Method and device for encrypting a message
Abstract
A method in a digital pen (hereinafter DP) to encrypt a message for the safe transmission of said message from the digital pen (DP) to a receiver (hereinafter ALS, SH, SP) characterized by the steps of obtaining the message by the registration of images of a surface (2) provided with a pattern (3) of position code using an optical detector (8) of the digital pen (DP) and the determination of at least one position from the images; obtaining (410-420) optical data for the generation of an encryption key using the optical detector (8) of the digital pen (DP), whose optical data electronically represents values of an optical parameter readable by said optical detector (8); generate (430-450) exclusively by electronic treatment in a treatment unit (10) of the digital pen, the encryption key, use said optical data as a random seed; and encrypt (480) said message using said encryption key in an encryption algorithm.

Term
Term ended
Projected expiry passed 7 June 2021, 5.3 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
36 claims: 9 independent, 27 dependent
- 1ES 2 269 415 T3 REIVINDICACIONES 1. Un método en un bolígrafo digital (en adelante DP) para cifrar un mensaje para la transmisión segura de dicho mensaje desde el bolígrafo digital (DP) a un receptor (en adelante ALS, SH, SP) caracterizado por las etapas de obtener el mensaje mediante el registro de imágenes de una superficie (2) provista de un patrón (3) de código de posición usando un detector óptico (8) del bolígrafo digital (DP) y la determinación de al menos una posición a partir de las imágenes;obtener (410-420) datos ópticos para la generación de una clave de cifrado usando el detector óptico (8) del bolígrafo digital (DP), cuyos datos ópticos representan electrónicamente valores de un parámetro óptico legible por dicho detector óptico (8);generar (430-450) exclusivamente por tratamiento electrónico en una unidad de tratamiento (10) del bolígrafo digital, la clave de cifrado, usar dichos datos ópticos como semilla aleatoria;y cifrar (480) dicho mensaje usando dicha clave de cifrado en un algoritmo de cifrado.
- 2El método de acuerdo con la reivindicación 1, en el que se detecta el brillo en dicho parámetro óptico mediante dicho detector óptico (8).
- 3El método de acuerdo con las reivindicaciones 1 ó 2, en el que la etapa (410-420) de obtener datos ópticos comprende la. etapa de obtener dichos datos ópticos a partir de una parte de una superficie (2) provista de un patrón (3) de código de posición, en el que dicho patrón (3) de código de posición incluye unas marcas ópticas legibles (4), y en el que dicho parámetro óptico es representativo de dicha parte.
- 4El método de acuerdo con una cualquiera de las reivindicaciones 1 a 3, en el que la etapa (430-450) de generar una clave de cifrado comprende las etapas de tratar (430) dichos datos ópticos de acuerdo con un esquema predeterminado, organizar (440) dichos datos ópticos tratados en campos de datos, en los que cada campo de datos tiene un tamaño predeterminado, y organizar (440) dichos campos de datos en un orden predeterminado en registros de datos.
- 5El método de acuerdo con la reivindicación 4, en el que la etapa (430) de tratar dichos datosópticos comprende la etapa de calcular propiedades estadísticas de conjuntos de dichos valores de parámetros ópticos representados por dichos datos ópticos, por lo que dichas propiedades estadísticas constituyen dichos datos ópticos tratados.
- 6El método de acuerdo con la reivindicación 5, en el que dichas propiedades estadísticas comprenden un valor máximo, un valor mínimo y un valor suma de dicho conjunto de valores de parámetros ópticos, y en el que las etapas (440) de organizar comprenden las etapas de organizar dicho valor máximo en al menos un campo de datos máximos, dicho valor mínimo en al menos un campo de datos mínimos, y dicho valor suma en al menos un campo de datos suma, y organizar dichos campos de datos máximos, mínimos y suma en un registro de datos de acuerdo con dicho orden predeterminado.
- 7El método de acuerdo con una cualquiera de las reivindicaciones 4 a 6, en el que la etapa (430-450) de generar una clave de cifrado comprende además las etapas de redisponer (520) el orden de dichos campos de datos dentro de al menos un registro de datos de una primera serie de registros de datos de acuerdo con un primer algoritmo de reordenación, obteniendo de ese modo una primera serie de registros de datos redispuestos, y redisponer (530) el orden de dichos campos de datos dentro de al menos un registro de datos de una segunda serie de registros de datos de acuerdo con un segundo algoritmo de reordenación, obteniendo de ese modo una segunda serie de registros de datos redispuestos.
- 8El método de acuerdo con la reivindicación 7, en el que una clave de cifrado comprende datos de clave y datos de entrada, y en el que la etapa (430-450) de generar una clave de cifrado comprende las etapas de usar (540) dicha primera serie de registros de datos redispuestos como dichos datos de clave, y ES 2 269 415 T3 usar (540) dicha segunda serie de registros de datos redispuestos como dichos datos de entrada.
- 9El método de acuerdo con una cualquiera de las reivindicaciones 4 a 6, en el que la etapa (430-450) de generar una clave de cifrado comprende las etapas de tratar un conjunto de un número predeterminado de dichos registros de datos en una primera etapa (810-820), usando una primera función resumen, obteniendo de ese modo una primera salida, tratar dicha primera salida en una segunda etapa (830-840) usando un algoritmo iterativo, obteniendo de ese modo una segunda salida, y usar (850) dicha segunda salida como dicha clave de cifrado o para generar dicha clave de cifrado.
- 10El método de acuerdo con la reivindicación 9, en el que, en dicha segunda etapa (830-840), dicha primera salida se trata usando una segunda función resumen.
- 11El método de acuerdo con las reivindicaciones 9 ó 10, en el que en dichas etapas primera y segunda (810-820, 830-840), se usan, respectivamente, un primero y un segundo algoritmos de cifrado simétrico.
- 12El método de acuerdo con la reivindicación 11, en el que se usa un algoritmo de cifrado simétrico como dicho primero y como dicho segundo algoritmos de cifrado simétrico.
- 13El método de acuerdo con la reivindicación 12, en el que se usa un algoritmo de cifrado simétrico como dicho algoritmo de cifrado simétrico para realizar dicha etapa (460) de cifrar dicho mensaje, y como dichos algoritmos simétricos primero y segundo.
- 14El método de acuerdo con una cualquiera de las reivindicaciones precedentes, en el que la clave de cifrado comprende datos de clave y datos de entrada, cuyo método comprende además las etapas de usar un primer subconjunto de dichos datos ópticos para generar dichos datos de clave, y usar un segundo subconjunto de dichos datos ópticos para generar dichos datos de entrada.
- 15El método de acuerdo con una cualquiera de las reivindicaciones precedentes, en el que dicho algoritmo de cifrado para cifrar dicho mensaje es un algoritmo de cifrado simétrico.
- 16El método de acuerdo con la reivindicación 1, que comprende además las etapas de obtener datos de presión usando medios de detección de presión, en el que la etapa (430-450) de generar una clave de cifrado comprende la etapa de generar la clave de cifrado usando dichos datos de presión en combinación con dichos datos ópticos como semilla aleatoria.
- 17El método de acuerdo con la reivindicación 1, que comprende además las etapas de obtener datos de tiempo, en el que la etapa (430-450) de generar una clave de cifrado comprende la etapa de generar la clave de cifrado usando dichos datos de tiempo combinados con dichos datos ópticos como semilla aleatoria.
- 18El método de acuerdo con una cualquiera de las reivindicaciones precedentes, en el que dichas etapas se realizan en un bolígrafo digital (en adelante DP), que comprende dicho detector óptico (8) y medios de transmisión (12).
- 19Un medio legible por ordenador que comprende instrucciones para llevar a un ordenador a realizar un método de acuerdo con una cualquiera de las reivindicaciones precedentes.
- 20Un bolígrafo digital (DP) para cifrar un mensaje para la transmisión segura de dicho mensaje desde el bolígrafo digital (DP) a un receptor (ALS, SH, SP), caracterizado por un detector óptico (8) para registrar imágenes de una superficie (2) provista de un patrón (3) de código de posición;medios de recepción (10) para recibir datos ópticos del detector óptico (8) para la generación de una clave de cifrado, cuyos datos ópticos representan electrónicamente valores de un parámetro óptico legible por dicho detector óptico (8), medios de tratamiento (10) para generar, exclusivamente mediante tratamiento electrónico, la clave de cifrado usando dichos datos ópticos como semilla aleatoria, y para obtener dicho mensaje mediante la determinación de al menos una posición de dichas imágenes registradas;ES 2 269 415 T3 medios de cifrado (10) para cifrar el mensaje a transmitir usando dicha clave de cifrado.
- 21El bolígrafo digital de acuerdo con la reivindicación 20, en el que dichos datos ópticos se han obtenido de una parte de una superficie (2) provista de un patrón (3) de código de posición que tiene unas marcas ópticas legibles (4).
- 22El bolígrafo digital de acuerdo con la reivindicación 21, en el que dichos medios de tratamiento (10) están dispuestos además para tratar dichos datos ópticos de acuerdo con un esquema predeterminado, organizar dichos datos ópticos tratados en campos de datos, en los que cada campo de datos tiene un tamaño predeterminado, y organizar dichos campos de datos en un orden predeterminado en registros de datos.
- 23El bolígrafo digital de acuerdo con la reivindicación 22, en el que dichos medios de tratamiento (10) están dispuestos además para calcular propiedades estadísticas de conjuntos de dichos valores de parámetros ópticos representados por dichos datos ópticos, por lo que dichas propiedades estadísticas constituyen dichos datos ópticos tratados.
- 24El bolígrafo digital de acuerdo con la reivindicación 23, en el que dichas propiedades comprenden un valor máximo, un valor mínimo y un valor suma de dicho conjunto de valores de parámetros ópticos, y en el que dichos medios de tratamiento (10) están dispuestos además para organizar dicho valor máximo en al menos un campo de datos máximos, dicho valor mínimo en al menos un campo de datos mínimos, y dicho valor suma en al menos un campo de datos suma, y organizar dichos campos de datos máximos, mínimos y suma en un registro de datos de acuerdo con dicho orden predeterminado.
- 25El bolígrafo digital de acuerdo con una cualquiera de las reivindicaciones 22 a 24, en el que dichos medios de tratamiento (10) están dispuestos además para redisponer el orden de dichos campos de datos dentro de al menos un registro de datos de una primera serie de registros de datos de acuerdo con un primer algoritmo de reordenación, obteniendo de ese modo una primera serie de registros de datos redispuestos, y redisponer el orden de dichos campos de datos dentro de al menos un registro de datos de una segunda serie de registros de datos de acuerdo con un segundo algoritmo de reordenación, obteniendo de ese modo una segunda serie de registros de datos redispuestos.
- 26El bolígrafo digital de acuerdo con la reivindicación 25, en el que una clave de cifrado comprende datos de clave y datos de entrada, y en el que los medios de tratamiento (10) están dispuestos además para usar dicha primera serie de registros de datos redispuestos como dichos datos de clave, y usar dicha segunda serie de registros de datos redispuestos como dichos datos de entrada.
- 27El bolígrafo digital de acuerdo con una cualquiera de las reivindicaciones 22 a 24, en el que los medios de tratamiento (10) están dispuestos además para tratar un conjunto de un número predeterminado de dichos registros de datos en una primera etapa usando una primera función resumen, obteniendo de ese modo una primera salida, tratar dicha primera salida en una segunda etapa usando un algoritmo iterativo, obteniendo de ese modo una segunda salida, y usar dicha segunda salida como dicha clave de cifrado o para generar dicha clave de cifrado.
- 28El bolígrafo digital de acuerdo con la reivindicación 27, en el que dichos medios de tratamiento (10) están dispuestos además para usar una segunda función resumen para tratar dicha primera salida en dicha segunda etapa.
- 29El bolígrafo digital de acuerdo con las reivindicaciones 27 ó 28, en el que, en dichas etapas primera y segunda, se usan respectivamente un primero y un segundo algoritmo de cifrado simétrico.
- 30El bolígrafo digital de acuerdo con la reivindicación 29, en el que los medios de tratamiento están dispuestos además para usar un algoritmo de cifrado simétrico como dicho primero y como dicho segundo algoritmos de cifrado simétrico.
- 31El bolígrafo digital de acuerdo con la reivindicación 29, en el que se usa uno y el mismo algoritmo de cifrado simétrico por dichos medios (10) de cifrado para cifrar dicho mensaje, y por dichos medios de tratamiento (10) como dicho primero y dicho segundo algoritmos de cifrado simétrico. ES 2 269 415 T3
- 32El bolígrafo digital de acuerdo con una cualquiera de las reivindicaciones 20 a 31, en el que dichos medios de cifrado (10) están dispuestos además para cifrar dicho mensaje usando un algoritmo de cifrado simétrico.
- 33El bolígrafo digital de acuerdo con una cualquiera de las reivindicaciones 20 a 32, en el que dichos medios de cifrado (10) están dispuestos además para usar un subconjunto de dichos datos ópticos como datos de clave para dicho algoritmo de cifrado, y usar un segundo subconjunto de dichos datos ópticos como datos de entrada para dicho algoritmo de cifrado.
- 34El bolígrafo digital de acuerdo con la reivindicación 20, en el que dichos medios de recepción (10) están dispuestos además para recibir datos de presión, y en el que dichos medios de tratamiento (10) están dispuestos para generar dicha clave de cifrado usando dichos datos de presión en combinación con dichos datos ópticos.
- 35El bolígrafo digital de acuerdo con la reivindicación 20, en el que dichos medios de tratamiento (10) están dispuestos además para obtener datos de tiempo, y para generar dicha clave de cifrado usando dichos datos de tiempo combinados con dichos datos ópticos.
- 36Un método para la autenticación de un mensaje enviado, en el que dicho mensaje se envía desde un bolígrafo digital (DP) a un receptor (ALS, SH, SP), caracterizado por las etapas de obtener el mensaje mediante el registro de imágenes de una superficie (2) provista de un patrón (3) de código de posición usando un detector óptico (8) del bolígrafo digital (DP) y la determinación de al menos una posición de las imágenes, obtener datos ópticos para la generación de datos de números aleatorios usando el detector óptico (8) del bolígrafo digital (DP), cuyos datos ópticos representan electrónicamente valores de un parámetro óptico legibles por dicho detector óptico (8), usar dichos datos ópticos para generar los datos de números aleatorios, exclusivamente mediante el tratamiento electrónico en una unidad de tratamiento (10) del bolígrafo digital (DP), cifrar dichos datos de números aleatorios, y usar dichos datos de números aleatorios para la autenticación de dicho mensaje.
Independent claims36
134 paragraphs in 9 sections, as filed
ES 2 269 415 T3
DESCRIPTION
Method and device to encrypt a message.
Field of application of the invention
The present invention relates generally to the field of transmitting information from a transmitter to a receiver. More specifically, the present invention relates to a method and a device for encrypting a message for the secure transmission of said message from a sending device to a receiver. The invention further relates to a computer-readable medium comprising instructions for leading a computer to perform said method, and to a sending device and a system, respectively, comprising said device.
Background of the invention
During the transmission of information from a sender to a receiver, for example in a system that includes handheld devices, there are basically four aspects that need to be satisfied in order to obtain a secure transmission with respect to authenticity, integrity, confidentiality and non-repudiation. However, confidentiality, that is, that the information is kept secret during transmission, is crucial in the field of digital communication, for example in financial transactions or in foreign trade. This aspect, as well as the other aspects, can be fulfilled through the use of cryptography.
When using cryptography or a network security algorithm based on cryptography, random number data is used for different reasons and plays an essential role. For example, random numbers are frequently used as encryption keys or for generating encryption keys. Also, by definition random data is difficult to determine or guess.
Normal cryptography methods include symmetric encryption and asymmetric encryption. When using symmetric encryption, the same key is used for encryption and decryption. The encryption key is used in conjunction with an encryption algorithm, and different keys will result in different outputs from the algorithm. The degree of security of the encrypted message depends on the secret of the key and therefore on the random number used as the key or to generate the key, not on the secret of the algorithm. This makes it possible to use standard algorithms, such as the Advanced Encryption Standard (hereinafter AES), the Data Encryption Standard (hereinafter DES) or the International Data Encryption Standard (hereinafter IDEA). The degree of security also depends on the length or bit size of the key. The longer the encryption key, the more difficult it is to break the encryption language.
When asymmetric encryption is used, the sender and receiver each have a private encryption key and a public encryption key. Therefore, from the point of view of confidentiality, authentication and non-repudiation are achieved. Commonly used asymmetric encryption algorithms include, for example, RSA (Rhivest-ShamirAdleman) and DH (Diffie-Hellman).
It is a well known problem that sources of true random numbers are difficult to find. Physical noise generators, such as pulse detectors for ionizing radiation events, gas discharge tubes, and leaky condensers, are a potential source. However, such devices are of limited utility in network security applications. For example, incorporating one of these devices into a handheld device will require a complex and possibly bulky design of the handheld device. Furthermore, there are problems with both the degree of randomness and the precision of the numbers generated by such devices.
Another solution to obtain random numbers for cryptographic applications is the use of algorithmic techniques. However, these algorithms are deterministic and therefore produce sequences of numbers that are not statistically random. These numbers are often referred to as pseudo-random numbers.
A widely used technique for generating pseudo-random numbers is the linear congruential method. A sequence of numbers is obtained by the following equation
X<sub>n</sub>+<sub>1</sub> = (aX<sub>n</sub> + b) mod c, where X<sub>0</sub> is an initial number, that is, the random seed. Usually, in a handheld device or in a computer, the microseconds of the internal clock are used as a random seed to start the algorithm.
One problem with the aforementioned method is that once a value, the random seed, has been chosen, subsequent numbers in the sequence follow deterministically. This means that someone with knowledge of a part of the sequence could theoretically determine the subsequent elements of the sequence.
It is possible to implement more advanced random number generators that use the internal clock as a random seed, for example, like the algorithm used in Blue-tooth. This and other similar algorithms are capable of generating
ES 2 269 415 T3 pseudo-random numbers with improved statistical characteristics compared to the numbers generated by the linear congruential method. However, pseudo-random numbers are still of insufficient quality in a statistical sense, that is, when the degree of randomness is considered.
The article entitled "Stream cipher based on pseudo random number generation with optical affine transformation" by Sasaki et al., Published in Applied Optics, Volume 39, No. 14, pages 2340-2346, May 10, 2000, describes a technique for generate an image with pseudo-random intensity distribution by optical treatment. Specifically, an optical feedback treatment is used to display an initial image on a cathode ray tube (hereinafter CRT). The image of the CRT is then formed into an image in a camera with a charge-coupled device (hereinafter CCD), by means of optical components that split, rotate, reflect, convert and recombine the image, after which the treated image is presented visually on the TRC. The same procedure is then repeated for a large number of iterations. The final output image is used to encrypt an image message by optical modulo-n addition of the final output image to the image message. Apart from its obvious inability to be easily implemented in a handheld device, the known optical technique appears to suffer from limited precision and slow speed of treatment.
Therefore, the problem of finding a method, which can be implemented in a system comprising handheld devices, that provides good quality random numbers, according to the aforementioned criteria, for the generation of encryption keys with the in order to provide a secure transmission of information between a sender and a receiver.
An example of a handheld device is described in US-A-5 852 434 which relates to an absolute position determination device for indicating the instantaneous position and movement of a stylus on a surface formatted with a related code. with the position to indicate the XY coordinates.
Summary of the invention
Therefore, an object of the present invention is to provide an improved method and device for generating an encryption key and for encrypting a message.
This and other objects are achieved in accordance with the present invention by providing a method for encryption according to claim 1, a digital pen according to claim 20, and a method for authentication according to claim 36. In The dependent claims define preferred embodiments.
Thus, the present invention is based on the advantageous consideration of using optical data as a random seed for the generation of an encryption key, which in turn is used as an encryption algorithm to encrypt a message. The optical data obtained in accordance with the method of the present invention exhibits the required degree of randomness and unpredictability. In fact, the optical data can be considered to be "truly" random. Consequently, the degree of randomness is higher, and the optical data used is more unpredictable compared to the data used for random seed in the known method described above. Thus, an improved degree of secrecy of the generated encryption key is achieved.
Traditionally, two different and not necessarily compatible criteria are used to determine the quality of a random number sequence, unpredictability and randomness. In a "true" random sequence, each number is statistically independent of any other number in the sequence, and therefore is unpredictable. Two criteria are used to validate the randomness of a sequence of numbers. First, the uniform distribution of the random numbers, which means that the frequency of occurrence of each of the numbers should be approximately the same. Second, the independence between random numbers, which means that no value in the sequence can be inferred from any of the others.
According to the preferred embodiment of the present invention, a surface, or a part thereof, is scanned or read with an optical detector, preferably a camera or a light-sensitive detector, thereby obtaining optical data representative of the characteristics of the surface read. The light sensitive detector is, for example, a charge-coupled detector (hereinafter CCD), or a complementary metal oxide detector (hereinafter CmOS). The optical data obtained is determined by - and represents - the values of at least one optical parameter, which is representative of the physical conditions on the part of the surface.
Preferably, the optical data is obtained from a portion of a surface provided with a position code pattern, wherein the position code pattern includes readable optical markings. Each of these marks could be designed in a more or less arbitrary way. However, preferably the design of each marking is elementary, for example in the form of round dots, as shown in the detailed description below. The position code pattern is implemented using any parameter, which could be used to obtain symbols of the aforementioned type that can be detected by an optical detector. The fact that the position code pattern is optimally readable makes it easy to apply the pattern to the surface. Accordingly, the pattern should have the ability to reflect light, which does not necessarily have to have a wavelength in the visible spectrum.
ES 2 269 415 T3
Preferably, the parameter detected and used for the generation of the encryption key is brightness, which is a relative measure of the intensity of the output energy of a light source that is visible to an optical detector. In the preferred embodiment of the present invention, the brightness of light reflected from a portion of an illuminated surface is recorded. Of course, the detected light does not necessarily have to be reflected light. Detection of light emitted from luminous surfaces, or any combination of emitted light and reflected light, is also contemplated within the scope of the present invention. The brightness in the detected light could depend, for example, on variations in the surrounding lighting, the quality of the pattern printing, the blackening of the markings, and / or the quality of the surface, for example, a surface of paper. Biometric factors could also have an impact on brightness, for example pen tilt. These and other factors introduce a considerable degree of randomness into the optical data. Furthermore, the fact that the optical detector itself is a noise generator will further increase the degree of randomness in the optical data.
In accordance with preferred embodiments of the invention, the optical data is processed according to a preprogrammed order or scheme and organized into data fields of a predetermined length. The data fields, in turn, are preferably organized into data records according to a predetermined schema, eg, in a predetermined order.
According to a specific preferred embodiment of the present invention, and in order to further improve the stochasticity of the optical data organized in said data records, the order of the data fields within the data records is rearranged according to a cyclical rearrangement algorithm. According to the cyclic rearrangement algorithm, the order of the rearranged data fields in the different data records could differ from one data record to another. Thus, a number of different reordering schemes could be used, including the case where for some data records, the order of the data fields has not been altered at all. Preferably, the cyclic reordering is done by shifting all the data fields in each data record. The data fields could be shifted by a number of steps ranging from zero, that is, no shifting takes place, to a number corresponding to the number of data fields in the data record minus 1. Thus, the reordering algorithm contains information as to the number of stages in which each data field is shifted for a specific data record.
According to a specific embodiment of the present invention, the order of the data fields of each record included in a first set of data records is rearranged according to a first reordering algorithm. Thus, a first rearranged data record set is obtained. Then, the order of the data fields of each data record in a second set of data records is rearranged according to a second reordering algorithm, resulting in a second set of data records rearranged in the generation of the encryption key, the first set of rearranged data records forms key data, and the second set of rearranged data records forms input data, or vice versa, of the encryption key used in the encryption algorithm. Alternatively, the key data and the input data form encryption data that can be used as material in an encryption process. For example, the material can be encrypted with the recipient's public key, to use as an encryption key or key material, to be compressed to an encryption key, for a symmetric encryption algorithm. The advantage of the described rearrangement process is that the statistical characteristics, that is, randomness and unpredictability, are significantly improved.
According to a further preferred embodiment of the invention, it has surprisingly been found that a high degree of stochasticity has been obtained using the specific rearrangement algorithm explained in greater detail below. In fact, the output data of the encryption algorithm, when the optical data is used as the random seed and the described rearrangement algorithm, constitutes a uniformly distributed noise according to the prevailing statistical test methods.
According to an alternative preferred embodiment of the invention, the stochasticity of the obtained optical data organized into data records is improved using hash functions. According to this embodiment, a first summary is performed on a set of a predetermined number of data records by a first algorithm, that is, a first summary function. As understood by those skilled in the art, the abstract is an iterative procedure that will not be described in detail. Thus, the term summary output, as used hereinafter, refers to the result of all iterations included in the summary. Thus, a first output, that is, a first summary output, is obtained from the first summary. The first output is then used as an input to a second algorithm, which could be a second summary function. The output of the second algorithm, i.e. random numbers, is then used, for example, as the encryption key or to generate an encryption key in an encryption algorithm to encrypt a message. However, the second algorithm could alternatively be an iterative algorithm other than a summary function. For example, algorithms A3 or A5 could be used, which are current figures and are used for symmetric encryption.
The first summary function introduces distortion or noise in the obtained optical data used as input data. In other words, it disturbs the regularities of the optical data and the correlation between data fields included in the data records. The use of a second summary function, or an alternative, preferably iterative algorithm, in the first output further improves the statistical characteristics of the data and provides additional distortion on the first output. In this way, the statistical characteristics, that is, the randomness and unpredictability, of the optical data processed using the method according to this embodiment are significantly improved. The refinement is such that the random numbers generated as a result of the method of this embodiment are
ES 2 269 415 T3 can be regarded as uniformly distributed white noise according to prevailing statistical test methods. According to a preferred alternative of this embodiment, symmetric encryption algorithm are used in the first and second algorithms. By using the same encryption algorithm for the algorithms, you get the benefits of a simplified implementation of the algorithms' program code and memory capacity savings.
Furthermore, when a symmetric encryption algorithm, such as AES, is used for the actual encryption of the message, this encryption algorithm is preferably also used in at least one of said algorithms, and preferably both. However, within the scope of the present invention it is conceivable that other and different encryption algorithms could be used in each of said algorithms, as well as for the actual encryption of the message. Preferably, in order to further improve the stochasticity of the encryption key, or of the random numbers used to generate the encryption key, are the statistical properties of the parameter. This results in a greater degree of randomness and unpredictability. Examples of the statistical properties that are preferably used include the minimum, maximum and sum values of the detected parameter. However, other statistical properties are conceivable, such as mean values, standard deviation values, etc. As those skilled in the art will observe, the use of such calculation of statistical properties is in no way limited to a specific embodiment of the present invention. Rather, the statistical properties of the optical data could be calculated and the results of the same could be used to refine the stochasticity of the optical data and the encryption key generated with them, regardless of the method chosen to generate the encryption key. encryption.
Furthermore, the optical data used to generate an encryption key could constitute part of the message to be encrypted and transmitted. Alternatively, the optical data is not part of the message. Additionally, the step of obtaining optical data to encrypt the message can be obtained before, during, or following the procedure of obtaining the message to be encrypted. By way of example, the encryption of the message could take place just before the actual transmission of the message. Then, the encryption key, including obtaining optical data, whether the optical data is extracted from the message or not, could be generated in connection with the encryption procedure. Alternatively, the generation of the encryption key could have been performed earlier, for example in connection with obtaining and storing the message, and a stored encryption key is used for encryption.
Suitably, the optical data used to generate an encryption key is saved on a storage medium prior to processing thereof. In an alternative embodiment, the optical data is saved after processing thereof.
Preferably, a symmetric encryption algorithm is used for the actual encryption of the message. There are a number of conceivable symmetric encryption algorithms that are suitable, for example AES, DES, or IDEA. The use of an asymmetric encryption algorithm, such as RSA, for actual encryption of the message is also conceivable and falls within the scope of the present invention. However, the present invention is not limited to a specific encryption algorithm.
The method of the present invention is implemented in a digital pen. Said digital pen comprises an optical detector to obtain a message to be transmitted. for example from a surface provided with a position code pattern as described above. Preferably, the digital pen also comprises illumination means for illuminating a surface to be read by the optical detector. The illumination means and the optical detector could be restricted to a limited range of wavelengths, such that the optical detector mainly detects reflected light that is provided by the illumination means. The optical detector is also used to obtain the optical data used to generate an encryption key. Therefore, no additional detector or additional random number generator is required within the limited interior of the digital pen.
Additionally, the digital pen comprises a processing unit or processing means to carry out the steps of the present invention, as well as all the steps required to obtain, encrypt and transmit a message. Furthermore, the digital pen also comprises, among other things, storage means suitable for storing data, means for supplying electrical energy, for example a battery, as well as transmission means for transmitting the message to a receiver.
According to a further embodiment of the invention, a pressure sensor is provided to obtain pressure data. As the pressure data is related to biometric factors, such as hand movements, the degree of randomness in the pressure data is high. The pressure data can then be used in combination with the optical data as random number data or random seed, in generating an encryption key, in order to amplify the degree of randomness in the random seed.
Also, according to still another embodiment of the invention, time data is obtained and used in combination with the optical data as a random seed in order to amplify the stochasticity of the random seed. Although the time data is deterministic in nature, it will not diminish the degree of randomness of the combined data. The time data is preferably provided by the internal clock of the processing means. The random seed thus obtained could subsequently be used in the generation of the encryption key in the manner described above.
As those skilled in the art will understand, there are other related areas in which random numbers generated from optical data could be used in accordance with the present invention. One such area is the authentication of a sent or received message.
ES 2 269 415 T3
Another area is the transport of keys from a sender to a receiver. In that case, the random numbers are encrypted with a public key of the recipient and used as an encryption key or key data, to be subsequently compressed to an encryption key, for a symmetric encryption algorithm.
Random numbers can also be used to generate prime numbers for RSA or DH keys.
As those skilled in the art will appreciate, the method and device of the present invention, as well as preferred embodiments thereof, are suitable for performing as a computer program or computer-readable medium, preferably within the contents of a digital pen. .
Still other objects and advantages of the present invention are described below by way of exemplary embodiments.
Brief description of the drawings
Preferred embodiments of the invention are described below in greater detail and with reference to the accompanying drawings, in which:
Figure 1 shows an embodiment of an information management system;
Figure 2 shows an embodiment of a broadcast device according to the present invention;
Figure 3 shows an embodiment of a broadcast device according to the present invention;
Figure 4 presents a flow chart illustrating one embodiment of a method in accordance with the present invention for encrypting a message using optical data;
Figure 5 shows a flow chart illustrating an algorithm of a first embodiment for increasing randomness in the optical data used to generate an encryption key;
Figure 6 schematically shows the order of data fields within a key data block and an input data block prior to a cyclic reordering procedure in accordance with an embodiment of the present invention;
Figures 7A and 7B schematically show the order of the data fields within the key data block and the input data block, respectively, after said cyclic reordering procedure; Y
Figure 8 shows a flow chart illustrating an algorithm of a second embodiment for increasing randomness in the input data used to generate an encryption key.
Description of preferred embodiments
An information management system in which this invention can be implemented is described below with reference to Figure 1. After this general presentation of the system structure, a product provided with a position code pattern will be described with reference to to Figure 2. Then, with reference to Figure 3, an emission device is shown, in which the method and device of the present invention can be implemented, designed to read and obtain optical data from the position code of Figure 2.
Referring first to Figure 1, an information management system is shown in which a position code product and a transmission device, such as a digital pen, can be integrated. There are many interrelated companies involved in the system in Figure 1: companies that manufacture digital pens (“pen manufacturers”), companies that manufacture position-coded products (“paper manufacturers”), companies that provide different services through service marketing units (“service marketers”) , a company that manages the position code based on the virtual space database ("pattern manager"), operators that provide the communication links between the digital pens and the different units ("network operators"), and a multitude of users of digital pens ("pen owners").
The system of Figure 1 includes a multitude of transmission devices or digital pens (hereinafter DP) and position code products (hereinafter P), of which only one is shown in Figure 1), a unit of consultation (hereinafter ALS), and a plurality of service marketing units (hereinafter SH, of which only one is shown in Figure 1). It should be noted that the information can be transmitted in any suitable mode from the DP digital pen to the ALS inquiry unit and the SH service marketing unit. In one embodiment, wireless transmission of information is effected from the digital pen DP to a network connection unit, which in turn transmits the information to the query unit ALS and the service marketer unit SH, respectively. The network connection unit can be an integral part of the DP digital pen. Alternatively, the network connection unit may be a mobile phone or a computer or any other suitable unit with an interface to a computer network such as the Internet or a local area network.
ES 2 269 415 T3 (hereinafter LAN). The ALS query unit is connected to a virtual space database (hereinafter GSDB) that includes data on the functionality of each position encoded by the position code (hereinafter PC) and the company related to each of said positions . The ALS query unit is also connected to a pen database (hereinafter PDB), which includes data about all digital pens in the system, such as the unique pen identifier of each pen and all the settings or properties that are related to each pen. The PDB pen database also includes data related to the manufacturer of each pen. In addition to the above, the query unit is connected to an event database (hereinafter GEDB), which includes data on the transactions that take place in the ALS query unit, that is, the address requests made by the pens in the system and management responses answered to the pens, as well as any errors that occur in the process. As an alternative to the individual databases shown in Figure 1, the ALS query unit could be connected to an all-encompassing database.
The system also includes one or more networks in which the network operators manage the communication between the digital pens DP and the query unit ALS, and between the digital pens DP and the service marketing unit SH. In this regard, the owner of a pen has opened a subscription in one of the network operators. This network operator could also act as a service manager in the system, for example by means of a server unit (hereinafter SP) that provides communication services that allow the owner of a pen to send electronic messages, for example e-mail. , short messages (hereinafter SMS) or fax, based on the information written on the position coded products P by means of the digital pen DP. The server unit SP of the network operator could also provide the network storage of the information generated in this system, for example entries in a calendar or agenda with encoded positions. When acting as a service manager, the network operator maintains an application database (hereinafter ASDB) containing data on user-specific settings for different applications, for example a signature or an electronic business card to attach to the applications. e-mails, where and how to save sent messages, etc.
In the embodiment of Figure 1, the system includes Internet portals that are owned by one or more web servers that form an interface with the databases of the system, one of whose portals P1 is shown in Figure 1. The P1 portal is a portal called the partner portal, that is, a portal that allows pen manufacturers, paper manufacturers, service marketers and network operators to access selected parts of the system databases, through an interface unit (hereinafter IF). An example of another portal is one called the pen owner portal, that is, a portal that allows pen owners to access selected parts of the system databases. In an alternative embodiment, the functionalities of the two portals are merged into a common portal.
In the communication between the different participants illustrated in Figure 1, it is desirable that the information is sent in a secure way, that is, through the use of encryption and digital signatures. If the DP digital pen sends confidential information to the SH service marketing unit, the DP digital pen encrypts the information and the SH service marketing unit, in order to decrypt the information, will decode it. The DP digital pen can use symmetric encryption or asymmetric encryption.
In Figure 2, a part of a product, such as the position-coded product used in the system of Figure 1, is shown in the form of a paper 1, provided, on its surface 2, with a part 3 legible optical position code that allows position determination. The position code pattern includes markings 4, which are methodically arranged on surface 2. The applicant proposes in the international patent application WO 01/16691, which has been incorporated herein by reference, the use of a product having a writing surface that is provided with said position code. The position code, which encodes a plurality of positions on the surface, allows the electronic recording of the information that is written on the writing surface, by means of a digital pen that detects the position code. The position code can encode the coordinates of a large number of positions, much greater than the number of positions required in the product. Thus, the position code can be seen as forming a virtual space that is defined by all the positions that the position code is capable of encoding, so that the different positions in the virtual space can be assigned for different functions and / or participants. It should be noted that, for clarity, the position code pattern shown in Figure 2 has been enlarged to a large scale.
Figure 3 shows a schematic representation of an embodiment of a broadcast device designed to read, for example, a position code pattern of Figure 2. The device is a digital pen. The DP pen comprises a housing 5, shaped in a pen-like shape. An opening 6 is provided in an end part of the housing 5. The aperture is intended to abut against - or to be clamped a small distance from - the surface S from which information is to be obtained.
Inside the housing 5 an optical unit, an electronic unit, and an electrical power supply unit are incorporated. According to further embodiments of the digital pen, a pressure sensor unit could also be included within the housing 5, which is described below.
The optical unit comprises a diode 7, intended to illuminate the surface provided with the position code, and a detector 8 sensitive to light, for example a charge-coupled detector (hereinafter CCD) or a detector of
ES 2 269 415 T3 complementary metal-oxide semiconductor (hereinafter CMOS), intended to record two-dimensional images. The electrical power supply unit is in this embodiment a battery 9, installed in a separate container.
The electronic unit 10 comprises a processing device including image processing means, encryption means and processing equipment programmed to read images from the detector 8 and perform position determination and information decoding based on the images. Additionally, the processing equipment is programmed to perform calculations in order, for example, from an image received from the detector, to calculate the properties of the optical data from the image. The data resulting from these calculations can be used as input data for other calculations or algorithms, such as encryption algorithms. In this embodiment, the AES and RSA algorithms have been implemented in the processing device.
Likewise, the electronic unit 10 comprises a memory or data storage element that is intended, for example, to save the data received from the treatment equipment or the detector, as well as program instructions for the treatment device.
Additionally, the pen could comprise a keyboard 11, which allows actuation and control of the pen. Also included is a transceiver 12 for wireless communication, by means of radioelectric waves or infrared light, with other participants of the system of Figure 1. Additionally, a display screen 13 may be included to show, for example, the information registered. The keyboard, transceiver, and display screen are in communication with - and controlled by - the electronic unit 10.
It should be noted that the illustration in Figure 3 is schematic, and that the actual configuration of the parts comprised within the pen could differ from the configuration shown without departing from the scope of the present invention.
In the aforementioned embodiment, the position code pattern is a readable optical pattern, and therefore the detector is an optical detector. The position code pattern may be based on a parameter other than an optical parameter as mentioned above. In that case, of course the detector must be of such a type that it can read the parameter in question.
The combination of a digital pen and a position code product can be used as an input device to a computer, a PDA, a mobile phone, or the like.
For example, text and sketches written in a position-coded notepad can be transferred using the pen to a computer. Additionally, the combination of a pen and a product with a position code allows global communication, directly from the product through the pen, by means of the position code on the product that is assigned for said communication. For example, the information recorded by the pen can be transformed into a fax message, an email message, or an SMS, and can then be sent from the pen to a recipient. In addition, the combination of a pen and a product with a position code can be used in foreign trade. For example, the digital pen can be used to order an item from a position code advertisement in a magazine, using the position code of the advertisement that is assigned to that service.
The above concept has been implemented in a system or infrastructure, which is shown in Figure 1, and which is further described in the applicant's international patent application numbers WO 0 148 678, WO 0 148 591 and WO 0 148 685.
The method of the invention for encrypting a message based on the information written on the position-coded products of Figure 2 is presented below, in the form of a flow chart, with reference to Figure 4 by means of the sender device of Figure 3, and to thereby provide a secure transmission of said message from a sender device to a receiver, for example in the form of an email message, an SMS, or a fax. Additionally, the position-coded product and the emitting device have preferably been incorporated into a system such as that presented in Figure 1.
Starting at step 410, a patterned surface is read or scanned by detector 8, thereby obtaining an optical image (hereinafter OI). The OI image is then saved as a representation of the pattern on an image storage medium. The optical image OI of the optical data representing the image includes a predetermined number of pixels. The size and number of these pixel representations, that is, the resolution, are adjustable.
According to an exemplary embodiment, each optical image includes 96x96 pixels. Additionally, the 96x96 pixels are divided into a matrix consisting of 16x16 pixel elements in which each pixel therefore consists of 6x6 pixels. Of course, there are any number of conceivable configurations of pixels in an optical image that can be used without departing from the scope of the present invention.
In step 420, decoding of the information comprised in the optical image data is performed. In the preferred embodiment, the resulting optical data OD comprises brightness information on the portion of the surface that has been read. The factors influencing the detected brightness have already been described above.
ES 2 269 415 T3
Brightness is represented by discrete values. In the preferred embodiment of the present invention, a white surface corresponds to a value of 255 and a black surface, for example a black mark, corresponds to a value of 0. To increase the dynamics of the optical data, it is preferred that each element of Image, representing a part of the surface, includes data for at least one mark and for at least a part of a surface surrounding the marks.
However, any of the input values from the digital pen detectors, such as pen pressure, coordinates, time, or the like, can be used for the generation of a key. These parameters are then used in combination with the OD optical data or in combination with random computer diversifications.
In step 430, the optical data OD produced by the detector is processed to calculate the specific statistical properties of the optical data. According to the most preferred embodiments, a maximum value, a minimum value and a sum value of the intensity or brightness of a number of pixels are calculated and used in the continuous processing as optical data. Statistical values thus calculated will hereinafter be referred to as processed optical data (POD). This calculation is performed on each pixel, that is, on the optical data OD represented on each pixel, respectively. Of course, there are other preferably statistical properties that could be calculated, such as an average value, or a standard deviation value.
Next, in step 440, the resulting stream of POD processed optical data is organized into groups of bits or data fields. According to the most preferred embodiment of the present invention, each pixel is represented by a data record (hereinafter DR), and each data record consists of four data fields. The first two data fields contain the calculated sum value, the third contains the minimum calculated value, and the fourth contains the maximum calculated value. Thus, a sequence of DR data records is produced from an optical image, each data record corresponding to one pixel of the image. When DR data records are produced, they are optionally stored in a cyclic recorder, prior to use as random number data, and arranged in the treatment device for access by the treatment team when needed, for example in the transmission of a message.
Then, in step 450, the sequence of data records DR is processed in an algorithm in order to increase the stochasticity of the optical data processed in the data records. This is due to the fact that the POD treated optical data is not 100 percent random in a statistical sense. Therefore, it is desirable to carry out further processing in order to refine the statistical characteristics of the optical data, that is, to increase the randomness or stochasticity of the processed optical data, before the processed optical data is used as a random seed. . Figures 5 and 8 present two different algorithms of two alternative embodiments of the present invention to increase the randomness of the processed optical data. These algorithms are described in more detail later.
Finally, in step 460, the optical data processed as an encryption key (hereinafter EK) is used in an encryption algorithm, and encryption of a message obtained from the position-coded surface is performed using the digital pen.
According to an alternative embodiment, in step 460 the processed optical data is used for the authentication of a sent message. The processed optical data is then used as random number data, which is encrypted by means of an encryption key, for example a private key from the digital pen, and the encrypted random number data is used for authentication of said sent message. .
Encryption algorithms, such as the AES encryption algorithm, use block encryption. A block cipher, that is, an encryption algorithm that uses block encryption, is a ciphertext method (to produce ciphertext) in which an encryption key and an algorithm are applied to a block of data from once as a group instead of one bit at a time. The main alternative method, used much less frequently, is called stream encryption.
There is a cryptological difficulty when the text to be encrypted contains static data, which does not change from one text to another. If different encryption keys are used to encrypt text containing static data, an intruder could draw conclusions regarding the key if the position of the static data is known to the intruder. To prevent this, it is common to apply the ciphertext from the previous cipher block to the next block in the sequence. This mode of ciphering in cipher blocks is often referred to as cipher block chaining cipher (CBC). Then, the encryption of the block that includes the static data depends on all the previous text blocks, which makes it more or less impossible to draw conclusions related to the key of the encryption of the static data. To ensure this, an initiation vector obtained from a random generator is combined with the text from the first block. Accordingly, and in accordance with preferred embodiments of the present invention, the processed optical data is used to form both the encryption key, that is, the key data block, and the initiation vector, that is, the data block. input.
Referring now to Figure 5, there is shown a flow chart of the method according to a first preferred algorithm according to the present invention for increasing the randomness or stochasticity of the processed optical data and for producing random numbers. It should be noted that the following description with reference to Figures 5, 6, 7A, and 7B corresponds to step 450 of Figure 4.
ES 2 269 415 T3
First, in step 510, the sequence of data records, obtained in step 440 of Figure 4, is organized into data blocks, in which each block is determined or labeled either as a key data block (hereinafter KB) or as an input data block (hereinafter IB), according to the previous description. According to the most preferred embodiment of the present invention, four subsequent data records are organized into a single data block. Also, a yes and a no data block is a KB key data block, and intermediate data blocks are IB input data blocks.
Then, in step 520, the key data blocks KB are processed according to a first mathematical algorithm, and in step 530 the input data blocks IB are processed according to a second mathematical algorithm. Mathematical algorithms define a cyclic reordering procedure or an offset procedure of the data fields included in the key data block KB and the input data block IB, respectively.
With particular reference to Figure 6, the order of the data fields within a KB key data block or IB input data block prior to the scrolling procedure is shown. The records are shown schematically as boxes divided into four elements, each element representing a data field. In the most preferred embodiment, the fields indicated with the numbers 1 and 2 include the sum of brightness value, the fields indicated with the number 3 the minimum value, and the field indicated with the number 4 the maximum value. Table 1 below shows the cyclical scrolling scheme of the data fields included in the KB key data block.
TABLE 1
<td>Data register</td><td>Stages</td>
<td>TO</td><td> 0</td>
<td>B</td><td> 3</td>
<td>C</td><td> 2</td>
<td>D</td><td> 1</td>
In Fig. 7A, the ordering of the data fields within the key data block has been performed after cyclical scrolling as shown. Data fields in the first data record, record A, retain their positions, data fields within the second record, record B, shift three positions to the right, fields within the third record, record C, shift two positions to the right, and the fields within the fourth record, record D, are shifted one position to the right. The data block output as a result of the reordering algorithm for a key data block is referred to as the reordered key data block (hereinafter RKB).
Table 2 shows the cyclical scrolling scheme of the data fields included in the input data block IB.
TABLE 2
<td>Data register</td><td>Stages</td>
<td>TO</td><td> 1</td>
<td>B</td><td> 2</td>
<td>C</td><td> 3</td>
<td>D</td><td> 1</td>
In Figure 7B, the order of the data fields within the input data block is shown after cyclical scrolling, to the right. The data fields within the first data record, record A, have shifted one position, the data fields within the second data record, record B, have shifted two positions, the data fields within the third data record , record C, have been shifted three positions, and the data fields within the fourth data record, record D, retain their positions. The data block output as a result of the reordering algorithm for an input data block is referred to as a reordered input data block (hereinafter RIB).
ES 2 269 415 T3
It should be noted that a wide variety of shift algorithms could be used within the scope of the present invention to obtain reordered or rearranged key and input data blocks. However, it has surprisingly been found that the above-described rearrangement of the data fields within the data records included in the key data block and in the input data block provides a particular and considerable refinement of the desired statistical properties. for the output data of a resulting cipher, when the result of the reordering procedure is used as key data and input data for the cipher. In other words, the randomness and stochasticity of the output data increases and the predictability decreases. In fact, according to art-recognized statistical testing procedures, the output data of the encryption algorithm, that is, the encrypted message, can be considered as uniformly distributed white noise. This unexpected effect is due to the fact that the correlation between the processed optical data included in the data fields within a data record, which in turn is transmitted to the output data of the encryption algorithm, is disturbed by the procedure aforementioned reordering.
Then, in step 540, the data contained in the thus reordered input and key data blocks is used as the encryption key, key data KD, and the initiation vector, input data ID, respectively, for the encryption algorithm.
Finally, at step 550, the method reverts to the procedure shown in Figure 4 at step 460, where the actual encryption of the message is performed using, in this preferred embodiment, the AES encryption algorithm. However, other encryption algorithms are of course contemplated within the scope of the present invention.
A second alternative preferred embodiment of an algorithm for improving the statistical characteristics of the processed optical data is described below, with particular reference to Figure 8.
The algorithm can be considered to have two parts. In the first part, referred to as a seed update, a random seed is calculated based on the optical data processed. In the second part, referred to as the random number calculation, the thus calculated random seed is used as input data for the calculation of the random numbers to be used in the encryption algorithm.
The data blocks that include a subset of the sequence of data records containing the processed optical data form the input data in the seed update portion. The data records comprise data fields, preferably organized as described above in connection with the first preferred embodiment. Thus, each data record includes four data fields, of which the first two include the sum value, the third the minimum value, and the fourth the maximum value, see Figure 6.
In step 810, each data block is processed in a first summary function, which in this embodiment is an encryption algorithm, in order to increase the randomness of the data records containing the processed optical data. The first digest function is, in this embodiment, a symmetric encryption algorithm. The data records containing the processed optical data are used as the encryption key, and an arbitrarily chosen vector is used as the initiation vector. However, it is preferred that the number of ones and zeros be substantially equal and approximately distributed throughout the initiation vector. This can be achieved by using the above seed as the initiation vector for the summary algorithm, which will eliminate the risk of patterns that could occur due to frequent seed updates with substantially similar input data, and improve the quality of the random seed.
Then, in step 820, an iterative process concatenates each summary output or summary value, (hereinafter HV) and thus forms summary output data blocks. This is due to the fact that a summary procedure typically results in an output that has a data size that is smaller, or much smaller, than the data size of the input data. The number of iterations depends on the desired size of the output data.
The output data blocks are then divided into key data blocks and seed data blocks in step 830. The key data blocks and seed data blocks are used as input data in the calculation part. of random numbers. This can be expressed mathematically as
<td>Input data:</td><td>optical data</td><td>= SU<sub>2</sub>,<sub>m</sub>-<sub>1</sub> ..ITS! South</td>
<td>Calculation:</td><td>SIx</td><td>= Summary<sub>n</sub> (YES<sub>x</sub>, ITS<sub>x</sub>)</td>
<td>Output data:</td><td>entrance of</td><td> = <sup>YES</sup>2 * m-1 ..<sup>YES</sup>1<sup>, YES</sup>0</td>
<td></td><td>seed</td><td>= SKm-i, ... SKiSKoSDm-i ... SDi SD,</td>
<td></td><td>key data</td><td>= SKm -! ... SKiSKo</td>
<td></td><td>seed data</td><td>= SDm-1 ... SDiSDo</td>
where in Y / n, Y is the bit length of the random number to be generated in the second stage, and n is the bit length of the output data of the summary algorithm, Summary. Besides, his<sub>x</sub> is the x block of input data, IF<sub>x</sub> is block x of output data, SK<sub>x</sub> is block x of key data y SD<sub>x</sub> is block x of seed data. In this embodiment,
ES 2 269 415 T3 the digest algorithm is performed using a symmetric encryption algorithm, AES. As those skilled in the art will understand, there are a significant number of conceivable algorithms that can be used to obtain increased randomness and that can be implemented in place of the AES algorithm. The seed update can be done with a total update of the seed, that is, with all the data blocks included in SI, or with a data block, SI<sub>x</sub>. This depends on the requirements of the random number calculation algorithm in part two and the available computing power.
Then, in step 840, in the part of the random number calculation, the key data blocks and the seed data blocks are used as input data in a second algorithm, which in this embodiment uses a symmetric encryption algorithm. , for example AES. The algorithm performed in step 840 is an iterative algorithm. As mentioned above, there are a number of alternative encryption algorithms that can be used in said second algorithm instead of AES, for example IDEA or DES. Alternatively, the algorithms A3 or A5 could be used, which are current figures and are used for symmetric encryption. A counter is also included, for the seed count. The counter counts the number of times the random number calculation has been used since the input data was updated in the seed update. Mathematically, the calculation of random numbers can be expressed as
<td>Input data:</td><td>key data seed data seed count</td><td>= SKm-i ... SKiSKo = SDm-i ... SDiSDo</td>
<td>Calculation:</td><td>For x from 0 to (m-1) 1.1 PR<sub>X</sub> 1.2 <sup>SK</sup>(<sub>x</sub>+2) modm 1.<sup>3 S</sup>D (x + 1) modm seed count</td><td>= Encryption (key = SKx, input = SDx)<sup>= SK</sup>(x + 2) modm <sup>xorPR</sup>x<sup>= SD</sup>(x + 1) modm <sup>xorPR</sup>x = seed count +1</td>
<td>Output data:</td><td>random number key data seed data seed count</td><td>= PRm-1 ... PR1PR0 = SKm-l ... SKiSKo = SDm-1 .... SD1SD0</td>
where PRx is a block x of random number data, xor is an XOR operation, mod is a modulo operation, and "cipher" is a symmetric cipher algorithm. Also, in the calculation stage, a block transformation is performed. This transformation further increases the randomness of the random numbers.
The transformation of stages 1.2 and 1.3 could be done in a number of other ways, but the method described ensures that all changes in a block are transformed throughout most of the random seed, and thus ensures a seed high quality random for the next calculation.
According to an alternative embodiment, the second algorithm is a digest function, preferably using the same symmetric encryption algorithm as in the second algorithm described above.
Finally, in step 850, the method returns to the procedure shown in Figure 4 in step 460, in which the actual encryption of the message is performed using, in this preferred embodiment, the AES encryption algorithm, where the number data Random PRx obtained by means of the above method are used as the encryption key in step 460 of Figure 4.
Alternatively, encryption of the random number data PRx is performed, for example by using an asymmetric encryption algorithm. The encrypted random number data is then sent to the recipient of the encrypted message. The receiver performs a digest of the encrypted random number data and uses the resulting digest value as a private encryption key, which is then used as an asymmetric encryption algorithm for decryption of the received message.
Although specific embodiments have been shown and described herein by way of illustration and example, those skilled in the art will understand that the specific embodiments shown and described could be substituted for a wide variety of alternative and / or equivalent embodiments without departing from the scope of the invention. of the present invention. Those skilled in the art will readily appreciate that the present invention can be implemented in a wide variety of embodiments, including various hardware and software implementations, or combinations thereof. This application is intended to cover any adaptations or variations of the preferred embodiments described herein. Accordingly, the present invention is defined by the text of the appended claims.
Contents9
7 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7
21 members in 9 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 0002158 | Sweden | A | |
| 0002158 | Sweden | A | |
| 20000002158 | Sweden | – | |
| 000215801938930 | – | – | – |
| SE20000002158 | – | – | – |
Members21
| Document | Office | Kind | |
|---|---|---|---|
| SE0002158D0 | Sweden | D0 | |
| SE0002158L | Sweden | L | |
| WO0195091A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO0195559A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU6448001A | Australia | A | |
| AU6450101A | Australia | A | |
| SE516567C2 | Sweden | C2 | |
| US2002034300A1 | United States of America | A1 | |
| US2002035687A1 | United States of America | A1 | |
| EP1292882A1 | European Patent Office (EPO) | A1 | |
| EP1293061A1 | European Patent Office (EPO) | A1 | |
| JP2003536299A | Japan | A | |
| EP1292882B1 | European Patent Office (EPO) | B1 | |
| AT334443T | Austria | T | |
| ATE334443T1 | Austria | T1 | |
| DE60121764D1 | Germany | D1 | |
| DE60121764T2 | Germany | T2 | |
| ES2269415T3This record | Spain | T3 | |
| US7278017B2 | United States of America | B2 | |
| US7457413B2 | United States of America | B2 | |
| JP4815094B2 | Japan | B2 |
Numbers
- Publication
- 2269415
- Publication, DOCDB
- 2269415
- Publication, EPODOC
- ES2269415T
- Application
- 1938930
- Application, DOCDB
- 01938930
- Application, EPODOC
- ES20010938930T
Titles2
- Spanish
- METODO Y DISPOSITIVO PARA CIFRAR UN MENSAJE.
- English
- METHOD AND DEVICE FOR ENCRYPTING A MESSAGE.
Classification
- CPC, 7
- G06F7/588
- H04L9/0866
- H04L9/3231
- H04L9/0662
- H04L9/0643
- H04L2209/805
- H04W12/033
- IPC, 6
- G06F7 58
- H04L9 08
- H04L9 14
- H04L9 22
- H04L9 30
- H04L9 32