IL219906A

Verifiable, leak-resistant encryption and decryption

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

50 claims: 8 independent, 42 dependent

  1. 1
    219906/3 What is claimed is:1. A method for encrypting plaintext data by a device with an internal secret state, while limiting the re-use of cryptographic keys, comprising: (a) deriving a message key from said internal secret state and a message identifier by computing, using a hardware unit, a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, where each successive key is derived based on at least a portion of said message identifier and a prior key;(b) using said one or more cryptographic keys based on at least said message key to encrypt one or more segments of said plaintext data to produce one or more encrypted data segments;(c) computing a cryptographic hash from at least one said encrypted data segment;(d) deriving a validator from at least a secret value and said cryptographic hash, where said deriving includes computing a plurality of successive intermediate values, starting with said secret value, where each successive value is at least based on a prior one of said values and a portion of said cryptographic hash;(e) outputting said one or more encrypted data segments and said validator.
  2. 16
    A method for encrypting plaintext data by a device with an internal secret state, while limiting the re-use of cryptographic keys, comprising:(a) deriving a message key from said internal secret state and a message identifier by computing, using a hardware unit, a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, where each successive key is derived based on at least a portion of said message identifier and a prior key;(b) using said one or more cryptographic keys based on at least said message key to encrypt one or more segments of said plaintext data to produce one or more encrypted data segments;(c) using a secret key to compute a cryptographic verification value at least based on, and usable to verify, one or more of said encrypted data segments;and (d) outputting said one or more encrypted data segments and said cryptographic verification value.
  3. 18
    A method for decrypting data by a device with an internal secret state, while limiting the re-use of cryptographic keys, comprising:(a) receiving one or more encrypted data segments and a cryptographic verification value, and obtaining a message identifier corresponding thereto;40 219906/3 (b) verifying said cryptographic verification value to determine whether said message identifier or at least one of said encrypted data segments have been modified, including: (i) computing, using a hardware unit, a cryptographic hash from at least one said encrypted data segment;(ii) deriving, using the hardware unit, an expected validator from at least a secret value and said cryptographic hash, where said deriving includes computing a plurality of successive intermediate values, starting with said secret value, where each successive value is at least based on a prior one of said values and a portion of said cryptographic hash;and (iii) comparing said derived expected candidate validator with said received cryptographic verification value;(c) deriving a message key from said internal secret state and said message identifier by computing a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, where each successive key is derived based on at least a portion of said message identifier and a prior key;and (d) using said one or more cryptographic keys based on at least said message key to decrypt one or more verified segments of said encrypted data to produce one or more plaintext data segments.
  4. 32
    A method for decrypting data by a device with an internal secret state, while limiting the re-use of cryptographic keys, comprising:(a) receiving one or more encrypted data segments and a cryptographic verification value, and obtaining a message identifier corresponding thereto;(b) verifying said cryptographic verification value to determine whether said message identifier or at least one of said encrypted data segments have been modified;(c) deriving a message key from said internal secret state and said message identifier by computing, using a hardware unit, a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, where each successive key is derived based on at least a portion of said message identifier and a prior key;and (d) using said one or more cryptographic keys based on at least said message key to decrypt one or more verified segments of said encrypted data to produce one or more plaintext data segments.
  5. 34
    A device for encrypting plaintext data while limiting the re-use of cryptographic keys, comprising:a hardware unit configured to 43 219906/3 (a) derive a message key from an internal secret state and a message identifier by computing a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, each successive key to be derived based on at least a portion of said message identifier and a prior key;(b) use said one or more cryptographic keys based on at least said message key to encrypt one or more segments of said plaintext data to produce one or more encrypted data segments;(c) compute a cryptographic hash from at least one said encrypted data segment;(d) derive a validator from at least a secret value and said cryptographic hash, where said deriving includes computing a plurality of successive intermediate values, starting with said secret value, each successive value to be at least based on a prior one of said values and a portion of said cryptographic hash;and (e) output said one or more encrypted data segments and said validator.
  6. 39
    A device for encrypting plaintext data while limiting the re-use of cryptographic keys, comprising:a hardware unit configured to (a) derive a message key from said internal secret state and a message identifier by computing a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, each successive key to be derived based on at least a portion of said message identifier and a prior key;(b) use said one or more cryptographic keys based on at least said message key to encrypt one or more segments of said plaintext data to produce one or more encrypted data segments;(c) use a secret key to compute a cryptographic verification value at least based on, and usable to verify, one or more of said encrypted data segments;and (d) output said one or more encrypted data segments and said cryptographic verification value.
  7. 41
    A device for decrypting data, while limiting the re-use of cryptographic keys, comprising:a hardware unit configured to (a) receive one or more encrypted data segments and a cryptographic verification value, and obtaining a message identifier corresponding thereto;(b) verify said cryptographic verification value to determine whether said message identifier or at least one of said encrypted data segments have been modified, including;(i) computing a cryptographic hash from at least one said encrypted data segment;(ii) deriving an expected validator from at least a secret value and said cryptographic hash, where said derivation includes computing a plurality of successive intermediate values, starting with said secret value, where each successive value is at least based on a prior one of said values and a portion of said cryptographic hash;and (iii) comparing said derived expected candidate validator with said received cryptographic verification value;45 219906/3 (c) derive a message key from said internal secret state and said message identifier by computing a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, where each successive key is derived based on at least a portion of said message identifier and a prior key;and (d) use said one or more cryptographic keys based on at least said message key to decrypt one or more verified segments of said encrypted data to produce one or more plaintext data segments.
  8. 49
    A device for encrypting plaintext data while limiting the re-use of cryptographic keys, comprising:a hardware unit configured to (a) derive a message key from said internal secret state and a message identifier by computing a plurality of successive intermediate keys, starting with at least a portion of said internal secret state and leading to said message key, each successive key to be derived based on at least a portion of said message identifier and a prior key;(b) use said one or more cryptographic keys based on at least said message key to encrypt one or more segments of said plaintext data to produce one or more encrypted data segments;(c) use a secret key to compute a cryptographic verification value at least based on, and usable to verify, one or more of said encrypted data segments;and (d) output said one or more encrypted data segments and said cryptographic verification value.