Multiple module encryption method
Abstract
When an encrypting-decrypting module is being used, there are various methods for determining the key or keys used by said module by analysing the module input or output data. To remedy this inconvenience, the inventive multiple module method is characterised in that the downstream module starts its encrypting-decrypting operations as soon as part of the results of the upstream module is available.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 6 independent, 4 dependent
- 1A method of encryption and decryption using multiple modules of encryption-decryption in series, characterized in that the downstream encryption-decryption module begins its operation as soon as part of the result of the encryption-decryption module upstream is available. REVENDICATIONS 1. Méthode de cryptage et de décryptage utilisant plusieurs modules d'encryptage-décryptage en série, caractérisée en ce que le module d'encryptage-décryptage en aval débute son opération dès qu'une partie du résultat du module d'encryptage-décryptage amont est disponible.
- 4Method according to Claims 1 to 3, characterized in that it implements three modules (A1, S, A2), the central module (S) being of the secret symmetric key type (k). 4. Méthode selon les revendication 1 à 3, caractérisée en ce qu'elle met en œuvre trois modules (A1 , S, A2) , le module central (S) étant de type à clé symétrique secrète (k).
- 5Method according to the preceding claim, characterized in that the first module (A1) and the last module (A2) for encryption and the first module (A2) and the last module (A1) for decryption are of the RSA type with keys asymmetric with either a private key and a public key. 5. Méthode selon la revendication précédente, caractérisée en ce que le premier module (A1 ) et le dernier module (A2) pour l'encryptage et le premier module (A2) et le dernier module (A1 ) pour le décryptage sont du type RSA à clés asymétriques soit avec une clé privée et une clé publique.
- 6Method according to the preceding claim, characterized in that the two modules (A1, A2) use the so-called private key (d, n, d1, n1, d2, n2) for the encryption and the so-called public key (e, n;e1, n1;e2, n2) for decryption. 6. Méthode selon la revendication précédente, caractérisée en ce que les deux modules (A1 , A2) utilisent la clé dite privée (d,n;d1 ,n1 ;d2,n2) pour l'encryptage et la clé dite publique (e, n;e1 ,n1 ;e2,n2) pour le décryptage.
- 7Method according to the preceding claim, characterized in that the two modules (A1, A2) use the same set of private key (d, n) and public (e, n). 7. Méthode selon la revendication précédente, caractérisée en ce que les deux modules (A1 , A2) utilisent un même jeu de clé privée (d, n) et publique (e, n).
Independent claims6
40 paragraphs in 1 section, as filed
ENCRYPTION METHOD OF MULTI-MODULE
The present invention relates to the field of encryption, or encryption and deciphering or decrypting data, especially data that must remain inaccessible to unauthorized persons or devices as part of pay-TV systems. In such systems, the data is encrypted in a secure environment, housing significant computing power, and called the encoding subsystem and sent, by known means, to at least one decentralized subsystem where they is decrypted, typically through a IRD (Integrated Receiver Decoder) and with the help of a smart card. This smart card and the decentralized subsystem which cooperates with it are freely accessible through a possibly unauthorized person.
It is known to chain different means of encryption-decryption in an encryption-decryption system. In the following, we will call encryption - decryption a particular encryption means used in a broader system of encryption-decryption.
It has long sought to optimize the operation of these systems the triple point of view of speed, of the place of memory and security. The speed has the meaning of time required to decrypt the received data.
It is known encryption systems - symmetric key decryption. Their inherent security can be classified according to several criteria.
The first criterion is physical security, on the ease or difficulty of extraction method of investigation of certain components, followed by their possible replacement by other components. These replacement components, designed to inform the unauthorized person on the nature and operation of the system chiffrage- decryption, are chosen by it so as to not be detected, or as little as possible, for the rest of the system. A second criterion is the security system, under which the attacks are not intrusive from the physical point of view but use of mathematical type of analysis. Typically, these attacks will be carried out by high-powered computers that attempt to break the algorithms and encryption codes.
Means encryption - symmetric key decryption are eg systems called DES (Data Encryption Standard). These means, relatively old, offer only a system security and physical security for all. This is particularly why increasingly, DES, the key lengths are too small to meet the system security conditions, is replaced by means of encryption - new decryption or with longer keys. Generally, these symmetric key means make use of algorithms including encryption round.
Other attack strategies are called Simple Power Analysis and Timing Analysis. In Simple Power Analysis, one uses the fact that a microprocessor tasked with encrypting or decrypting data is connected to a voltage source (typically 5 volts). When at rest, it is traversed by a current of intensity i fixed. When active, the instantaneous intensity i is a function not only of the incoming data, but also of the algorithm encryption. Simple Power Analysis consists in measuring the current i as a function of time. the type of algorithm that performs the microprocessor can thereby deduce.
Similarly, the method Timing Analysis consists in measuring the duration of computation as a function of a sample presented to the decryption module. Thus, the relationship between the sample presented and the calculation result of the time allows to retrieve the decryption module secret parameters such as the key. Such a system is described for example in the document "Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and Other Systems" published by Paul Kocher, Cryptography Research, 870 Market St, Suite 1088, San Francisco, CA-USA. To improve the security of the encryption system, it was proposed asymmetric key algorithms such as RSA said systems (Rivest, Shamir and Adleman). These systems include the generation of a pair of matched keys, one for encrypting called public and private said other used for decryption. These algorithms have a high level of security so that physical system. They are against slower than traditional systems, especially at the stage of encryption.
The latest attack techniques involve the so-called DPA concept, English Differential Power Analysis. These methods are based on suppositions, verifiable after a large number of trials, about the presence of a 0 or a 1 in a given position of the encryption key. They are virtually non-destructive, giving them a good indétectabili side, and employ both a physical intrusion component and a mathematical analysis component. Their operation recalls the techniques of investigation of oil fields, where a known power explosion is generated at the surface and where earphones and probes, placed at likewise known distances from the site of the explosion, possible to make assumptions on the stratigraphic composition of the subsurface without much having to dig through the reflection of shock waves by the boundaries of sedimentary layers in the basement. DPA attacks are described in particular in § 2.1. the document "A Cautionary Note Regarding Evaluation of AES Candidates on Smart-Cards", published on 1 February 1999 by Suresh Chari, Charanjit Jutla, Josyula R. Rao and Pankaj Rohatgi, IBM TJ Watson Research Center, Yorktown Heights, NY .
The requirement of having to resist DPA attacks forces the use of said jamming systems "whitening" or in the information to the input or output of an encryption-decryption algorithm. The technique of whitening is described in § 3.5 of the aforementioned document.
Also the fact that the computing power are limited in decentralized sub a pay-TV system system creates a problem, which has never yet been satisfactorily resolved, to perform a sufficient extent chaining described previously. The object of the present invention is to provide a method of encryptage- décrytage resistant to modern methods of investigation such as described above.
The aim of the present invention is achieved by the method described in the characterizing part of claim 1.
The peculiarity of the method lies in the fact that an intermediate module does not start when the result of the previous module (or upstream) finished but starts from an already part of the information available. Thus, to an outside observer, it is not possible to input or output conditions for this module.
As deciphering occurs in the decentralized subsystem cooperating with the chip card, this chip card housing does of computing powers relatively limited compared with the encoding subsystem, it is for example advantageous to use a public asymmetric key, relatively fast operation, during the final stages of decoding. This allows on the one hand to preserve the invulnerability characteristics of the system in process output, and the other hand to concentrate the computational power, related essentially to encryption by using the private key, in the subsystem encoding.
It has been discovered that extra security is afforded by the possibility of concatenating, or of partially interleaving, two means of encryption-decryption which follow sequentially. Means this concatenation or partial interleaving, which is a translation of the English "interleaving" the process of starting the action of the second means of encryption-decryption of data at a time when the first encryption means -décryptage has not yet completed its work on the same data. This will hide the data as result of the work of the first module and before they are subjected to the action of the second module. The chaining can start as soon as data calculated output of the first module are partially available for processing by the second module.
The invention helps guard against these attacks by combining various means of encryption-decryption in a system of chiffrage- decryption, and possibly involving a concatenation or partial interleaving with the sequence in which these means will follow.
In a particular embodiment of the invention, the ciphering-deciphering system comprises an encoding subsystem where three algorithms are used sequentially:
a) an asymmetric algorithm A1 with private key d1. This algorithm A1 performs a signature on plain data, represented by a message m, this operation delivering a first cryptogram, using mathematical operations generally denoted in the profession by the formula: d = m exponent d1, modulo neither. In this formula, nor is part of the public key of the asymmetric algorithm A1, mod represents the mathematical operator well known congruence in all integers, and d1 is the private key of the algorithm A.
b) a symmetric algorithm S using a secret key K. This algorithm converts the cryptogram c2 into a cryptogram.
c) an asymmetric algorithm A2 with private key d2. This algorithm A2 converts the cryptogram c2 into a cryptogram c3, by means of the mathematical operation denoted as before by: c3 = c2 exponent d2 mod n2, wherein n2 is part of the public key of the asymmetric algorithm A2 , and d2 is the private key of the algorithm A2
The cryptogram c3 part of the encoding subsystem and arrives at the decentralized subsystem by means known in itself. In the case of pay TV systems, it can be anything from video data messages. The decentralized subsystem uses, in reverse order of the previous three algorithms A1 ', S' and A2 '. These three algorithms form part of three encryption-decryption means A1-A1 ', S-S' and A2-A2 ', distributed between the encoding subsystem and the decentralized subsystem, and representing the encryption-decryption system.
d) the algorithm A2 'performs a mathematical operation on c3 c2 and returning denoted: c2 = c3 exponent e2 mod n2. In this formula, the set consisting of e2 and n2 is the public key of the asymmetric algorithm A2-A2 '.
e) the symmetric algorithm S 'using symmetrical secret key K restores the cryptogram.
f) the algorithm A1 'with asymmetric public key e1 nor found m by performing the mathematical operation denoted: m = d exponent e1 mod neither.
Concatenation, in the decentralized subsystem, consists in starting the decoding step e) whilst c2 has not yet been fully restored by the previous step), and starting the decoding step f) then of that has not been fully restored by step e. The advantage is to thwart an attack that would aim for example first to extract, in the decentralized subsystem, the cryptogram of the end of step e, to compare with the data in clear m, then by d and m to attack the algorithm A1 \ remount the step by step coding chain.
The concatenation is not necessary in the encoding subsystem, which is installed in a secure physical environment. It is against useful in the decentralized subsystem. In the case of pay TV, the IRD is in fact installed at the subscriber and can be the object of attacks such prédécrit.
It is conceivable that an attack of a combination of three decryption algorithms A1 \ S 'and A2' concatenated much less likely to succeed than if the cryptograms d and c2 are fully reconstructed between each step d), e) and f ). Moreover, the fact that the algorithms A1 'and A2' are used with public keys e1 or e2, n2 fact that calculating means required in the decentralized subsystem are much reduced than in the encoding subsystem.
By way of example and to fix ideas, steps a) and c) that is to say the encryption steps with private keys, are 20 times longer than the steps d) and f) decryption with public keys.
In a particular embodiment of the invention, derived from the previous one, the algorithms A1 and A2 are the same as their counterparts AV and A2 '.
In a particular embodiment of the invention, also derived from the previous one, in step c) using the public key e2, n2 of the asymmetric algorithm A2, whereas in step d) decrypts the cryptogram c3 with the private key d2 of this algorithm. This form is a possible alternative when the resources of the decentralized subsystem in computing power are far from being reached.
While smart cards are used mainly for decrypting data, there are also chip cards having the capacity to perform encryption operations. In this case, the attacks described above will also address these encryption cards which operate outside protected areas such as management center. This is why the method of the invention applies also to serial encryption operations that is to say that the downstream module begins its encryption operation as soon as part of the information delivered by the upstream module is available. This method has the advantage of interleaving the various encryption modules with the consequence that the result of the upstream module is not available at a given time completely. In addition, the downstream module does not begin its operations with a complete result but on parts making it impracticable to interpret the operation of a module relative to an input state or known output.
The present invention will be understood in greater detail through the following drawings, given by way non-limiting, in which: Figure 1 represents the encryption operations
Figure 2 represents the decryption operations
3 shows an alternative to the encryption method
In Figure 1, a set of m data is introduced into the encryption chain. A first element A1 performs an encryption operation using the so-called private key composed of d1 and expose or modulo. The result of this operation is represented by C1. Depending on the mode of operation of the invention, once a part of the result C1 is available, the next module begins its operation. This next S module performs its encryption operation with a secret key. C2 result from partially available is transmitted to the module A2 for the third encryption operation using the so-called private key composed of the exponent d2 and of the modulo n2. The end result, here called C3 is ready to be transmitted by known pathways such as air or via cable.
Figure 2 represents the decryption system composed of the three decryption modules A1 'S', A2 'similar to those used for encryption, but inversely directed. Thus, it first starts with the module A2 'which performs its decryption operation on the basis of the so-called public key composed of the exponent e2 and of the modulo n2. In the same way as for encryption, as soon as a part of the result C2 from the module A2 'is available, it is transmitted to the module S' for the second decryption operation. To complete the decryption, the module A1 'performs its operation on the basis of the so-called public key composed of the exposed and modulo e1 or.
In a particular embodiment of the invention, the two key modules A1 and A2 are identical, that is to say, encryption side, d1 = d2 and n1 = n2. By analogy, during decryption, e1 = e2 and n1 = n2. In this case, we talk about the private key d, n and public key e, n.
In another form of the invention, as illustrated in Figures 3 and 4, the module A2 uses the so-called public key instead of the so-called private key. At the time of encryption, the public key e2, n2 is used by the module A2, (See Figure 3) and during decryption (see Figure 4), the module A2 'uses the private key d2, n2 to operate. Although this configuration has a workload to all decryption, the use of a private key reinforces the security offered by the module A2.
The example illustrated in Figures 3 and 4 is not restrictive for other combinations. For example, it is possible to configure the module A1 so that it performs the encryption operation with the public key and decryption with the private key.
It is also possible to replace the encryption-decryption module secret key S by an asymmetric key-type module of the same type as the A1 and A2 module.
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US11689549B2 | Cited by | United States of America | – | Applicant | – |
| US10977631B2 | Cited by | United States of America | – | Applicant | – |
| DE19539700C1 | Cites | Germany | A | International search | 1-10 |
| US5594797A | Cites | United States of America | A | International search | 1-10 |
8 priority claims, no other members on record
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 157399 | Switzerland | A | |
| 157399 | Switzerland | A | |
| 19417100 | United States of America | P | |
| 19417100 | United States of America | P | |
| 157399 | – | – | – |
| 60194171 | – | – | – |
| CH19990001573 | – | – | – |
| US20000194171P | – | – | – |
34 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: grant in national officeWWG | WWG | WO | |
| Wipo information: grant in national officeWWG | WWG | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Procedure relating to pct application: ceased to have effect for deCeased8642 | 8642 | DE | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Entry into the national phaseENP | ENP | BG | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)DFPE | DFPE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO |
Numbers
- Publication
- 01/17159
- Publication, DOCDB
- 0117159
- Publication, EPODOC
- WO0117159
- Application
- 1157
- Application, DOCDB
- 0001157
- Application, EPODOC
- WO2000IB01157
Titles2
- English
- MULTIPLE MODULE ENCRYPTION METHOD
- French
- METHODE D'ENCRYPTAGE MULTI-MODULES
Classification
- CPC, 5
- H04L9/003
- H04L9/00
- H04L9/08
- H04L9/14
- H04L9/50
- IPC, 3
- H04L9 00
- G09C1 00
- H04L9 14
Designated states111
- Regional, 58
- African Regional Intellectual Property Organization (ARIPO)
- Ghana
- Gambia
- Kenya
- Lesotho
- Malawi
- Mozambique
- Sudan
- Sierra Leone
- Eswatini
- United Republic of Tanzania
- Uganda
- Zimbabwe
- Eurasian Patent Organization (EAPO)
- Armenia
- Azerbaijan
- Belarus
- Kyrgyzstan
- Kazakhstan
- Republic of Moldova
- Russian Federation
- Tajikistan
- Turkmenistan
- European Patent Office (EPO)
and 34 moreShow fewer
- Austria
- Belgium
- Switzerland
- Cyprus
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- African Intellectual Property Organization (OAPI)
- Burkina Faso
- Benin
- Central African Republic
- Congo
- Côte d’Ivoire
- Cameroon
- Gabon
- Guinea
- Guinea-Bissau
- Mali
- Mauritania
- Niger
- Senegal
- Chad
- Togo
- National, 53
- United Arab Emirates
- Antigua and Barbuda
- Albania
- Australia
- Bosnia and Herzegovina
- Barbados
- Bulgaria
- Brazil
- Belize
- Canada
- China
- Costa Rica
- Cuba
- Czechia
- Dominica
- Algeria
- Estonia
- Grenada
- Georgia
- Croatia
- Hungary
- Indonesia
- Israel
- India
and 29 moreShow fewer
- Iceland
- Japan
- Democratic People’s Republic of Korea
- Republic of Korea
- Saint Lucia
- Sri Lanka
- Liberia
- Lithuania
- Latvia
- Morocco
- Madagascar
- North Macedonia
- Mongolia
- Mexico
- Norway
- New Zealand
- Poland
- Romania
- Singapore
- Slovenia
- Slovakia
- Türkiye
- Trinidad and Tobago
- Ukraine
- United States of America
- Uzbekistan
- Viet Nam
- Yugoslavia, later Serbia and Montenegro (until 2006)
- South Africa