Block cipher apparatus using auxiliary transformation
Abstract
A data transformation apparatus having a key generation unit (300, 600) to generate output key data based on K input key data, and a data processing unit to perform at least one of the data encryption and data decryption based on the output key data, characterized in that the key generating unit comprises: a first G bit transformation unit (320) to transform the K input key data entered therein into the first G bit key data represented by G bits, and a second G bit key transformation unit ( 330) to transform the first G bit key data entered therein into the second G bit key data represented by G bits, and because the key generating unit, if the K input key data is represented by G bits, it generates first K 1 key data by means of the transformation of the K key data entered by means of the G bit key transformation unit (320), and it takes out the first K 1 G bit key data as the exit key data, and because the key generating unit, if the K input key data is represented by 2 G bits, generates key data represented by G bits from the K input key data, and generates first K1 key data of G bits by transforming the key data generated by the first G key transformation unit bits (320) and generates second K2 G bit key data represented by G bits by means of the transformation of the first K 1 G bit key data by the second G bit key transformation unit (330), concatenates the first K1 G bit key data and the second K2 G bit key data, and takes out the concatenated key data as the exit key data.

Term
Term ended
Projected expiry passed 8 March 2021, 5.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
6 claims: 2 independent, 4 dependent
- 1ES 2 327 263 T3 REIVINDICACIONES 1. Un aparato de transformación de datos que tiene una unidad de generación de clave (300,600) para generar datos de clave de salida en base a K datos de clave de entrada, y una unidad de procesado de datos para realizar al menos uno de entre el encriptado de datos y el desencriptado de datos en base a los datos de clave de salida, caracterizado porque la unidad generadora de clave comprende:una primera unidad de transformación de G bits (320) para transformar los K datos de clave de entrada introducidos en la misma en los primeros datos de clave de G bits representados por G bits, y una segunda unidad de transformación de clave de G bits (330) para transformar los primeros datos de clave de G bits introducidos en la misma dentro de los segundos datos de clave de G bits representados por G bits, y porque la unidad de generación de clave, si los K datos de clave de entrada están representados por G bits, genera primeros K1 datos de clave por medio de la transformación de los K datos de clave introducidos por medio de la unidad de transformación de clave de G bits (320), y saca los primeros K1 datos de clave de G bits como los datos de clave de salida, y porque la unidad generadora de clave, si los K datos de clave de entrada están representados por 2 G bits, genera datos de clave representados por G bits a partir de los K datos de clave de entrada, y genera primeros K 1 datos de clave de G bits por medio de la transformación de los datos de clave generados por la primera unidad de transformación de clave de G bits (320) y genera segundos K2 datos de clave de G bits representados por G bits por medio de la transformación de los primeros K 1 datos de clave de G bits por la segunda unidad de transformación de clave de G bits (330), concatena los primeros K1 datos de clave de G bits y los segundos K2 datos de clave de G bits, y saca los datos de clave concatenados como los datos de clave de salida.
- 2El aparato de transformación de datos de la reivindicación 1, en el que la primera unidad de transformación de clave de G bits incluye:Una unidad de transformación no lineal que tiene dos rondas para realizar la transformación no lineal de los K datos de clave de entrada;y Una unidad de operación lógica para realizar una operación lógica sobre datos de clave transformados a medio camino representados por G bits sacados de una segunda ronda de la unidad de transformación no lineal y los K datos de clave de entrada introducidos en la primera unidad de transformación de clave de G bits.
- 3El aparato de transformación de datos de la reivindicación 1, en el que la unidad generadora de clave incluye de manera adicional una unidad de transformación de longitud binaria para convertir los datos de clave de Q bits en datos de clave representados por 2G bits si se introducen los datos de clave de Q bits (G Q 2G).
- 4Un procedimiento de transformación de datos para ejecutar un proceso de generación de clave para generar datos de clave de salida en base a K datos de clave de entrada, y una unidad de procesado de datos para realizar al menos uno de entre el encriptado de datos y el desencriptado de datos en base a los datos de clave de salida, caracterizado porque el proceso de generación de clave comprende:un primer proceso de transformación de G bits para transformar los K datos de clave de entrada introducidos en la misma en los primeros datos de clave de G bits representados por G bits, y un segundo proceso de transformación de clave de G bits para transformar los primeros datos de clave de G bits introducidos en la misma dentro de los segundos datos de clave de G bits representados por G bits, y porque el proceso de generación de clave, si los K datos de clave de entrada están representados por G bits, genera primeros K1 datos de clave por medio de la transformación de los K datos de clave introducidos por medio del proceso de transformación de clave de G bits, y saca los primeros K1 datos de clave de G bits como los datos de clave de salida, y porque el proceso de generación de clave, si los K datos de clave de entrada están representados por 2G bits, genera datos de clave representados por G bits a partir de los K datos de clave de entrada, y genera primeros K 1 datos de clave de G bits por medio del proceso de los datos de clave generados por medio de la transformación de los datos de clave de G bits por el primer proceso de transformación de clave de G bits, y genera segundos K2 datos de clave de G bits representados por G bits por medio de la transformación de los primeros K1 datos de clave de G bits por el segundo proceso de de transformación de clave de G bits, concatena los primeros K1 datos de clave de G bits y los segundos K2 datos de clave de G bits, y saca los datos de clave concatenados como los datos de clave de salida.
- 5Un programa de ordenador que comprende un medio de código de ordenador adaptado para realizar los pasos del procedimiento de la reivindicación 4 cuando el mencionado programa de ordenador se está ejecutando en un ordenador.
- 6Un medio portador legible por un ordenador que soporta el programa de ordenador de la reivindicación 5.
Independent claims6
229 paragraphs in 12 sections, as filed
ES 2 327 263 T3
DESCRIPTION
Block cipher apparatus and block cipher procedure that includes programming a variable length key.
Technical field
The present invention refers to a data transformation apparatus, to data transformation procedures, and to storage means in which the data transformation procedures are registered, for their encryption, decryption, and dissemination of the data with the in order to protect existing digital information in information communications.
Background technique
Fig. 25 represents an encryption function used in DES described in “Gendai Ango Riron (Modern Cipher Theory)” “(Modern Cipher Theory)”] (Institute of Electronics, Information and Communication Engineers [“The Institute of Electronics, Information and Communication Engineers ”] published on November 15, 1997, page 46).
As shown in Fig. 25, eight S-boxes are used. These eight S-boxes are different tables from each other. Each table outputs 4-bit data from 6-bit input data.
Fig. 26 shows a nonlinear transform function that is described in "Specification of E2 - a 128-bit Block Cipher" ["Specification of E2 - a 128-bit Block Cipher"] ("Nippon Telegraph and Telephone Corporation" published June 14, 1998, page 10), as well as in Kanda M. et al .: “E2 - a new 128-bit block cipher” [“E2 - a new 128-bit block cipher”], Transactions on Fundamentals of Electronics [“IEICE Transactions on Fundamentals of Electronics”], Communications and Computer Sciences, Engineering Sciences Society, Tokyo, JP. Vol. E38-A, No. 1, January 2000, (2000-01), pages 48-59, XP 002367858 ISSN: 0916-8508.
As shown in Fig. 26, each function unit S is made up of eight S boxes.
Conventional encryption devices use multiple S-boxes. Since some ciphers are equipped with tables different from each other, the memory usage is increased compared to those equipped with an S-box. Since, on the other hand, other ciphers use only an S box, the encryption security is reduced.
As shown in Fig. 7, when a normal data transformation unit (FL) 250 is inserted into the encryption unit, it is required to supply an inverse data transformation unit (FL<sup>-1</sup>) 270 in a decryption unit to decrypt the encrypted texts. Since, as a general rule, the normal data transformation unit (FL) 250 and the inverse data transformation unit (FL<sup>-1</sup>) 270 are different circuits from each other, this causes a problem in that the encryption unit and the decryption unit cannot provide the same configuration.
On the other hand, in the generation of extension keys, complex operations are required in order to generate extension keys that offer greater security. There is another problem in the case of the generation of extension keys in that the number of bits of the key data that must be entered as the initial value must be fixed. Document EP-A-0 982 895 (by Kabushiki Kaisha Toshiba) describes a data processor in which a plaintext is encrypted to an encrypted text by means of the use of an encryption key and / or an encrypted text is decrypted to a plain text by means of the use of a decryption key, and in which the device is constructed by a plurality of sequentially connected key conversion functions, which are an involution type, and that direct the key conversion processing and the output extended keys based on the key for the encryption or the decryption or key conversion results and from a key conversion section in which the key conversion results are transferred sequentially between the key conversion functions in order or in reverse order.
The present invention aims to provide systems in which the encryption and decryption circuits are the same, and in which the area of the circuits, the size of the programs and the use of the memories that are used for a switching of nonlinear transformation can be reduced, and likewise, extension keys can be generated using a simpler configuration.
Description of the invention
This objective is solved by the data transformation apparatus according to claim 1, with the data transformation method according to claim 4, with the computer program according to claim 5 and with the carrier means according to with claim 6. Further improvements to the data transformation apparatus are offered in the dependent claims.
A data transformation apparatus of the present invention is characterized in that in the data transformation apparatus having a data processing unit for inputting key data and for performing at least one
ES 2 327 263 T3 data encryption or data decryption, and a key generating unit for generating key data to be used by the data processing unit and supplying the key data to the data processing unit,
The key generating unit includes:
a first G-bit key transformation unit for inputting G-bit key data having G bits, transforming the G-bit key data, and outputting the first G-bit transformed key data having G bits; <sup>Y</sup> a second G-bit transformation unit to input the output of the first G-bit transform key data from the first G-bit key transform unit, transform the G-bit key data, and output second transformed key data of G bits.
the key generating unit, if the key generating unit input K G-bit key data, input the K G-bit key data to the first G-bit key transformation unit to transform and output K<sub>1</sub> G-bit key data from the first G-bit key transformation unit as G-bit key data, and the key generator unit, if the key generator unit inputs K 2G-bit key data, generates data from G-bit key from the K 2G-bit key data, input the generated G-bit key data into the first G-bit key transform unit to transform, and output the first Ki G-bit key data , enter the first K<sub>1</sub> G-bit key data transformed to the second G-bit transform unit, and outputs K seconds<sub>2</sub> G-bit key data, concatenates the output of the first K<sub>1</sub> G-bit key data reported, with the output of the first G-bit key transformation unit and outputs a concatenated result as 2-bit key data G (K<sub>1</sub>, K<sub>2</sub>)
The above first G-bit key transform unit includes:
a non-linear transformation unit having two rounds to perform non-linear transformation on the G-bit key data; and a logical operation unit for performing a logical operation of a half-way transformed G-bit key data output from a second round of the non-linear transformation unit and from the G-bit key data input to the first G-bit key transformation unit.
The above key generation unit additionally includes a bit length transform unit to convert Q-bit key data into 2G-bit key data if Q-bit key data G <Q <2G is input. .
A data transformation procedure of the present invention is characterized in that in a data transformation procedure for executing a data processing procedure for entering key data and performing at least one data encryption and one data decryption , and a key generation process for generating key data to be used by the data processing procedure and supplying the key data to the data processing procedure, the key generation procedure includes:
a first G-bit key transformation process for inputting G-bit key data having G bits, transforming the G-bit key data, and outputting the first G-bit transformed key data; <sup>Y</sup> a second G-bit transformation process to input the first G-bit transformed key data output from the first G-bit key transformation process, transforming the G-bit key data, and outputting second transformed key data from G bits, and the key generation process, if the key generating unit inputs K G-bit key data, it inputs K G-bit key data into the first G-bit key transformation unit, transforms the K G-bit key data, and outputs K1 G-bit key data from the G-bit key transformation process as transformed G-bit key data, and the key generation process, if the key generating unit inputs K 2G-bit key data, generates G-bit key data from the K 2G-bit key data, inputs the generated G-bit key data into the first G-bit key transform unit to transform and outputs the first K<sub>1</sub> Transformed G-bit key data, input the first K1 transformed G-bit key data into the second G-bit transform process to transform, and output second K<sub>2</sub> G-bit key data, concatenates the output of the first K<sub>1</sub> G-bit key data transformed from the G-bit key transformation unit and the output of the second K2 transformed G-bit key data from the second G-bit transformation unit and outputs a concatenated result as the transform of the 2G bit key data (K<sub>1</sub>, K<sub>2</sub>).
ES 2 327 263 T3
The present invention features a computer-readable storage medium for storing a program for a computer to carry out the data transformation procedure set forth.
The present invention is characterized by a program for a computer to carry out the data transformation procedure set forth.
Brief explanation of the drawings
Fig. 1 shows a data transformation unit for an encryption 100 and a data transformation unit for a decryption 400.
Fig. 2 shows annotations.
Fig. 3 shows a configuration of an encryption unit 200 or a decryption unit 500.
Fig. 4 shows another configuration of the encryption unit 200 or the decryption unit 500.
Fig. 5 shows a configuration of a normal data transformation unit (FL) 251.
Fig. 6 shows a configuration of an inverse data transformation unit (FL<sup>-1</sup>) 271.
Fig. 7 shows a part of a conventional encryption unit and a conventional decryption unit.
Fig. 8 shows a part of the encryption unit 200 and the decryption unit 500.
Fig. 9 shows the normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 that are located in point symmetry.
Fig. 10 shows the relationship between the normal data transformation unit (FL) 251 and the inverse data transformation unit (FL ·<sup>1</sup>) 271 that are located in point symmetry.
Fig. 11 shows a nonlinear unit of function F.
Fig. 12 shows a configuration of a first S-box transformation unit 13 and a second S-box transformation unit 14.
Fig. 13 shows a configuration of a transformation unit 21 of a box S.
Fig. 14 shows a configuration of a linear transformation unit85.
Fig. 15 shows a configuration of a linear transformation unit87.
Fig. 16 shows a configuration of a key generation unit 300 or a key generation unit 600.
Fig. 17 explains the operations of a bit length transformation unit 310.
Fig. 18 shows a configuration of an A 341 shift register.
Fig. 19 shows a configuration of a control table of a displacement control unit 345.
Fig. 20 shows the operations of shift register A 341 and shift register B 342.
Fig. 21 shows the correspondence between shift register A 341, shift register B 342, and extension keys.
Fig. 22 shows the operations of shift registers A 341 to D 344.
Fig. 23 shows the correspondence between shift registers A 341 to D 344 and the extension keys.
Fig. 24 shows a computer equipped with the data transformation unit for encryption 100 and the data transformation unit for decryption 400.
Fig. 25 shows a configuration of the DES encryption function.
ES 2 327 263 T3
Fig. 26 shows a configuration of a non-linear function of the 128-bit E2 block cipher.
Fig. 27 shows another example of S box transformation units.
Fig. 28 shows a non-linear function unit F that is equipped with the first to fourth box transform units S.
Fig. 29 shows another non-linear function unit F in which the key function unit 25 is displaced.
Fig. 30 shows another non-linear function unit F in which a location of the key function unit 25 is displaced.
Fig. 31 shows another configuration of the function unit P 30.
Fig. 32 shows another configuration of the function unit P 30.
Fig. 33 shows the settings and operations of S1 to S4 of Fig. 31.
Fig. 34 shows a proof of the non-existence of equivalent keys.
Fig. 35 shows a proof of the non-existence of equivalent keys.
Fig. 36 shows another configuration of the encryption unit 200 or the decryption unit 500.
Fig. 37 shows another configuration of the encryption unit 200 or the decryption unit 500.
Fig. 38 shows another configuration of the encryption unit 200 or the decryption unit 500.
Fig. 39 shows another configuration of the encryption unit 200 or the decryption unit 500.
Fig. 40 shows another configuration of the encryption unit 200 or the decryption unit 500.
Fig. 41 shows another configuration of the encryption unit 200 or the decryption unit 500.
Fig. 42 shows a configuration in which the units of Fig. 39 and Fig. 40 are combined.
Fig. 43 shows a configuration of the encryption unit 200 or decryption unit 500, which is shown in Fig. 3, using the non-linear function unit F shown in Fig. 28.
Fig. 44 shows a modified configuration of Fig. 43 by using a non-linear function unit F 'in which the key function unit 25 of the non-linear function unit F is suppressed.
Fig. 45 shows a modified configuration of Fig. 44 by fusing the bleach extension keys with the extension keys.
Fig. 46 shows a modified configuration in which the key function unit 25 is suppressed from the non-linear function unit F and in which an extension key k is supplied to an XOR circuit 298, when the function unit Nonlinear F is configured as shown in Fig. 29.
Fig. 47 shows a modified configuration in which the key function unit 25 is suppressed from the non-linear function unit F and in which a non-linearly transformed extension key k 'is supplied to the XOR circuit 298, when the non-linear function unit F is configured as shown in Fig. 30.
Best mode of carrying out the invention
Embodiment 1
Fig. 1 shows an encryption data transformation unit 100 and a decryption data transformation unit 400 in this embodiment.
The encryption data transformation unit 100 is, for example, an encryption device that outputs 128-bit ciphertext from input 128-bit clear text. The decryption data transformation unit 400 is a decryption device that outputs 128-bit clear texts from 128-bit input encryption texts. The encryption data transformation unit 100 is composed of an encryption unit 200 and a key generation unit 300. The encryption unit 200 is a data processing unit for encrypting clear texts. The key generation unit 300 generates multiple 64-bit or 128-bit extension (n) keys using constants V from 128-bit, 192-bit, or 256-bit input key data and to supply them to the
ES 2 327 263 T3 encryption unit 200. The decryption data transformation unit 400 is composed of a decryption unit 500 and a key generation unit 600. The decryption unit 500 is a data processing unit for decrypt encrypted texts. The key generation unit 600 is the same or similar to the disclosed key generation unit 300. Also, since the encryption unit 200 and the decryption unit 500 can perform the same procedure, they can share a circuit or a program, although the encryption unit 200 and the decryption unit 500 are illustrated separately in the figures. Similarly, the key generation units 300 and 600 cannot share a circuit or a program. That is, a circuit or a program can be shared by the encryption data transformation unit 100 and by the decryption data transformation unit 400.
Fig. 2 shows the meanings of the annotations used for the following figures or descriptions.
In Fig. 3 and subsequent figures, a left half of the data is called "left data L" and a right half of data is called "right data R". Likewise, the data entered in the non-linear data transformation units 210, 220, 230 and 240 are called "input data", the internal data of the non-linear data transformation units 210,220,230, and 240 are called "data intermediates ", and the output data from the non-linear data transformation units 210, 220, 230, and 240 are called" output data ".
Fig. 3 shows an example of the encryption unit 200 or the decryption unit 500.
Fig. 3 shows a configuration in which the 6-round non-linear data transformation unit 210, the 6-round non-linear data transformation unit 220, and the data non-linear transformation unit 230 are cascaded. of 6 rounds. The normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 are inserted between the 6-round data non-linear transformation unit 210 and the 6-round data non-linear transformation unit 220. Likewise, the normal data transformation unit (FL) 253 and the inverse data transformation unit (FL<sup>-1</sup>) 273 are inserted between the 6-round data non-linear transformation unit 220 and the 6-round data non-linear transformation unit 230. Within the 6-round data nonlinear transformation unit 210, 6 rounds of data nonlinear transformation units are arranged. For example, a data non-linear transformation unit 280 is composed of a non-linear function unit F and an XOR (exclusive-OR) circuit 290. Thus, in the case of Fig. 3, in total 18 rounds of data nonlinear transformation units are supplied.
The nonlinear data transformation unit 210 is equipped with a first nonlinear data transformation unit 280 and with a second nonlinear data transformation unit 281. For two arbitrary input data items, the input data of the right R<sub>or</sub> and the left input data L<sub>or</sub>, the first performs the first nonlinear transformation on the left input data L<sub>or</sub> using a first k key extension<sub>1</sub>, outputs a result operated with the XOR function of the output data of the first nonlinear transformation and the input data on the right Ro as the first intermediate data on the left L1 and outputs the input data on the left Lo as first intermediate data on the right R1. The latter performs a second non-linear transformation on the first left intermediate data R1 using a second extension key k<sub>2</sub>, outputs a result operated with the XOR function of the output data of the second nonlinear transformation and the first intermediate data of the right R1 as second intermediate data of the left L2, and outputs the first intermediate data of the left L1 as second intermediate data from right R2. The nonlinear data transformation unit 210, in which the first nonlinear data transformation unit 280 to the sixth nonlinear data transformation unit 285 are cascaded, outputs the final intermediate data on the right R<sub>6</sub> and the intermediate data on the left L<sub>6 </sub>as output data after transformation.
Fig. 4 shows a configuration in which a normal data transformation unit (FL) 255, an inverse data transformation unit (FL<sup>-1</sup>) 275, and a 6-round nonlinear data transformation unit 240 is added to the encryption unit 200 as shown in Fig. 3. In total, the data transformation is carried out by 24 rounds of data units. nonlinear transformation of data.
Fig. 5 shows the normal data transformation unit (FL) 251.
Fig. 5 shows that the normal data transformation unit (FL) 251 divides the input data into two data items, the input data 51 on the left and the input data 52 on the right, performs the same tasks. logical operations for both data items, and generates the output data from the input data 60 on the left and the input data 61 on the right. The input data 51 on the left is ANDed with an extension key 53 in an AND circuit 54, and then the data operated with the AND function is rotationally shifted to the left (also called “circular shift”). by 1 bit in a 1-bit left rotational shift unit 55. The shifted data is operated with the XOR function with the input data 52 from the right in an XOR circuit 56. The output from the XOR circuit 56 is converted into the output data 61 on the right, and is operated with the OR function with an extension key 57 in an OR circuit 58. Next, the result operated with the OR function is operated with the XOR function with the input data 51 on the left in an XOR circuit 59 to generate the output data 60 on the left.
ES 2 327 263 T3
Fig. 6 shows the inverse data transformation unit (FL ') 271.
Fig. 6 shows that the inverse data transformation unit (FL<sup>-1</sup>) 271 splits the input data into two data items, the input data 71 on the left and the input data 72 on the right, performs the logical operations for both data items, and generates the output data from of the output data 80 on the left and the output data 81 on the right.
The input data 72 on the right is operated with the OR function with an extension key 73 in an OR circuit 74, and then the data operated with the OR function is operated with the XOR function with the input data 71 of the left in an XOR circuit 75. Next, the output from the XOR circuit 75 is converted to the left output data 80 and is operated with the AND function with an extension key 76 in an AND circuit 77. After that, the result operated with the AND function is rotationally shifted to the left by 1 bit in a rotational shift unit 78 to the left of 1 bit, and the shifted data is operated with the XOR function with the input data 72 on the right in an XOR circuit 79. The output from the XOR circuit 79 becomes the output data 81 on the right.
The normal data transformation unit (FL) 251 shown in Fig. 5 and the inverse data transformation unit (FL<sup>-1</sup>) 271 shown in Fig. 6 carry out mutually opposite operations. Accordingly, using the same key extension, the input data X of Fig. 5 can be obtained as output data X of Fig. 6 by making the output data Y of Fig. 5 the data of input Y of Fig. 6.
The relation in which the input data in one unit can be obtained as output data from the other unit by making the output data from another unit the input data in the other unit is called a relation between the transformations normal and reverse. The normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 are circuits that perform this relationship between normal and inverse transformations.
Both the 1-bit left rotational shift unit 55 of Fig. 5 and the 1-bit left rotational shift unit 78 of Fig. 6 perform left shift, but both can perform the shift to the right. Likewise, the normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 can be any of one or the other configurations, as long as they maintain the relationship between normal and inverse transformations. For example, the number of offsets can be changed. Furthermore, an AND circuit with a "not" operation, an OR circuit with a "not" operation, and / or an XOR circuit with a "not" operation can be added. That is, the following are the definitions shown of the AND circuit with a “not” operation, the OR circuit with a “not” operation, and the XOR circuit with a “not” operation, represented by “andn”, “orn” , and "xorn", respectively.
x andn y: (not x) eyx orn y: (not x) oyx xorn y: (not x) ey
Some modern CPUs are provided with "and", "or", and "xor" commands including "not". These commands can be executed at the same cost as the "and", "or", and "xor" commands.
Fig. 7 shows a conventional encryption unit 201 and a conventional decryption unit 501.
The conventional encryption unit 201 is equipped with two normal data transformation units FL. Thus, the decryption unit must be equipped with two reverse data transformation units FL<sup>-1 </sup>in order to carry out the reverse operations. Consequently, since the encryption unit generally has a different configuration than the decryption unit, the encryption unit and the decryption unit cannot share the same circuit.
On the other hand, as shown in Fig. 8, in the present embodiment, the normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 are located side by side in the encryption unit 200, so that the decryption unit with the same configuration can carry out the decryption. For example, the data on the right R are transformed by the normal data transformation unit (FL) 251 to obtain the data on the left L ', and the data on the left L are transformed by the inverse data transformation unit (FL<sup>-1</sup>) 271 to get the data on the right R '. In this case, the data on the right R can be obtained by inputting the data on the left L 'into the inverse data transformation unit (FL<sup>-1</sup>) 271, and the data on the left L can be obtained by inputting the data on the right R 'into the normal data transformation unit (FL) 251.
As described above, the encryption unit 200 and the decryption unit 500 can be implemented by the same configuration, and the encryption unit 200 and the decryption unit 500 can share the circuit.
ES 2 327 263 T3
Fig. 9 shows a configuration in which the normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 are located in point symmetry on the nonlinear data transformation unit 280.
Thus, when the normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 are located in point symmetry on the nonlinear data transformation unit 280, encryption and decryption can be carried out using the same configuration.
Fig. 10 shows the correspondence between the data transformation unit (FL) and the inverse data transformation unit (FL<sup>-1</sup>) located in point symmetry.
As shown in Fig. 10, in the case of Fig. 3, the normal data transformation unit (FL) 251 and the inverse data transformation unit (FL<sup>-1</sup>) 271 are located in point symmetry on the 6-round nonlinear data transformation unit 220.
In Figs. 3, 4, 8, and 9, the data transformation unit (FL) and the inverse data transformation unit (FL<sup>-1</sup>) can be substituted for each other. Furthermore, in Figs. 3, 4, 8, and 9, the data on the right R and the data on the left L can be substituted for each other.
Fig. 36 shows a configuration in which the encryption unit 200 is composed of the 6-round data non-linear transformation unit 210, the 6-round data non-linear transformation unit 220, and the non-linear data transformation unit. linear data 230 of 6 rounds.
The 6-round non-linear data transformation unit 210, the 6-round non-linear data transformation unit 220, and the 6-round non-linear data transformation unit 230 are circuits that can be used for encryption and decryption. .
Here, a normal / inverse data transformation unit 211 is composed of the non-linear data transformation unit 210 of 6 rounds, and the normal data transformation unit (FL) 250, and the inverse data transformation unit ( FL<sup>-1</sup>) 271. The normal / inverse data transformation unit is a circuit that can be used for both encryption and decryption. That is, the normal / inverse data transformation unit is a normal / inverse transformation circuit in which the input data to the unit can be obtained as output data from the other unit by making the output data from the drive are the input data on the other drive.
A normal / inverse data transformation unit 221 is also composed of the non-linear data transformation unit 220 of 6 rounds, and the normal data transformation unit (FL) 251, and the inverse data transformation unit (FL<sup>-1</sup>) 273.
Likewise, a normal / inverse data transformation unit 231 is composed of the non-linear data transformation unit 230 of 6 rounds, the normal data transformation unit (FL) 253, and the inverse transformation unit of data (FL<sup>-1</sup>) 275.
Encryption unit 200 is configured by cascading these normal / reverse data transformation units 211, 221, and 231. And this encryption unit 200 can also be used as decryption unit 500.
Likewise, if a set of the 6-round nonlinear data transformation unit 210, the 6-round nonlinear data transformation unit 220, the normal data transformation unit (FL) 251, and the inverse data transformation unit (FL<sup>-1</sup>) 271 is supposed to be a data non-linear transformation unit 1210, the data non-linear transformation unit 1210 is a circuit that can be used for encryption and decryption. Here, a normal / inverse data transformation unit 1211 is composed of the non-linear data transformation unit 1210, the normal data transformation unit (FL) 250, and the inverse data transformation unit (FL<sup>-1</sup>) 273.
Likewise, if a set of the non-linear data transformation unit 220 of 6 rounds, of the non-linear data transformation unit 230 of 6 rounds, of the normal data transformation unit (FL) 253, and of the inverse data transformation unit (FL<sup>-1</sup>) 273 is assumed to be a data non-linear transformation unit 1220, a data normal / inverse transformation unit 1221 is composed of the data non-linear transformation unit 1220, from the data normal transformation unit (FL) 251, and the inverse data transformation unit (FL<sup>-1</sup>) 275.
The normal / inverse data transformation units 1211 and 1221 can be used for the decryption unit.
Likewise, if a set of the 6-round data nonlinear transformation units 210 to 230 is assumed to be a data nonlinear transformation unit 2210, the data nonlinear transformation unit 2210 is a circuit that can be used for both encryption and decryption.
ES 2 327 263 T3
Here, the nonlinear data transformation unit 2210, the normal data transformation unit (FL) 250, and the inverse data transformation unit (FL<sup>-1</sup>) 275 constitute a unit of normal / inverse transformation of data 2211.
The normal / inverse data transformation unit 2211 may be used for the decryption unit.
In accordance with the above, the encryption unit 200 or the decryption unit 500 can be configured by cascading multiple normal / reverse data transformation units.
Likewise, in the encryption unit 200 or in the decryption unit 500, the normal / inverse data transformation unit can be hierarchically constituted by housing the normal / inverse data transformation unit within the normal / inverse data transformation unit. .
Fig. 37 shows a case where the encryption unit 200 and the decryption unit have the same configuration that includes the 6-round non-linear data transformation unit 210.
In Fig. 37, the 6-round nonlinear data transformation unit 210 includes even rounds of nonlinear data transformation units 280 as shown in Figs. 3 and 4. Data A is transformed into data A 'by a first normal data transformation input unit 256, data A' is input to a first input port 261, data A 'input from first input port 261 is output output from a first output port 263 as data A<sub>1</sub>'. Likewise, the input of data B from a second input port 262 is output from a second output port 264 as data B<sub>1</sub>. Data B<sub>1</sub> emitted output from the second output port 264 are transformed into data B<sub>1</sub>'by a second inverse data transformation output unit 279.
Data A<sub>1</sub>'output from the first output port 263 of the encryption unit 200 are input to the second input port 262 of the decryption unit 500 as data A<sub>1</sub>'. Data B<sub>1</sub>'output from the second data reverse transformation output unit 279 are input to the first data normal transformation input unit 256 as data B<sub>1</sub>', and output as B data<sub>1</sub>.
The nonlinear data transformation unit 210 inputs the data B<sub>1</sub> and outputs the data B. Likewise, the non-linear transformation unit 210 inputs the data A<sub>1</sub>'and outputs the data A'. The second inverse data transformation output unit 279 inputs the data A 'and outputs the data A.
In FIG. 38, the odd round data nonlinear transformation unit 219 includes an odd round of data nonlinear transformation units 280. Accordingly, the input of the data A 'from the first input port 261 are output from the second output port 264 as data A1 '. Below data A<sub>1</sub>'are transformed by the second output data reverse transfer unit 279, and output as data A<sub>1</sub>”. Likewise, the data B entered in the second input port 262 is output from the first output port 263 as data B<sub>1</sub>.
Data B1 output from the first output port 262 of the encryption unit 200 is input to the second input port 262 of the decryption unit 500 as data B<sub>1</sub>. Data A<sub>1</sub> "" Output from the second inverse data transformation unit 279 of the encryption unit 200 is input to the decryption unit 500 as data A<sub>1</sub>"And entered into the first input data normal transformation unit 256.
In the cases of Figs. 37 and 38, the encryption unit 200 and the decryption unit 500 have the same configuration, carrying out the encryption and decryption.
Fig. 39 shows a case where the second input data normal transformation unit 257 is arranged at the second input port 262, and the first output data reverse transformation unit 278 is arranged at the first output port. exit 263.
Fig. 40 shows a case in which the first input data reverse transformation unit 276 is arranged at the first input port 261, and the second output data normal transformation unit 259 is arranged at the second output port. exit 264.
Fig. 41 shows a case where normal / inverse data transformation units 256/258 are arranged at left input / output ports 261, 263 and inverse data transformation units 277, 279 are arranged in the inlet / outlet ports 262, 264 on the right.
Fig. 42 shows a case in which Figs. 39 and 40 are combined.
Another assumption can be implemented by combining Figs. 37 and 39, case not shown in the figure. Also, Figs. 38 and 39 can be combined. Likewise, the non-linear data transformation unit 210 of 6 rounds (even rounds) can be replaced by the non-linear data transformation unit 219 of odd rounds
ES 2 327 263 T3 in Figs. 37, 39 to 42, which are not shown in the figures. In the cases of Figs. 39 to 42, the encryption unit and the decryption unit can be implemented by the same configuration.
Embodiment 2
FIG. 11 shows a configuration of a nonlinear function unit F of the nonlinear data transformation unit 280.
A unit of nonlinear function F inputs input data 10 of function F, carries out nonlinear transformation, and outputs data output 40 of function F. Input data 10 of function F of 64 bits are divided into eight data elements, and processed in the 8-bit unit. Each of the 8-bit data is input to each of the eight XOR circuits 12 of a key function unit 25, operated with the XOR function with an extension key 11, and a non-linear transformation is performed using a substitution in a function unit S 20. Next, in a function unit P 30, two elements of the 8-bit data are operated with the XOR function by sixteen XOR circuits 815, and the output data 40 of the 64-bit function F is output. In the function unit 20 S, four first box transformer units S 13 and four second box transformer units S 14 are arranged.
Fig. 12 shows an example of implementation of the first S-box transformation unit 13 and the S-box second transformation unit 14.
Inside the first box transformation unit S 13, a transformation table T is provided. The transformation table T previously stores the values from 0 to 255 arbitrarily (at random) corresponding to the values from 0 to 255. The transformation table T enters the values from 0 to 255 and outputs the value (value from 0 to 255) corresponding to each value. For example, when 1 is entered, the transformation table T outputs 7. The transformation table T performs a non-linear transformation determined according to safety considerations, for example, checking whether the function is bijective or not, whether the differential probability is small enough or not, etc.
The second box transform unit S 14 includes the first box transform unit S 13 and a rotational shift unit 22 to the left of 1 bit (in the figure, “<<<” of “<<< 1” shows rotational shift to the left and "1" shows 1 bit). The 1-bit left rotational shift unit 22 performs the 1-bit left shift unit to an output from the first box transform unit S 13. For example, when 1 is input, the first box transform unit S 13 outputs 7, and the left 1-bit rotational shift unit 22 outputs 14.
If the first box transformation unit S 13 and the second box transformation unit S 14 are configured as shown in Fig. 12, an effect similar to the case where two kinds of transformation tables are provided can be obtained T, although it is not required that there are two types of transformation tables T. By including a single transformation table T, the memory usage required for storing the transformation table T can be reduced, and the circuit scale can also be reduced.
Also, as shown in Fig. 27, by providing a 1-bit right rotational shift unit (">>> 1" of the third box transform unit S 15 of Fig. 27) as well as, or, instead of the 1-bit left rotational shift unit 22, a similar effect can be obtained in a case where a different transformation table T is also provided. Otherwise, it is also possible to transform the input data and using the data transformation table T after shifting the input data and by the 1-bit left rotational shift unit (“<<< 1” of the fourth box transformation unit S 16 of Fig. 27) arranged for the input data y. Fig. 27 shows the cases of s (y), s (y) <<< 1, s (y) >>> 1, s (and <<< 1), but the cases of s (y >>> 1 are also applicable ), s (and <<< 1) <<< 1, s (and <<< 1) >>> 1, s (and >>> 1) <<< 1, s (and >>> 1)> >> 1. By making the amount shifted 1 bit, it is sometimes possible to run faster than in cases of shifting of 3 bits or 5 bits in the case of CPUs etc. have a single bit shift command. Also, when this scrolling process is carried out using software that performs a 1-bit scrolling, it is sometimes possible to run faster. Also, the shift is not limited to being carried out in 1 bit, but an arbitrary number of bits can be used, such as 2 bits or 3 bits. By shifting an arbitrary number of bits, it is sometimes possible to obtain an effect similar to that of providing different types of tables.
Fig. 28 shows an S function unit 20 using the first to fourth transformation units 13, 14, 15, 16 shown in Fig. 27 of four S boxes.
Another configuration of the function unit P 30 is shown in Fig. 31.
From the 8-bit input data and<sub>1</sub>, Y<sub>2</sub>, Y<sub>2</sub>, Y<sub>4</sub>, Z data is obtained<sub>1</sub>, Z<sub>2</sub>, Z<sub>3</sub>, Z<sub>4</sub>, 32 bits by reference to S1, S2, S3, S4, respectively, and are operated with the XOR function in a 913 circuit. From the 8-bit input data and<sub>5</sub>, Y<sub>6</sub>, Y<sub>7</sub>, Y<sub>8</sub>, the data Z are obtained<sub>5</sub>, Z<sub>6</sub>, Z<sub>7</sub>, Z<sub>8</sub>, 32 bits by reference to S2, S3, S4, S1, respectively, and are operated with the XOR function in a 916 circuit. This result U<sub>2</sub> operated with function
ES 2 327 263 T3
XOR and the first result U<sub>1</sub> operated with the XOR function are operated with the XOR function in a 917 circuit to output z /, z<sub>2</sub>', z<sub>3</sub>', z<sub>4</sub>'. Then the result U<sub>1</sub>, operated with the XOR function from circuit 913 is shifted to the left by one byte (in Fig. 31, “<<< 1” represents a 1-byte rotational shift, not a 1-bit rotational shift) in a circuit 918. The shifted result is operated with the XOR function with the output from circuit 917 to output z<sub>5</sub>', z<sub>6</sub>', z<sub>7</sub>', z<sub>8</sub>'.
As shown in (a) to (d) of Fig. 33, S1 is configured using the first box transmission unit S 13, S2, is configured using the second box transformer unit S 14, S3 is configured using the third box transformation unit S 15, S4 is configured using the fourth box transformation unit S 16. The 8-bit output data from each transformation unit is copied four times to obtain 32-bit data, and likewise, the 32-bit data is masked to output only three elements of the data (24 bits).
The 1-byte rotational shift of circuit 918 is a cyclic shift per unit bit length (8 bits = 1 byte) which is processed by the S box.
Fig. 32 shows the function unit P whose configuration is equivalent to Fig. 31, but the implementation is different.
From the 8-bit input data and<sub>1</sub>, Y<sub>2</sub>, Y<sub>3</sub>, Y<sub>4</sub>, you get the 32-bit data z<sub>1</sub>, z<sub>2</sub>, z<sub>3</sub>, z<sub>4</sub>, by reference to S5, S6, S7, S8, and are operated with the XOR function in a circuit 933 to output an operating result A. From the 8-bit input data and<sub>5</sub>, Y<sub>6</sub>, Y<sub>7</sub>, Y<sub>8</sub>, the 32-bit data Z is obtained<sub>5</sub>, Z<sub>6</sub>, Z<sub>7</sub>, Z<sub>8 </sub>by reference to S9, SA, SB, SC, and are operated with the XOR function in a circuit 936 to output an operating result B. The operating result B is rotationally shifted to the right by 1 byte (in Fig. 32 , similar to Fig. 31, the shift is carried out by a unit of bit length (8 bits = 1 byte) which is processed by box S, not 1 bit) in a circuit 937 and the operating result B and the operating result A are operated with the XOR function in a circuit 938. This operating result C is rotationally shifted to the top (left) by one byte in a circuit 939, and the operating result C is also operated with the XOR function with the operating result A in a circuit 940. This operating result D is rotationally shifted up (left) by 2 byte in a circuit 941, and the operating result D is also operated with the XOR function with the output from circuit 939 in a circuit 942. This operating result E is shifted rotationally (clockwise) by 1 byte in a 943 circuit, and the operating result E is also operated with the XOR function with the output coming from the 941 circuit in a 944 circuit. Output F from circuit 944 is output as z<sub>1</sub>', z<sub>2</sub>', z<sub>3</sub>', z<sub>4</sub>', and the output from circuit 943 is output as z<sub>5</sub>,, z<sub>6</sub>, z<sub>7</sub>', z<sub>8</sub>'.
S5 and SC are configured using the first box transform unit S 13 and a logical offset, S6 and S9 are configured using the second box transform unit S 14 and a logical offset, S7 and SA are configured using the third drive unit. box transform S 15 and a logical shift, S8 and SB are configured using the fourth box transform unit S 16 and a logical shift. Logical offset is used to output 8-bit output data from each transform unit to a predetermined location within the 32-bit output data. The logical shift is set to shift left by 0 byte in S5 and SA, by 1 byte in S6 and SB, by 2 bytes in S7 and SC, by 3 bytes in S8 and S9. That is, assuming an 8-bit output from the transform unit as z, a 32-bit output can be represented as [0, 0, 0, z] (0 shows that each of the eight bits is 0) in S5 and SA, [0, 0, z, 0] in S6 and SB, [0, z, 0, 0] in S7 and SC, [z, 0, 0, 0] in S8 and S9.
The implementation is possible using substitution tables whose input is 8 bits and whose output is 32 bits, which is calculated to directly produce a predetermined output.
In the cases of Figs. 31 and 32, the apparatus can be arranged which performs a transformation at a higher speed than the transformation employed for the conventional E2 cipher shown in Fig. 26, and on which a flexible implementation is also possible.
In Fig. 11, when the S-boxes of the S function unit 20 are respectively configured by different types of S-boxes, eight transformation tables T are required. On the other hand, when the S-boxes are configured as shown in the Fig. 12, the memory usage required for storing the transformation tables T can be reduced to at least half.
Likewise, eight 8-bit data elements are input by time division in the first box transformation unit S 13 and in the second box transformation unit S 14 shown in Fig. 12, so that the respective eight Conventional S boxes can be replaced by the first box transformer S 13 and by the second box transformer S 14.
Fig. 13 shows another example of the S box of the S function unit 20.
The specific configuration is explained in detail in Matui, Sakurai, "Galois Field division circuit and shared circuit for multiplication and division"] (Japanese Patent Registration No. 2641285 [May 2, 1997]).
ES 2 327 263 T3
The 8-bit data is input to the box transform unit S 21 and the 8-bit data is output. The box transformation unit S 21 is configured by an N-bit linear transformation unit 17 (here, N = 8), a subfield transformation unit 18, and an N-bit linear transformation unit 19. The N-bit linear transform unit 17 performs 8-bit data operations. Subfield transformation unit 18 performs 4-bit data operations that are elements of the Galois Field, GF (2<sup>4</sup>). The N-bit linear transform unit 19 performs an 8-bit data operation. A linear transformation unit 85 of the N-bit linear transformation unit 17 is a circuit that carries out the linear transformation shown in Fig. 14. A linear transformation unit 87 is a circuit that carries out the linear transformation shown. in Fig. 15.
The linear transformation unit 85 can be replaced by a circuit that performs an affine transformation (a linear transformation can be thought of as a type of affine transformation). Similarly, the linear transformation unit 87 can be replaced by a circuit that performs another affine transformation. Affine transformation unit 85 transforms 8-bit data (X) into 8-bit data (X '). The obtained 8-bit data (X ') is assumed to be elements of the Galois Field (2<sup>8</sup>). The upper 4-bit data and the lower 4-bit data (X1 and X0) of the X 'data are assumed to be, respectively, elements of the Galois Field of subfield (2<sup>4</sup>) and are output up to subfield transformation unit 18. Here, for example, assuming that a β element of CG (2<sup>8</sup>) is an element that satisfies the irreducible polynomial X<sup>8</sup> + X<sup>6</sup> + X<sup>5</sup> + X<sup>3</sup> + 1 = 0, and α = β<sup>238</sup>, a base of the CG (2<sup>4</sup>) subfield can be represented as [1, α, α<sup>2</sup>, α<sup>3</sup>]. If the elements of CG (2<sup>4</sup>), X0, X<sub>1</sub>, are represented using this, the subsequent relation can be stated as X '= X<sub>OR</sub> + β X<sub>1</sub>. (For details, see Matui, Sakurai, "Galois Field division circuit and shared circuit for multiplication and division"] (Japanese Patent Registration No. 2641285 [2 May 1997])). The subfield transformation unit 18 is configured only by the operating units each of which carries out 4-bit data operations.
Here, as an example of an extraction “subfield”, the CG (2<sup>m</sup>) where n = 2m can be taken into consideration for a CG (2<sup>n</sup>) determined. In this example, n = 8, m = 4.
The subfield transformation unit 18 is an inverse element circuit that uses the subfield constructed by the circuit shown in the document “Galois Field division circuit and shared circuit for multiplication and division "] (Japanese Patent Registration No. 2641285 [May 2, 1997]). As an operating result of this inverse element circuit, the upper 4-bit data and the lower 4-bit data (Y1 and Y0), each of which can be considered as an element of the CG (2<sup>4</sup>), are output up to the linear transformation unit 87 as 8-bit data Y which can be considered as an element of the CG (2<sup>8</sup>), where Y = Y<sub>0</sub> + β Y<sub>1</sub>. As discussed earlier, this inverse element circuit is a Y = Y computing circuit<sub>0</sub> + β Y<sub>1</sub> = 1 / (X<sub>or</sub> + β X<sub>1</sub>). Likewise, there are some ways to adopt a "base", such as a "polynomial base" and a "normal base", in the representation of the "finite field" element (how to adopt a base) in the inverse element circuit. .
A first characteristic of the box transform unit S 21 shown in Fig. 13 is to compute the data with a bit width (4 bits) that is half the bit width (8 bits) of the data input of nonlinear transformation. That is, the inverse element circuit is characterized by carrying out data operations of only 4 bits.
However, the computing speed can be reduced by performing only 4-bit operations. This assumption offers the advantage that the scale of a complete circuit can be much smaller than in an assumption where 8-bit data operations are performed.
Likewise, a second characteristic of the box transformation unit S 21 is that the N-bit linear transformation unit 17 and the N-bit linear transformation unit 19, where N = 8, are arranged on both sides of the subfield transformation unit 18. When the box transformation unit S 21 is implemented using the subfield transformation unit 18, there is the advantage that a scale of the whole circuit can be reduced and the configuration is simpler compared to the assumption using a transformation table T which stores random values, while conversely, security can be lowered. Accordingly, linear transformations or affine transformations are carried out on both sides of the transformation unit of subfield 18, so that the reduction of the security level can be recovered due to the implementation using the transformation unit of subfield 18.
In Fig. 13, linear transformations are carried out on both sides of the subfield transformation unit 18; however, the linear transformation can be carried out only on one side. In another variant, the linear transformation can be carried out on one side, and the affine transformation can be carried out on the other side.
Fig. 29 shows an assumption in which the key function unit 25 is shown in Fig. 11, that is, the key function unit 25 located before the S function unit 20 and the function unit P 30, now comes after function unit S 20 and function unit P 30.
Fig. 30 shows a scenario in which the key function unit 25 is located between the function unit S and the function unit 30.
ES 2 327 263 T3
By employing the configuration shown in Fig. 29 or Fig. 30, an effect can be had that one implementation provides higher speed operation than does the configuration shown in Fig. 11. Likewise By modifying the generation of the extension keys, the same output can be obtained using the configuration shown in Fig. 29 or in Fig. 30 from the same input as that of the configuration of Fig. 11. In the conventional F function unit shown in Fig. 26, two S functions are offered, in each of which an extension key operation is performed first and then a function operation is performed. S. On the contrary, in the case shown in Fig. 29, a key function unit 25 is located in the final stage of the function F. In the case shown in Fig. 30, the key function unit 25 is located between the function unit S 20 and the function unit P 30.
Fig. 43 shows a case where the non-linear transformation unit F shown in Fig. 28 is used in the encryption unit 200 or the decryption unit 500 shown in Fig. 3.
The data on the left is input into the nonlinear transformation unit F as input data 10 of the function F, and the output data 40 of the function F is output. The output data 40 of the F function is operated with the XOR function with the data on the right, and the result operated with the XOR function becomes the data on the left of the next round. When the data on the left is input into the linear transformation unit F as input data 10 of the function F, at the same time, the data on the left is used as data on the right of the next round. In the configuration shown in Fig. 43, the operations of the key function unit 25, the function unit S 20, and the function unit P 30 are carried out in the non-linear transformation unit F, so that the charging of the operations is considerable within the nonlinear transformation unit F. An exemplary case in which a higher processing speed can be achieved by distributing the operating load of the non-linear transformation unit F will be discussed below with reference to the figures.
Fig. 44 shows a scenario in which the non-linear transformation unit F 'is used. The nonlinear transformation unit F 'is a unit in which the unit of the key function 25 is suppressed from the nonlinear transformation unit F shown in Fig. 43. The extension key ki is operated with the function XOR with the data on the left L<sub>0</sub> in an XOR 891 circuit. Likewise, the extension key k<sub>2</sub> is operated with the XOR function with the data on the right R<sub>0</sub> in an XOR circuit 297. The data on the left are input into the non-linear transformation unit F 'as input data 10 of the function F, and transformed by the function unit F 20 and by the function unit P 30. The output from the XOR circuit 297 and the output data 40 of the function F are operated with the XOR function in an XOR circuit 290 to output the data on the left L<sub>1</sub>.
On the other hand, the key generation units 300, 600 carry out an XOR operation of the keys of extension k<sub>1</sub> and k<sub>2</sub> and output the modified extension key k<sub>1</sub> + k<sub>3</sub>. The R output<sub>1</sub> of the XOR 891 circuit and the extension key k<sub>1</sub> + k<sub>3</sub> they are operated with the XOR function in an XOR circuit 298 to output the data on the right. Key generation units 300, 600 modify extension keys to generate and output k<sub>1</sub> + k<sub>3</sub>, k<sub>2</sub> + k<sub>4</sub>, k<sub>3</sub> + k<sub>5</sub>, ..., k<sub>16</sub> + k<sub>18</sub>. The key generation units 300, 600 supply the modified extension keys to processes other than the non-linear function (F) process to operate on the data. As a result, the data on the left L<sub>18</sub> and the data on the right R<sub>18</sub> turn out to be the same as the data on the left L<sub>18</sub> and that the data on the right R<sub>18</sub> in the case of Fig. 43.
The modified extension keys are supplied to processes other than the nonlinear function process (F) and operated on the data, and consequently, operations on the keyed data can be performed outside of the nonlinear function unit. F ', namely in the XOR circuits 297 and 298, while the operations of the function unit S 20 and of the function unit P 30 are carried out in the non-linear function unit F'. Accordingly, the operations of the key function unit 25 are removed from the non-linear function unit F, and the load of the non-linear function unit F is distributed, which enables high-speed implementation.
Fig. 45 shows a case where the operations of the bleach extension key kw<sub>1</sub>, are also carried out as operations of the other extension keys in the configuration shown in Fig. 44. Fig. 45 shows a case in which the key generation unit previously performs a one-part XOR operation. of bleach extension key, kw<sub>1high</sub> y of the first extension key k<sub>1</sub> (that is, the key generation unit modifies the extension key) and supplies the result of the operation to the XOR 891 circuit.
The figure also shows a case where the key generation unit previously performs an XOR operation as part of the kw bleach extension key<sub>1ba</sub>j<sub>to</sub> and the second key of extension k<sub>2</sub> (that is, the key generation unit modifies the extension key) and supplies the result of the operation to the XOR circuit 297.
In this way, the operation in the XOR circuit 293 shown in Fig. 44 can be eliminated. Also, in a case shown in Fig. 45, the key generation unit performs an XOR operation of a part of the kw bleach extension key<sub>2ba</sub>j<sub>to</sub> y of the extension key k<sub>17</sub> (that is, the key generation unit modifies the extension key) and supplies the result of the operation to the XOR circuit 299. Likewise, the key generation unit performs an XOR operation of the other part of the the bleach extension key kw2aita and the extension key k18 (that is, the key generation unit modifies the extension key) and supplies the result of the operation to the XOR 892 circuit.
ES 2 327 263 T3
In this way, the operation of the XOR circuit 296 shown in Fig. 44 is eliminated.
Fig. 46 shows a case where the key function unit 25 is suppressed from the non-linear function unit F, and instead, the key generation unit supplies the extension key k to the XOR circuit 298 when the non-linear function unit F is configured as shown in Fig. 29.
Fig. 47 shows a case where the key function unit 25 is suppressed from the non-linear function unit F, and instead, the key generation unit supplies the non-linearly transformed extension key k '= P (k) to the XOR circuit 298 when the non-linear function unit F is configured as shown in Fig. 30. In the case of Fig. 47, the same operation performed by the P function process is carried out on the keyed data to generate nonlinearly transformed keyed data, and the nonlinearly transformed keyed data is supplied to processes other than the process of nonlinear function (F) to process the data to be operated with the data as keyed data intended for the processing data. In both cases, from Figs. 46 and 47, because the key function unit 25 is removed from the non-linear function unit F, the operating load of the non-linear function unit F is reduced, and the operation of the XOR circuit 298 located outside the unit Nonlinear function unit F can be carried out in parallel with operations carried out by nonlinear function unit F, which enables high speed processing.
Embodiment 3
Fig. 16 shows a configuration of the key generation unit 300 (or the key generation unit 600) shown in Fig. 1.
The key generation unit 300 includes a bit length transformation unit 310, a first G-bit key transformation unit 320, a second G-bit key transformation unit 330, and a shift unit of keys 340. From the data with input key with 128 bits, 192 bits, or 256 bits, the key generation unit 300 generates data with key k<sub>1</sub> 128 bits and some data with key k<sub>2</sub> 128-bit, and outputs multiple 64-bit extension keys. The bit length transformation unit 310 converts the bit length of the keyed data to be output so that the bit length of the set output key data even if the data is input with key with different number of bits. In other words, the bit length transformation unit 310 generates data with key SK<sub>alt0S</sub> 128-bit higher and some data with SK key<sub>low</sub> 128-bit lower bits and outputs the first ones up to the G-bit key transformation unit 320 and up to the key shift unit 340. Likewise, the last ones are output up to the second key transformation unit 330 of G bits and up to key shift unit 340. Likewise, the data with a 128-bit key that is a result operated with the XOR function of the first and last are output to the first G-bit key transformation unit 320.
Fig. 17 shows the internal operations of the bit length transformation unit 310.
When 128-bit keyed data is input to bit length transformation unit 310, the inputted keyed data is output as SK keyed data.<sub>alt0S</sub> of the upper 128 bits without any change. Likewise, the data with SK key<sub>ba</sub>j<sub>0S</sub> of the lower 128 bits are set to 0 and output.
When the 192-bit keyed data is input to the bit-length transformation unit 310, the upper 128-bit data of the input keyed data is output as 128-bit upper keyed data SK<sub>alt0S</sub> without any change. Likewise, the data with lower key of 128 bits SK<sub>ba</sub>j<sub>0S</sub> are generated by combining the lower 64 bits of the entered 192-bit key data and the 64-bit inverse data, which are generated by inverting the lower 64-bit data of the 192-bit key data introduced, and emitted of exit.
When the 256-bit keyed data is input, the upper 128-bit data of the entered keyed data is output as SK<sub>alt0S</sub>, and the lower 128-bit data is output as SK<sub>ba</sub>j<sub>0S</sub>.
An XOR data of the data with 128 bit key SK<sub>alt0S</sub> and SK<sub>ba</sub>j<sub>0S</sub> are input to the first G-bit key transformation unit 320 from the bit length transformation unit 310, operated by two-round non-linear transformations, operated with the XOR function with the 128-bit upper key data SK<sub>alt0S</sub>, additionally operated by two-round linear transformations, and data with a 128-bit key K<sub>1</sub> are issued out.
When the length of the keyed data input into the bit length transformation unit 310 is 128 bits, the key shift unit 340 generates the extension key using the 128-bit keyed data output from the G-bit key transformation unit 320 and the originally input keyed data. When the length of the keyed data input into the bit length transformation unit 310 is 192 bits or 256 bits, the 128-bit keyed data output from the first key transformation unit 320 of G bits are also input into the second G-bit transformation unit 340, operated with the XOR function with the lower key data of 128 bits SK<sub>ba</sub>j<sub>0S</sub>, operated by
ES 2 327 263 T3 two non-linear transformations of two rounds, and a data with key of 128 bits K<sub>2</sub> are issued out. Two items of the 128-bit key data from the G-bit key transformation unit 320 and the second G-bit key transformation unit 330 are output to the key shift unit 340. The key shifting unit 340 generates the extension key using the two 128-bit keyed data items and the originally entered keyed data.
The key shift unit 340 includes an A shift register 341, a B shift register 342, a C shift register 343, a D shift register 344, and a shift control unit 345. The shift control unit 345 outputs a select signal 346 to each of the shift registers to control the operations of the shift registers.
Fig. 18 shows a configuration of shift register A 341.
Shift register A 341 includes a selector A 347 incorporating a group of switches for 128 bits and a register A 348 for 128 bits. A select signal 346 includes a switch signal to indicate connection to all A selector switches 347 at the same time on side A and on side B. The figure shows a case where the A selector switch group 347 has selected A based on the select signal 346, and in this case, the A register 348 performs a rotational shift to the left by 17 bits. Also, when the group of switches is connected to B, register A performs the rotational shift to the left by 15 bits. The 15-bit shift or 17-bit shift is performed by a timed cycle.
The number of shift bits (15, 17) is one among many examples, and another number of shift bits can be applied.
Fig. 19 shows a portion of a control table stored in the displacement control unit 345.
The control table is a table that stores the number of bits that the register shifts in each clock. For example, in the control table of register A, in the first clock, a 15-bit offset is specified. And, on the second clock, an additional 15-bit offset is specified. Similarly, in each of the third and fourth clocks, a 15-bit offset is specified. A 17-bit offset is specified in each of the fifth to eighth clocks.
Fig. 20 shows a control result according to which the shift control unit 345 controls each shift register using the table shown in Fig. 19 in the case of generating the extension key from the keyed data. 128 bit.
Data with key higher than 128 bit SK<sub>tall</sub> input from the bit-length transformation unit 310 are inserted into shift register A 341. Data with 128-bit key K<sub>1</sub> Outputs from the G-bit key transformation unit 320 are inserted into shift register B 342. In this situation, shift register A 341 and shift register B 342 operate based on the control table shown in Fig. 19. In Fig. 20, the data for a sloped column shows that it should be ignored and should not be output. The data in the other columns is output as extension keys as shown in Fig. 21.
Fig. 21 shows a correspondence between the value of the registers and the extension key.
Fig. 20 shows a case where four 15-bit shifts are performed on each clock, and from the fifth clock, shifts are performed by 17 bits on each clock. The decision to output or not output the upper 64 bits and lower 64 bits from shift register A 341 and shift register B 342 as the extension key and their output output order is specified in the control table, which is not shown in the figure. And according to the control table, by outputting the select signal 346 that includes an output instruction signal to the shift register, the extension key is output from each shift register in 64 bits.
Fig. 22 shows a case where the extension key is generated from a 192-bit or 256-bit key data.
That is, the data with key higher than 128 bits SK<sub>tall</sub> input from the transformation unit 310 the length of the bits are inserted into the shift register A 341, the lower key data of 128 bits SK<sub>low</sub> is inserted into shift register B 342, the data with 128-bit key K<sub>1</sub> output from the first G-bit key transformation unit 320 is inserted into the C shift register 343, and the data with 128-bit key K<sub>2</sub> Outputs from the second G-bit key transformation unit 330 are inserted into the D shift register 344.
The data in a column that has a slant shows the unused keys for the extension keys.
Fig. 23 shows a correspondence between the registry value and the extension key.
ES 2 327 263 T3
The unused keys for the extension keys and the correspondence between the registry value and the extension key shown in Fig. 23 are stored in the control table located in the controller.
As shown in Fig. 19, shift control unit 345 stores the number of shift bits of the keyed data set in shift register A 341. That is, the extension keys are generated sequentially by shifting keyed data inserted into shift register A 341 by Z<sub>0</sub> = 0 bits, Z<sub>1</sub> = 15 bits, Z<sub>2</sub> = 45 bits, Z<sub>3</sub> = 60 bits, Z<sub>4</sub> = 77 bits, Z<sub>5</sub> = 94 bits, Z<sub>6</sub> = 111 bits, Z<sub>7</sub> = 128 bits as shown in shift register A control table.
The sum of the number of shift bits turns out to be 15 + 15 + 15 +15 + 17 +17 + 17 +17 = 128, so that the 128-bit register performs the 128-bit rotational shift and the register returns to its initial state.
The reason why the sum of the number of shift bits reaches 128 bits (the number of bits in the register) to return to the initial state is that the next processing can start immediately if the next processing is assigned to the initial state register. Likewise, in the event that a reverse transformation (decryption) is carried out, the extension key generation process starts from the initial state, and accordingly, both the transformation (encryption) and the transformation Reverse (decryption) can be carried out by setting the initial state. Likewise, the reason why the sum of the number of shift bits is not set to more than 128 bits (the number of bits in the register) is to prevent the generation of values identical to those of the existing status in the same register of offset due to the offset execution in more than one cycle (greater than 128 bits of offset). This is because, for example, performing the rotational shift in 2 bits that is less than 128 bits (the number of bits in the register) and performing the rotational shift in 130 bits, which is more than 128 bits (the number of bits registry), produce the identical value. It is desirable to fix such values in the control table of register A because, when shifting the register in one cycle, the number of shift bits varies irregularly throughout the single cycle. However, in order to facilitate shift register setup, a shift by a fixed number of bits is desired. Accordingly, a register is configured to carry out two types of shifts in 15 bits and in 17 bits (in a clock), and the shift operation by different numbers of bits can be implemented using the two types of shifts, according to the following procedure.
Established the relationship so that Z<sub>1</sub> - Z<sub>0</sub> = 15 (here, Z<sub>1</sub> - Z<sub>0</sub> = B<sub>1</sub>), Z<sub>2</sub> - Z<sub>1</sub> = 30 (that is, Z<sub>2</sub> - Z<sub>1</sub> = 2B<sub>1</sub>), therefore Z<sub>2</sub> - Z<sub>1</sub> = 2 (Z<sub>1-</sub> Z<sub>0</sub>). Likewise, as shown in the control table of shift register B, the relationship has been established so that Z<sub>5</sub> - Z<sub>4</sub> = 34 (here, Z<sub>5</sub> - Z<sub>4</sub> = 2B<sub>2</sub>), Z<sub>6</sub> - Z<sub>5</sub> = 17 (that is, Z<sub>6</sub> - Z<sub>5</sub> = B<sub>2</sub>), therefore Z<sub>5</sub> - Z<sub>4</sub> = 2 (Z<sub>6</sub> - Z<sub>5</sub>). That is, the difference between the numbers of the offset bits gives us 15 bits and 30 bits, or 17 bits and 34 bits, and the number of offset bits (30 bits or 34 bits) is set to an integral multiple (2 times = I times) of the number of bits (15 bits and 17 bits) for a one-time shift.
In this way, when the differences in the number of shift bits are established either with respect to the number of shift bits for a single time, or for the multiple of the integer greater than two (I times, I is a greater integer of 2) and the number of shift bits for a single time, by operating shift register A 341 once or twice (I times), it is possible to easily implement shift operations whose number of shift bits is stored in the control table. Operate twice (I times) means that the shift operation ends with two clocks (I clocks) from the supplied operational clock to operate shift register A 341.
Here, when scrolling I times (twice), both the highest data and the lowest data of the data scrolled up to I - 1 times (2 - 1 = 1 time) are ignored and not used for the extension key. For example, in the case of displacement of Z<sub>1</sub> = 15 to Z<sub>2</sub> = 45, I = (Z<sub>2</sub> - Z<sub>1</sub>) / (the number of bits to shift at one time) = (45 -15) / 15 = 2, and both the highest data and the lowest data of the data shifted after the shift I - 1 times (2 - 1 = 1 time) are ignored and not used for the extension key. This can be seen in Fig. 20, in which the columns of key [8] and key [9] have slopes, showing that these keys are not used for extension keys. And one or the other or both higher data and lower data of the data shifted after shifting of I times (2 times) is or is used as the extension key. This can be seen in Fig. 20, which shows that key [12] and key [13] are output as extension keys.
The reasons why shift operations based on a multiple of an integer greater than two used in accordance with the above, are due to the possibility of shifting not only 15 bits or 17 bits, but also 30 (= 15 x 2) bits, 34 (= 17 x 2) bits, (or 45 (= 15 x 3) bits or 51 (= 17 x 3) bits, etc.), which modifies the number of shifts and further improves security. And, the reason that cases are provided where the displaced data is not used for the extension key is also to improve security.
You want to generate the data that is not used for the extension key (in Figs. 20 and 22, the keys of the columns with slopes, which are not used for the extension keys) when, for example, the processing of the hardware or program processing does not take place consecutively. As concrete examples, in Fig. 3 you want to generate such data when you carry out the operations of the normal data transformation unit (FL) and the inverse data transformation unit (FL<sup>-1</sup>), or before or after such operations or
ES 2 327 263 T3 at times of inactivity of processes or times of process switching, such as a function call by a program, a subroutine call, or an interrupt handling process.
The characteristic of the control table shown in Fig. 19 is that the control table specifies the number of offset bits of B<sub>1</sub> = 8x2-1 = 15 (B<sub>1</sub> = 8xJ<sub>1</sub> -1, where J<sub>1</sub> is an integer greater than 1) and the number of offset bits B<sub>2</sub> = 8 x 2 + 1 = 17 (B<sub>2</sub> = 8 x J<sub>2</sub> + 1, where J<sub>2</sub> is an integer greater than 0, J<sub>1</sub> = J<sub>2 </sub>or J<sub>1</sub> + J2). Setting the amount of scrolling to within ± of the integral multiple of eight is for odd-bit scrolling, which improves security compared to scrolling only by even numbers, since the extension key operation of the data processing unit is carried out by an 8-bit unit, that is, a unit of even bits. And since the amount of shift can be set by adding / subtracting a bit to / from the multiple of eight, for example, in some CPU that has a single-bit shift command, the shift operation of the exposed type leads to perform high speed processing compared to shifting in 3 bits or 5 bits. And likewise, in the case that this shift operation using the hardware that can shift only 1 bit, there are cases where it is possible to carry out high-speed processing.
In the above description of the bit length unit 310, three types of keyed data bit widths are introduced. Even when keyed data is Q bits long, in which Q ranges from 128 bits (G bits) to 256 bits (2G bits) (G <Q <2G), the bit length transformation unit 310 You can extend the keyed data to the same size as the keyed data when the 256-bit keyed data is entered, using some kind of algorithm. That is, when keyed data with a length of Q, which ranges from G bits to 2G bits, is input, the bit length transformation unit 310 can convert keyed data of Q bits into keyed data of 2G bits.
Next, the proof of the non-existence of an equivalent key will be discussed with reference to Fig. 34.
In the explanation below of Fig. 34, "+" indicates an XOR operation. Here, it is assumed that two data with 128-bit key SK1 and SK2 (SK1 + SK2) are entered and that the bit length transformation unit 310 outputs SK1<sub>tall</sub> = SK1 = (SKH1 | SKL1) from SK1 and SK2<sub>tall</sub> = SK2 = (SKH2 | SKL2) from SK2. Here, SKHi (i = 1.2) means the upper 64-bit data of SKi and SKLi (i = 1,2) means the lower 64-bit data of SKi.
Assuming that the XOR data of SKH1 and SKH2 is AA and that the XOR data of SKL1 and SKL2 is AB, it can be said "at least AA + 0 or AB + 0", given that SK1 + SK2.
As shown in Fig. 34, these AA and AB are converted to AA + AD, AB + AC, respectively, by receiving the two rounds of non-linear transformations. This means that the XOR (AA | AB) data of SK1<sub>tall </sub>SK2<sub>tall</sub> are converted to XOR data (AA + AD | AB + AC) after performing the two rounds of nonlinear transformations on SK1<sub>tall</sub> and the transformed data after performing the two rounds of nonlinear transformations in SK2<sub>tall</sub>. Accordingly, when these data elements after carrying out the two rounds of non-linear transformations are operated with the XOR function with SK1<sub>tall</sub> and SK2<sub>tall</sub>, respectively, in an XOR 999 circuit, the results operated with the XOR function of two data items are converted to (AD | AC). If the nonlinear transformation is a bijective function, the introduction of AX + 0 always determines the output emission of AY + 0, so that, when “at least AA + 0 or AB + 0”, it can be said that “at least AC + 0 or AD + 0 ". Therefore, since it is impossible to output the same data from SK1<sub>tall</sub> and SK2<sub>tall</sub> By means of the two rounds of non-linear transformations, the non-existence of the equivalent key is demonstrated.
On the other hand, as shown in Fig. 35, another case will be taken into consideration, in which three rounds of non-linear transformations are carried out instead of two rounds of non-linear transformations. Since it can be said that "at least AA + 0 or AB + 0", there can be a case in which either AA or AB can be 0. If AA = 0, AC = 0, and in the same way explained above, the XOR data (0 | AB) of SK1<sub>tall</sub> and SK2<sub>tall</sub> are converted to the XOR data (AB + AE | AD) after performing the three rounds of nonlinear transformations on SK1<sub>tall</sub> and the transformed data after performing the three rounds of nonlinear transformations in SK2<sub>tall</sub>. Accordingly, when these data elements after receiving the three rounds of non-linear transformations are operated with the XOR function with SK1<sub>tall</sub> and SK2<sub>tall</sub>, respectively, in the XOR circuit 999, the results operated with the XOR function of two data items are converted to (AB + AE | AB + AD). Here, when AB = AD = AE + 0 is assumed, the following is true: (AB + AE | AB + AD) = (0 | 0). That is, when these data elements after carrying out the three rounds of non-linear transformations are operated with the XOR function with SK1<sub>tall</sub> and SK2<sub>tall</sub>, respectively, the results of the operation are the same. IE SK1<sub>tall</sub> and SK2<sub>tall</sub> they output the same data, so the equivalent keys exist, which is a security concern.
Not only the three round linear transformation case, but a general nonlinear transformation can output the K1 equivalent from different SK1 and SK2, which means that an equivalent key can exist. However, it is possible to prove the non-existence of the equivalent key when the two-round linear transformation is employed according to the present embodiment.
Likewise, there may be another case in which the non-existence of the equivalent key is proven other than that of the two-round non-linear transformation according to the present embodiment, however, it is preferable
ES 2 327 263 T3 use the two-round nonlinear transformation due to its simple configuration in addition to the proven non-existence of the equivalent key.
Fig. 24 shows a computer for the installation of the data transformation unit for encryption 100 or the data transformation unit for decryption 400.
The data transformation unit for encryption 100 and / or the data transformation unit for decryption 400 are connected to the bus as a printed circuit board. This printed circuit board is provided with a CPU, a memory, and a logic circuit element, and it encrypts the clear texts supplied from the CPU by converting them into ciphertext using the above-mentioned operation, and returns the data to the CPU. . Or it decrypts the ciphertext supplied from the CPU and returns the clear texts to the CPU.
In this way, the data transformation unit for encryption 100 or the data transformation unit for decryption 400 can be implemented by hardware. Likewise, the data transformation unit for encryption 100 or the data transformation unit for decryption 400 can also be implemented by software as a data transformation method. That is, the above operation can be carried out using the program stored in a magnetic disk drive or a floppy disk drive. As an alternative, the exposed operation can be implemented by combining hardware and software, although this is not shown in the figure. Likewise, it is not required to implement the entire operation referred to using a computer, but it is possible to implement the referred operation through a distributed system, such as a server and a client, or a central computer and a terminal computer, although this is not shown in the figure.
In Figs. Illustrated 1 to 47, an arrow shows a direction of the operational flow, and the figures with the arrow are block diagrams of the data transformation unit and flow diagrams. "... unit" shown in the exposed block diagram can be replaced by "... stage" or "... process", so that the diagrams can be considered as operational flow diagrams or program flow diagrams. showing the data transformation procedure.
In the above embodiments, a case has been disclosed in which clear texts and 128-bit encrypted texts are used, but the data can be clear texts and 256-bit encrypted texts, or clear texts and encrypted texts with another number of bits.
Likewise, in the previous embodiments, a case has been exposed in which data with a 128-bit, 192-bit, 256-bit key and 64-bit extension keys have been used, but the keyed data may have another number of bits.
If the bit length of the clear texts and the ciphertext, the keyed data and the extension key are modified, of course, the bit length to be processed by each unit, each stage, or each process , is modified according to the length of the bits.
Industrial availability
According to the present invention, even if the key data has a different number of bits, the length transformation unit 310 switches to the key data with a fixed length, which makes it possible to operate a flexible key generation.
Contents12
47 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35 Sheet 36 Sheet 37 Sheet 38 Sheet 39 Sheet 40 Sheet 41 Sheet 42 Sheet 43 Sheet 44 Sheet 45 Sheet 46 Sheet 47
113 members in 16 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 20000064614 | Japan | – | |
| 2000064614 | Japan | A | |
| 2000064614 | Japan | A | |
| 060100742000064614 | – | – | – |
| JP20000064614 | – | – | – |
Members113
| Document | Office | Kind | |
|---|---|---|---|
| CA2373432A1 | Canada | A1 | |
| CA2449662A1 | Canada | A1 | |
| CA2449665A1 | Canada | A1 | |
| CA2449669A1 | Canada | A1 | |
| CA2449672A1 | Canada | A1 | |
| WO0167425A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU4105801A | Australia | A | |
| NO20015461D0 | Norway | D0 | |
| NO20015461L | Norway | L | |
| KR20020016624A | Republic of Korea | A | |
| EP1193665A1 | European Patent Office (EPO) | A1 | |
| CN1364284A | China | A | |
| US2002159599A1 | United States of America | A1 | |
| MXPA01011323A | Mexico | A | |
| AU2003213312A1 | Australia | A1 | |
| AU2003213315A1 | Australia | A1 | |
| AU2003213317A1 | Australia | A1 | |
| AU2003213318A1 | Australia | A1 | |
| AU767323B2 | Australia | B2 | |
| AU2003213312B2 | Australia | B2 | |
| AU2003213315B2 | Australia | B2 | |
| AU2003213317B2 | Australia | B2 | |
| AU2003213318B2 | Australia | B2 | |
| KR20040066870A | Republic of Korea | A | |
| KR20040066871A | Republic of Korea | A | |
| KR20040066872A | Republic of Korea | A | |
| KR20040066874A | Republic of Korea | A | |
| KR20040066875A | Republic of Korea | A | |
| KR20040066876A | Republic of Korea | A | |
| KR20040066877A | Republic of Korea | A | |
| CA2449662C | Canada | C | |
| KR100449594B1 | Republic of Korea | B1 | |
| AU2003213312C1 | Australia | C1 | |
| KR100465070B1 | Republic of Korea | B1 | |
| KR100465071B1 | Republic of Korea | B1 | |
| KR100465072B1 | Republic of Korea | B1 | |
| KR100465073B1 | Republic of Korea | B1 | |
| KR100465074B1 | Republic of Korea | B1 | |
| KR100465075B1 | Republic of Korea | B1 | |
| KR100468338B1 | Republic of Korea | B1 | |
| CA2373432C | Canada | C | |
| CA2449669C | Canada | C | |
| CA2449672C | Canada | C | |
| CA2449665C | Canada | C | |
| CN1734526A | China | A | |
| CN1734527A | China | A | |
| CN1737880A | China | A | |
| US2006045265A1 | United States of America | A1 | |
| US2006050872A1 | United States of America | A1 | |
| US2006050873A1 | United States of America | A1 | |
| US2006050874A1 | United States of America | A1 | |
| EP1193665A4 | European Patent Office (EPO) | A4 | |
| CN1808526A | China | A | |
| EP1686719A1 | European Patent Office (EPO) | A1 | |
| EP1686720A1 | European Patent Office (EPO) | A1 | |
| EP1686721A1 | European Patent Office (EPO) | A1 | |
| EP1686722A1 | European Patent Office (EPO) | A1 | |
| EP1689113A2 | European Patent Office (EPO) | A2 | |
| EP1689114A2 | European Patent Office (EPO) | A2 | |
| EP1689113A3 | European Patent Office (EPO) | A3 | |
| SG124291A1 | Singapore | A1 | |
| SG124292A1 | Singapore | A1 | |
| SG124293A1 | Singapore | A1 | |
| SG124294A1 | Singapore | A1 | |
| EP1689114A3 | European Patent Office (EPO) | A3 | |
| JP2007041620A | Japan | A | |
| TWI275049B | Taiwan Province of China | B | |
| CN100392688C | China | C | |
| JP4127472B2 | Japan | B2 | |
| EP1686719B1 | European Patent Office (EPO) | B1 | |
| AT419692T | Austria | T | |
| ATE419692T1 | Austria | T1 | |
| DE60137269D1 | Germany | D1 | |
| DK1686719T3 | Denmark | T3 | |
| ES2319560T3 | Spain | T3 | |
| EP1686720B1 | European Patent Office (EPO) | B1 | |
| AT431983T | Austria | T | |
| ATE431983T1 | Austria | T1 | |
| DE60138773D1 | Germany | D1 | |
| EP1689114B1 | European Patent Office (EPO) | B1 | |
| DK1686720T3 | Denmark | T3 | |
| DE60139280D1 | Germany | D1 | |
| DK1689114T3 | Denmark | T3 | |
| ES2327263T3This record | Spain | T3 | |
| CN100557663C | China | C | |
| ES2329819T3 | Spain | T3 | |
| CN100583192C | China | C | |
| US7697684B2 | United States of America | B2 | |
| US7760870B2 | United States of America | B2 | |
| US7760871B2 | United States of America | B2 | |
| US7822196B2 | United States of America | B2 | |
| JP4598744B2 | Japan | B2 | |
| US7864950B2 | United States of America | B2 | |
| JP2011018065A | Japan | A | |
| CN1734527B | China | B | |
| EP1193665B1 | European Patent Office (EPO) | B1 | |
| AT545991T | Austria | T | |
| ATE545991T1 | Austria | T1 | |
| DK1193665T3 | Denmark | T3 | |
| ES2382454T3 | Spain | T3 |
Numbers
- Publication
- 2327263
- Publication, DOCDB
- 2327263
- Publication, EPODOC
- ES2327263T
- Application
- 6010074
- Application, DOCDB
- 06010074
- Application, EPODOC
- ES20060010074T
Titles2
- Spanish
- APARATO DE CIFRADO DE BLOQUES Y PROCEDIMIENTO DE CIFRADO DE BLOQUES QUE INCLUYE LA PROGRAMACION DE UNA CLAVE DE LONGITUD VARIABLE.
- English
- BLOCK ENCRYPTION DEVICE AND BLOCK ENCRYPTION PROCEDURE INCLUDING THE PROGRAMMING OF A VARIABLE LENGTH KEY.
Classification
- CPC, 5
- H04L9/0625
- G09C1/00
- H04L2209/125
- H04L2209/24
- H04L2209/122
- IPC, 3
- H04L9 06
- G09C1 00
- H04L9 28