><mspace width="1em" /><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced></math><img file="EP1358732B2_D0002.tif" /></maths> where SBOX is the nonlinear operator used in a known DES process, X<sub>2</sub>, X<sub>3</sub> are the random parameters, and FCT is a function such that: <maths id="math0003"><math display="block"><mi mathvariant="normal">SBOXʹ</mi><mfenced open="[" close="]"><mi mathvariant="normal">AT</mi><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo mathvariant="normal">=</mo><mi>SBOX</mi><mfenced open="[" close="]"><mi mathvariant="normal">AT</mi></mfenced><mo></mo><mi mathvariant="normal">#</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub><mo mathvariant="normal">,</mo></math><img file="EP1358732B2_D0003.tif" /></maths> for all A.
0064"@", "#" are linear mixing operators, having properties similar to those of the operator "&". "@", "#" can be different from each other, they can also be different from the operator "&".
0065The first round of operations is then carried out; it is broken down into nine stages ET1 to ET9.
0066During the key calculation step ET1, a derived key M<sub>1</sub> is calculated from the secret key K<sub>0</sub>. The first 'derived key M<sub>1</sub> updated is given by the relation: M<sub>1</sub> = PC (S<sub>1</sub>(K<sub>0</sub>)) = PC (K<sub>1</sub>). K<sub>1</sub> is a first updated intermediate key, which will be supplied later to the second round of operations (not shown on the <figref idref="f0004">Figures 4a, 4b</figref>). PC, S operators<sub>1</sub> are respectively a permutation -compression and a bit shift operation as defined in the case of a known DES method. Step ET1 is thus identical to a key calculation step as defined in the context of a known DES method.
0067The following steps ET2 to ET8 form a transformation step F ', which corresponds to the transformation F of a known process, modified by the addition of steps ET3, ET4 and the replacement of the operator SBOX by the new operator SBOX' according to the invention.
0068During step ET2, an expansion is performed on the data R '<sub>0</sub>.
0069The result E (R '<sub>0</sub>) of this operation is then mixed with parameter X<sub>3</sub> via the second masking operator "@".
0070The following step ET4 is a first unmasking step, which aims to remove from the result of the previous operation, the contribution to this result made by the masking parameter X<sub>1</sub>. For this, the following operation is carried out:<maths id="math0004"><math display="block"><mtable columnalign="left"><mtr><mtd><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">Rʹ</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo></mo><msup><mo mathvariant="normal">&</mo><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><msub><mi>VX</mi><mn mathvariant="normal">1</mn></msub></mtd><mtd><mo mathvariant="normal">=</mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">Rʹ</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo></mo><msup><mo mathvariant="normal">&</mo><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo></mo><msup><mo mathvariant="normal">&</mo><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mtd></mtr></mtable></math><img file="EP1358732B2_D0004.tif" /></maths>
0071During the next step ET5, the result of the previous step ET4 is mixed with the updated derived key m<sub>1</sub> by an Exclusive OU. Step ET5 thus provides the result:<maths id="math0005"><math display="block"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mn mathvariant="normal">.</mn></math><img file="EP1358732B2_D0005.tif" /></maths>
0072During step ET6, the non-linear operation SBOX 'is performed on the result of the previous operation. Step ET6 provides the result:<maths id="math0006"><math display="block"><mi mathvariant="normal">SBOXʹ</mi><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo mathvariant="normal">=</mo><mi>SBOX</mi><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub></mfenced><mo></mo><mi mathvariant="normal">#</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub><mn mathvariant="normal">.</mn></math><img file="EP1358732B2_D0006.tif" /></maths>
0073This results from the very definition of the non-linear operator SBOX '.
0074A bit permutation operation P is then applied to this result (step ET7). We thus obtain:<maths id="math0007"><math display="block"><mtable columnalign="left"><mtr><mtd><mi mathvariant="normal">Fʹ</mi><mfenced><msub><mi mathvariant="normal">Rʹ</mi><mn mathvariant="normal">0</mn></msub></mfenced></mtd><mtd><mo mathvariant="normal">=</mo><mi mathvariant="normal">P</mi><mfenced open="[" close="]"><mi>SBOX</mi><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub></mfenced><mo></mo><mi mathvariant="normal">#</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><mi mathvariant="normal">P</mi><mfenced open="[" close="]"><mi>SBOX</mi><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub></mfenced></mfenced><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced><mn mathvariant="normal">.</mn></mtd></mtr></mtable></math><img file="EP1358732B2_D0007.tif" /></maths>
0075This last result is deduced simply because of the linearity of the operator P.
0076During step ET8, the result of the permutation P is then added (via an Exclusive-OR) to the data L '<sub>0</sub> calculated during step ET01. Step ET8 is similar to the corresponding step of a known DES method. We then obtain:<maths id="math0008"><math display="block"><mtable columnalign="left"><mtr><mtd><mi mathvariant="normal">P</mi><mfenced open="[" close="]"><mi>SBOX</mi><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub></mfenced></mfenced><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced><mo>⊕</mo><msub><mi>Where</mi><mn>0</mn></msub></mtd></mtr><mtr><mtd><mspace width="2em" /><mo>=</mo><mfenced open="[" close="]"><mi mathvariant="normal">P</mi><mfenced><mi>SBOX</mi><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub></mfenced></mfenced><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mfenced><mo>⊕</mo><msub><mi mathvariant="normal">L</mi><mn>0</mn></msub><mo>&</mo><msub><mi mathvariant="normal">X</mi><mn>1</mn></msub></mtd></mtr><mtr><mtd><mspace width="2em" /><mo>=</mo><mfenced open="[" close="]"><mi mathvariant="normal">P</mi><mfenced open="[" close="]"><mi>SBOX</mi><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub></mfenced></mfenced><mo>⊕</mo><msub><mi mathvariant="normal">L</mi><mn>0</mn></msub></mfenced><mo>&</mo><msub><mi mathvariant="normal">X</mi><mn>1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mtd></mtr><mtr><mtd><mspace width="2em" /><mo>=</mo><msub><mi mathvariant="normal">R</mi><mn>1</mn></msub><mo>&</mo><msub><mi mathvariant="normal">X</mi><mn>1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mtd></mtr></mtable></math><img file="EP1358732B2_D0008.tif" /></maths>where R<sub>1</sub> is the right part of the first intermediate datum (L<sub>1</sub>, R<sub>1</sub>) as defined in the context of the known DES type process. Again, all of the above inequalities are deduced due to the linearity of the operators P, &, #.
0077The following step ET9 is a second unmasking step, which aims to remove from the result of the previous operation, the contribution to this result made by the masking parameter X<sub>2</sub>. For this, the following operation is carried out:<maths id="math0009"><math display="block"><mtable><mtr><mtd><mfenced open="[" close="]"><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mfenced><mo mathvariant="normal">&</mo><msub><mi>VX</mi><mn mathvariant="normal">2</mn></msub><mo mathvariant="normal">=</mo><mfenced open="[" close="]"><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mfenced><mo></mo><msup><mi mathvariant="normal">#</mi><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><mi mathvariant="normal">P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mtd></mtr></mtable></math><img file="EP1358732B2_D0009.tif" /></maths>
0078At the end of the first round, the updated intermediate data provided is equal to (L '<sub>1</sub>, R '<sub>1</sub>), With l'<sub>1</sub> = R '<sub>0</sub> = R<sub>0</sub>& X<sub>1</sub> = L<sub>1</sub>& X<sub>1</sub>, and R '<sub>1</sub> = R<sub>1</sub>& X<sub>1</sub>.
0079Thus, with the DES method according to the invention, the intermediate data (L '<sub>1</sub>, R '<sub>1</sub>) calculated during the first round of operations is equal to the intermediate data (L<sub>1</sub>, R<sub>1</sub>) provided by a known unsecured DES type process, masked by the random parameter X<sub>1</sub> through the operator "&".
0080The second round is then performed, using the new intermediate data (L '<sub>1</sub>, R '<sub>1</sub>) updated as well as the updated intermediate key K<sub>1</sub> calculated during step ET1.
0081Generally speaking, the i<sup>th</sup> round of process operations is broken down into nine stages ET1 to ET9.
0082During step ET1, a derived key M<sub>i</sub> is calculated from an intermediate key K<sub>i-1</sub>, calculated in the previous round, to provide an updated derived key M<sub>i</sub> = PC (S<sub>i</sub>(K<sub>i-1</sub>)) = PC (K<sub>i</sub>). K<sub>i</sub> is an i<sup>th</sup> updated intermediary, which will be provided subsequently to the next round of operations (not shown on the <figref idref="f0004">Figures 4a, 4b</figref>). PC, S operators<sub>i</sub> are respectively a permutation-compression and a bit shift operation as defined in the case of a known DES method.
0083During step ET2, the expansion is carried out on the data R '<sub>i-1</sub>.
0084The result E (R '<sub>i-1</sub>) of this operation is then mixed with parameter X<sub>3</sub> via the second masking operator "@".
0085During step ET4, the following operation is carried out: <maths id="math0010"><math display="block"><mtable columnalign="left"><mtr><mtd><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">Rʹ</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo></mo><msup><mo mathvariant="normal">&</mo><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><msub><mi>VX</mi><mn mathvariant="normal">1</mn></msub></mtd><mtd><mo mathvariant="normal">=</mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">Rʹ</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo></mo><msup><mo mathvariant="normal">&</mo><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo></mo><msup><mo mathvariant="normal">&</mo><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mtd></mtr></mtable></math><img file="EP1358732B2_D0010.tif" /></maths>
0086During the following step ET5, the result of step ET4 is mixed with the updated derived key M<sub>i</sub> by an Exclusive OU. Step ET5 thus provides the result:<maths id="math0011"><math display="block"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mn mathvariant="normal">.</mn></math><img file="EP1358732B2_D0011.tif" /></maths>
0087During step ET6, the non-linear operation SBOX 'is performed on the result of the previous operation. Step ET6 provides the result:<maths id="math0012"><math display="block"><mi mathvariant="normal">SBOXʹ</mi><mo></mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub></mfenced><mo mathvariant="normal">=</mo><mi>SBOX</mi><mo></mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><mo>-</mo><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub></mfenced><mo></mo><mi mathvariant="normal">#</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub><mn mathvariant="normal">.</mn></math><img file="EP1358732B2_D0012.tif" /></maths>
0088This results from the very definition of the non-linear operator SBOX '.
0089A bit permutation operation P is then applied to this result (step ET7). We thus obtain:<maths id="math0013"><math display="block"><mi mathvariant="normal">P</mi><mo></mo><mfenced open="[" close="]"><mi>SBOX</mi><mo></mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub></mfenced><mo></mo><mi>#</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn>2</mn></msub></mfenced><mo mathvariant="normal">=</mo><mi mathvariant="normal">P</mi><mo></mo><mfenced open="[" close="]"><mi>SBOX</mi><mo></mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub></mfenced></mfenced><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced><mn mathvariant="normal">.</mn></math><img file="EP1358732B2_D0013.tif" /></maths>
0090During step ET8, the result of the permutation P is then added (via an Exclusive-OR) to the data L '<sub>i-1</sub> calculated during the previous round. We then obtain:<maths id="math0014"><math display="block"><mtable columnalign="left"><mtr><mtd><mi mathvariant="normal">P</mi><mo></mo><mfenced open="[" close="]"><mi>SBOX</mi><mo></mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub></mfenced></mfenced><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced><mo>⊕</mo><msub><mi>Where</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mtd></mtr><mtr><mtd><mspace width="2em" /><mo>=</mo><mfenced open="[" close="]"><mi mathvariant="normal">P</mi><mo></mo><mfenced><mi>SBOX</mi><mo></mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub></mfenced></mfenced><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mfenced><mo>⊕</mo><msub><mi mathvariant="normal">L</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub><mo>&</mo><msub><mi mathvariant="normal">X</mi><mn>1</mn></msub></mtd></mtr><mtr><mtd><mspace width="2em" /><mo>=</mo><mfenced open="[" close="]"><mi mathvariant="normal">P</mi><mo></mo><mfenced open="[" close="]"><mi>SBOX</mi><mo></mo><mfenced open="[" close="]"><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mfenced><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub></mfenced></mfenced><mo>⊕</mo><msub><mi mathvariant="normal">L</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mfenced><mo>&</mo><msub><mi mathvariant="normal">X</mi><mn>1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mtd></mtr><mtr><mtd><mspace width="2em" /><mo>=</mo><msub><mi mathvariant="normal">R</mi><mi mathvariant="normal">i</mi></msub><mo>&</mo><msub><mi mathvariant="normal">X</mi><mn>1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mtd></mtr></mtable></math><img file="EP1358732B2_D0014.tif" /></maths>where R<sub>i</sub> is the right part of the i<sup>th</sup> updated data (L<sub>i</sub>, R<sub>i</sub>) as defined in the context of the known DES process. Here again, all the above equalities are deduced due to the linearity of the operators P, &, #.
0091The following step ET9 is a second unmasking step, which aims to remove from the result of the previous operation, the contribution to this result made by the masking parameter X<sub>2</sub>. For this, the following operation is carried out:<maths id="math0015"><math display="block"><mtable><mtr><mtd><mfenced open="[" close="]"><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn mathvariant="normal">1</mn></mrow></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mfenced><mo></mo><msup><mi>#</mi><mrow><mo>-</mo><mn>1</mn></mrow></msup><mo></mo><msub><mi>VX</mi><mn mathvariant="normal">2</mn></msub><mo mathvariant="normal">=</mo><mfenced open="[" close="]"><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn mathvariant="normal">1</mn></mrow></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mo></mo><mi>#P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced></mfenced><mo></mo><msup><mi mathvariant="normal">#</mi><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><mi mathvariant="normal">P</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn mathvariant="normal">1</mn></mrow></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mtd></mtr></mtable></math><img file="EP1358732B2_D0015.tif" /></maths>
0092At the end of the i<sup>th</sup> round, the updated intermediate data provided is equal to (L '<sub>i</sub>, R '<sub>i</sub>), with: <maths id="math0016"><math display="block"><msub><mi mathvariant="normal">Where</mi><mi mathvariant="normal">i</mi></msub><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">Rʹ</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">L</mi><mi mathvariant="normal">i</mi></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">,</mo><mspace width="1em" /><mi>and</mi><mspace width="1em" /><msub><mi mathvariant="normal">Rʹ</mi><mi mathvariant="normal">i</mi></msub><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">R</mi><mi mathvariant="normal">i</mi></msub><mo mathvariant="normal">&</mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mn mathvariant="normal">.</mn></math><img file="EP1358732B2_D0016.tif" /></maths>
0093Thus, with the DES method according to the invention, the intermediate data (L '<sub>i</sub>, R '<sub>i</sub>) calculated during the i<sup>th</sup> round of operations is equal to the intermediate data (L<sub>i</sub>, R<sub>i</sub>) provided during the same round by a known unsecured DES process, but masked by the random parameter X<sub>1</sub> through the operator "&".
0094The new intermediate data (L '<sub>i</sub>, R '<sub>i</sub>) is then provided to the next round.
0095The 16<sup>th</sup>, process round provides the 16<sup>th</sup> intermediate data (L '<sub>16'</sub> R '<sub>16</sub>)<sub>.</sub> During a third final unmasking step ET10, the contribution of the parameter X<sub>1</sub> at 16<sup>th</sup> data is deleted via the operator &<sup>-1</sup> : L<sub>16</sub> = The <sub>16</sub>&<sup>-1</sup>X<sub>1</sub>, R<sub>16</sub> = R '<sub>16</sub>&<sup>-1</sup>X<sub>1</sub>.
0096The final IP permutation<sup>-1</sup>, carried out after step ET10, completes the DES process according to the invention. IP swapping<sup>-1</sup> is identical to the equivalent permutation of a known DES type process.
0097With the DES method according to the invention, the output data produced is the same as that supplied by a known DES method, provided that the input data ME and the secret key K<sub>0</sub> are identical for the known method and the method according to the invention.
0098On the other hand, it will be noted that in the method according to the invention (<figref idref="f0002 f0003">figure 3</figref>), and unlike the known DES process (<figref idref="f0001">figures 1, 2</figref>) : <ul id="ul0006" list-style="dash" compact="compact"><li>type intermediate data (L '<sub>i</sub>, R '<sub>i</sub>) are all masked by parameter X1 (1st masking level); the data (The<sub>i</sub>, R '<sub>i</sub>) are used or produced by the rounds of calculation.</li><li>the intermediate results within the same round of calculation, produced at the end of a P, PC, E, Si, SBOX ', ⊕, etc. operation, are all masked by at least one of the parameters of masks (X1, X2, X3) or by a derived value (E (x1), P (X2), etc.); the second level of masking is thus correctly implemented.</li></ul>
0099Like X<sub>1</sub>, X<sub>2</sub> or X<sub>3</sub> are chosen randomly at each implementation of the method, the value of all the intermediate results and of all the intermediate data is different at each implementation of the method and this whatever the value of the input data (L<sub>0</sub>, R<sub>0</sub>) or the value of the secret key K<sub>0</sub> used by the method of the invention. In particular, the value of all the intermediate results is different, including in the case where the method is implemented twice with the same input data ME and the same secret key K<sub>0</sub>.
0100The presence of at least one random parameter removes any correlation, at the level of a result or of an intermediate datum, between the secret key K<sub>0</sub> and the input data ME. A DPA-type statistical analysis therefore does not make it possible to obtain information on the secret key used by a secure method according to the invention.
0101Modifications and / or improvements to the process <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref> are possible, without departing from the scope of the invention.
0102For example, the order of carrying out certain steps of the process can be modified:<ul id="ul0007" list-style="dash" compact="compact"><li>Steps IP, ET01, round 1, ..., round i, ..., round 16, ET10, IP<sup>-1</sup> must be executed in the order presented on the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref> if the desired process should be similar to that of <figref idref="f0001">figures 1, 2</figref>.</li><li>Step ET00 must be performed before step ET01. The step ET00 can be carried out before or in parallel with the step IP.</li><li>Stage ET02 is carried out between stage ET00 and stage ET4 of the 1<sup>time</sup> round of operations; it can be carried out before or in parallel with the IP step, the ET01 step, the ET1 or ET2 steps.</li><li>Stage ET03 is carried out between stage ET00 and stage ET6 of the 1<sup>time</sup> round of operations; it can be carried out before or after the IP step, possibly in parallel with the step ET01, the steps ET1, ET2, ET3 or ET4. For reasons of symmetry, step ET10 will be performed after the IP step<sup>-1</sup> if step ET01 is carried out before the IP step. Conversely, the ET10 step will be performed before the IP step<sup>-1</sup> if step ET01 is performed after the IP step.</li><li>In each round i, step ET1 must be carried out so that the derived key M<sub>i</sub> that it supplies is available for carrying out step ET5; step ET1 can for example be carried out in parallel with steps ET2, ET3 or ET4.</li></ul>
0103In the example described above in relation to <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>, three random parameters X<sub>1</sub>, X<sub>2</sub>, X<sub>3</sub> are used. This solution makes it possible to mask all the intermediate results in the most effective way possible. In another example, it is possible to use only two parameters, the parameters X<sub>1</sub>, X<sub>2</sub>. In this case, step ET02 is limited to the calculation of P (X<sub>2</sub>), the steps ET3, ET4 of all the rounds of operations are deleted, and the step ET03 is modified to calculate a new non-linear operator SBOX "by the relation: <maths id="math0017"><math display="block"><mi mathvariant="normal">SBOXʺ</mi><mo mathvariant="normal">=</mo><mi mathvariant="normal">FCTʺ</mi><mfenced><mi>SBOX</mi><mo mathvariant="normal">,</mo><mspace width="1em" /><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">,</mo><mspace width="1em" /><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">2</mn></msub></mfenced><mo>,</mo></math><img file="EP1358732B2_D0017.tif" /></maths> with FCT "a function such as <maths id="math0018"><math display="block"><mi mathvariant="normal">SBOXʺ</mi><mfenced><mi mathvariant="normal">AT</mi><mo mathvariant="normal">&</mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">1</mn></msub></mfenced></mfenced><mo mathvariant="normal">=</mo><mi>SBOX</mi><mfenced><mi mathvariant="normal">AT</mi></mfenced><mo></mo><msub><mi>#X</mi><mn mathvariant="normal">2</mn></msub><mn mathvariant="normal">.</mn></math><img file="EP1358732B2_D0018.tif" /></maths>
0104Here again, all the intermediate results are masked by a random parameter, this random parameter being modified each time the method is implemented. In particular, in the round of rank i, at the end of step ET2, the intermediate result E (R '<sub>0</sub>) = E (R<sub>0</sub>)&EX<sub>1</sub>) is masked by the derived parameter E (X<sub>1</sub>). Similarly, at the end of step ET5, the intermediate result E (R '<sub>0</sub>) ⊕M<sub>i</sub> is masked by the derived parameter E (X<sub>1</sub>). At the end of step ET6, the intermediate result is masked as in the previous example by the parameter X<sub>2</sub>.
0105Similarly, in the example described above in relation to the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>, the three parameters X<sub>1</sub>, X<sub>2</sub>, X<sub>3</sub> are chosen randomly, each time the process is implemented. However, it is possible to modify the parameters X<sub>1</sub>, X<sub>2</sub>, X<sub>3</sub> more or less often. For example, it is possible to modify the parameters, in particular X<sub>2</sub> and / or X<sub>3</sub> each time a round i of operations is carried out. In this case, steps ET02, ET03 will be carried out at each round to take into account the parameters X<sub>2</sub>, X<sub>3</sub> modified.
0106In the same spirit, it is possible to modify the parameters X<sub>1</sub>, X<sub>2</sub>, X<sub>3</sub> all the M executions of the method, if it is considered that M embodiments are not sufficient to carry out a DPA attack. M is an integer. In this case, only the step ET01 is carried out during the step ET0. Steps ET00, ET02, ET03 are performed only every M implemented in the process.
0107Another important improvement makes it possible to secure the process also against SPA type analyzes. For this type of analysis, the steps for calculating the derived key M<sub>i</sub> are particularly sensitive. The improvement therefore consists in hiding the derived keys, in addition to the intermediate results.
0108The process of <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref> is then improved by adding (see <figref idref="f0004">figure 4</figref>): <ul id="ul0008" list-style="dash" compact="compact"><li>sub-steps ET05, ET06 in the initialization step ET0,</li><li>steps ET11, ET12 in each of the 16 rounds of process operations.</li></ul>
0109For the sake of clarity and simplification, only the i<sup>th</sup> process round was shown on the <figref idref="f0004">figure 4</figref>, accompanied by the new steps ET05, ET06.
0110During step ET05, a fourth parameter Y<sub>0</sub> is chosen randomly. The step ET05 is for example carried out simultaneously with the step ET00, or else in parallel with one of the steps IP, ET01, ET02, ET03.
0111During the masking step ET06-, performed after the step ET05, the fourth masking parameter Y<sub>0</sub> is mixed with secret key K<sub>0</sub>, to provide a hidden secret key K '<sub>0</sub>. The mixing is done by the following relation:<maths id="math0019"><math display="block"><msub><mi mathvariant="normal">Kʹ</mi><mn mathvariant="normal">0</mn></msub><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">K</mi><mn mathvariant="normal">0</mn></msub><mrow><mo mathvariant="normal">|</mo></mrow><msub><mi mathvariant="normal">Y</mi><mn mathvariant="normal">0</mn></msub></math><img file="EP1358732B2_D0019.tif" /></maths>
0112The operator "|" is preferably chosen linear with respect to the two variables it mixes. In one embodiment, the operator "|" is an Exclusive-OR. The "|" operator can also be any type of linear operator. In general, the operator "|" has properties similar to those of the operators "&", "@" or "#".
0113The 1<sup>time</sup> round of operations (not shown <figref idref="f0004">figure 4</figref>) is then performed. The key calculation step ET1 is carried out here no longer directly from the secret key K<sub>0</sub>, but from the hidden secret key K '<sub>0</sub>. Step ET1 provides a masked derived key M '<sub>1</sub> according to the relationship: <maths id="math0020"><math display="block"><mtable columnalign="left"><mtr><mtd><msub><mi mathvariant="normal">Mʹ</mi><mn mathvariant="normal">1</mn></msub></mtd><mtd><mo mathvariant="normal">=</mo><mi>PC</mi><mfenced><msub><mi mathvariant="normal">S</mi><mn mathvariant="normal">1</mn></msub><mfenced><msub><mi mathvariant="normal">Kʹ</mi><mn mathvariant="normal">0</mn></msub></mfenced></mfenced><mo mathvariant="normal">=</mo><mi>PC</mi><mfenced><msub><mi mathvariant="normal">S</mi><mn mathvariant="normal">1</mn></msub><mfenced><msub><mi mathvariant="normal">K</mi><mn mathvariant="normal">0</mn></msub><mrow><mo mathvariant="normal">|</mo></mrow><msub><mi mathvariant="normal">Y</mi><mn mathvariant="normal">0</mn></msub></mfenced></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><mi>PC</mi><mfenced><msub><mi mathvariant="normal">S</mi><mn mathvariant="normal">1</mn></msub><mfenced><msub><mi mathvariant="normal">K</mi><mn mathvariant="normal">0</mn></msub></mfenced></mfenced><mrow><mo mathvariant="normal">|</mo></mrow><mi>PC</mi><mfenced><msub><mi mathvariant="normal">S</mi><mn mathvariant="normal">1</mn></msub><mfenced><msub><mi mathvariant="normal">Y</mi><mn mathvariant="normal">0</mn></msub></mfenced></mfenced><mn mathvariant="normal">.</mn></mtd></mtr></mtable></math><img file="EP1358732B2_D0020.tif" /></maths>
0114The last equality is simply deduced from the fact that the operators PC, S<sub>1</sub> and "|" are linear operators and therefore in particular have properties of the commutative or associative type.
0115As PC (S<sub>1</sub>(K<sub>0</sub>)) = M<sub>1</sub>, we finally deduce that M '<sub>1</sub> = M<sub>1</sub> | PC (S<sub>1</sub>(Y<sub>0</sub>), M<sub>i</sub> being the derived key calculated according to the method described in relation to the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>.
0116The difference calculation step ET11 is carried out for example before, in parallel or after the key calculation step ET1. Step ET11 determines contribution C<sub>1</sub> provided by the parameter Y<sub>0</sub> to the hidden derived key M '<sub>1</sub>.
0117Step ET11 is similar to step ET1; step ET11 thus comprises an operation S<sub>1</sub> to provide a masking parameter Y<sub>1</sub> = S<sub>1</sub>(Y<sub>0</sub>) updated by shifting the bits of Y<sub>0</sub>, and a PC operation to calculate the contribution C<sub>1</sub>. Contribution C<sub>1</sub> is thus calculated according to the relation: C<sub>1</sub> = PC (S<sub>1</sub>(Y<sub>0</sub>)). We finally deduce M '<sub>1</sub> = M<sub>1</sub> | VS<sub>1</sub>. The masking parameter Y<sub>1</sub> updated is provided to the next round of operations.
0118The unmasking step ET12 is a sub-step of the transformation F "(which corresponds to the transformation F 'of the DES process according to the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>, modified by the addition of step ET12); in the example of the<figref idref="f0004">figure 4</figref>, step ET12 is carried out between step ET5 and step ET6. Stage ET12 aims to remove the contribution C<sub>1</sub> provided by the updated masking parameter Y<sub>1</sub>. For this, the operator "|<sup>-1</sup>"operator inverse" | "is used. At the end of step ET12, we have:<maths id="math0021"><math display="block"><mrow><mo mathvariant="normal">(</mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">Mʹ</mi><mn mathvariant="normal">1</mn></msub><mo></mo><msup><mrow><mo mathvariant="normal">|</mo></mrow><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><msub><mi mathvariant="normal">VS</mi><mn mathvariant="normal">1</mn></msub></mrow><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub><mo></mo><msup><mfenced open="|" close="|"><msub><mi mathvariant="normal">VS</mi><mn mathvariant="normal">1</mn></msub></mfenced><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><msub><mi mathvariant="normal">VS</mi><mn mathvariant="normal">1</mn></msub><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mfenced><msub><mi mathvariant="normal">R</mi><mn mathvariant="normal">0</mn></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mn mathvariant="normal">1</mn></msub></math><img file="EP1358732B2_D0021.tif" /></maths>
0119Thus, after deletion of the contribution C<sub>1</sub>, the variable that appears at the input of the operator of type SBOX '(step ET6) is equal to E (R<sub>0</sub>) @X<sub>3</sub> ⊕ M<sub>1</sub>, that is to say that it is identical to the variable which appears at the input of the operator SBOX 'of the process described in relation to the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>.
0120Consequently, the output data which appears at the output of the transformation F "is identical to that which appears at the output of the transformation F 'of the process of <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>.
0121More generally, during the i<sup>th</sup> round of operations, step ET1 provides a masked derived key M '<sub>i</sub> according to the relationship: <maths id="math0022"><math display="block"><mtable columnalign="left"><mtr><mtd><msub><mi mathvariant="normal">Mʹ</mi><mi mathvariant="normal">i</mi></msub></mtd><mtd><mo mathvariant="normal">=</mo><mi>PC</mi><mo></mo><mfenced><msub><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi></msub><mo></mo><mfenced><msub><mi mathvariant="normal">Kʹ</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced></mfenced><mo mathvariant="normal">=</mo><mi>PC</mi><mo></mo><mfenced><msub><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi></msub><mo></mo><mfenced><msub><mi mathvariant="normal">K</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub><mrow><mo mathvariant="normal">|</mo></mrow><msub><mi mathvariant="normal">Y</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><mi>PC</mi><mo></mo><mfenced><msub><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi></msub><mo></mo><mfenced><msub><mi mathvariant="normal">K</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced></mfenced><mrow><mo mathvariant="normal">|</mo></mrow><mi>PC</mi><mo></mo><mfenced><msub><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi></msub><mo></mo><mfenced><msub><mi mathvariant="normal">Y</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced></mfenced></mtd></mtr><mtr><mtd><mspace width="1em" /></mtd><mtd><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">Mʹ</mi><mi mathvariant="normal">i</mi></msub><mo mathvariant="normal">=</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub><mrow><mo mathvariant="normal">|</mo></mrow><mi>PC</mi><mrow><mo mathvariant="normal">(</mo><msub><mi mathvariant="normal">S</mi><mi mathvariant="normal">i</mi></msub><mo></mo><mfenced><msub><mi mathvariant="normal">Y</mi><mrow><mi mathvariant="normal">i</mi><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msub></mfenced></mrow><mo mathvariant="normal">,</mo></mtd></mtr></mtable></math><img file="EP1358732B2_D0022.tif" /></maths>
0122M<sub>i</sub> being the derived key calculated according to the method described in relation to the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>.
0123Recall that the PC operators are identical for all the rounds of the process (same characteristics, same parameters, etc.). On the other hand, S operations<sub>i</sub> bit shift are different from one round of operations to another.
0124Step ET11 determines contribution C<sub>i</sub> provided by the parameter Y<sub>i-1</sub> (or more generally Y<sub>0</sub>) to the masked derived key M '<sub>i</sub>. Step ET11 provides a masking parameter Y<sub>i</sub> = S<sub>i</sub>(Y<sub>i-1</sub>) updated, and a contribution C<sub>i</sub> updated according to the relationship: C<sub>i</sub> = PC (S<sub>i</sub> (Y<sub>i-1</sub>)). We finally deduce M '<sub>i</sub> = M<sub>i</sub> | VS<sub>i</sub>. The masking parameter Y<sub>i</sub> updated is provided to the next round of operations.
0125Step ET12 is carried out between step ET5 and step ET6. At the end of step ET12, we have:<maths id="math0023"><math display="block"><mrow><mo mathvariant="normal">(</mo><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">Mʹ</mi><mi mathvariant="normal">i</mi></msub><mo></mo><msup><mrow><mo mathvariant="normal">|</mo></mrow><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><msub><mi mathvariant="normal">VS</mi><mi mathvariant="normal">i</mi></msub></mrow><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub><mo></mo><msup><mfenced open="|" close="|"><msub><mi mathvariant="normal">VS</mi><mi mathvariant="normal">i</mi></msub></mfenced><mrow><mo mathvariant="normal">-</mo><mn mathvariant="normal">1</mn></mrow></msup><mo></mo><msub><mi mathvariant="normal">VS</mi><mi mathvariant="normal">i</mi></msub><mo mathvariant="normal">=</mo><mi mathvariant="normal">E</mi><mo></mo><mfenced><msub><mi mathvariant="normal">R</mi><mrow><mi mathvariant="normal">i</mi><mo>-</mo><mn>1</mn></mrow></msub></mfenced><mo></mo><mi mathvariant="normal">@</mi><mo></mo><msub><mi mathvariant="normal">X</mi><mn mathvariant="normal">3</mn></msub><mo mathvariant="normal">⊕</mo><msub><mi mathvariant="normal">M</mi><mi mathvariant="normal">i</mi></msub></math><img file="EP1358732B2_D0023.tif" /></maths>
0126Thus, after deletion of the contribution C<sub>i</sub>, the variable that appears at the input of the operator of type SBOX '(step ET6) is equal to PE (R<sub>i-1</sub>) @X<sub>3</sub>+ M<sub>i</sub>, that is to say that it is identical to the variable which appears at the input of the operator SBOX 'of the process described in relation to the <figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>. The output data which appears at the output of the transformation step F 'is therefore identical to that which appears at the output of the transformation operation F' of the process of<figref idref="f0002">figures 3a</figref>, <figref idref="f0003">3b</figref>.
0127Finally, with the process of <figref idref="f0004">figure 4</figref>, all intermediate results are masked by at least one of the parameters X<sub>1</sub>, X<sub>2</sub>, X<sub>3</sub> (or a form derived from these parameters). In addition, all the intermediate keys K '<sub>i</sub>, all the derived keys M '<sub>i</sub> are also hidden by the Y parameter<sub>0</sub> or a form derived from Y<sub>0</sub>.
33 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP0981223A | Cites | European Patent Office (EPO) |
| WO0041356A | Cites | World Intellectual Property Organization (WIPO) |
| WO0108012A | Cites | World Intellectual Property Organization (WIPO) |
| FR2776445A | Cites | France |
14 members in 6 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 0101685 | France | – | |
| 0101685 | France | A | |
| 0200453 | France | W |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| FR2820576A1 | France | A1 | |
| WO02063821A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2820576B1 | France | B1 | |
| EP1358732A1 | European Patent Office (EPO) | A1 | |
| US2004071288A1 | United States of America | A1 | |
| JP2004533630A | Japan | A | |
| EP1358732B1 | European Patent Office (EPO) | B1 | |
| DE60223337D1 | Germany | D1 | |
| DE60223337T2 | Germany | T2 | |
| JP2008295108A | Japan | A | |
| JP4347568B2 | Japan | B2 | |
| EP1358732B2This record | European Patent Office (EPO) | B2 | |
| US8306218B2 | United States of America | B2 | |
| DE60223337T3 | Germany | T3 |
37 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Expiry of rightR071 | R071 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Change of representativeR082 | R082 | DE | |
| Change of representativeR082 | R082 | DE | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Epo decision maintaining patent in amended form now finalR102 | R102 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Patent maintained in amended form27A | 27A | EP | |
| Designated contracting statesAK | AK | EP | |
| Epo decision maintaining patent in amended form now finalR102 | R102 | DE | |
| Patent maintained in amended formORIGINAL CODE: 0009272PUAH | PUAH | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: PATENT MAINTAINED AS AMENDEDSTAA | STAA | EP | |
| Appeal procedure closedAppealORIGINAL CODE: EPIDOSNNOA9OAPBU | APBU | EP | |
| Appeal reference modifiedAppealORIGINAL CODE: EPIDOSCREFNOAPAH | APAH | EP | |
| Appeal reference recordedAppealORIGINAL CODE: EPIDOSNREFNOAPBM | APBM | EP | |
| Date of receipt of notice of appeal recordedAppealORIGINAL CODE: EPIDOSNNOA2OAPBP | APBP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Reply of patent proprietor to notice(s) of opposition receivedOppositionORIGINAL CODE: EPIDOSNOBS3PLBB | PLBB | EP | |
| Information modified related to communication of a notice of opposition and request to file observations + time limitOppositionORIGINAL CODE: EPIDOSCOBS2PLAF | PLAF | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Notice of opposition and request to file observation + time limit sentOppositionORIGINAL CODE: EPIDOSNOBS2PLAX | PLAX | EP | |
| Opposition filedOppositionORIGINAL CODE: 0009260PLBI | PLBI | EP | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1358732
- Application
- 27036607
Titles3
- German
- VERFAHREN ZUR GESICHERTEN VERSCHLÜSSELUNG UND BAUSTEIN ZUR AUSFÜHRUNG EINES SOLCHEN VERSCHLÜSSELUNGSVERFAHRENS
- English
- SECURE ENCRYPTION METHOD AND COMPONENT USING SAME
- French
- PROCEDE DE CRYPTAGE SECURISE ET COMPOSANT UTILISANT UN TEL PROCEDE DE CRYPTAGE
Classification
- CPC, 5
- H04L9/0625
- G06F2207/7219
- H04L9/003
- H04L2209/046
- H04L2209/24
- IPC, 2
- H04L9 06
- G09C1 00
Designated states4
- Contracting states, 4
- Germany
- France
- United Kingdom
- Italy
