EP1934883A2

Method and system for block cipher encryption

Abstract

This record has no abstract on file.

Term

Projected expiry 5 October 2026.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

96 claims: 36 independent, 60 dependent

  1. 1
    Claims of equivalent WO 2007043045 A2 What is claimed is:CLAIMS 1. A method of encrypting a block of data, the method comprising: providing a combining unit operative to combine a key with a block of data, the block of data expressed as a block of bits;providing a mix and condense unit operative to mix bits comprised in the block of bits among themselves;receiving an input comprising the block of data expressed as the block of bits;combining, at the combining unit, the block of bits with a key;and mixing, at the mixing and condensing unit, the combined block of bits, wherein the mix and condense unit comprises a plurality of layers, each layer among the plurality of layers comprising a plurality of mini-functions.
  2. 5
    The method according to any of claims 1 - 4 and wherein a mini- function layer comprises two micro-functions:one balanced micro-function;and one non-linear micro-function.
  3. 10
    . The method according to any of claims 1 - 9 and further comprising:providing a first function Fj and a second function F;;providing a round key generation function, the round key generation function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function FJ;providing a round mixing function, the round mixing function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function Fi;utilizing the round key generation function in at least a first round to generate a second round key for use in a second round;and utilizing the round mixing function in at least the first round to mix a first round key with a cipher state, wherein one of the following is performed in the first round: the round key generation function utilizes the first function Ff to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the second function Fj to mix the first round key with the cipher state;and the round key generation function utilizes the second function Fj to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the first function F1 to mix the first round key with the cipher state.
  4. 11
    A method of encrypting a block of data, the method comprising:providing an expansion unit operative to expand the block of data, expressed as a block of bits, from a first bit size to a second bit size, the second bit size being greater than the first bit size;providing a combining unit operative to combine an expanded block of data with a key;providing a mix and condense unit operative to mix the bits of a combined expanded block of data of the second bit size and condense the bit size of the input to a third bit size, the third bit size being less than the second bit size;receiving an input comprising the block of data expressed as the block of bits;inputting the block of bits into the expansion unit, and therein expanding the block of bits to a block of bits of the second bit size;combining, at the combining unit, the block of bits of the second bit size with a key;mixing, at the mixing and condensing unit, the block of bits of the second bit size;and condensing, at the mixing and condensing unit, the block of bits of the second bit size to a block of bits of the third size, thereby producing an encrypted block of data, the encrypted block of data being expressed as a block of bits of the third bit size, wherein the mixing and condensing unit comprises a plurality of layers, each layer among the plurality of layers comprising a plurality of mini- functions.
  5. 16
    The method according to any of claims 11 - 15 and wherein the combining unit is operative to perform a XOR operation.
  6. 17
    The method according to any of claims 11 - 16 and wherein the expansion unit comprises a linear transformation.
  7. 22
    The method according to any of claims 11 - 21 and wherein the expansion unit comprises two layers of gates operative to combine two inputs.
  8. 25
    The method according to any of claims 11 - 24 and wherein the method of encrypting cannot be implemented except on specialized hardware.
  9. 32
    The method according to any of claims 11 - 31 and further comprising:providing a first function F{ and a second function FJ;providing a round key generation function, the round key generation function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function F;;providing a round mixing function, the round mixing function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function FJ;utilizing the round key generation function in at least a first round to generate a second round key for use in a second round;and utilizing the round mixing function in at least the first round to mix a first round key with a cipher state, wherein one of the following is performed in the first round: the round key generation function utilizes the first function Fj to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the second function Fj to mix the first round key with the cipher state;and the round key generation function utilizes the second function Fj to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the first function Fj to mix the first round key with the cipher state.
  10. 33
    A method of encrypting a block of data, the method comprising an emulation resistant combine key method comprised in a Feistel-like structure.
  11. 41
    The method according to any of claims 36 - 40 and wherein the combining unit is operative to perform a XOR operation.
  12. 42
    The method according to any of claims 36 - 41 and wherein the expansion unit comprises a linear transformation.
  13. 47
    The method according to any of claims 36 - 46 and wherein the mix and condense unit comprises a plurality of layers, each layer among the plurality of layers comprising a plurality of mini-functions.
  14. 54
    The method according to any of claims 33 - 53 and further comprising:providing a first function F1 and a second function FJ;providing a round key generation function, the round key generation function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function FJ;providing a round mixing function, the round mixing function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function FJ;utilizing the round key generation function in at least a first round to generate a second round key for use in a second round;and utilizing the round mixing function in at least the first round to mix a first round key with a cipher state, wherein one of the following is performed in the first round: the round key generation function utilizes the first function Fj to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the second function Fi to mix the first round key with the cipher state;and the round key generation function utilizes the second function F;to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the first function Fj to mix the first round key with the cipher state.
  15. 55
    A method of encrypting a block of data, the method comprising:providing a combining unit operative to combine the block of data with a key;providing a mixing unit operative to mix the bits of a combined key and block of data;receiving an input comprising the block of data expressed as a block of bits;combining, at a combining unit, the block of bits with a key;and mixing, at the mixing unit, the block of bits, thereby producing an encrypted block of data, wherein the mix and condense unit comprises a plurality of layers, each layer comprising a plurality of mini-functions.
  16. 58
    The method according to any of claims 55 - 57 and wherein a mini- function layer comprises two micro-functions:one balanced micro-function;and one non-linear micro-function.
  17. 63
    The method according to any of claims 55 - 62 and further comprising:providing an expansion unit operative to expand the block of data, expressed as a block of bits, from a first bit size to a second bit size, the second bit size being greater than the first bit size;and prior to the combining, inputting the block of bits into the expansion unit, and therein expanding the block of bits to a block of bits of the second bit size.
  18. 65
    The method according to any of claims 55 - 64 and further comprising:providing a first function Fj and a second function FJ;providing a round key generation function, the round key generation function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function FJ;providing a round mixing function, the round mixing function being operative to utilize, in any given round, exactly one of: the first function FJ;and the second function FJ;utilizing the round key generation function in at least a first round to generate a second round key for use in a second round;and 6 001167 76 utilizing the round mixing function in at least the first round to mix a first round key with a cipher state, wherein one of the following is performed in the first round: the round key generation function utilizes the first function Fj to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the second function Fj to mix the first round key with the cipher state;and the round key generation function utilizes the second function Fi to generate the second round key for use in the second round, substantially simultaneously with the round key mixing function utilizing the first function F1 to mix the first round key with the cipher state.
  19. 66
    A method comprising:combining a control input derived from a right part of a Feistel-like structure with a transformation input comprising a left part of the Feistel-like structure;and producing an output comprising a combination of bits comprised in the control input and bits comprised in the transformation input, wherein no bit of the combination of bits comprises a linear combination of bits from the control input and bits from the transformation input.
  20. 69
    The method according to any of claims 66 - 68 and wherein the method comprises a non-linear layer comprising at least one S-box.
  21. 70
    The method according to of claims 66 - 68 and also comprising a linear transformation of the control input and the transformation input.
  22. 74
    The method according to any of claims 71 - 73 and wherein the transformation input splitter permutes the transformation input prior to the splitting at the transformation input splitter.
  23. 75
    The method according to any of claims 71 - 74 wherein the output joiner permutes an output after the joining operation.
  24. 76
    The method according to any of claims 71 - 75 and wherein the linearly combining comprises (A(C) x I) θ C, where C represents the control input sub-block, I represents the transformation input sub-block, and A(C) comprises a matrix depending on C, of size mxm, where m is a size of the control input sub-block.
  25. 78
    The method according to any of claims 70 - 77 and also comprising a non-linear layer comprising at least one S-box.
  26. 81
    . The method according to any of claims 69 or claims 910 - 912 and wherein at least one of the S-boxes comprises an S-box according to the Serpent Cipher specification.
  27. 82
    The method according to any of claims 69 or claims 910 - 913 and wherein the S-box layer comprises S-boxes which are simple to implement in hardware.
  28. 83
    The method according to any of claims 66 - 82 and wherein the method is cryptographically secure and non-involutable.
  29. 84
    A multi-round Feistel-like cipher comprising a permutation layer ("P-box") wherein the P-box is used in less than all rounds of the Feistel-like cipher. 1167 79
  30. 86
    A method of encrypting a plaintext, the method comprising:receiving a plaintext;inputting a portion of the plaintext into a CombineKeyRight (CKR) scrambling method, the CKR scrambling method comprising: providing a combining unit operative to combine a key with a block of data, the block of data expressed as a block of bits;providing a mix and condense unit operative to mix bits comprised in the block of bits among themselves;receiving an input comprising the block of data expressed as the block of bits;combining, at the combining unit, the block of bits with a key;and mixing, at the mixing and condensing unit, the combined block of bits, such that the mix and condense unit comprises a plurality of layers, each layer among the plurality of layers comprising a plurality of mini- functions;inputting the output of the CKR scrambling method into a CombineRightPartLeftPart (CRL) method, the CRL method comprising: combining a control input derived from a right part of a Feistel-like structure with a transformation input comprising a left part of the Feistel-like structure;and producing an output comprising a combination of bits comprised in the control input and bits comprised in the transformation input, such that no bit of the combination of bits comprises a linear combination of bits from the control input and bits from the transformation input;and outputting an encrypted text, the encrypted text corresponding to the plaintext.
  31. 88
    A method of encrypting a plaintext, the method comprising:receiving a plaintext;inputting a portion of the plaintext into a CombineKeyRight (CKR) scrambling method, the CKR comprising: providing an expansion unit operative to expand the block of data, expressed as a block of bits, from a first bit size to a second bit size, the second bit size being greater than the first bit size;providing a combining unit operative to combine an expanded block of data with a key;providing a mix and condense unit operative to mix the bits of a combined expanded block of data of the second bit size and condense the bit size of the input to a third bit size, the third bit size being less than the second bit size;receiving an input comprising the block of data expressed as the block of bits;inputting the block of bits into the expansion unit, and therein expanding the block of bits to a block of bits of the second bit size;combining, at the combining unit, the block of bits of the second bit size with a key;mixing, at the mixing and condensing unit, the block of bits of the second bit size;and condensing, at the mixing and condensing unit, the block of bits of the second bit size to a block of bits of the third size, thereby producing an encrypted block of data, the encrypted block of data being expressed as a block of bits of the third bit size, such that the mixing and condensing unit comprises a plurality of layers, each layer among the plurality of layers comprising a plurality of mini-functions ;inputting the output of the CKR scrambling method into a CombineRightPartLeftPart (CRL) method, the CRL comprising: combining a control input derived from a right part of a Feistel-like structure with a transformation input comprising a left part of the Feistel-like structure;and producing an output comprising a combination of bits comprised in the control input and bits comprised in the transformation input, such that no bit of the combination of bits comprises a linear combination of bits from the control input and bits from the transformation input;and outputting an encrypted text, the encrypted text corresponding to the plaintext.
  32. 90
    An encryptor for encrypting a block of data, the encryptor comprising:a combining unit operative to combine a key with a block of data, the block of data being expressed as a block of bits;and a mix and condense unit operative to mix bits comprised in the block of bits among themselves, wherein a received input comprising the block of data expressed as the block of bits is combined, at the combining unit, with a key, and bits comprised in the combined block of bits are mixed among themselves at the mixing and condensing unit, and the mix and condense unit comprises a plurality of layers, each layer among the plurality of layers comprising a plurality of mini -functions.
  33. 92
    An encryptor for encrypting a block of data, the encryptor comprising:an expansion unit operative to expand the block of data, expressed as a block of bits, from a first bit size to a second bit size, the second bit size being greater than the first bit size, thereby producing an expanded block of data;a combining unit operative to receive the expanded block of data from the expansion unit and combine the expanded block of data with a key thereby producing a combined expanded block of data of the second bit size;and a mix and condense unit operative to mix the bits of the combined expanded block of data of the second bit size and condense the bit size of the combined expanded block of data of the second bit size to a third bit size, the third bit size being less than the second bit size, wherein the mixing and condensing unit comprises a plurality of layers, each layer among the plurality of layers comprising a plurality of mini- functions.
  34. 94
    A Feistel-like structure operative to encrypt a block of data, the Feistel-like structure comprising an emulation resistant combine key unit.
  35. 95
    An encryptor operative to encrypt a block of data, the encryptor comprising:a combining unit operative to combine the block of data with a key and produce a combined key and block of data;and a mixing unit operative to mix the bits of the combined key and block of data, wherein the mixing unit comprises a plurality of layers, each layer comprising a plurality of mini-functions.
  36. 96
    An apparatus comprising:a combiner operative to combine a control input derived from a right part of a Feistel-like structure with a transformation input comprising a left part of the Feistel-like structure;and an outputter operative to producing an output comprising a combination of bits comprised in the control input and bits comprised in the transformation input, wherein no bit of the combination of bits comprises a linear combination of bits from the control input and bits from the transformation input.
Independent claims36