Method to enciphering/deciphering data packets of a data steam
19 claims: 3 independent, 16 dependent
- 1Verfahren zur Verschlüsselung von Datenpaketen eines Datenstroms, bei dem ein zu verschlüsselndes Datenpaket automatisch sequentiell in wenigstens zwei aufeinander folgenden Verschlüsselungsstufen verschlüsselt wird, aufweisend die folgenden Schritte:- (S10) Bestimmen von Anzahl, Art und Reihenfolge von in den aufeinander folgenden Verschlüsselungsstufen zu verwendenden unterschiedlichen Schlüsselungsalgorithmen;- (S12) Bestimmen von in den aufeinander folgenden Verschlüsselungsstufen zu verwendenden unterschiedlichen Kodierschlüsseln;- (S13) Zuordnen jeweils eines Kodierschlüssels zu jeweils einem Schlüsselungsalgorithmus in jeweils einer Verschlüsselungsstufe;- (S16, S17) Sequentielles Verschlüsseln eines zu verschlüsselnden Datenpakets in wenigstens zwei aufeinander folgenden Verschlüsselungsstufen, um ein mehrfach verschlüsseltes Datenpaket zu erhalten;- (S18) Erstellen einer unverschlüsselten Schlüsselungs-Charakteristik zu dem mehrfach verschlüsselten Datenpaket, welche Schlüsselungs-Charakteristik wenigstens den zeitlich zuletzt verwendeten Schlüsselungsalgorithmus und den zugeordneten Kodierschlüssel angibt;und - (S19) Ausgeben der Schlüsselungs-Charakteristik zusammen mit dem mehrfach verschlüsselten Datenpaket.
- 2Verfahren nach Anspruch 1, weiter umfassend - Hinzufügen der erzeugten unverschlüsselten Schlüsselungs-Charakteristik in jeder Verschlüsselungsstufe nach dem Verschlüsseln zu dem jeweiligen verschlüsselten Datenpaket.
- 3Verfahren nach einem der vorangegangenen Ansprüche, wobei jede Verschlüsselungsstufe umfasst:- (S14) Ermitteln wenigstens einer Formatvorschrift des in der jeweiligen Verschlüsselungsstufe verwendeten Schlüsselungsalgorithmus, wobei die wenigstens eine Formatvorschrift einen Aufbau der mit dem jeweiligen Schlüsselungsalgorithmus verschlüsselbaren Datenpakete festlegt;und - (S15) Anpassen des Aufbaus des zu verschlüsselnden Datenpakets an den jeweiligen Schlüsselungsalgorithmus unter Verwendung der wenigstens einen Formatvorschrift.
- 4Verfahren nach Anspruch 3, wobei das Anpassen des zu verschlüsselnden Datenpakets umfasst:- Segmentieren des zu verschlüsselnden Datenpakets in mehrere zu verschlüsselnde Teildatenpakete;- Verwenden der Teildatenpakete anstelle des zu verschlüsselnden Datenpakets;- Erstellen einer unverschlüsselten Segmentier-Charakteristik zu den zu verschlüsselnden Teildatenpaketen, wobei die Segmentier-Charakteristik Teildatenpakete bezeichnet, die durch Segmentieren eines einzelnen Datenpakets gewonnen wurden;und - Ausgeben der Segmentier-Charakteristik zusammen mit den segmentierten zu verschlüsselnden Teildatenpaketen.
- 5Verfahren nach einem der Ansprüche 3 oder 4, wobei das Anpassen des zu verschlüsselnden Datenpakets umfasst:- Erstellen eines Datenblocks, welcher Datenblock das zu verschlüsselnde Datenpaket und eine Block-Charakteristik enthält, wobei die Block-Charakteristik das zu verschlüsselnde Datenpaket in dem Datenblock kennzeichnet;und - Verwenden des Datenblocks anstelle des zu verschlüsselnden Datenpakets.
- 6Verfahren zur Entschlüsselung von gemäß Anspruch 1 mehrfach verschlüsselten Datenpaketen eines Datenstroms, aufweisend die folgenden Schritte:- (S20) Detektieren wenigstens einer dem mehrfach verschlüsselten Datenpaket zugeordneten unverschlüsselten Schlüsselungs-Charakteristik, welche Schlüsselungs-Charakteristik wenigstens einen Schlüsselungsalgorithmus und einen zugeordneten Kodierschlüssel angibt;und - (S21) Sequentielles Entschlüsseln des zu entschlüsselnden Datenpakets in wenigstens zwei aufeinander folgenden Entschlüsselungsstufen unter Verwendung des in der wenigstens einen Schlüsselungs-Charakteristik angegebenen wenigstens einen Schlüsselungsalgorithmus und zugeordneten Kodierschlüssels.
- 7Verfahren nach Anspruch 6, wobei wenigstens eine Entschlüsselungsstufe die folgenden Schritte umfasst:- (S22) Detektieren einer dem Datenpaket zugeordneten unverschlüsselten Segmentier-Charakteristik, wobei die Segmentier-Charakteristik Datenpakete bezeichnet, die Segmente eines einzelnen Gesamtdatenpakets sind;- (S23) Bilden des Gesamtdatenpakets anhand der entschlüsselten Datenpakete und der Segmentier-Charakteristik nach dem Entschlüsseln;und - (S24) Verwenden des Gesamtdatenpakets anstelle des Datenpakets.
- 8Verfahren nach einem der Ansprüche 6 oder 7, wobei wenigstens eine Entschlüsselungsstufe umfasst:- (S25, S26) Detektieren einer unverschlüsselten Block-Charakteristik in dem Datenpaket nach dem Entschlüsseln, wobei die Block-Charakteristik in dem Datenpaket ein im weiteren Verfahren zu verwendendes Datenpaket kennzeichnet.
- 9Verfahren nach einem der vorangegangenen Ansprüche, wobei die unterschiedlichen Schlüsselungsalgorithmen und/oder Kodierschlüssel voneinander unabhängig sind.
- 10Signalfolge, welche die Ausführung des Verfahrens nach einem der Ansprüche 1 bis 9 veranlasst, wenn sie in einen Datenverarbeiter (61, 62;63, 64, 65;66), insbesondere einen Mikroprozessor, eines Datenverarbeitungssystem (11;12;13) geladen ist.
- 11Datenverarbeitungssystem (11;12;13), wobei das Datenverarbeitungssystem (11;12;13) wenigstens Datenpakete eines Datenstroms empfängt und die empfangenen Datenpakete gemäss einer vorgegebenen Vorschrift verarbeitet, dadurch gekennzeichnet, dass das Datenverarbeitungssystem (11;12;13) dazu programmiert und eingerichtet ist, das Verfahren nach einem der Ansprüche 1 bis 9 auszuführen.
- 12Datenverarbeitungssystem (11) nach Anspruch 11, umfassend eine Speichereinrichtung (41, 41'), in welcher wenigstens zwei unterschiedliche Kodierschlüssel (K1, K3) gespeichert sind;wenigstens zwei Datenverarbeiter (61, 62), die jeweils eine festkodierte Schaltungslogik aufweisen, welche Schaltungslogik jeweils unterschiedliche Schlüsselungsalgorithmen (S1, S3) zur Verarbeitung eines empfangenen Datenpakets unter Verwendung eines Kodierschlüssels (K1, K3) implementiert;ein Schaltnetzwerk (71), um die Datenverarbeiter (61, 62) wahlweise seriell zu verbinden, wobei die Reihenfolge änderbar ist;und eine Steuereinrichtung (81), welche das Schaltnetzwerk (71) und die wenigstens zwei Datenverarbeiter (61, 62) steuert, wenigstens die Datenpakete des Datenstroms empfängt und an einen ersten der wenigstens zwei Datenverarbeiter (61, 62) ausgibt, aus der Speichereinrichtung (41, 41') unterschiedliche Kodierschlüssel (K1, K3) ausliest und an die Datenverarbeiter (61, 62) ausgibt.
- 13Datenverarbeitungssystem (12) nach Anspruch 11, umfassend eine Speichereinrichtung (42), in welcher wenigstens zwei unterschiedliche Kodierschlüssel (K1-K9) und wenigstens zwei unterschiedliche Schlüsselungsalgorithmen (S1-S9) gespeichert sind;wenigstens zwei Datenverarbeiter (63, 64, 65), die jeweils eine programmierbare Schaltungslogik zum Verarbeiten empfangener Datenpakete aufweisen;ein Verbindungsnetz (72), welches die Datenverarbeiter (63, 64, 65) seriell mit einer vorgegebenen Reihenfolge verbindet;und eine Steuereinrichtung (82), welche die wenigstens zwei Datenverarbeiter (63, 64, 65) steuert, aus der Speichereinrichtung (42) unterschiedliche Schlüsselungsalgorithmen (S1-S9) ausliest und die Schaltungslogiken der Datenverarbeiter (63, 64, 65) entsprechend programmiert, wenigstens die Datenpakete des Datenstroms empfängt und an einen ersten der wenigstens zwei Datenverarbeiter (63, 64, 65) ausgibt, und aus der Speichereinrichtung (42) unterschiedliche Kodierschlüssel (K1-K9) ausliest und an die Datenverarbeiter (63, 64, 65) ausgibt, wobei die gemäss eines jeweiligen Schlüsselungsalgorithmus (S1-S9) programmierten Schaltungslogiken der jeweiligen Datenverarbeiter (63, 64, 65) die jeweils empfangenen Datenpakete unter Verwendung des jeweiligen empfangenen Kodierschlüssels (K1-K9) verarbeiten.
- 14Datenverarbeitungssystem (13) nach Anspruch 11, umfassend eine Speichereinrichtung (43, 43'), in welcher wenigstens zwei unterschiedliche Kodierschlüssel (K2, K3) und wenigstens zwei unterschiedliche Schlüsselungsalgorithmen (S2, S3) gespeichert sind;einen Datenverarbeiter (66) mit einer programmierbaren Schaltungslogik zum Verarbeiten empfangener Datenpakete;und eine Steuereinrichtung (83), welche wenigstens die Datenpakete des Datenstroms empfängt, aus der Speichereinrichtung (43, 43') zeitlich nacheinander unterschiedliche Schlüsselungsalgorithmen (S2, S3) ausliest und die Schaltungslogik des Datenverarbeiter (66) entsprechend programmiert sowie aus der Speichereinrichtung (43, 43') zeitlich nacheinander unterschiedliche Kodierschlüssel (K2, K3) ausliest und zusammen mit zu verarbeitenden Daten an den Datenverarbeiter (66) ausgibt, wobei die Steuereinrichtung (83) weiter von dem Datenverarbeiter (66) unter Verwendung des jeweiligen Kodierschlüssels (K2, K3) und Schlüsselalgorithmus verarbeitete Daten erhält, und wobei die Steuereinrichtung (83) weiter die von dem Datenverarbeiter (66) empfangenen verarbeiteten Daten wenigstens einmal an den Datenverarbeiter (66) ausgibt und diesen so steuert, dass der Datenverarbeiter (66) ein von der Steuerungseinrichtung empfangenes zu verarbeitendes Datenpaket wenigstens zweimal zeitlich hintereinander unter Verwendung unterschiedlicher Schlüsselungsalgorithmen (S2, S3) und unterschiedlicher Kodierschlüssel (K2, K3) verarbeitet.
- 15Datenverarbeitungssystem (11;12;13) nach einem der Ansprüche 11 bis 14, wobei die Steuereinrichtung (81;82;83) beim Empfang eines zu verschlüsselnden Datenpakets automatisch eine Anzahl, Art und Reihenfolge von in aufeinander folgenden Verschlüsselungsstufen zu verwendende unterschiedliche Schlüsselungsalgorithmen (S1-S9) bestimmt, in den aufeinander folgenden Verschlüsselungsstufen zu verwendende unterschiedliche Kodierschlüssel (K1-K9) bestimmt und jeweils einen Kodierschlüssel (K1-K9) zu jeweils einem Schlüsselungsalgorithmus (S1-S9) in jeweils einer Verschlüsselungsstufe zuordnet, wobei die Steuereinrichtung (81;82;83) weiter den wenigstens einen Datenverarbeiter (61-66) entsprechend steuert, um ein mehrfach verschlüsseltes Datenpaket zu erhalten, und wobei die Steuereinrichtung (81;82;83) weiter automatisch eine unverschlüsselte Schlüsselungs-Charakteristik erstellt, welche Schlüsselungs-Charakteristik wenigstens den zeitlich zuletzt verwendeten Schlüsselungsalgorithmus (S1-S9) und den zugeordneten Kodierschlüssel (K1-K9) angibt, und die Schlüsselungs-Charakteristik zusammen mit dem mehrfach verschlüsselten Datenpaket ausgibt.
- 16Datenverarbeitungssystem (11;12;13) nach Anspruch 15, wobei die Steuereinrichtung (81;82;83) weiter automatisch wenigstens eine Formatvorschrift des in der jeweiligen Verschlüsselungsstufe verwendeten Schlüsselungsalgorithmus (S1-S9) ermittelt, wobei die wenigstens eine Formatvorschrift einen Aufbau der mit dem jeweiligen Schlüsselungsalgorithmus (S1-S9) verschlüsselbaren Datenpakete festlegt und den Aufbau des zu verschlüsselnden Datenpakets vor der Ausgabe an den jeweiligen Datenverarbeiter (61-66) unter Verwendung der wenigstens einen Formatvorschrift an den jeweiligen Schlüsselungsalgorithmus (S1-S9) anpasst.
- 17Datenverarbeitungssystem (11;12;13) nach Anspruch 15 oder 16, wobei die Steuereinrichtung (81;82;83) weiter automatisch aus der Speichereinrichtung (41, 41';42;43, 43') eine Schlüsselformatvorschrift des in der jeweiligen Verschlüsselungsstufe zu verwendenden Schlüsselungsalgorithmus (S1-S9) ausliest, wobei die wenigstens eine Schlüsselformatvorschrift einen Aufbau der mit dem jeweiligen Schlüsselungsalgorithmus (S1-S9) verwendbaren Kodierschlüssel (K1-K9) festlegt und die Schlüsselformatvorschrift bei der Bestimmung des in der jeweiligen Verschlüsselungsstufe zu verwendenden Kodierschlüssels (K1-K9) berücksichtigt.
- 18Datenverarbeitungssystem (11;12;13) nach einem der Ansprüche 11 bis 14, wobei die Steuereinrichtung (81;82;83) beim Empfang von zu entschlüsselnden mehrfach verschlüsselten Datenpaketen automatisch wenigstens eine dem Datenpaket zugeordnete unverschlüsselte Schlüsselungs-Charakteristik detektiert, welche Schlüsselungs-Charakteristik wenigstens einen Schlüsselungsalgorithmus (S1-S9) und einen zugeordneten Kodierschlüssel (K1-K9) angibt und den wenigstens einen Datenverarbeiter (61-66) so steuert, dass dieser das zu entschlüsselnde Datenpaket sequentiell in wenigstens zwei aufeinander folgenden Entschlüsselungsstufen unter Verwendung des in der wenigstens einen Schlüsselungs-Charakteristik angegebenen wenigstens einen Schlüsselungsalgorithmus (S1-S9) und zugeordneten Kodierschlüssels (K1-K9) entschlüsselt.
- 19Datenverarbeitungssystem (11;12;13) nach Anspruch 18, wobei die Steuereinrichtung (81;82;83) vor der Ausgabe des verschlüsselten Datenpakets als mehrfach verschlüsseltes Datenpaket bzw. des entschlüsselten Datenpakets als mehrfachentschlüsseltes Datenpaket weiter automatisch das verschlüsselte Datenpaket bzw. das entschlüsselte Datenpaket an ein Format des empfangenen unverschlüsselten Datenpakets bzw. des empfangenen verschlüsselten Datenpakets anpasst.
Independent claims19
150 paragraphs, as filed
p0001The present invention relates to a process for encryption or decryption of data packets of a data stream as well as a signal sequence and a data processing system for executing the method.
p0002The increasing globalization of business means that both different company locations as well as locations of suppliers and customers are often spread all over the world. To enable data exchange between these parties, different types of transmission networks such as Telephonnetzwerke, wireless networks or computer networks (such as the World Wide Web / Internet) are used. The same applies for data exchange between private or public institutions.
p0003The transmission networks mentioned above, it is disadvantageous that an experienced third comparatively easily intercept the data transmitted, read along and / or manipulate. This is problematic since often sensitive data, which may for example comprise a trade secret is exchanged over the network.
p0004To solve this problem, it is known that the data to be exchanged are encrypted before transmission over the network by a transmitter using a coding key and a coding algorithm. The encrypted data is transmitted via the transmission network and decoded by a receiver using the same respective coding key and coding algorithm to obtain the original data. The coding and the coding algorithm are chosen such that the encrypted data for an unauthorized third party who does not know the coding and / or coding algorithm, are difficult to decrypt. In order to achieve a certain degree of security, the coding and / or coding algorithm therefore may be known only to the sender and authorized recipient.
p0005The respective security depends, inter alia on the type of the coding algorithm used and the length of the coding key used. Is understood to coding and coding algorithm, a between the transmitter and receiver individually agreed key or algorithm which does not depend on a particular network protocol, operating system, or the like of the transmission network used. Such dependence is given for example, in an SSL connection in combination with a VPN connection. For SSL connections and VPN connections the type of algorithm used is provided independently in a respective configuration file, so that, if necessary, also used in two of the same algorithm.
p0006The problem with the above-described transfer of encrypted data that encrypt and decrypt data using a coding key and a coding algorithm requires a certain expertise and partly is very time consuming. As a result, data is often not required encryption even when sensitive.
p0007Next has been shown in the past that it unauthorized third parties due to the ever-increasing power of computers getting faster manages to decrypt using a coding key and a coding algorithm encrypted data without knowing the coding key and / or coding algorithm used. This problem is amplified by the so-called "grid computing," in which the force required to overcome a coding algorithm or coding key computing power is provided by a plurality of distributed computer over a network.
p0008To solve this problem it is known from <patcit id="pcit0001" dnum="WO8701483A"><text>WO 8701483</text></patcit> known, one behind the other for encrypting data to be encrypted more than once with the same coding algorithm and different coding keys.
p0009document <patcit id="pcit0002" dnum="US2002107001A"><text>US 2002 107001</text></patcit> discloses a method for encrypting data, soft are used in two consecutive levels of encryption.
p0010However, this approach has the disadvantage that the security of the encrypted data is significantly reduced, despite the multiple encryption when there is an unauthorized third party managed to obtain knowledge of the coding algorithm and its overcoming. Determining the different coding is then comparatively simple.
p0011Further, it is to solve this problem from the <patcit id="pcit0003" dnum="WO0026791A"><text>WO 0026791</text></patcit> known to divide the data to be encrypted in part to encrypt data and the partial data each with different coding algorithms.
p0012This has the advantage that only the security of the corresponding portion of data is reduced if an unauthorized third party knowledge of one of the coding algorithms used and its overcoming received. Nevertheless, an unauthorized third party can then comparatively easily become aware of these partial data. This may already be extremely harmful to sensitive data.
p0013Based on the above problems, an automatic encryption of data to be transmitted by a hardware is currently only be achieved with significant disadvantages, because the hardware needs to be quickly outdated, and then replaced.
p0014Proceeding from this, it is an object of the present invention to provide a method for encryption and decryption of data packets of a data stream, which can be difficult to overcome by unauthorized third parties even with increasing computing power, and so has a particularly high level of security.
p0015It is another object of the present invention to provide a signal sequence and a data processing system for implementing the method, which have a particularly simple, inexpensive and reliable construction.
p0016The above object is achieved by a method of encrypting data packets of a data stream with the features of independent claim 1.
p0017Further, the above object is achieved by a method for decrypting multi-encrypted data packets of a data stream with the features of independent claim 1.
p0018In addition, the above object is achieved by a signal sequence, preferably in the form of a computer program product that causes the execution of the method according to one of claims 1 to 9, when used in a data processor (in particular, a microprocessor) is a data processing system loaded.
p0019Finally, the above object is achieved by a data processing system, said data processing system receives at least the data packets of a data stream, the received data packets is processed in accordance with a predetermined rule, and programmed and adapted to perform the method of any of claims 1 to 9.
p0020Advantageous developments can be found in the respective dependent claims.
p0021According to the present invention, a method of encrypting data packets of a data stream in which a to be encrypted data packet is automatically encrypted sequentially in at least two subsequent encryption stages, comprising the steps of: determining the number, type and order of the subsequent encryption stages to used different coding algorithms. Determining to be used in the subsequent encryption stages of different coding keys. Assigning each one coding key each to one coding algorithm each in one encryption stage and sequentially encrypting a data packet to be encrypted in at least two subsequent encryption stages to obtain a multi-encrypted data packet.
p0022Thus, to receive encrypted data packets in the inventive process and issued by sequential passage through multiple levels of encryption with different coding algorithms and coding keys as multiple encrypted data packets.
p0023The process of the invention is in principle suitable for encrypting files: Uploaded files consist of a data stream of data packets. The size of a file is finite and dependent variable of a relevant content of the file. The size is limited only by an underlying file system. Data packets on the other hand have a fixed maximum size, which (for example, an operating system) depends on the data packets processing algorithms. If the allowable size of a data packet is exceeded, it must be segmented, ie split into at least two new data packets.
p0024The data packets to be processed can thereby be as complete data packets, ie a purely attributable to a respective used transmission protocol protocol data part and the other data comprises payload containing. Alternatively, the data packets to be processed can be only separated by their log data part Nutzdatenteile.
p0025To make sure that the encryption is carried out successively in at least two levels of encryption, a counter can be provided for example, which is set at the beginning of the process to zero and is incremented after each encryption level. Based on this counter can be determined by comparing whether a specified number of different levels of encryption was run consecutively.
p0026It is emphasized that the determination of the sequence does not have to be carried for each data packet, but the order may be made permanent once.
p0027According to a further preferred embodiment, the method comprises the steps of creating an unencrypted coding characteristic for the multi-encrypted data packet, and of outputting the coding characteristic together with the multi-encrypted data packet. Here, the coding characteristic is at least at the last time coding algorithm used and the assigned coding.
p0028The output of the coding characteristic causes together with the multi-encrypted data packet, express or implied assignment of the coding characteristic to the multi-encrypted data packet. An explicit assignment can be made for example by express designation of the associated multi-encrypted data packet. An example of an implicit mapping is a temporal correlation of the output of the coding characteristic and the output of the multi-encrypted data packet. It is important to emphasize that the coding characteristic neither the at least one coding algorithm still contains at least one coding key, but this refers only. This can be done for example by specifying a particular name of at least one coding algorithm used and at least one assigned coding key. The steps of creating and outputting the coding characteristic can be selectively performed in a higher-level separate device.
p0029It may be advantageous, if the method of encrypting comprises the step of adding the created unencrypted coding characteristic for the respective encrypted data packet in each encryption level.
p0030In this case, each coding characteristic is preferably only the coding algorithm used in the respective current level of encryption and assigned coding. The addition of the coding characteristic to the respective encrypted data packet is explicitly only optional. Alternatively, the coding characteristic may for example be issued along with the encrypted data packet in each level of encryption to encrypt.
p0031It may be advantageous if each encryption step of the process according to the invention comprises the steps of determining at least one formatting instruction of the coding algorithm used in the respective encryption stage, and of matching the structure of the data to be encrypted packet to the respective coding algorithm using the at least one formatting instruction. The at least one formatting instruction defines a structure for encryptable with the respective coding algorithm packets.
p0032Thus, the format instruction is one of a respective coding algorithm abhängende provision for processable by the respective algorithm input data. An example of such a format instruction is z. B. the block size of the data to be processed etc ..
p0033In this case, adjusting the data to be encrypted packet preferably include: segmenting the data to be encrypted packet in several part to be encrypted data packets. Using the partial data packets instead of the data to be encrypted packet. Creating an unencrypted segmenting characteristic to be encrypted part data packets, wherein the segmenting characteristic designated partial data packets obtained by segmenting a single data packet and outputting the segmenting characteristic together with the segmented to be encrypted part data packets.
p0034This may be necessary, since the encrypted data packet in response to a respectively used coding algorithm in each encryption stage can be greater. Without providing a segmentation is therefore a danger that provided in each level of encryption Buffer or a centrally provided, for example, the data transfer buffer for the encrypted data packets is too small. As a result, the size of the data to be encrypted packet is preferably automatically adjusted in any level of encryption to a coding algorithm that is used.
p0035Alternatively, it is also possible to estimate an expected maximum size of the multi-encrypted data packet before passing through the first encryption stage or during passage through the first level of encryption. This may for example be effected, be that multiplied in the respective levels of encryption depending expected from a respective coding algorithm magnification factors together. As a result, the data to be encrypted packet are already segmented at the beginning based on the format requirements of various coding algorithms automatically so that maximum packet sizes of to be encrypted by the different coding algorithms, data packets are not exceeded.
p0036Alternatively, the outputting of the segmenting characteristic can also be done for all levels of encryption together at the end of multiple encryption of data to be encrypted packet. Further, the segmenting characteristic are added to the multi-encrypted data packet optionally in each encryption stage to the part to be encrypted data packets or at the end of the multiple encryption.
p0037Further adjusting the data to be encrypted packet can be a Create a block of data containing the data to be encrypted packet and a block characteristic, wherein the block characteristic identifies the data to be encrypted packet in the data block, and include using the data block instead of the data to be encrypted packet , This known under the term "padding" approach results in response to a respective format provision of a respective coding algorithm to data blocks whose size is a multiple of a block size of the respective coding algorithm. For this, a data block to be encrypted at its end, for example, as long as with other characters (such as random data or predetermined data) are replenished until the respective block size is reached. The number of filled characters is then recorded in the form of block characteristic. Optionally, the block characteristic to be added each data block as the last character (byte) of the data block.
p0038According to one embodiment, the method may further comprise in each case a partial coding key each to one coding algorithm each in one encryption stage, a dividing a master coding key into several different sub-coding and assigning.
p0039This is particularly useful in conjunction with the coding characteristic described above. In this case, may be given (for example, a predetermined random number space existing) main coding permanently. By means of the at least one coding characteristic can be specified areas of the main coding key, each corresponding to a partial coding.
p0040Determining the to be used in the subsequent encryption stages different coding may comprise a coding format instruction of to be used in the respective encryption level coding algorithm further includes determining at least, said at least specifies a coding format instruction a configuration of the usable with the respective coding algorithm coding. A typical example of a coding format instruction are the minimum and maximum length of a usable coding key. Subsequently, the coding format instruction can be considered in the determination of to be used in the respective encryption level coding key.
p0041According to one embodiment, at least one level of encryption comprising the steps of: adding random data to the data to be encrypted packet before encryption. Use of the random data having data packet instead of the data to be encrypted packet. Creating a random data characteristic to which the random data having data to be encrypted packet, the random data characteristic indicates a container filled with random data area of having the random data to be encrypted data packet and outputting the random data characteristic, together with the random data having data to be encrypted packet.
p0042Due to the addition of random data in each different encrypted data packets are obtained if an identical data packet using an identical key algorithm and an identical coding key is encrypted in steps identical to, but at different times. Adding random data thus serves to obfuscate a coding algorithm and coding used in the encrypted data packet. In this case, a container filled with random data area can be easily identified in the data to be encrypted package due to the use of random data characteristic. The random data characteristic can optionally be output together at the end of the last level of encryption for all encryption levels or at the end of each level of encryption for this level of encryption. The output can be carried out separately from the data to be encrypted packet. Alternatively, the random data characteristic can be added to the data packet to be encrypted as well.
p0043In order to check the integrity of the encrypted data packets during a subsequent decoding, at least one encryption step ahead of the encryption can further comprise the steps of calculating a control value for the data to be encrypted packet, and of outputting the control value together with the data to be encrypted packet.
p0044In this case, the control value can be calculated mathematically, preferably from the data to be encrypted packet. This can be done for example by means of a "hash algorithm" or "checksum algorithm". The output of the control value can be done either separately from the data to be encrypted packet. Alternatively, the control value can be added to the data to be encrypted package also. The output can be done either at the end of the last level of encryption in common for all encryption levels or at the end of each level of encryption for this level of encryption.
p0045According to the present invention, a method of decrypting multi-encrypted data packets of a data stream comprises the steps of: detecting at least one of the multi-encrypted data packet associated unencrypted coding characteristic, which coding characteristic specifying at least one coding algorithm and one assigned coding and sequentially decrypting the to decrypting the data packet in at least two successive decryption steps using the specified in the at least one coding characteristic at least one coding algorithm and assigned coding key supplied.
p0046The assignment of the coding characteristic to the encrypted data packet can be carried out either explicitly (eg, by reference to the associated data packet) or implicitly (for example, by temporal correlation of receiving coding characteristic and encrypted data packet). Alternatively, a separate transmission of the coding characteristic, these may be the encrypted data packet also added unencrypted.
p0047The coding characteristic can be common for all decoding stages. In this case, the coding characteristic is in addition to the order of the to be used coding algorithms and assigned coding.
p0048Alternatively it may be provided separately for each decoding step, the coding characteristic. In this case, each decoding stage a comprise the steps of detecting the respective associated data to be decrypted packet unencrypted coding characteristic and of decrypting the data to be decrypted packet in the respective level of decryption using the respectively indicated in the detected coding characteristic coding algorithm and assigned coding key. In this case, therefore, it is not necessary that the coding characteristic a rich sequence to be used coding algorithms and assigned coding indicating explicitly.
p0049At the end of a respective decoding stage corresponds to the decrypted data packet, preferably to the original data packet, which was encrypted by the coding algorithm and coding key to form an encrypted data packet.
p0050In this case, at least one decryption stage comprises the following steps: detecting the data packet associated unencrypted segmenting characteristic, wherein the segmenting characteristic called data packets, the segments of a single whole data packet as is. Form of the total data packet based on the decrypted data packets and the segmenting characteristic after decryption and use of the total data packet instead of the data packet. Depending on the contents of the segmenting characteristic, the above steps may be performed selectively in each decoding step or after completion of all decoding stages.
p0051Further, it may be advantageous if at least one decryption step includes detecting an unencrypted block characteristic in the data packet after decryption, the block characteristic in the data packet identifies a method to be used in further data packet.
p0052This step may be provided in each level of decryption. Using algorithms with the same block size, this step may be, however, alternatively be provided jointly for all decoding stages, and are executed after all decoding stages. Then, a swelling of the data packets is avoided by adding the block characteristic, since the block characteristic is added to the data to be decrypted only once.
p0053Next, the steps of dividing a main coding key into several different sub-coding in dependence on the respective coding characteristic and of associating each of a sub-coding key to a respective coding algorithm in each of decryption stage in dependence on the respective coding characteristic in the be provided according to the invention process. The costs associated with the splitting of a main coding key into several sub-coding advantages have already been explained above.
p0054Also, at least, a decryption step include: detecting the data packet associated unencrypted random data characteristics, wherein the random data characteristic indicates a container filled with random data field of the data packet, and removing the random data from the data packet after decryption using the detected random data characteristic. Depending on the content of the random data characteristic can be made common to all decoding steps, this step optionally in each decoding step or after completion of all decoding stages.
p0055It may be advantageous if at least also comprising a decryption step after decrypting the steps of detecting a data packet associated control value, calculating a check value by using contained in the data packet data, and of comparing the control value with the check value. Then the data packet is preferably rejected if the check value does not match with the check value, because the integrity or correct decryption of the data packet is not ensured.
p0056It is important to stress that the notion of discarding the data packet is not to be interpreted restrictively in the form that the data packet is, for example, be deleted immediately. Alternatively, it may be sufficient to mark the data packet, for example, by adding a marker to be faulty or warping. About the further processing of a provided with a corresponding marker data packet can then be decided later. For example, can not be forwarded, are not further processed or deleted the selected data packet.
p0057In general, it can be advantageous if the coding characteristic specifying the order of all the coding algorithms used in the context of sequential encryption or decryption in the different levels of encryption or decryption steps associated with the respective coding keys. In this case, the coding characteristic need not be separately provided for all the different levels of encryption or decryption steps. In this way, unnecessary inflation of the data to be processed due to the dispensing / addition of the coding characteristic is avoided. In the simplest case, an indication of the order can be done by simple enumeration of the coding algorithms descriptive name.
p0058It may be advantageous if the output of coding characteristic, segmenting characteristic and random data characteristic for a data packet to be encrypted is carried out together as a collective characteristic.
p0059Such collective characteristic then contains all the encryption and decryption key information and can optionally be processed by a higher-level entity / device. The collection characteristics can be controlled separately for all encryption and decryption stages or be common for all successive encryption or decryption steps.
p0060Generally it can be provided that a product obtained under a previous level of encryption of sequential encryption encrypted data packet is in a subsequent encryption level of sequential encryption to be encrypted data packet. Accordingly, it can be provided that an image obtained in a previous decoding stage of the sequential decoding data packet is to be decrypted in a subsequent decryption stage of the sequential decoding data packet.
p0061A particularly high degree of safety is achieved if the different coding algorithms and / or coding keys are independent. This means that the different coding algorithms and / or coding keys are not, for example, by mathematical methods from each derivable.
p0062Examples of suitable coding algorithms are Blowfish, AES, DES, 3DES, and Twofish. An example of suitable different coding keys are random numbers. It is emphasized that the present invention however is not limited to these examples.
p0063The above object is also achieved by a signal sequence which causes the embodiment of the method according to one of claims 1 to 20 when it is loaded into a data processor, in particular a microprocessor, a data processing device. Such signal sequence may be retrieved stored for example in the form of a computer program product on a data carrier or via a transmission network.
p0064Further, the above object is achieved by a data processing system, said data processing system receives data packets of a data stream and at least processes the received data packets according to a predetermined rule. In this case, the data processing system according to the invention is programmed and adapted to perform the method of any of claims 1 to twentieth
p0065The above steps can be performed either by a common data processing system, or else by the Parent or child data processing systems. For example, a superordinate data processing system may be provided (ie, a higher authority), which creates and detects the coding characteristic.
p0066According to a first embodiment of the data processing system includes a memory device in which at least two different coding keys are stored, at least two data processors, each having a solid-coded logic circuitry, the circuit logic implemented each with different coding algorithms for processing a data packet received using a coding key and a switching network to selectively serially connecting the data processor, the sequence can be changed. Further, the data processing system comprises a control device which controls the switching network and the at least two data processors, at least receives the data packets of the data stream and outputs it to a first of the at least two data processors, and reads from said memory means different coding and outputs them to the data processor.
p0067Thus may comprise a plurality of serially interconnectable variable, hard-coded logic circuits of the data processing system according to the first embodiment, respectively implement different coding algorithms, thus causing an encryption or decryption of data packets to be processed in circuit technology successive stages. It is emphasized that the memory device, a simple input buffer (a buffer is a memory for temporary storage of data) may be to temporarily store received coding via a separate input interface. The storage device does not have to be permanently integrated into the data processing system, but may also be a connectable via an interface to the data processing system separate storage medium.
p0068In this embodiment, it may be advantageous if each data processor has a buffer for temporarily storing processed data packets, the size of the buffer depends on a particular application of the data processing system of the invention.
p0069The provision of the buffer, the circuit logic can operate substantially independent of each other and thus also at the same time. This possibility of parallel processing of different data packets in different logic circuits, and thus different processing steps is just in the processing of data packets of a data stream of great importance, since new data packets of the data stream to be received and processed.
p0070The adaptation of a respective buffer of the particular application of the data processing system of the invention can take many forms. For example, an adaptation to the size of the of the data processing system according to the invention from the outside (for example from a transmission network or a computer program) received data packets. But as an implemented by the respective data processors coding algorithm can only handle a given block size at a time, the adjustment can for example also be made to the block size of the respective coding algorithm.
p0071According to a second embodiment of the data processing system includes a memory device in which at least two different coding keys and at least two different coding algorithms are stored, at least two data processors, each having a programmable logic for processing received data packets, and a connecting network, which the data processor serially predetermined with a sequence connects. Further, the data processing system comprises a control device which controls the at least two data processors, reads out from said memory means different coding algorithms and programs the logic circuits of the data processors accordingly, at least receives the data packets of the data stream and outputs it to a first of the at least two data processors, and different from the storage device encoding key and dumps the data processors. The programmed according to a respective coding algorithm logic circuits of the respective data processors process the respective data packets received using the respective coding key received.
p0072Thus, the data processing system according to the second embodiment, a plurality of interconnected serially fixed, but have freely programmable logic circuits. Also in this embodiment, the storage device, for example, be an input buffer or be in the form of a connectable via an interface to the data processing system storage medium. By programming the controller, the logic circuits of the data processor according to different coding algorithms and controls so that the respective data processors process the respective received data packets using the respective received coding key, encryption and decryption of the processed data packets is effected in circuit technology successive stages.
p0073It may be advantageous if each data processor further comprises at least an input interface for receiving data to be processed packets and an output interface for outputting processed data packets, wherein at least the output interface of the first data processor via the switching network and the connection network with the input interface of a second data processor is connected.
p0074In other words, the control means controls the switching network so that the various data processors are connected in series one behind the other. As a result, the data to be processed through successively more data processors.
p0075According to a third embodiment of the data processing system includes a memory device in which at least two different coding keys and at least two different coding algorithms are stored, and a data processor with a programmable logic circuit for processing received data packets. Further, the data processing system comprises a control device, which the data packets of the data stream receiving at least, from the memory device reads out sequentially in time different coding algorithms and programs the circuit logic of the data processor accordingly, and from the memory device reads out sequentially in time different coding and, together with data to be processed to the data processor outputs , The controller continues to receive from the data processor using the respective coding key and key algorithm processed data. The control means outputs the data received from the data processor processed data at least once to the data processor and controls it so that the data processor after the other processes a signal received from the control device to be processed the data packet at least twice in time using different coding algorithms, and different coding keys.
p0076Thus, the data processing system having only according to the third embodiment, a single programmable data processor. In this case, the data to be processed packets are successively processed using different coding algorithms and coding by the programmable logic circuit of the data processor and is encoded as in several consecutive steps or decrypted. Also in this embodiment, for example, be an input buffer memory means, or be in the form of a connectable via an interface to the data processing system separate storage medium.
p0077If it is in the data to be processed to be encrypted data, it may be advantageous in all three embodiments, when the control device upon receipt of a data to be encrypted packet automatically a number, type and preferably sequence of successive levels of encryption (ie circuitry or successive following processing operations determined by the at least one data processor) to use different coding algorithms, determined in the successive levels of encryption to use different coding and each assigns a coding to a respective coding algorithm in each case a level of encryption. The control means further controls the at least one data processor accordingly to obtain a multi-encrypted data packet. Next, the controller automatically creates an unencrypted coding characteristic which coding characteristic specifying at least the coding algorithm time last used and the assigned coding, and outputs the coding characteristic of along with the multi-encrypted data packet.
p0078Preferably, the output of the coding characteristic can be configured such that an implicit or explicit allocation of the coding characteristic to each data packet takes place. The output can be carried out in each encryption level separately in each encryption level or for all levels of encryption together at the end of the last level of encryption. As an alternative to a separate issue, the controller generated unencrypted coding characteristic example automatically add to the respective encrypted data packet and so make an association.
p0079If it is in the data to be processed, however in order to decrypt data, it may be advantageous in all three embodiments, when the control device when receiving to decrypt multiple encrypted data packets automatically detects at least one data packet associated unencrypted coding characteristic which coding characteristic at least one coding algorithm and assigned coding indicates. Then, the controller controls the at least one data processor such that it sequentially of decrypts the decipherable data packet in at least two successive decoding stages using in the at least given a coding characteristic at least one coding algorithm and assigned coding key.
p0080The coding characteristic can be provided separately optional for all decoding steps together or for each decoding step. If the coding characteristic common to all decoding stages, it can be advantageous if the coding characteristic specifies a sequence to be used coding algorithms.
p0081Hereinafter, preferred embodiments of the present invention with reference to the accompanying drawings will be briefly described. Where the same or similar reference numbers will be used throughout the drawings to refer to the same or similar elements. In which:<dl id="dl0001" compact="compact"><dt>figure 1</dt><dd>schematically shows the construction of a communication network in which the present invention finds the data processing system use;</dd><dt>figure 2</dt><dd>schematically shows the construction of a data processing system according to a first preferred embodiment of the present invention;</dd><dt>figure 3</dt><dd>schematically shows the construction of a data processing system according to a second preferred embodiment of the present invention;</dd><dt>figure 4</dt><dd>schematically shows the construction of a data processing system according to a third preferred embodiment of the present invention;</dd><dt>figure 5</dt><dd>a flow diagram of a preferred embodiment of the method of encrypting data packets of a data stream;</dd><dt>figure 6</dt><dd>a flow diagram of a preferred embodiment of the method for decrypting multi-encrypted data packets of a data stream; and</dd><dt>Figure 7A, 7B</dt><dd>each a flow diagram illustrating the use of a control value.</dd></dl>
p0082In the following preferred embodiments of the inventive method and the data processing system according to the invention will be described with reference to the accompanying drawings. Since the data processing system of the invention is explicitly programmed and adapted to perform the inventive method described above, apparatus and method are considered together.
p0083In this case, data processing systems of the invention are particularly well suited for use in a communication network, as in <figref idrefs="f0001">figure 1</figref> is shown.
p0084In the communication network, a plurality of communication interfaces 31, 32, 33, 34, 35, 36, 37 connected to the mutual exchange of data via a communication network 20 together. In the example shown, the communications interfaces are 31-37 personal computer and the communication network 20, a TCP / IP network.
p0085Between the communication interfaces 31-36 and the transmission network 20 in each case an inventive data processing system 11, 12, 13, 14, 16 is arranged. 16 To connect to the transmission network 20 and the communication interfaces 31-36, the data processing systems 11-14, each have two interfaces 51 and 52nd The received data packets are processed in the data processing systems 11-16 according to a predetermined rule, as will be explained in the following.
p0086The data processing system 15 in this example is designed by a personal computer and, therefore, not specifically associated with a communication interface.
p0087Each data processing system 11-16 includes a memory device 40, 41, 42, 43, in at least two different coding keys K1-K9 are stored. Depending on the configuration of the data processing systems 11-16 can in the storage means 40, 41, 42, 43 in addition also at least two different coding algorithms S1, S2, S3 be stored. In the following examples are in the different coding keys K1-K9 to predetermined random data and the different coding algorithms S1, S2, S3 to the algorithms "Blowfish", "AES" and "Twofish". However, also any other, preferably conventional standardized algorithms.
p0088A similar communication network is described in the patent application filed on 21 September 2005 <patcit id="pcit0004" dnum="DE102005046462"><text>DE 10 2005 046 462</text></patcit>, Is made to the content of which expressly incorporated by reference, described. Note that the data processing systems of the invention 11-16 are preferably integrated into the network components described in this application. Then it may be advantageous if the data processing systems of the invention 11-16 not complete (ie a protocol data part and a payload containing) process data packets of the data stream, but only Nutzdatenteile.
p0089In the following, referring to <figref idrefs="f0002">figure 2</figref> the structure of a data processing system according to a first preferred embodiment of the present invention will be described.
p0090The data processing system 11 includes in addition to the memory means 41, 41 'and the interfaces 51, 52, two data processors 61, 62, a switching network 71 and a control device 81 on.
p0091As already indicated, the interfaces 51, 52 serve to receive or output, and thus to connect the data processing system 11 to the transmission network 20 and the communication interface 31 data packets of a data stream.
p0092In that in <figref idrefs="f0002">figure 2</figref> illustrated embodiment, the memory device is formed by a chip card 41 and therefore by a portable nonvolatile storage medium, are stored on the two different coding keys K1, K3. The smart card 41 is connected via a memory interface 41 'with the data processing system eleventh By changing the smart card 41 to the data processing system 11 various different coding can be provided.
p0093The two data processors 61, 62 each have a hard-coded logic circuit in the form of an FPGA (Field Programmable Gate Array), which implement the different coding algorithms S1, S3 "Blowfish" and "Twofish". Further, each data processor 61, 62, a buffer 91, 92 for temporarily storing processed data packets on. The size of the buffers 91, 92 respectively received at a size of the data processing system according to the invention of the of the transmission network 20 or the communication interface 31 data packets (eg. B. 1500 characters) is adjusted. However, the present invention is not limited thereto. For example, can also be done on a processable with each implemented coding algorithm S1, S3 maximum block size of data packets (eg., 64 characters or 128 characters) adaptation.
p0094The two data processors 61, 62 are selectively connectable in series via the switching network 71st In the present example, the switching network 71 may the two data processors 61, 62 interconnected so that either the sequence data processor 61 followed by data processor 62 or data processor 62 followed by data processors 61 results.
p0095The control device 81, which is a microprocessor in the present example, controls the switching network 71 and the two data processors 61, 62. In <figref idrefs="f0002">figure 2</figref> is the control of the two data processors 61, 62 (for example by transmission of coding keys K1, K3) shown with a dashed line, whereas the solid lines represent connections via which data packets (and possibly control commands) to be transported. Next, the controller 81 receives via the interfaces 51, 52 to processing data packets of the data stream.
p0096In this case (S10) automatically determines the control device 81 upon reception of a data to be encrypted packet from the communication interface 31 via the interface 51, the order of the successive levels of encryption to use different coding algorithms S1, S3 and thus the required for encryption connection of the two data processors 61, 62. In the present case, the interconnection means of the switching network 71 should be such that the data processor 62 to the data processor 61 precedes. Further reads the control device 81 via the memory interface 41 'of the chip card 41, the two different coding keys K1, K3, and outputs each one of the two encoding key K1, K3 to one of the two data processors 61, 62 from (S13). Since the two data processors 61, 62 permanently implement only a respective coding algorithm S1, S3, the selection of an appropriate key length by the controller 81 is easily possible. The controller 81 determines to be used in the subsequent encryption stages coding K1, K3 accordingly (S12). The coding keys K1, K3 are each a coding algorithm S1, S3 of a data processor 61, 62 and thus a level of encryption assigned (S13).
p0097determined with reference to the set to be used coding algorithms S1, S3 (S14), the controller 61 then S3 automatically a format specification, which defines for each coding algorithm S1, a structure of encryptable with the respective coding algorithm S1, S3 data packets. The controller 61 automatically adjusts the structure of the data to be encrypted packet using the at least one formatting instruction in this embodiment, so that the data packet with the formal requirements of both coding algorithms S1, S3 corresponds to (S15).
p0098When the data to be encrypted packets are larger than a defined maximum packet size or encrypted by the first data processor 61 data packets will be greater than the defined maximum packet size, this customize the data to be encrypted packet includes a segmenting the data to be encrypted packet into several to Encrypting data packets and a portion using the partial data packets instead of the data to be encrypted packet. In this case, the controller 61 automatically creates an unencrypted segmenting characteristic, which is part of data packets denoted which have been obtained by segmenting a single data packet. In the embodiment shown, the control means controls the segmenting characteristic adds 61 automatically to the respective segmented sub-data packets is added, and so they made together with the segmenting characteristic.
p0099If the size of the buffers 91, 92 is (unlike in this embodiment) adapted to the maximum processable at once block size of the implemented by the data processor 61, 62 coding algorithms S1, S3, so the segmentation can be done, for example, if the data to be encrypted packets larger than the block size of coding algorithms or will be after encryption by the first data processor 61st
p0100If the size of data to be encrypted packet equal to a multiple of the maximum processable at once block size of the respective coding algorithm to customize the data to be encrypted packet includes filling the data to be encrypted block by the controller 61 at its end with characters until the respective nearest multiple of block size is reached. In parallel, the controller 61 creates a block characteristic which identifies the data packet to be encrypted in the data block, and adds it to the data block. Then uses the controller 61 these adjusted data block instead of the data to be encrypted packet.
p0101Subsequently, the control means 81, the data to be encrypted packet through the switch network 71 to the first of the two data processors 61, 62 from. After encrypting are the first data processor 62 simply encrypted data packet over the switch network 71 to the second data processor 61 from. After encryption is the second data processor 62, the doubly encrypted data packet through the switch network 71 to the controller 81 from. In this way a sequential encryption of the data packet causes (S16). Since the data processors 61, 62 are hard-wired in series, not necessary to consider whether all encryption levels were passed (S17).
p0102The controller 81 automatically creates a the twice-encrypted data packet associated unencrypted coding characteristic which the type and sequence of the coding algorithms used by the data processors 61, 62 S3, S2 and the assigned coding K3, K1 clearly indicates (S18). This information is provided in this example in the form of the word "Two3Blow1" to indicate that the data first with the key algorithm S3 "Twofish" and the coding key K3 and were then encrypted with the key algorithm S1 "Blowfish" and the coding key K1. Thus enables the coding characteristic together with the key algorithms and a coding keys decrypt the data.
p0103Finally, the control means 81, the coding characteristic coinciding with the twice-encrypted data packet via the interface 52 to the transmission network 20 from (S19) and thus establishes an implicit association with the encrypted data packet. Alternatively, this mapping can be explicitly.
p0104When receiving a to be decrypted twice-encrypted data packet from the communication network 20 via the interface 52, the control means detects 81 automatically to the data packet associated unencrypted coding characteristic (S20), indicating the type and sequence of the coding algorithms used in the encryption and assigned coding. In this example it is assumed that the coding characteristic "Two3Blow1" is to indicate that the data packet first with the key algorithm S3 "Twofish" and the coding was K3 and then encrypted with the key algorithm S1 "Blowfish" and the coding key K1 , It is evident that the decoding must be carried out in reverse order.
p0105Alternatively, the coding characteristic even further abstracted (eg in the form of a numerical code).
p0106Both the two coding algorithms S1, S3 and the two coding keys K1, K3 are the data processing system 11 of the invention Known in this example. Otherwise, decryption would not be possible by means of the data processing system eleventh
p0107Depending on the coding characteristic, the control device 81 controls the switching network 71 so that the data processors 61, 62 in accordance with serially connected in series, and outputs the to be decrypted data packet via the switching network 71 from the first of the two data processors 61, 62nd After decrypting using the coding algorithm "Blowfish" and coding key K1 is the first data processor 61 simply decrypted data packet over the switch network 71 to the second data processor 62 from. After decryption using the coding algorithm "Twofish" coding key and K3 are the second data processor 62, the doubly decrypted data packet via the switching network 71 to the controller 81 from. Thus was doubly encrypted data packet depending on the coding characteristic sequentially in two successive decryption steps using different coding algorithms, and different coding keys decrypted (S21).
p0108Subsequently, the controller checks 81 whether the decrypted data in addition to the coding characteristic another characteristic, for example, a segmenting characteristic or a block characteristic is assigned (S22, S25). In the present example, the assignment is made explicit and together with the coding characteristic in a separate record containing the further characteristics. Alternatively, these other characteristics may be the data packets also added directly as assigned.
p0109If the decrypted data is not assigned to another characteristic, the control device 81 the doubly decrypted data packet via the interface 51 to the associated communication interface 31 from (S28).
p0110Detected, the controller 81, however, a data packet associated unencrypted segmenting characteristic, wherein the segmenting characteristic called data packets, the segments of a single whole data packet are (S22), the controller 81 decrypted with reference to the data packets and the segmenting characteristic initially forms the total data packet ( S23). Subsequently, the controller 81 uses the total data packet instead of the decrypted data packet (S24) and outputs this via the interface 51 to the associated communication interface 31 from (S28).
p0111Detected, the controller 81, however, a data packet associated unencrypted block characteristic, wherein the block characteristic in the data packet to be used in the further process data packet indicates (S25), then uses the control device 81, the direction indicated by the block characteristic data packet (S26) and outputs this via the interface 51 to the associated communication interface 31 from (S28).
p0112It is obvious that can be dispensed with the use of the coding characteristic when the data processors are interconnected permanently connected in a predetermined sequence and the different coding keys are assigned to the data processors permanently. In such a case, it is sufficient to use for the encryption and decryption data processing systems of identical construction. Even if possible to dispense with the coding characteristic, in this case, may optionally further be required using the segmenting characteristic and / or the block characteristic. The reason is that these characteristics can not be derived from the concrete structure of the data processing system.
p0113Hereinafter, referring to <figref idrefs="f0003">figure 3</figref> the structure of a data processing system according to a second preferred embodiment of the present invention will be described. It deals only with aspects that differ from the first embodiment.
p0114Unlike the first embodiment, the memory means 42 of the data processing system 12 of the second embodiment, a permanently in the data processing system 12 integrated non-volatile memory in the form of an EEPROM 42. In addition to different coding keys K1-K9 42 different coding algorithms S1-S9 are stored in the EEPROM. The coding keys K1-K9 are not separately stored in the EEPROM, but are in the form of a main coding key front, in which the controller can define 82 different areas, each corresponding to a (partial) coding K1-K9. This (partial) coding K1-K9 are used in the encryption or decryption. Accordingly, the coding characteristic indicates the areas used in the encryption of the main coding key to specify the encoding key.
p0115Unlike the first embodiment, the data processing system 12 has three data processors 63, 64, 65, each with a programmable logic circuit for processing received data packets. In the embodiment, the data processor 63, 64, 65 microprocessors that may be programmed and adapted to implement and execute as the coding algorithms S1-S9. Instead of the intended in the first embodiment, the switching network 71, a network connection 72 is provided which connects the data processors 63, 64, 65 in series with a predetermined order. Here, the data processor 63, 64, 65 so connected via the communication network 72, that an input interface 93 of a first data processor 63 to the control device 82, an output interface 94 of the first data processor 63 with an input interface 93 of a second data processor 64, an output interface 94 of the second data processor 64 is connected to an input interface 93 of a third data processor 65 and an output interface 94 of the third data processor 65 to the control device 82nd
p0116Consequently, does not set the controller 82 in this embodiment, the order of the to be used coding algorithms on the order of connection of the data processors 63, 64, 65, but by appropriately programming the data processor 63, 64, 65 firmly. For this purpose, reads the control device 82 from the storage device 42, three different coding algorithms S1, S2, S3, and programs the logic circuits of the data processors 63, 64, 65 accordingly (S10). Further reads the control device 82 from the storage device 42 has three different coding keys K1, K2, K3 and assigns a respective encoding key K1, K2, K3 a data processor 63, 64, 65 to (S13).
p0117For processing, the control device via a one of the interfaces 51, 52 received data packet of a data stream to the input interface 93 of the first data processor 63 from. The data packet is processed by the data processors 63, 64, 65 sequentially, that of a preceding data processor 63 obtained the data packet in the subsequent data processor 64 to be processed data packet (S16).
p0118The processing of data packets by the data processors 63, 64 and 65 is not different from the processing by the data processor 61, 62 of the first embodiment.
p0119As in the first embodiment, the control device 82 segment data packets or process a segmenting characteristic and processing data blocks, and a block characteristic.
p0120In addition, reads the control means 82 in this embodiment for the assignment of the coding keys K1, K2, K3 to the coding algorithms S1, S2, S3 from the memory device 42 automatically a coding format instruction of the to be used coding algorithms from (S11) showing a construction of using the respective coding algorithm usable coding sets.
p0121This coding format instruction is of the control means 82 in the determination of the partial coding keys K1, K2, K3 from the main coding (S12) and thus in the assignment of different coding keys K1, K2, K3 to the respective coding algorithms S1, S2, S3 ( S13) is used. In this example, the coding format instruction specifies the permitted for a respective coding algorithm S1, S2, S3 maximum key length of the respective coding key K1, K2, K3.
p0122Hereinafter, referring to <figref idrefs="f0004">figure 4</figref> the structure of a data processing system according to a third preferred embodiment of the present invention will be described. It deals only with aspects that differ from the first and / or second embodiment.
p0123Unlike in the previous embodiments, the memory device is in this embodiment made of a permanently integrated in the data processing system 13 the non-volatile EEPROM 43, in which at least two different coding algorithms, S2, S3 and two different coding keys K2, K3 are stored, and a buffer 43 '. In the buffer 43 ', the coding algorithms S2, S3 and the coding key K2, loading K3, if any device connected to the data processing system 13 input element (here a keyboard 96) by a user, a release by entering a secret code such as a PIN (personal identification number) takes place.
p0124Alternatively, it is also possible for example, that the input of the different coding is performed directly by the user via the input element. In this case, the coding need not be permanently stored in the data processing system according to the invention.
p0125Next, only one data processor 66 is provided with a programmable logic circuit in this embodiment. As in the previous two embodiments, the data processor 66 is designed to be set programmatically so that it processes a received data packet according to a predetermined coding algorithm S2, S3 and associated coding key K2, K3.
p0126The operation of the control device 83 corresponds substantially to the operation of the known from the preceding embodiments controllers.
p0127Unlike in the previous embodiments, however, the controller 83 causes a sequential processing of a data packet using different coding algorithms and associated different coding keys (S16, S21) the fact that it from the memory means 43, 43 'first of all a first coding algorithm S2 and a first assigned coding K2, reads and programs the circuit logic of the data processor 66 accordingly. Subsequently, the controller 83 outputs from the data to be processed packets to the data processor 66 and controls it so that it processes the data packets, first using the first coding algorithm and S2 of the first assigned coding key K2. The processed data is latched by the controller 83 in a buffer associated with this 95th Then reads the controller 83 from the memory means 43, 43 'a further, different to the coding algorithm S2 already used coding algorithm S3 and a further, different to the previously used first encoding key K2 coding key K3 and programs the circuit logic of the data processor 66 accordingly. Subsequently, the control means 83 from the temporarily stored in the buffer 95 data packets to the data processor 66 and controls it so that it processes the data packets using the new coding algorithm S3 and the new assigned coding key K3. The processed data is temporarily stored by the control device 83 again in the buffer 95th This procedure is repeated by the control device 83, until the desired number is achieved by processing steps. This can be monitored, for example by means of a counter.
p0128Unlike in the previous embodiments, the controller does not make the coding characteristic (S18) at the end of processing, but in the context of each processing step performed by the data processor 66th Next, the controller 83, the coding characteristic not separately at the end of (S19), but attaches it to the processed data packet directly in each processing step added. In this case, the order of the coding algorithms used and assigned coding need not be explicitly specified in the coding characteristic. Rather, the coding characteristic specifies only the coding algorithm used in each processing step and assigned coding. The other characteristics are processed by the controller 83 in the context of each processing step by the data processor 66 and added to the processed data packets.
p0129Next automatically adds the controller 83 for encryption of a data packet before each edition of the data to be encrypted packet to the data processor 66 random data to the data to be encrypted packet added. The controller 83 automatically creates a random data characteristic which indicates a container filled with random data field of having the random data to be encrypted data packet, and adds them to the data to be encrypted packet. Accordingly automatically the data packet associated unencrypted random data characteristic and removes the random data automatically using the detected random data characteristic of the data packet is detected, the control means 83 in decryption of a data packet according to any decryption.
p0130In addition, the controller automatically calculates 83 before each edition of the data to be encrypted packet to the data processor 66 a control value for the data to be encrypted packet (S30) and adds this control value added (S31) the data to be encrypted packet. This is in<figref idrefs="f0007">7A</figref> shown. In the present embodiment this is done using a hash algorithm.
p0131Accordingly, the controller 83 detects at a one decryption automatically with the data packet associated control value (S40) and calculated using data contained in the data packet a check value for the decrypted data packet (S41). Subsequently, the controller compares the check value with the check value (S42). The data package will be marked by the tax filing 83 automatically as to warping if the control value does not match the check value matches (S44). Otherwise, the data packet is re-used and is output, for example, to the data processor 66 or via the interface 51 to the communication interface 33 (S43). This is in<figref idrefs="f0007">7B</figref> shown.
p0132Although the use of the control value has been described above only in connection with the third embodiment, the present invention is not limited thereto. It is obvious that both the control value and the various characteristics of such. As the coding characteristic, the segmenting characteristic, the block characteristic and the random data characteristic can be used simultaneously or alternatively in all three embodiments. Further, this use of the control value and the characteristics can be carried out selectively in each of the successive processing steps or only in one of the successive processing steps (such as the first or last processing step).
p0133In the embodiments described above, only user data packets were received and processed by the data processing systems. However, if data packets are processed which have both a protocol data portion and a user data part, it is advantageous when the respective control device, the encrypted data packet or the decrypted data packet before outputting the encrypted data packet as a multi-encrypted data packet or the decrypted data packet as mehrfachentschlüsseltes data packet automatically adapts to a format of the received unencrypted data packet or the received encrypted data packet. In the simplest case it is sufficient to adapt the protocol data unit to the new size of the useful data.
p0134In all three embodiments, the different coding algorithms and coding keys are independent. This means that two or more coding algorithms or two or more coding without knowledge of all coding algorithms or coding keys not specifically mathematically derivable apart. This does not exclude that with knowledge of two coding keys and coding algorithms subsequently a mathematical relationship between the respective coding keys and coding algorithms can be made or there is accidental.
p0135The inventive method can be easily realized by a signal sequence and so a computer program product that causes the execution of the method according to one of claims 1 to 20, when loaded into a microprocessor of a data processing system. This one is easy to configure and simultaneously strong encryption is provided.
p0136Although above, the use of a variety of different characteristics will be described, the present invention is not limited to these characteristics. For example, an encryption or decryption stage depending on a coding algorithm used in each case additionally at least one setting an initialization vector for the respective coding algorithm include.
p0137In addition, the division of processing between the respective control device and the respective at least one data processor is not static but can be changed.
p0138Although in all three embodiments, the control device, the at least be described a data processor, the interfaces, the storage device and the switching network or carrier network as separate elements may be several or even all elements integrated into a common semiconductor device such as a microprocessor.
p0139The data processing system according to the invention can also be integrated in a total of a superior system, such as a personal computer, a digital telephone or fax, a modem, a network card or the like. In this case it may be advantageous if the data processing system of the invention operates independently of an operating system of the host system. Thereby, the operability of the data processing system of the invention is assured regardless of the superordinate system.
p0140As an alternative to a permanent storage of different coding keys and / or different coding algorithms in a memory device can also be provided that the data stored in the storage device different coding and / or different coding algorithms during maintenance, which can also be a remote maintenance can be replaced. This can for example also take place in that the coding algorithms and / or coding keys are stored on removable media. Then replacing the coding algorithms and / or coding can be done simply by changing the storage medium. This data processing system according to the invention can easily be adapted, for example, when the security of a coding key or coding algorithm has been overcome. Of course, it can be provided by different coding algorithms any number (greater than 2) of different coding keys and any number (greater than 2).
p0141Next is emphasized that the data processing system, additional (not shown) may include memory and auxiliary elements such as a power supply to support the functionality of the data processing system of the invention.
p0142Further, the above embodiments using symmetric coding keys and coding algorithms will be described. This also has a symmetry of different characteristics and in particular the coding characteristic result. However, the present invention is not limited thereto. Rather, asymmetric coding and coding algorithms can be used. As a result, important to distinguish between encryption coding keys and decryption coding keys and encryption algorithms and decryption algorithms. It is apparent to those skilled in the art that the different characteristics are to be adjusted accordingly to the asymmetry. As the skilled person not in principle differ from the inventive solution described above, but this must only adapt is no separate description.
p0143In summary, the present invention relates to a method of encrypting data packets of a data stream and for decrypting multi-encrypted data of a data stream, which provides increased security of the encryption, and by means of a signal sequence can be automated (a computer program product), or a data processing device. Here, a to be encrypted data packet or decrypted data to a packet is automatically encrypted sequentially in at least two successive processing steps using different coding algorithms and different associated coding key or decrypted. This results in an order-dependent processing steps encrypt or decrypt with increased data security.
p0144Here, the process from outside is preferably opaque. Consequently, the flow inside a data processing system according to the invention is preferably not detectable from outside. Rather, preferably the data processing system provides a "blackbox" represents that data to be processed and, if coding and / or coding algorithms and possibly additional data (characteristics) obtained and processed data, and additional data (characteristics) outputs.
p0145Here, the interfaces of the data processing system of the invention preferably do not differ from those of conventional encryptor / decryptor, which use the same coding algorithm, as used in the first processing stage of the data processing system. This facilitates a modular use of the data processing system of the invention. From the outside, the at least two consecutive stages act as a new encryption algorithm with increased efficiency. Accordingly, the coding characteristic may specify the name of the new encryption algorithm.
p0146The achieved high data security makes the data processor according to the invention and the inventive method as well as the signal sequence of the invention for use in a mobile / external communication of sensitive communications networks such as the transmission networks of banks or authorities particularly suitable.
p0147Due to the sequential use of at least two different coding algorithms, and different coding keys assigned to the inventive solution is even then adequate data security provided when one of the at least two coding algorithms and / or coding used is vulnerable to attack. Consequently, the risk of obsolescence in a hardware implementation is greatly reduced.
p0148It is emphasized that the present invention is not limited to the embodiments described above, but many variations are possible without the need to deviate from the claimed solution.
p0149In summary, the invention thus provides a method of encrypting data packets of a data stream, a corresponding method for decrypting multi-encrypted packets of a data stream, a signal sequence that causes the execution of these methods, as well as a data processing system to the corresponding processing data packets.
p0150Here, the method for encryption of data packets as follows can be described:<ol><li>1. A method of encrypting data packets of a data stream in which a data packet is to be encrypted is automatically encrypted sequentially in at least two subsequent encryption stages, comprising the steps of:<ul><li>Determining the number, type and order of to be used in the subsequent encryption stages of different coding algorithms;</li><li>Determining to be used in the subsequent encryption stages of different coding keys;</li><li>Associating each of a coding key to a respective coding algorithm in each case an encryption level; and</li><li>Sequentially encrypting a data packet to be encrypted in at least two subsequent encryption stages to obtain a multi-encrypted data packet.</li></ul></li><li>2. The method of item 1, further comprising the steps of:<ul><li>Creating an unencrypted coding characteristic for the multi-encrypted data packet, which coding characteristic specifying at least the coding algorithm temporally last used and the assigned coding; and</li><li>Outputting the coding characteristic together with the multi-encrypted data packet.</li></ul></li><li>3. The method of item 2, further comprising<ul><li>Adding the generated unencrypted coding characteristic in each encryption stage after encryption to the respective encrypted data packet.</li></ul></li><li>4. The method according to any one of the preceding points, each level of encryption includes:<ul><li>Determining at least one formatting instruction of the coding algorithm used in the respective encryption stage, said a format instruction specifies at least one structure of encryptable with the respective coding algorithm packets; and</li><li>Adjusting the configuration of the data packet to be encrypted to the respective coding algorithm using the at least one formatting instruction.</li></ul></li><li>5. The method of item 4, wherein adjusting the data packet to be encrypted comprises: <ul><li>Segmenting the data to be encrypted packet into several packets to be encrypted partial data;</li><li>Using the partial data packets instead of the data to be encrypted packet;</li><li>Creating an unencrypted segmenting characteristic for the partial data packets to be encrypted wherein the segmenting characteristic designated partial data packets obtained by segmenting a single data packet; and</li><li>Outputting the segmenting characteristic together with the segmented part to be encrypted data packets.</li></ul></li><li>6. A method according to any one of items 4 or 5, wherein adjusting the data packet to be encrypted comprises:<ul><li>Creating a data block, which data block containing data to be encrypted packet and a block characteristic, said block characteristic features to be encrypted data packet in the data block; and</li><li>Use of the data block instead of the data to be encrypted packet.</li></ul></li><li>7. The method according to any one of the preceding items, further comprising:<ul><li>Splitting a main coding key in different sub-coding; and</li><li>Assigning each a partial coding key to a respective coding algorithm in each case a level of encryption.</li></ul></li><li>8. The method according to any one of the preceding points, wherein the determining to be used in the subsequent encryption stages of different coding comprises: <ul><li>Determining at least one coding format instruction of to be used in the respective encryption level coding algorithm, the one coding format instruction specifies at least one structure of the usable with the respective coding algorithm coding; and</li><li>Consider the coding format instruction in the determination of to be used in the respective encryption level coding key.</li></ul></li><li>9. A method according one of the preceding points, wherein at least one level of encryption comprising the steps of:<ul><li>Adding random data to the data to be encrypted packet before encryption;</li><li>Use of the random data having data packet instead of the data to be encrypted packet;</li><li>Creating a random data characteristic to which the random data having data to be encrypted packet, the random data characteristic indicates a container filled with random data field of the random data having the data to be encrypted packet; and</li><li>Outputting the random data characteristic along with the random data having to be encrypted data packet.</li></ul></li><li>10. The method according to any one of the preceding points, wherein at least further comprising an encryption step before encrypting the steps of:<ul><li>Calculating a control value for the data to be encrypted packet; and</li><li>Outputting the control value along with the data to be encrypted packet.</li></ul> The method for decoding multi-encrypted data packets can be described as follows:</li><li>11. A method of decrypting multi-encrypted data packets of a data stream, comprising the steps of:<ul><li>Detecting at least one of the multi-encrypted data packet associated unencrypted coding characteristic which coding characteristic specifying at least one coding algorithm and assigned coding; and</li><li>Sequentially decrypting the data packet to be decrypted in at least two successive decryption steps using the specified in the at least one coding characteristic at least one coding algorithm and assigned coding key supplied.</li></ul></li><li>12. The method of item 11, wherein at least one decryption stage comprises the following steps:<ul><li>Detecting the data packet associated unencrypted segmenting characteristic, wherein the segmenting characteristic called data packets, the segments of a single whole data packet are;</li><li>Form of the total data packet based on the decrypted data packets and the segmenting characteristic after decryption; and</li><li>Use of the total data packet instead of the data packet.</li></ul></li><li>13. The method according to any of items 11 or 12, wherein at least one decryption stage comprises:<ul><li>Detecting an unencrypted block characteristic in the data packet after decryption, said block characteristic in the data packet identifies a method to be used in the further data packet.</li></ul></li><li>14. The method according to any one of items 11 to 13, further comprising:<ul><li>Splitting a main coding key in different sub-coding function of the respective coding characteristic; and</li><li>Assigning each of a sub-coding key each to one coding algorithm each in a decrypting step, depending on the respective coding characteristic.</li></ul></li><li>15. The method according to any one of items 11 to 14, wherein at least one decryption stage comprises the following steps:<ul><li>Detecting the data packet associated unencrypted random data characteristic, the random data characteristic specifying a container filled with random data field of the data packet; and</li><li>Removing the random data from the data packet after decryption using the detected random data characteristic.</li></ul></li><li>16. The method according to any one of items 11 to 15, wherein at least one decryption stage after the decrypting comprises the steps of:<ul><li>Detecting a data packet associated control value; </li><li>Computing a check value using data contained in the data packet;</li><li>Comparing the check value with the check value; and</li><li>Discarding the data packet when the control value does not correspond to the test value.</li></ul></li><li>17. The method according to any one of items 2 to 16, wherein said coding characteristic specifying the order of all the coding algorithms used in the context of sequential encryption or decryption in the different levels of encryption or decryption steps associated with the respective coding keys.</li><li>18. The method according to any of items 2 to 17, wherein the output of coding characteristic, segmenting characteristic and random data characteristic for a data packet to be encrypted is carried out together as a collective characteristic.</li><li>19. The method according to any one of the preceding points, wherein an image obtained in a previous encoding stage of the sequential encoding encrypted data packet is in a subsequent encryption level of the sequential encryption to be encrypted data packet and / or a product obtained in a previous decoding stage of the sequential decoding data packet the in a subsequent decryption stage of sequential decryption to decrypt data packet. </li><li>20. The method according to any one of the preceding points, wherein the different coding algorithms and / or coding keys are independent. The signal sequence can be characterized as follows:</li><li>21 signal sequence which causes the embodiment of the method according to any one of items 1 to 20, when loaded into a data processor, in particular a microprocessor, of a data processing system. The data processing system also can be described by the following points:</li><li>22. Data processing system, said data processing system receives data packets of a data stream at least, and processes the received data packets according to a predetermined rule, characterized in that the data processing system is programmed and adapted to perform the method of any of items 1 to twentieth</li><li>23. A data processing system according to item 22, comprising a memory means, in which at least two different coding keys are stored; at least two data processors, each of which has a hard-coded logic circuitry, the circuit logic implemented in each different coding algorithms for processing a received data packet using a coding key; a switching network for selectively connecting the data processors in series, where the order is changeable; and a control device which controls the switching network and the at least two data processors, at least receives the data packets of the data stream and outputs it to a first of the at least two data processors, from the memory device reads different coding keys and outputs them to the data processor.</li><li>24. A data processing system according to item 23, wherein each data processor includes a buffer for temporarily storing processed data packets, the size of the buffer depends on a particular application of the data processing system of the invention.</li><li>25. A data processing system according to item 22, comprising a memory means, in which at least two different coding keys and at least two different coding algorithms are stored; at least two data processors, each having a programmable logic circuit for processing received data packets; a connection network that connects the data processors in series with a predetermined order; and a control device which controls the at least two data processors, reads out from said memory means different coding algorithms, and the logic circuits of the data processors programmed accordingly, at least receives the data packets of the data stream and outputs it to a first of the at least two data processors, and reads from said memory means different coding and the data processor outputs the programmed according to a respective coding algorithm logic circuits of the respective data processors process the respective data packets received using the respective coding key received.</li><li>26. Data processing system according to any one of items 23 to 25, wherein each data processor further comprises at least an input interface for receiving data to be processed packets and an output interface for outputting processed data packets and wherein at least the output interface of the first data processor via the switching network or the network connection is connected to the input interface of a second data processor.</li><li>27. A data processing system according to item 22, comprising a memory means, in which at least two different coding keys and at least two different coding algorithms are stored; a data processor with a programmable logic circuit for processing received data packets; and a control means, which the data packets of the data stream receiving at least, from the memory device reads out sequentially in time different coding algorithms and programs the circuit logic of the data processor accordingly, and sequentially in time different from the storage device coding and dumps together with data to be processed to the data processor, wherein the control means further from the data processor using the respective coding key and key algorithm processed data obtained, and wherein said control means further outputs the data received from the data processor processed data at least once to the data processor and this controls so that the data processor one by the control means received to be processed data packet comprising at least twice in chronological succession processed using different coding algorithms and different coding.</li><li>Determined 28. A data processing system according to any one of items 22 to 27, wherein the control means on receipt of a data to be encrypted packet automatically determines a number, type and sequence of successive levels of encryption to use different coding algorithms in the subsequent encryption stages to use different coding and each a coding to a respective coding algorithm each in one encryption stage assigns, wherein said control means passes the at least controlling a data processor accordingly to obtain a multi-encrypted data packet, and wherein the control unit further automatically creates an unencrypted coding characteristic, which coding characteristic at least the temporally last coding algorithm used and the assigned coding specifies, and outputs the coding characteristic together with the multi-encrypted data packet.</li><li>29. A data processing system according to item 28, wherein the control unit further automatically determines at least one formatting instruction of the coding algorithm used in the respective encryption stage wherein the structure of the data to be encrypted packet prior to output to at least one formatting instruction defines a structure of the encryptable using the respective coding algorithm data packets and the respective data processor adapts using the at least one formatting instruction to the respective coding algorithm.</li><li>30. A data processing system according to item 28 or 29, wherein the control unit further automatically reads a main coding key from the storing means and these divided into several different sub-coding, and each having a part-coding to a respective coding algorithm each in one encryption stage assigns.</li><li>31. A data processing system according to item 28, 29 or 30, wherein the control unit further automatically reads a coding format instruction of the to be used in the respective encryption stage coding algorithm from the memory device, wherein the at least specifies a coding format instruction a structure of usable with the respective coding algorithm coding and the coding format instruction in the provision of to be used in the respective encryption stage coding key considered.</li><li>32. The data processing system any one of items 28 to 31, wherein the control unit further automatically adds to the data to be encrypted packet prior to an output of the data to be encrypted packet to the respective data processors random data, and a random data characteristic to which the random data having created data to be encrypted packet, the random data characteristic specifying a container filled with random data field of having the random data to be encrypted data packet.</li><li>33. The data processing system any one of items 28 to 32, wherein the control unit further automatically calculates a control value for the data packet to be encrypted before an output of the data to be encrypted packet to the respective data processors.</li><li>34. A data processing system according to any one of items 22 to 27, wherein the control means on receipt of to be descrambled multi-encrypted data packets automatically at least detects the data packet associated unencrypted coding characteristic, which coding characteristic specifying at least one coding algorithm and one assigned coding and the at least one data processor controls so that it sequentially of decrypts the data packet to be decrypted in at least two successive decoding stages using in the specified at least one coding characteristic at least one coding algorithm and assigned coding key supplied.</li><li>35. A data processing system according to item 34, wherein the control unit further automatically detects the data packet associated unencrypted segmenting characteristic, wherein the segmenting characteristic called data packets, the segments of a single whole data packet are, and decrypted on the basis of data packets and the segmenting characteristic after decryption a total data packet forms. </li><li>36. A data processing system according to item 34 or 35, wherein the control unit further automatically detected after decrypting an unencrypted block characteristic in the data packet, wherein the block characteristic identifies the data packet contained in a payload data packet.</li><li>37. A data processing system according to item 34, 35 or 36, wherein the control unit further automatically reads a main coding key from the storing means and these divided depending on the respective coding characteristic into several different sub-coding, and each having a part-coding in dependence assigning of the respective coding characteristic in each case to one coding algorithm each in a decryption step.</li><li>38. A data processing system according to any one of items 34 to 37, wherein the control unit further automatically detects the data packet associated unencrypted random data characteristics, wherein the random data characteristic indicates a container filled with random data field of the data packet, and the random data after decryption of the data packet among using the detected random data characteristic removed.</li><li>39. A data processing system according to any one of items 34 to 38, wherein the control unit further automatically detects a data packet associated control value calculated by using contained in the data packet data a check value, compares the control value with the check value and the data packet discards, if the control value is not matches the verification value.</li><li>40. A data processing system according to any one of items 34 to 39, wherein the control means before outputting the encrypted data packet as a multi-encrypted data packet or the decrypted data packet as mehrfachentschlüsseltes data packet further automatically or the encrypted data packet or the decrypted data packet to a format of the received unencrypted data packet adapts. the received encrypted data packet.</li></ol>
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP0957651A2 | Cites | European Patent Office (EPO) |
| WO0146782A2 | Cites | World Intellectual Property Organization (WIPO) |
| US2002107001A1 | Cites | United States of America |
| SCHNEIER B: "Applied Cryptography, COMBINING BLOCK CIPHERS" APPLIED CRYPTOGRAPHY. PROTOCOLS, ALGORITHMS, AND SOURCE CODE IN C, NEW YORK, JOHN WILEY & SONS, US, 1996, Seiten 357-368, XP002244523 ISBN: 0-471-11709-9 | Non-patent | – |
9 members in 5 offices; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 102005051577 | Germany | – | |
| 102005051577 | Germany | A |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| CA2563709A1 | Canada | A1 | |
| EP1777913A1 | European Patent Office (EPO) | A1 | |
| DE102005051577A1 | Germany | A1 | |
| US2008034197A1 | United States of America | A1 | |
| DE102005051577B4 | Germany | B4 | |
| EP1777913B1This record | European Patent Office (EPO) | B1 | |
| AT450112T | Austria | T | |
| ATE450112T1 | Austria | T1 | |
| DE502006005447D1 | Germany | D1 |
64 legal events, as 8 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| European patents designating ireland treated as always having been voidFD4D | FD4D | IE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lt: invalidation of european patent or patent extensionLTIE | LTIE | EP | |
| New agentNV | NV | CH | |
| Discontinued in the netherlands as no translation has been filedVDEP | VDEP | NL | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Designation fees paidAKX | AKX | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1777913
- Application
- 61218939
Titles3
- German
- Verfahren zur Verschlüsselung bzw. Entschlüsselung von Datenpaketen eines Datenstroms
- English
- Method to enciphering/deciphering data packets of a data steam
- French
- Procédé pour le chiffrement/déchiffrement de paquets de données d'un flux de paquets
Classification
- CPC, 2
- H04L63/0428
- H04L63/06
- IPC, 1
- H04L29 06
Designated states31
- Contracting states, 31
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
- Netherlands (Kingdom of the)
and 7 moreShow fewer
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
