Padding data
By generating padding data containing random numbers and length information through the Oracle Absence Padding (OAP) scheme, the problem of low data padding efficiency and insufficient security in existing technologies is solved, realizing a more efficient and secure data padding method and enhancing resistance to padding attacks and timed attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- STMICROELECTRONICS INT NV
- Filing Date
- 2025-10-14
- Publication Date
- 2026-04-17
AI Technical Summary
Existing data padding methods are inefficient and insecure in generating padding data, making them difficult to resist padding attacks and timed attacks, especially in terms of the lack of robustness in handling message length during encryption.
The Oracle Absence Padding (OAP) scheme is adopted. By generating padding data containing random numbers and length information, it ensures that the length of the second part of the padding data is equal to the integer part of the base-2 logarithm of the first number. Furthermore, it avoids the use of message authentication codes for verification during the encryption process, thereby enhancing security and efficiency.
It improves the security and efficiency of the data filling process, effectively resists padding attacks and timed attacks, reduces the delay in the decryption process, and ensures message integrity and security even without using message authentication codes.
Smart Images

Figure CN121887367A_ABST
Abstract
Description
[0001] Priority Statement This application claims the benefit of U.S. Patent Application No. 19 / 353,806, filed October 9, 2025, which claims priority to French Patent Application No. FR2411177, filed October 16, 2024, and European Patent Application No. 25167471.9, filed March 31, 2025, the contents of which are incorporated herein by reference in their entirety to the fullest extent permitted by law. Technical Field
[0002] This disclosure generally relates to electronic systems and devices and their use of data. More specifically, this disclosure relates to the management and processing of data, such as the management of data during data encryption. Background Technology
[0003] When electronic systems and devices need to use information, the format of that information is important for creating messages. Message formatting is typically standardized by adding padding data to the data representing the information in the message.
[0004] It will be desirable to improve, at least in part, certain aspects of data processing, and more specifically, certain aspects of the methods used to populate the data.
[0005] A more efficient method is needed to generate populated messages that include padding data.
[0006] A safer method is needed to generate messages that include population data.
[0007] A more efficient method is needed to generate padding data that includes information about the length of the padding data.
[0008] It is necessary to address all or some of the shortcomings of known methods for generating messages that include populated data. Summary of the Invention
[0009] One embodiment provides a method for generating a message that includes padding data.
[0010] One embodiment provides an electronic device configured to perform a method for generating a message including padding data.
[0011] One embodiment provides a computer program product configured to perform a method for generating a message including padding data.
[0012] One embodiment provides a method for generating a message consisting of one or more blocks of a first number of bytes, the message including a first set of bytes containing data of the message and a second set of bytes corresponding to padding data of the message, wherein the padding data includes a first portion of bits representing a random number and a second portion of bits representing the result of applying a function to a first length, wherein the second length of the second portion of the padding data is equal to the integer part of the base-2 logarithm of the first number.
[0013] One embodiment provides an electronic device configured to generate a message including a first set of bytes containing data of the message and a second set of bytes corresponding to padding data of the message, wherein the padding data includes a first portion of bits representing a random number and a second portion of bits representing the result of applying a function to a first length, wherein a second length of the second portion of the padding data is equal to the integer part of the base-2 logarithm of the first number.
[0014] According to one embodiment, the second set of bits is placed at the end of the padding data.
[0015] According to one embodiment, the first number is a power of 2.
[0016] According to one embodiment, when the first number is equal to 8, the second length of the second portion of the filling data is equal to 3.
[0017] According to one embodiment, when the first number is equal to 16, the second length of the second portion of the padding data is equal to 4.
[0018] According to one embodiment, when the first number is equal to 32, the second length of the second portion of the padding data is equal to 5.
[0019] According to one embodiment, the padding data is placed at the end of the message.
[0020] According to one embodiment, the function is the sum of the first lengths of the padding data modulo a certain integer modulo a first number.
[0021] According to one embodiment, the integer is equal to 0.
[0022] According to one embodiment, the integer is equal to -1.
[0023] One embodiment provides a method for generating the second portion of the bits of the previously described padding data.
[0024] One embodiment provides a computer program product including instructions that, when executed by a computer, cause the computer to perform the previously described method.
[0025] One embodiment provides an encryption method that includes the previously described methods.
[0026] One embodiment provides an encryption device that includes the previously described device. Attached Figure Description
[0027] The foregoing features and advantages, as well as other features and advantages, will be described in detail in the following description of specific embodiments, which are given by way of illustration rather than limitation with reference to the accompanying drawings, wherein:
[0028] Figure 1 An embodiment of the electronic device is shown in block diagram form;
[0029] Figure 2 An example of a message is illustrated in the form of a block diagram;
[0030] Figure 3 An embodiment of the message is schematically illustrated in the form of a block diagram; and
[0031] Figure 4 The diagram schematically illustrates the concept. Figure 3 Examples of embodiments. Detailed Implementation
[0032] In the various figures, the same features have been designated by the same reference numerals. Specifically, structural and / or functional features common in various embodiments may have the same reference numerals and may be provided with exactly the same structure, dimensions, and material properties.
[0033] For clarity, operations and elements have been shown and described in detail, which are useful only for understanding the embodiments described herein.
[0034] Unless otherwise indicated, when referring to two elements connected together, it means that there is no direct connection between them except for the conductor, and when referring to two elements coupled together, it means that the two elements can be connected or they can be coupled via one or more other elements.
[0035] In the following disclosure, unless otherwise indicated, references to absolute positional qualifiers such as “front,” “back,” “top,” “bottom,” “left,” and “right,” or relative positional qualifiers such as “higher than,” “lower than,” “higher,” and “lower,” or directional qualifiers such as “horizontal” and “vertical,” refer to the orientation shown in the figure.
[0036] Unless otherwise specified, the expressions “around,” “approximately,” “substantially,” and “about” mean within 10%, preferably within 5%.
[0037] The above embodiments relate to managing and processing messages when using messages including data in several scenarios. According to one example, when an electronic device needs to apply a certain algorithm (such as an encryption algorithm), some aspects of the message format, such as the message length, can be standardized. To meet these requirements, padding data is typically used in the message to increase its length. The above embodiments relate to methods for generating messages including padding data. These embodiments also relate to electronic devices and computer program products configured to perform this method.
[0038] Furthermore, the above embodiments are specifically configured for use in any kind of industrial market where it is necessary to use filler data in data processing. More specifically, this filler method and related equipment can be intended for use in: the automotive industry, for example, the field of passenger car electrification or advanced driver assistance systems (ADAS); industrial sectors, for example, the green energy field, infrastructure electrification field, Internet of Things (IoT) field, and smart home field, where the consumption of electricity and energy and the exchange of data are key elements; the personal electronics industry, for example, the mobile phone field, the Internet of Things (IoT) field, and the high-speed interface field; and the communication equipment, computer, and peripheral industries, for example, the infrastructure and data center field, and the low Earth orbit satellite field.
[0039] Furthermore, the above embodiments are specifically configured for use in any device that uses encryption methods, such as encryption methods using cipherblock chaining (CBC).
[0040] Figure 1 An electronic device 100 configured to implement a method for generating a message including padding data is shown schematically in block diagram form.
[0041] Device 100 is an electronic device configured to process information and data in message format. Combined with... Figures 2 to 4 The structure of a message according to one embodiment is described.
[0042] Device 100 includes a processor 101 (CPU) configured to process data. According to one example, device 100 may include multiple processors, each configured to process different types of data. According to a particular example, device 100 may include at least one processor configured to process data and process filler data.
[0043] Device 100 also includes one or more memories 102 (MEM) storing data (e.g., critical data). According to one example, device 100 includes various types of memories, such as ROM (read-only memory), RAM (random access memory), volatile memory, and / or non-volatile memory.
[0044] Device 100 also includes one or more secure elements 103 (SEs) configured to process critical and / or confidential data. A secure element 103 may include its own processor(s), its own one or more memories, etc. One or more secure elements 103 may be integrated into or embedded in device 100.
[0045] The device 100 may also optionally include one or more input / output circuits 104 (I / O) that enable the device 100 to send and / or receive data and / or energy with one or more external electronic devices.
[0046] The device 100 also includes one or more circuits 105 (FCT1) and 106 (FCT2) that implement one or more functions of the device 100. According to one example, circuits 105 and 106 may include specific data processing circuitry, such as cryptographic circuitry, or circuitry capable of performing measurements, such as sensors.
[0047] Device 100 also includes one or more communication buses 107 that enable all circuits of device 100 to communicate. Figure 1 The diagram shows a single bus 107 that couples the processor 101, one or more memories 102, security element 103, and circuits 104 to 106, but in reality, the device 100 includes multiple communication buses that couple these different components.
[0048] According to a particular example, electronic device 100 is configured to implement (i.e., execute) a computer program product, specifically executing a computer program product including instructions that, when executed by a computer, cause the computer to perform data processing according to one embodiment.
[0049] According to one variation, electronic device 100 may be a simpler electronic device configured to implement the above embodiments. According to one embodiment, electronic device 100 may be a logic circuit, a controller, a finite-state-machine (FSM), or a field-programmable gate array (FPGA).
[0050] Figure 2 An example of a populated message 200 is illustrated in the form of a block diagram.
[0051] In this disclosure, references to message or data mean a set of data bits representing one or more pieces of information. When information is programmed in hexadecimal, the size of a message is usually discussed in terms of bytes, with one byte representing 8 bits. Furthermore, messages are typically divided into byte blocks of equal size. The size of these byte blocks is generally fixed according to the communication protocol or encryption algorithm.
[0052] In this disclosure, references to a padded message or padded data mean a message or data that includes padded data, i.e., a few data bits used only to increase the length of the message or data.
[0053] Message 200 includes data 201 (DD DD … DD) representing information and padding data 202 (XX XX … XX). The length of message 200 is given by multiplying the number of bytes N in a byte block forming message 200 by the number of blocks forming message 200, where N is an integer. The number of bytes Nd for data 201 and the number of bytes Np for padding data 202 are defined, where Nd is an integer and Np is an integer that is strictly greater than 0 and less than or equal to N. The sum of the number Nd and the number Np is equal to a multiple of the number N.
[0054] For message 200, padding data is mandatory, therefore its length Np is greater than 0. If the length Nd of data 201 is equal to the target size of message 200, then padding data 202 still exists in message 200, and its length Np is equal to the target size of message 200. In this case, the length of message 200 is twice the target size.
[0055] exist Figure 2 In the illustrated example, padding data 202 is placed at the end of message 200. However, it will be apparent to those skilled in the art that padding data can be placed at the beginning of message 200 or inside data 201.
[0056] According to one example, padding data 202 may include Np bytes representing a random number, or patterned data (such as "FF … FF"). According to one example, padding data 202 may include a one-byte indicating its length, meaning the number Np. Depending on the execution context of the data, according to one example, the composition of the padding data may be defined by the specification. In the context of a cryptographic algorithm, according to specification ISO 10126, the last byte of the padding data represents the number Np, while the remaining bytes of the padding data represent the value FF.
[0057] A message of the type of message 200 may also include a message authentication code (MAC), which is the result of a cryptographic operation designed to verify the integrity of the message. According to one example, the message authentication code may be part of the padding data.
[0058] Figure 3 An embodiment of the padded message 300 is shown very schematically in block diagram form.
[0059] The message 300 includes data 301 (DD DD … DD) representing information and padding data 302 (XX … XL …XX). Similar to Figure 2 the message 200, the length of the message 300 is given by the number of bytes N included in one byte block forming the message 300 multiplied by the number of blocks forming the message 300, where N is an integer. The number of bytes Nd of the data 301 and the number of bytes Np of the padding data 302 are defined. Nd is an integer, and Np is an integer strictly greater than 0 and less than or equal to N + 1. According to one embodiment, Np is greater than 1 and less than or equal to N + 1. The sum of the number Nd and the number Np is equal to a multiple of the number N.
[0060] For the message 300, having padding data is mandatory, so the length Np is greater than 0. If the length Nd of the data 301 is equal to the target size of the message 300, the padding data 302 is still present in the message 300, and its length Np is equal to the target size of the message 300. In this case, the length of the message 300 is equal to twice the target size.
[0061] According to one embodiment, the padding data 302 is divided into two groups of bits. The first group of bits represents a true random number, while the second part of the bits represents information related to the length Np of the padding data 302. According to one embodiment, this information is not equal to the length Np, but is equal to the result f(Np) of applying a function f. According to one embodiment, the function f is a reversible coding function. According to one embodiment, the function f is known to both the sender and the receiver of the message 300.
[0062] According to one example, the function f is the sum of length Np and any integer k (also called offset k) modulo the block size represented by the number N. According to one example, the value of integer k is known to both the sender and receiver of message 300. According to one example, the value of integer k is 0. According to another example, the message is equal to length Np minus 1, meaning integer k equals -1. According to this example, when integer k is 5, the number N is 16, and the length of padding data Np is 4, it means the length of the padding data is equal to 9. According to this example, when integer k is -10, the number N is 8, and the length of padding data Np is 3, it means the length of the padding data is equal to 1.
[0063] According to a preferred example, the second portion of the padding data 302 comprises p bits, where p is an integer equal to the base-2 logarithm of the number of bytes N in message 300. For example: when N equals 8, the second portion of the padding data has 3 bits; when N equals 16, the second portion of the padding data has 4 bits (this example is in...). Figure 4 (As shown in the figure); when the number N equals 32, the number of bits in the second part of the padding data is 5; while when the number N equals 512, the number of bits in the second part of the padding data is 9, meaning more than one byte.
[0064] In one example, the second set of bits is placed at the end of the padding data. In a variation, the second set of bits is placed at the beginning of the padding data inside the first set of bits. Considering this variation, in this case, the placement of the second set of bits is defined by the device using message 301.
[0065] According to one embodiment, a method for generating message 300 includes generating padding data 302 as defined above, and then adding the padding data 302 to data 301.
[0066] According to one embodiment, the method for generating message 300 can be used in a method for encrypting data and can be executed by an encryption device.
[0067] Furthermore, this specification also relates to a method for generating a value for the second portion of the padding data. According to one embodiment, the method may include the following steps: determining the length Np of the padding data 302; selecting a value for the offset k; calculating the result of applying a function f to the length Np; and generating p bits representing the value of the calculation result from the previous step.
[0068] Figure 4 An embodiment of the populated message 400 is illustrated schematically in the form of a block diagram. Message 400 is combined with... Figure 3A real-world example of a populated message 300.
[0069] According to one example, the padded message 400 comprises one or more blocks of 16 bytes, in which case the second portion of the padded data consists of 4 bits corresponding to half a byte. According to a preferred example, this second portion of the padded data is placed at the end of the padded data.
[0070] Using messages consisting of one or more 16-byte blocks is very common, especially in encryption, cryptographic compilation, and cryptographic techniques. Programming the information into 4 bits (meaning half a byte) helps to hide the information. When the information equals the number Np minus 1, all possible sizes that exactly fill the data can be covered with just 4 bits.
[0071] One advantage of this embodiment is that it improves security by preventing certain attacks. More specifically, one type of attack relies on invalid combinations that trigger the filling of data to obtain some information about the data. Several countermeasures are typically used to overcome these attack types, and most countermeasures use message authentication codes. The embodiment presented herein is configured to overcome these attack types without using message authentication codes that could potentially reveal information.
[0072] An example of an implementation of the present invention is as follows:
[0073] Oracle absent padding (OAP) is a padding scheme designed to better resist padding and timing attacks. It possesses unique properties and advantages compared to other known and standardized alternatives. Implementing OAP has the potential to accelerate the decryption process.
[0074] Oracle Absence Padding (OAP) aims to enhance resistance to padding and timing attacks while preserving information about the padding length. Additionally, OAP can speed up the decryption process because it allows the receiver to avoid the need to verify the Message Authentication Code (MAC) before decryption begins (see “HMAC: Keyed-Hashing for Message Authentication” by Krawczyk et al., incorporated herein by reference (RFC 2104 (1996); https: / / doi.org / 10.17487 / rfc21041)). Existing padding schemes often require MAC verification before decryption, which can be time-consuming and vulnerable to certain attacks. The MAC can even be omitted, or a similar checksum can be computed on the plaintext while still maintaining resistance to attacks such as oracle padding (see “Security flaws induced by CBC padding - Applications to SSL, IPSEC, WTLS” by Vaudenay, in *Advances in Cryptology - EUROCRYPT 2002* (pp. 534-545) (2002)).
[0075] This standard specifies a new padding scheme for block cipher algorithms used in cryptographic applications, such as AES (see National Institute of Standards and Technology (NIST) "FIPS PUB 197: Advanced Encryption Standard (AES)" (2001)) and RSA (see Shamir et al. "A Method for Obtaining Digital Signatures and Public-Key Cryptosystems" (Communications of the ACM, 21(2), 120-126, 1978)). The purpose of this padding scheme is to ensure that the plaintext data is properly aligned to the block size required by the cipher, while providing robust security properties and maintaining the length of the padding data. This padding scheme aims to enhance the security of every algorithm that requires the input parameters to be powers of 2.
[0076] A oracle padding attack is a cryptographic attack in which an attacker exploits padding verification in block ciphers within a chained cipher (CBC) mode (see NIST's "Recommendation for Block Cipher Modes of Operation: Methods and Techniques" (NIST Special Publication 800-38A, December 2001)). The attacker attempts to trigger an error by altering the initialization vector (IV), which predictably affects the plaintext because it is XORed just before padding is applied. The attack relies on the system revealing whether the padding is correct or incorrect through the time taken or (different) error responses. By analyzing this data, the attacker can gradually reveal parts of the plaintext without knowing the decryption key. This attack is particularly effective against systems using padding schemes like PKCS#7 (see Kaliski's "PKCS #7: Cryptographic Message Syntax Version 1.5" (RFC 2315, March 1998)), where the padding verification process leaks the entire plaintext. This is not important if the system only accepts messages of a specific length, because the attack exploits an invalid padding structure error, not an invalid message length error.
[0077] Consider encrypting a message using PKCS#7 padding: Example of text padding with PKCS#7 (Y = message): YYYY YY YY YY YY YY YY YY 07 07 07 07 07 07 07.
[0078] This attack relies on the fact that all the padding bytes are identical and have known values that depend on the length of the padding.
[0079] 1. Select Cipher Block: Select a cipher block that you want to attack.
[0080] 2. Modifying the IV: Changing the message's IV (Initialization Vector) will directly change the plaintext. Increment the IV until the system indicates that padding is valid again. Begin the attack by incrementing the last byte of the IV.
[0081] 3. Padding Verification: When padding is valid again, verify that the last byte of the plaintext is 0x01 by changing the second-to-last byte of the IV to another value to ensure you don't accidentally find a valid value other than 0x01. If the system still accepts the message after changing the second-to-last byte of the IV, we can be certain that the last byte of the plaintext is 0x01.
[0082] 4. Determine the intermediate plaintext byte: Modify the IV so that the last byte of the plaintext will be 0x00 (in this case, flip the last bit). This modified IV byte will contain the same value as the intermediate plaintext block because if X⊕Y=0, then X=Y.
[0083] 5. Prepare the IV for the next byte: To compute the subsequent bytes of the intermediate plaintext block, first modify the IV so that all bytes after the manipulated byte remain valid. For example, to compute the penultimate byte of the intermediate plaintext block, the last byte of the plaintext needs to be 0x02. This is easy to do because you already know the corresponding byte of the intermediate plaintext block, which is computed by XORing the intermediate plaintext byte with the expected value in the plaintext.
[0084] 6. Determine the intermediate plaintext block: Repeat steps 2, 4, and 5 for each byte in the IV (until the padding length is 0x10) to determine the complete intermediate plaintext block.
[0085] 7. Revealing the plaintext: XORing the calculated intermediate plaintext block with the original IV will reveal the complete plaintext.
[0086] Consider a message encrypted with ISO 10126 padding (see Kaliski's "PKCS #7: CryptographicMessage Syntax Version 1.5" (RFC 2315, March 1998)): Example of text padding with ISO 10126 (Y = message, R = random bytes): YY YY YY YY YY YY YY YY YY RR RR RR RR RR RR RR 07.
[0087] This attack relies on the fact that the penultimate nib of the plaintext must always be 0b0000.
[0088] 1. Select a ciphertext block: Select a ciphertext block to attack, but it doesn't have to be the last one.
[0089] 2. Modify IV: Since the IV directly changes the plaintext, we can modify the second-to-last byte of the IV so that the second-to-last byte of the plaintext becomes 0b0000. When this happens, the system will accept the message.
[0090] 3. Determine the intermediate plaintext: The second-to-last byte of the modified IV will have the same value as the second-to-last byte of the intermediate plaintext block, because if X⊕Y=0, then X=Y.
[0091] 4. Reveal plaintext: XOR the second-to-last nibble of the intermediate plaintext block with the original IV. This will now reveal the value of the plaintext.
[0092] The following definitions apply:
[0093] Message: Important data to be conveyed.
[0094] Block size: A fixed-length block of data processed as a single cryptographic unit. The typical block size is 16 bytes.
[0095] Padding scheme: Padding scheme is a practice used to extend a message until the data reaches a multiple of the block size.
[0096] Message Authentication Code (MAC): A small piece of information added to authenticate the message and ensure its integrity and the authenticity of any data sent.
[0097] Password: A set of well-known encrypted bytes that can be divided according to the block size used as input to a decryption algorithm or as output to an encryption algorithm.
[0098] Intermediate plaintext: Partially decrypted data generated during the decryption process before the final plaintext is obtained.
[0099] IV: A random or pseudo-random value used in conjunction with the secret key to ensure that the same plaintext is encrypted into different ciphertexts each time, thereby enhancing security.
[0100] Plaintext: The raw, unencrypted data that serves as input to an encryption algorithm or output to a decryption algorithm. This includes the message and padding.
[0101] Half-byte: A unit of digital information consisting of half a 4-bit or 8-bit byte. It can represent 16 different values from decimal 0 to 15 or hexadecimal 0 to F.
[0102] A method is proposed for generating messages (padded messages) that can be divided according to data block size. The message consists of two sets of bytes contiguously: the first set of bytes (Y) is the data to be sent, and the second set of bytes (P) is the padding data. The length of P is calculated as the block size (B) minus the remainder of the length of Y when divided by the block size. If this value is 0, the length of P is instead set to the block size.
[0103] The padding data consists of two consecutive sets of bits. The length of the second set of bits (V) is equal to the base-2 logarithm of the block size (usually 16). If this is not an integer, it should be rounded up to the nearest integer, but doing so will cause it to lose some of its resistance properties. The value of V contains the length of P in bytes modulo the length of the block size. The first set of bits (R) (whose length is the length of P in bits minus the length of V in bits) consists of randomly generated bits.
[0104] The message data can be calculated using the following formula, where |X| represents the length of message X in bytes, |X|_"b" represents the length of the same message in bits, and X"||"Y" represents the concatenation of two messages X and Y:
[0105]
[0106]
[0107]
[0108]
[0109]
[0110]
[0111] Resistance Property: When the maximum possible length of the padding (equal to the block length) is a power of 2, it can be encoded exactly using the base-2 logarithm of the block length in bits. If this is not the case, the padding scheme loses some of its resistance properties. The resistance property of the padding scheme depends on the decrypted message not containing invalid padding. This means that if an attacker can change the initialization vector (IV), thereby modifying the plaintext padding structure, the decryption process will not return an error indicating invalid padding, thus not providing an oracle to the attacker. This oracle may also manifest as a time difference during message decryption. Padding possesses this property because the first part of the padding is a random number, and changes here cannot affect the decryption algorithm. Furthermore, changes to the second part of the padding will only change the padding length to an acceptable value. This is because the minimum and maximum values that an attacker can set are precisely within the acceptable range.
[0112] Use Case: General Decryption Without a MAC. An example of this is transmitting a random number if a user decides not to add a MAC when encrypting a message because message integrity is not necessary or no additional value is added. This padding scheme protects such messages from oracle padding attacks even without using a MAC.
[0113] Use Case: General Decryption with MAC. A common practice to prevent padding oracle attacks is to add a MAC to the message. This MAC ensures the integrity of the ciphertext and IV. This prevents the system from decrypting data with an altered IV, thus rendering padding oracle attacks ineffective. In this approach, the user needs to verify the MAC before starting decryption. This is because starting to decrypt a modified message could provide an attacker with an oracle. Using a padding scheme inherently resistant to padding oracle attacks gives the user the option to start decryption first or decrypt in parallel with MAC verification, providing performance advantages such as reduced latency.
[0114] Use case: MAC over plaintext. In cases where the MAC needs to be computed on a portion of the plaintext, the message needs to be decrypted before we can verify its integrity. If the padding scheme used by the user inherently resists padding oracle attacks, then we will also be resistant to padding oracle attacks.
[0115] Conclusion: Comparing this padding scheme with other known solutions, I conclude that no padding scheme provides inherent protection against padding attacks while preserving the length of the padded bytes. However, if the block size is a power of 2, OAP can provide inherent protection and preserve the padded length. With this inherent protection, the padding scheme can potentially accelerate certain processes or enable certain configurations. Even with existing system safeguards (such as MAC protection against certain attacks), I still believe that using OAP can provide enhanced security and an additional layer of security against padding attacks.
[0116] The following provides an example of deploying OAP:
[0117] The blocks are separated by "|", and each character or number represents 4 bits. Here, Y represents data, R represents a random value, and the integer (0 F) represents the bit value of the length of the padding modulo (formerly known as V) the length of the block in bytes.
[0118] A 9-byte message using a 16-byte block size will have the following structure after padding: | YY YY YYYY YY YY YY YY YY RR RR RR RR RR RR RR R7 |
[0119] A 19-byte message using a 16-byte block size will have the following structure after applying padding: | YY YY YYYY YY YY YY YY YY YY YY YY YY YY YY YY | YY YY YY YY RR RR RR RR RR RR RR RR RR RR RR RR RR RD |
[0120] A 16-byte message using a 16-byte block size will have the following structure after padding: | YY YY YYYY YY YY YY YY YY YY YY YY YY YY YY YY | RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR R0 |
[0121] A 14-byte message using a 32-byte block size will have the following structure after padding: | YY YY YYYY YY YY YY YY YY YY YY YY YY YY RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR RR XX |; where XX (8 bits) will have the following structure: "RRR10010" where each character or number represents 1 bit.
[0122] Various embodiments and variations have been described. Those skilled in the art will understand that certain features of these embodiments can be combined, and other variations will readily conceive of them.
[0123] Finally, based on the functional descriptions provided above, the actual implementation of the embodiments and variations described herein is within the capabilities of those skilled in the art.
Claims
1. A method comprising: Generate a message consisting of one or more blocks of the first number of bytes, the message including a first group of bytes containing the data of the message and a second group of bytes corresponding to the padding data of the message; Generate the padding data for the second set of bytes, comprising a first set of bits representing a random number and a second set of bits representing the result of applying a function to the length of the padding data; and The length of the second portion of the padding data is equal to the base-2 logarithm of the number of bytes in the message.
2. The method of claim 1, wherein the second portion of bits is placed at the end of the padding data.
3. The method according to claim 1, wherein the number of the first byte is a power of 2.
4. The method of claim 3, wherein when the number of the first bytes is equal to 8, the length of the second portion of the padding data is equal to 3.
5. The method of claim 4, wherein when the number of the first bytes is equal to 16, the length of the second portion of the padding data is equal to 4.
6. The method of claim 3, wherein when the number of the first bytes is equal to 32, the length of the second portion of the padding data is equal to 5.
7. The method of claim 1, wherein the padding data is placed at the end of the message.
8. The method of claim 1, wherein the function is the sum of the length of the padding data and an integer modulo the number of the first bytes.
9. The method of claim 8, wherein the integer is equal to 0.
10. The method of claim 8, wherein the integer is equal to -1.
11. A computer program product comprising instructions, which, when executed by a computer, causes the computer to perform the method according to claim 1.
12. An encryption method comprising performing the method according to claim 1.
13. A method for generating padding data for a message, comprising: Generate padding data to include a first portion of bits representing a random number and a second portion of bits representing the result of applying a function to the length of the padding data; The length of the second part of the bits is equal to the base-2 logarithm of the number of bytes in the message.
14. The method of claim 13, wherein the number of bytes is a power of 2.
15. The method of claim 14, wherein when the number of bytes is equal to 8, the length of the second portion of the padding data is equal to 3.
16. The method of claim 14, wherein when the number of bytes is equal to 16, the length of the second portion of the padding data is equal to 4.
17. The method of claim 14, wherein when the number of bytes is equal to 32, the length of the second portion of the padding data is equal to 5.
18. The method of claim 13, wherein the function is the sum of the length of the padding data and an integer modulo the number of the first bytes.
19. A computer program product comprising instructions, which, when executed by a computer, causes the computer to perform the method according to claim 13.
20. An encryption method comprising performing the method according to claim 13.
21. An electronic device configured to generate a message, the message including a first set of bytes containing data of the message and a second set of bytes corresponding to padding data of the message; The padding data for the second group of bytes includes a first set of bits representing a random number and a second set of bits representing the result of applying a function to the length of the padding data; and The length of the second portion of the padding data is equal to the base-2 logarithm of the number of bytes in the message.
22. An encryption device, comprising the device according to claim 21.
Citation Information
Patent Citations
Acides (haloalkylthio-, -sulfinyl, ou -sulfonylphenyl)-2 alcanoiques
FR2411177A1