IL181206A

Permutation data transform to enhance security

Abstract

This record has no abstract on file.

IL181206A, drawing sheet 1
Sheet 1 of 20

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

71 claims: 6 independent, 65 dependent

  1. 1
    A data transformer, comprising:an input port to receive data;a divider to divide said data into a first segment and a second segment and to divide said second segment into at least one group;a permuter including an implementation of a permutation function to permute at least one of said groups into a permuted group according to a corresponding bit in said first segment;and an output port to output said first segment and at least said permuted group as transformed data.
  2. 5
    A data transformer according to any one of the preceding claims, wherein the permuter includes implementations of at least two permutation functions.
  3. 8
    A data transformer according to any one of claims 5-7, wherein the implementations of said permutation functions includes:an implementation of a base permutation function;and implementations of powers of the base permutation function.
  4. 9
    A data security device, comprising:a data transformer, including: an input port to receive data;a divider to divide said data into a first segment and a second segment and to divide said second segment into at least two groups, each group having a predefined size, so that a number of groups in said second segment equals a number of bits in said first segment;a permuter including an implementation of a permutation function to permute at least one of said groups into a permuted group according to a corresponding bit in said first segment;and an output port to output said first segment and at least said permuted group as transformed data;and an implementation of a security algorithm to secure said transformed data.
  5. 13
    A data security device according to any one of claims 9 to 12, wherein the implementation of said security algorithm includes an implementation of an encryption algorithm to use said transformed data to encrypt said data.
  6. 15
    A data security device according to any one of claims 9 to 14, further comprising a second divider to divide an input into at least two blocks, the data transformer operative separately on each block.
  7. 17
    A data security device according to any one of claims 9 to 16, wherein the permuter includes implementations of at least two permutation functions, a number of permutation functions is equal to a number of said groups in said second segment.
  8. 20
    A method for generating a data transform, comprising:receiving data;dividing the data into a first segment and a second segment, each of the first segment and the second segment including at least one bit;organizing the bits in the second segment into at least one group;associating each of the groups with a bit in the first segment;applying a permutation function to at least one of the groups according to the associated bit in the first segment;and constructing the data transform from the first segment and at least the permuted groups.
  9. 24
    A method according to any one of claims 20 to 23, further comprising defining the permutation function.
  10. 28
    A method according to any one of claims 25 to 27, wherein defining a number of permutation functions includes:defining a base permutation function;and defining each of the remaining permutation functions as a power of the base permutation function.
  11. 29
    A method for enhancing security of data, comprising:transforming the data, including: receiving the data;dividing the data into a first segment and a second segment, each of the first segment and the second segment including at least one bit;organizing the bits in the second segment into a number of groups, the number of groups equal to a number of bits in the first segment;associating each ofthe groups with a bit in the first segment;applying a permutation function to at least one of the groups according to the associated bit in the first segment;and constructing the data transfonn from the first segment and at least the permuted groups;and applying an implementation of a security algorithm to the data transfonn to secure the data transform.
  12. 33
    A method according to any one of claims 29 to 32, wherein:receiving the data includes receiving a key to be wrapped as the data;and applying an implementation of a security algorithm includes applying an implementation of a key wrapping function to the data transform to wrap the key.
  13. 35
    A method according to any one of claims 29 to 34, wherein applying an implementation of a security algorithm includes applying an implementation of an encryption algorithm using the data transform as a key to encrypt the data.
  14. 37
    A method according to any one of claims 29 to 36, wherein organizing the bits includes organizing the bits in the second segment into the number of groups, the number of groups equal to the number of bits in the first segment, each group having a same number of bits.
  15. 38
    A method according to any one of claims 29 to 37, further comprising defining the permutation function.
  16. 41
    A method according to any one of claims 29 to 40, further comprising:dividing an input into at least two blocks, transforming each block separately;and combining a result of the data transformation on each block into a single transformed data to be secured by the application of the implementation of the security algorithm.
  17. 42
    A data transformer according to any one of claims 1 to 8, wherein each of said groups includes a plurality of bits.
  18. 43
    A data security device according to any one of claims 9 to 19, wherein each of said groups includes a plurality of bits.
  19. 44
    A method according to any one of claims 20 to 28, wherein organizing the bits in the second segment into at least one group includes organizing the bits in the second segment into at least one group, each group including a plurality of bits.
  20. 45
    A method according to any one of claims 29 to 41, wherein organizing the bits in the second segment into a number of groups includes organizing the bits in the second segment into a number of groups, each of the group including a plurality of bits.
  21. 46
    A data transformer according to any one of claims 1 to 8, wherein said permuted group has a first size that is equal to a second size of said at least one group.
  22. 50
    A data transformer according to any one of claims 47 to 49, wherein the permuter is operative to permute each group of the second segment if said unique corresponding bit in said first segment is set, and to not permute each group of the second segment if said unique corresponding bit in said first segment is not set.
  23. 52
    A data security device according to any one of claims 9 to 19, wherein said permuted group has a first size that is equal to a second size of said at least one group.
  24. 53
    A data security device according to any one of claims 9 to 19, wherein each group of said second segment has a unique corresponding bit in said first segment.
  25. 56
    A data security device according to any one of claims 53 to 55, wherein the permuter is operative to permute each group of the second segment if said unique corresponding bit in said first segment is set, and to not permute each group of the second segment if said unique corresponding bit in said first segment is not set.
  26. 58
    A data security device according to any one of claims 9 to 19, wherein said number of said groups in said second segment is greater than two.
  27. 59
    A method according to any one of claims 20 to 28, wherein applying a permutation function includes applying the permutation function to the at least one of the groups according to the associated bit in the first segment, each of the permuted groups having a first size that is equal to a second size of the at least one of the groups.
  28. 63
    A method according to any one of claims 60 to 62, wherein applying a permutation function to at least one of the groups includes applying the permutation function to each group of the second segment if the unique corresponding bit in the first segment is set, and not applying the pennutation function to each group of the second segment if the unique corresponding bit in the first segment is not set.
  29. 65
    A method according to any one of claims 29 to 41, wherein applying a permutation function includes applying the permutation function to the at least one of the groups according to the associated bit in the first segment, each of the permuted groups having a first size that is equal to a second size of the at least one of the groups.
  30. 66
    A method according to any one of claims 29 to 41, wherein associating each of the groups with a bit in the first segment includes associating each of the groups with a unique corresponding bit in the first segment.
  31. 69
    A method according to any one of claims 66 to 68, wherein applying a permutation function to at least one of the groups includes applying the permutation function to each group of the second segment if the unique corresponding bit in the first segment is set, and not applying the permutation function to each group of the second segment if the unique corresponding bit in the first segment is not set.
  32. 70
    A method according to any one of claims 29 to 41, wherein organizing the bits in the second segment into a number of groups, the number of groups equal to a number of bits in the first segment includes organizing the bits in the second segment into the number of groups, the number of groups greater than two.
Independent claims32