System and method for LFSR based authentication

The multi-stage LFSR-based encryption system addresses vulnerabilities in existing authentication systems by introducing multiple layers of obfuscation and unpredictability, ensuring robust and adaptable security for diverse devices.

WO2026052192A1PCT designated stage Publication Date: 2026-03-12OFFICEINVENT
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Existing authentication systems face challenges in balancing security, flexibility, and efficiency, with vulnerabilities to cryptanalysis, replay attacks, and side-channel attacks, particularly due to the predictability of Linear Feedback Shift Register (LFSR) outputs and reliance on fixed-order algorithms.

Method used

A multi-stage encryption system using LFSRs with shift register, generator, and output encryption keys, combined with bit-level manipulation and input-dependent shifting, enhances security by introducing multiple layers of obfuscation and unpredictability, allowing flexible configuration and implementation in hardware, firmware, or software.

Benefits of technology

The system provides robust and adaptable authentication with enhanced security against attacks, flexible configuration, and efficient implementation across various devices, resistant to cryptanalysis and side-channel attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure DK2025050142_12032026_PF_FP_ABST
    Figure DK2025050142_12032026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure provides a computer-implemented method for authenticating devices using an encryption system (30). The method includes receiving an input word (31), obfuscating the input word (31) using a shift register encryption key (51) to obtain a shift register polynomial (41), and obfuscating the input word (31) using a generator encryption key (52) to obtain a generator polynomial (42). The method further includes shifting the shift register polynomial (41) through a Linear Feedback Shift Register (LFSR) (40) for at least one cycle using the generator polynomial (42) to obtain an output polynomial (43), obfuscating the output polynomial (43) using an output encryption key (53) to obtain an output codeword (32), and outputting the output codeword (32) for device authentication.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SYSTEM AND METHOD FOR LFSR BASED AUTHENTICATION

[0002] TECHNICAL FIELD

[0003] The present disclosure relates to authentication systems and methods, and more particularly to a system and method for device authentication using a Linear Feedback Shift Register (LFSR) based encryption system.

[0004] BACKGROUND

[0005] Authentication systems play a crucial role in securing access to devices, networks, and sensitive information. These systems typically rely on various methods to verify the identity of users or devices attempting to gain access. One common approach involves the use of cryptographic techniques to generate and validate authentication codes. Many authentication systems employ challenge-response protocols, where a challenge is issued by an authenticator and a valid response must be provided by the supplicant to gain access. The security of such systems often depends on the unpredictability and complexity of the challenge-response mechanism.

[0006] As the need for secure authentication continues to grow across various domains, including Internet of Things (loT) devices, automotive systems, and access control systems, there is an ongoing demand for authentication methods that provide robust security while remaining efficient and practical to implement. Balancing security, computational requirements, and ease of integration presents a persistent challenge in the field of authentication system design. Furthermore, the increasing sophistication of attacks on authentication systems necessitates continuous improvement and innovation in authentication technologies. Designers must consider various attack vectors, including replay attacks, side-channel attacks, and cryptanalysis attempts, when developing new authentication schemes.

[0007] Linear Feedback Shift Registers (LFSRs) have long been utilized in prior art cryptographic applications due to their ability to generate pseudo-random sequences. LFSRs are relatively simple to implement in hardware and software and can produce long sequences with good statistical properties. However, the predictability of LFSR outputs has led to concerns about their security when used alone in cryptographic systems.

[0008] Consequently, there are still several challenges and technical problems that persist in prior art authentication systems. Conventional designs often rely on fixed-order algorithms or methods to generate secure codewords, which can be difficult or impossible to modify if increased security is required. This lack of flexibility limits the adaptability of such systems to diverse applications with varying security needs. Additionally, many existing authentication systems are vulnerable to cryptanalysis due to the predictability of their outputs, or due to the use of serial and / or master keys, which, if cracked, may affect multiple systems, such as in the case of the Keeloq block cipher and authentication protocols built on top of it.

[0009] The efficiency of authentication is often compromised by complex algorithms that require significant computational resources, making implementation challenging in resource-constrained devices. Furthermore, some prior art systems are susceptible to replay attacks or side-channel attacks, compromising their overall security. These unresolved issues underscore the pressing demand for an improved authentication system that offers enhanced security, flexibility, and efficiency while remaining resistant to various attack vectors.

[0010] SUMMARY

[0011] An example embodiment of the present invention is directed to solving at least some of the issues present in the prior art by providing an authentication system which includes an authenticator and a supplicant apparatus using corresponding encryption systems comprising various elements including encryption keys, a linear feedback shift register and a random number generator. More specifically, one object is to provide a system and method for linear feedback shift register (LFSR) based authentication for providing an encryption system to be applied to a LFSR, for the purpose of authenticating devices.

[0012] Another object is to provide a System And Method For Lfsr Based Authentication that provides a secure output code from the supplicant in response to a randomly generated input code sent by the authenticator.

[0013] Another object is to provide a System And Method For Lfsr Based Authentication that the length, or order, of the system can be trivially increased such that it fulfils the security requirements of a particular system. For example, if used to open a door to a bank it could be made x bits longer than if used to open a private house.

[0014] Another object is to provide a System And Method For Lfsr Based Authentication that results in the output from the supplicant to have random properties, such that neither the encryption keys nor the secure code can be discovered by an attacker.

[0015] Another object is to provide a System And Method For Lfsr Based Authentication that may be implemented in a wide variety of authentication systems, for example unlocking doors or logging on to a computer or related device.

[0016] Another object is to provide a System And Method For Lfsr Based Authentication that can be implemented in hardware, firmware or software, else a combination thereof.

[0017] Another object is to provide a System And Method For Lfsr Based Authentication that allows the encryption system to be applied to the output of a pseudorandom number generator (PRNG), for the purpose of securing the PRNG outputs against algorithmic based cryptographic attacks.

[0018] The foregoing and other objects are achieved by the features of the independent claims. Further implementation forms will be apparent to a skilled person based on the dependent claims, the description, and the figures.

[0019] According to an aspect of the present disclosure, a computer-implemented method for authenticating devices using an encryption system is provided. The method includes receiving an input word and obfuscating the input word using a shift register encryption key to obtain a shift register polynomial, as well as obfuscating the input word using a generator encryption key to obtain a generator polynomial. The method further includes shifting the shift register polynomial through a Linear Feedback Shift Register (LFSR) for at least one cycle using the generator polynomial to obtain an output polynomial and obfuscating the output polynomial using an output encryption key to obtain an output codeword for device authentication. This multi-stage encryption process may enhance security by introducing multiple layers of obfuscation, making it significantly more challenging for potential attackers to reverse-engineer the original input or predict the output.

[0020] According to other aspects of the present disclosure, the method may include one or more of the following features.

[0021] The step of obfuscating the input word using the shift register encryption key, and / or obfuscating the input word using the generator encryption key, and / or obfuscating the output polynomial using the output encryption key may comprise the sub-steps of: selectively inverting the polarity of each bit of the input word or the output polynomial as applicable, based on corresponding bits of a polarity key; and mapping resulting bits to final positions based on corresponding position values of a position key to obtain the shift register polynomial, the generator polynomial or the output codeword as applicable. This bit-level manipulation may provide an additional layer of security by altering both the values and positions of individual bits, potentially increasing the complexity of the encryption and making it more resistant to cryptanalysis.

[0022] The method may further comprise circularly shifting the generator polynomial based on information derived from the input word prior to shifting the shift register polynomial through the LFSR, such as circularly shifting the generator polynomial by a number of bits equal to the number of ones or zeros in the input word. This input-dependent shifting may introduce variability into the encryption process, potentially making the relationship between input and output less predictable and more resistant to pattern analysis. Shifting the shift register polynomial through a LFSR may comprise: bitwise multiplying the generator polynomial with the shift register polynomial to obtain a multiplied polynomial; performing a modulo-2 addition on the multiplied polynomial to obtain a single bit; bitwise shifting the contents of the shift register causing the lowest order bit to be discarded, and adding the single bit from the modulo-2 addition to the highest order bit; and repeating these operations k times, where k is the order of the system to obtain the output polynomial. This process may leverage the pseudo-random properties of LFSRs while incorporating additional mathematical operations, potentially enhancing the unpredictability and complexity of the output.

[0023] The LFSR may be implemented in a Fibonacci configuration or a Galois configuration. This flexibility in LFSR implementation may allow for optimization based on specific hardware or software constraints, potentially improving efficiency while maintaining security.

[0024] The method may further comprise: checking the shift register polynomial at initialization and after each shift, such as by using an invalid number handler supplicant; and if all bits in the shift register polynomial are zero, inputting a one into the highest order bit of the shift register polynomial; or if all bits in the shift register polynomial are one, inputting a zero into the highest order bit of the shift register polynomial. This check may prevent the LFSR from entering a degenerate state, potentially ensuring the continued generation of complex, non-repeating sequences.

[0025] The method may further comprise: checking the output codeword, such as by using an invalid number handler authenticator; and if the output codeword is all zeros or all ones, rejecting the output codeword and generating a new input word. This additional check may prevent the transmission of potentially weak or predictable codewords, enhancing the overall security of the authentication process.

[0026] According to other aspects of the present disclosure, the method may be performed by an authenticator, and may further comprise: receiving a request from a supplicant, the request preferably comprising at least one of an identification or control data; in response to the request, generating a random message as the input word; using the generated random message as the input word for the encryption system to generate and store an output codeword; transmitting the random message to the supplicant; receiving a response codeword from the supplicant; comparing the response codeword with the stored output codeword; and initiating a preset action, such as an unlock procedure, if the response codeword matches the stored output codeword. Alternatively, the method may be performed by a supplicant, and may further comprise: transmitting a request to an authenticator, the request preferably comprising at least one of an identification or control data; receiving a random message from the authenticator; using the received random message as the input word for the encryption system to generate an output codeword; transmitting the output codeword to the authenticator as a response codeword. This challenge-response protocol may provide mutual authentication between devices while leveraging the security benefits of the encryption system, potentially offering protection against replay attacks and man- in-the-middle attacks.

[0027] According to another aspect of the present disclosure, a computer-implemented method for generating encrypted random numbers using a PRNG Encryption System is provided. The method includes generating a random number using a maximal length pseudorandom number generator. The method includes inputting the generated random number as an input word into an encryption system. The method includes processing the input word through the encryption system to generate an output codeword according to the method described above. The method includes outputting the output codeword as an encrypted random number. This method may combine the strengths of pseudorandom number generation with the additional security of the encryption system, potentially producing high-quality encrypted random numbers suitable for cryptographic applications.

[0028] According to another aspect of the present disclosure, a system for authenticating devices is provided. The system includes an authenticator comprising: a first encryption system; a random number generator; a transmitter; and a receiver. The system includes a supplicant comprising: a second encryption system corresponding to the first encryption system; a transmitter; and a receiver. The authenticator is configured to: generate a random message using the random number generator; process the random message through the first encryption system as an input word to generate an output codeword according to the method described above; transmit the random message to the supplicant using the transmitter; receive a response codeword from the supplicant using the receiver; and compare the response codeword with the output codeword. The supplicant is configured to: receive the random message from the authenticator using the receiver; process the received random message through the second encryption system as an input word to generate the response codeword according to the method described above; and transmit the response codeword to the authenticator using the transmitter. This system architecture may enable secure device-to- device authentication by leveraging the encryption method, potentially providing protection against various types of attacks while allowing for flexible implementation in different types of devices.

[0029] According to another aspect of the present disclosure, a system for authenticating devices is provided. The system includes an authenticator comprising: a first encryption system; a counter; an invalid number handler authenticator; a receiver. The system includes a supplicant comprising: a second encryption system; a counter; an invalid number handler supplicant; a transmitter. The authenticator is configured to: generate an input word using the counter; process the input word through the first encryption system to generate an output codeword according to the method described above; receive a response codeword from the supplicant using the receiver; compare the response codeword with the output codeword; and check the output codeword using the invalid number handler authenticator. The supplicant is configured to: generate an input word using the counter; process the input word through the second encryption system to generate the response codeword according to the method described above; check the response codeword using the invalid number handler supplicant; and transmit the response codeword to the authenticator using the transmitter. This system may provide an alternative authentication method using synchronized counters, allowing one-way transmission.

[0030] According to another aspect of the present disclosure, a computer program product is provided. The computer program product comprises a computer- readable storage medium having computer-readable instructions stored thereon, the computer-readable instructions being executable by a computerized device comprising a computer processor to cause the computerized device to perform the method described above. This computer program product may allow for flexible implementation of the authentication method across various types of computerized devices, potentially enabling widespread adoption of the secure authentication system.

[0031] These and other aspects will be apparent from the embodiments described below.

[0032] BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Aspects of this disclosure will be best understood from the following description of specific embodiments when read in connection with the accompanying drawings.

[0034] FIG. 1 illustrates a block diagram of an authentication system showing the interaction between authenticator and supplicant, according to an embodiment of the disclosure.

[0035] FIG. 2 illustrates a block diagram of an encryption system, according to an embodiment of the disclosure.

[0036] FIG. 3 illustrates a Fibonacci implementation of a Linear Feedback Shift Register circuit, showing the first of two main implementations of the LFSR as known in the prior art.

[0037] FIG. 4 illustrates a Galois implementation of a Linear Feedback Shift Register circuit, showing the second of two main implementations of the LFSR as known in the prior art. FIG. 5 illustrates a detailed block diagram of an encryption system according to an embodiment of the disclosure, showing the function of the LFSR in detail.

[0038] FIG. 6 is a diagram showing various encryption keys according to an embodiment of the disclosure, illustrating two methods of obfuscation employed by the encryption keys, namely mapping and polarity changes.

[0039] FIG. 7 illustrates a block diagram of an encryption system with invalid number handling using logic gates, according to an embodiment of the disclosure.

[0040] FIG. 8 illustrates a flowchart of an authentication process as implemented in the authenticator and the supplicant respectively, according to an embodiment of the disclosure.

[0041] FIG. 9 illustrates a detailed flowchart of an encryption system process, according to an embodiment of the disclosure.

[0042] FIG. 10 illustrates a hardware implementation of a linear feedback shift register circuit using logic devices, according to an embodiment of the disclosure.

[0043] FIG. 11 illustrates block diagram of a PRNG encryption system operating on the output of a pseudorandom number generator, according to an embodiment of the disclosure.

[0044] FIG. 12 illustrates a block diagram of an authentication system using one-way transmission from supplicant to authenticator, according to another possible embodiment of the disclosure.

[0045] DETAILED DESCRIPTION

[0046] The present disclosure provides a system and method for device authentication that leverages the properties of Linear Feedback Shift Registers (LFSRs) in conjunction with a multi-stage encryption system. The authentication system comprises two primary components: an authenticator and a supplicant. The authenticator generates a random input word and processes it through an encryption system to produce a secure output codeword. The random input word is then transmitted to the supplicant, which uses a corresponding encryption system to generate a response codeword. If the response codeword matches the original output codeword, the supplicant is authenticated.

[0047] In the case of authenticating a computer, or similar device such as a smart phone, the host device would act as the authenticator and the client device as the supplicant.

[0048] The encryption system employed in this authentication process includes multiple encryption keys and a Linear Feedback Shift Register (LFSR). The LFSR, a component known for its ability to generate pseudo-random sequences, is used in a novel way to enhance the security of the authentication process. The input word is obfuscated using a shift register encryption key and a generator encryption key to obtain a shift register polynomial and a generator polynomial, respectively. These polynomials are then processed through the LFSR to obtain an output polynomial, which is further obfuscated using an output encryption key to produce the output codeword.

[0049] This multi-stage encryption process introduces multiple layers of obfuscation, making it significantly more challenging for potential attackers to reverse-engineer the original input or predict the output. Furthermore, the system allows for flexibility in implementation, as the LFSR can be configured in either a Fibonacci or Galois configuration, and the encryption system can be implemented in hardware, firmware, software, or a combination thereof. This flexibility, combined with the enhanced security provided by the multi-stage encryption process, makes the disclosed authentication system a robust and adaptable solution for a wide range of applications.

[0050] Referring to FIG. 1 , the authenticator 10 is a key component of the authentication system. The authenticator 10 includes several interconnected modules. It comprises a random number generator 11 , a transmitter 13, a receiver 14, and an encryption system 30. The encryption system 30 is connected to an invalid number handler authenticator 34 and a repeat output codeword handler 17.

[0051] The random number generator 11 is responsible for generating a random input word 31 . In some aspects, the random number generator 11 may be a true random number generator, as opposed to a pseudorandom number generator. True random number generators can use various physical properties to generate 'true' random numbers. For instance, the physical properties of a resistor or the properties of photons in a quantum random number generator may be used to generate these random numbers.

[0052] A pseudorandom number generator, although generating good randomness, results in an output that can be predicted due to the linear nature of the LFSR driven generator. In such case, a PRNG Encryption System 70 such as illustrated in FIG. 11 may be used to encrypt the pseudorandom number, such that the PRNG output can no longer be predicted.

[0053] Optionally, a repeat random number handler 12 can be used to reject any random number which has already been used in previous transmissions, up to the limit determined by the repeat random number handler's 12 word storage capacity. It should, however, be noted that for high system orders, the chances of any repeated random numbers will be so close to zero that it could be considered impossible.

[0054] Given that the encryption system 30 outputs random words, it is theoretically possible that the same output codeword 32 may be generated for different input words 31. Although, for high order (k) values this is highly unlikely to occur, a repeat output codeword handler 17 can store previous output codewords 32, in order to compare with a current output codeword 32, which can then be rejected by the authenticator 10 if a match is found.

[0055] Prior to sending the random number, as outputted from the random number generator 11 , the authenticator 10 uses the encryption system 30 to ensure the random number is valid. Depending on the embodiment, certain words, such as all zeros or all ones, present at one or more of the encryption stages for example, the input word 31 , the generator polynomial 42, the shift register polynomial 45, or output codeword 32 are dealt with by the invalid number handler authenticator 34.

[0056] The generated random input word 31 is then processed by the encryption system 30. The encryption system 30 obfuscates the input word 31 using a shift register encryption key 51 and a generator encryption key 52 to obtain a shift register polynomial 41 and a generator polynomial 42, respectively. After shifting the shift register polynomial 41 through the LFSR 40 for one complete cycle, an output polynomial 43 is obtained. The output polynomial 43 is further obfuscated using an output encryption key 53, resulting in the output codeword 32.

[0057] The transmitter 13 and receiver 14 in the authenticator 10 facilitate the communication with the supplicant 20. The transmitter 13 sends the valid random number to the supplicant 20 to be used as input word 31 , and the receiver 14 acquires the data sent back from the supplicant 10, preferably using the same method as the transmitter 13. The data will consist of the correct codeword, and depending on the embodiment other data may be sent, either simultaneously or sequentially. These other data may be used to activate specific functions, such as starting a vehicle or turning on lights in a building, as determined by an ID and Data Handler 15. Noting, any specific data required by the particular communication method, such as synchronization or error correction data in the case of some wireless transmission protocols, are not considered here.

[0058] The received codeword is then compared with the expected codeword, as previously determined by the authenticator 10, in the compare codewords 16 stage. If the words match, the supplicant 20 is considered to be authentic and the system under protection, for example a door or computer / device log on, is unlocked. If the two codewords do not match, the system remains locked.

[0059] Further referring to FIG. 1 , the supplicant 20 is another key component of the authentication system. The supplicant 20 includes a second encryption system 30 configured to process a received random message from the authenticator 10 as an input word 31 , and generate a response codeword according to the method described earlier. As would be obvious to anyone conversant with the art, the encryption systems 30 used by the authenticator 10 and supplicant 20 must be equally implemented. For example, they must use the same encryption keys 50, and the same optional functions used such as generator polynomial shifting 33, or the invalid number handlers 34 / 35. Though, the invalid number handler authenticator 34 may act differently, in that it may refuse certain random numbers, such as one which would cause the generator polynomial 42, or the output codeword 32 to equal zero. The flowchart in FIG. 9 shows some of the invalid number handler functionality, such as the refusal by the authenticator 10 of an output codeword which equals zero.

[0060] Depending on the embodiment, an ID and Data Handler 15 may send data back to the supplicant 20, for example a vehicle, or building, could transmit information regarding the last time a door was opened, or the temperature inside the vehicle or building, else any other relevant information according to the embodiment.

[0061] It is also possible to use the authenticator if only one-way transmissions are allowed. Referring now to FIG. 12, it can be seen that the authenticator does not transmit a random number, rather it uses a counter 18, possibly with an offset, as the input to the encryption system 30. Furthermore, the counter number may also be incorporated into the encryption system 30 in a manner similar to that used by the Two Factor Authentication Handler. If the supplicant returns its counter number in plaintext, then the authenticator can use that number as the input to the encryption system 30. Otherwise, the authenticator would have to keep incrementing its own counter until a match is found. Given the supplicant uses the same counter number, then the codewords will match, and the system thereafter will be unlocked.

[0062] The supplicant 20 also comprises a transmitter 22 and a receiver 23. The receiver 23 is configured to receive the random message from the authenticator 10. Once the random message is received, it is processed through the second encryption system 30 to generate the response codeword. The transmitter 22 is then used to transmit the response codeword back to the authenticator 10. A basic block diagram of the supplicant 20 is shown in FIG. 1 , whereas FIG. 8 shows a software program flowchart for a basic implementation of the supplicant 20. Similarly, to the authenticator 10, the supplicant 20 runs the received random word 31 through the encryption system 30 in order to obtain the codeword 32 to be sent back to the authenticator 10.

[0063] In some cases, the supplicant 20 may also include an invalid number handler supplicant 35. This component checks the response codeword and, if necessary, adjusts it to avoid certain undesirable conditions, such as all bits being zero or all bits being one. This additional layer of processing enhances the security of the authentication process.

[0064] A delay 24 may also be incorporated into the supplicant 20 which may either be fixed, or triggered by the invalid number handler supplicant 35, the purpose of which is to make brute-force attacks, more difficult to perform.

[0065] Depending on the embodiment, an ID and Data Handler 25 may send other data, together with the codeword 32, relating to various functions which may be performed by the authenticator 10, such as, but not limited to, starting a vehicle engine or opening a door. Any data received may be acted on by the ID and Data Handler 25. In the case of information, some method must be incorporated which allows the user access to the information. As an example, a vehicle might let the user know the last time a door was opened on the vehicle, which could be shown on a led or similar screen. In addition to, or in place of, the preferred supplicant device, such as a key fob in the case of vehicles, buildings or rooms, other devices could be utilized, such as smart phones.

[0066] It is also possible to use the supplicant 20 if only one-way transmissions are allowed. Referring now to FIG. 12, it can be seen that the supplicant does not receive a random number, rather it uses a counter 26, possibly with an offset, as the input to the respective encryption system 30. The resultant codeword 32 is transmitted to the authenticator 10, possibly with the counter number being sequentially sent in order to synchronise with the authenticator 10. As mentioned before, the counter number may also be incorporated into the encryption system

[0067] 30 in a manner similar to that used by the Two Factor Authentication Handler.

[0068] The communication between the authenticator 10 and the supplicant 20 can be carried out using various methods, such as direct electrical contact between conductors, inductive coupling, wireless technologies like Bluetooth or near field contact (NFC), or light transmissions using infra-red or other suitable electromagnetic frequency ranges.

[0069] The described system allows for secure and robust authentication of devices, with the flexibility to be implemented in a wide range of applications and environments.

[0070] The encryption system 30 is illustrated in FIGS. 2, 5, 7, and 10 describes the components and methods necessary to transform a random input word 31 into a secure output codeword 32. FIG. 9 shows a firmware / software program flowchart for implementation of the basic encryption system 30.

[0071] Referring to FIG. 2, the encryption system 30 is shown in a block diagram. The encryption system 30 includes several key components: an input word 31 , multiple encryption keys, and a Linear Feedback Shift Register (LFSR) module. The input word 31 is the initial data that is to be encrypted. In some aspects, the input word

[0072] 31 may be a random number generated by a random number generator, such as the random number generator 11 in the authenticator 10. In other cases, the input word 31 may be a pseudorandom number generated by a pseudorandom number generator.

[0073] The encryption keys 50 used in the encryption system 30 include a shift register encryption key 51 , a generator encryption key 52, and an output encryption key 53. The encryption keys 50 would normally be randomly selected by the manufacturer, and in some cases tested for short runs to ensure the outputs are as random as possible. These encryption keys are used to obfuscate the input word 31 and the output of the LFSR module, thereby enhancing the security of the encryption process. The shift register encryption key 51 and the generator encryption key 52 are applied to the input word 31 to generate a shift register polynomial 41 and a generator polynomial 42, respectively. These polynomials are then used in the LFSR module to generate an output polynomial 43.

[0074] The LFSR module is a key component of the encryption system 30. The LFSR module can be implemented in various ways, such as in a Fibonacci configuration or a Galois configuration, as illustrated in FIGS. 3 and 4, depending on the specific requirements of the application. Although there are no figures specifically illustrating the Galois implementation, it is to be noted that the Galois is likely the preferred implementation of the system in software at least. However, the operation of both implementations is the same, given the exact same connections are made, though the output words will be different. This should be obvious to someone with ordinary skill in the art.

[0075] The LFSR module operates by shifting the shift register polynomial 41 through the LFSR. After being shifted through the LFSR 40 for one complete cycle, that is when the number of shifts equals the order (k) of the system, the output polynomial 43 is obtained. The order, denoted k, of the system is the number of stages of the LFSR 40. Thus, k=512 will result in a 512-bit system with 512 shift registers, and would therefore accept a 512-bit random input word 31 and output a 512-bit output codeword 32. FIGS. 5 and 7 show the encryption system 30 in more detail, noting that the shift register contents at initialization are shown as the input polynomial 41 , whilst the shift register contents after k shifts is shown as the output polynomial 43.

[0076] After the output polynomial 43 is generated by the LFSR module, it is further obfuscated using the output encryption key 53. This final obfuscation step transforms the output polynomial 43 into a secure output codeword 32. The output codeword 32 is the final output of the encryption system 30 and represents the encrypted version of the original input word 31 .

[0077] In contrast to the embodiments of the present disclosure, prior art authentication systems have a fixed order, determined by the particular algorithm or method used to generate the secure codeword. Changing (increasing) the order of such systems may be difficult, or even impossible, depending on the particular authentication system. The present embodiments can easily increase their order, by simply increasing the number of stages in the encryption system 30.

[0078] A potential problem for certain prior art authentication systems is the so-called RollBack attack. The system for locking and unlocking cars remotely is called Remote Keyless Entry (RKE), and such systems tend to rely on a rolling code which changes after each key press, preventing an attacker from simply replaying a previously transmitted code. However, the rolling code systems have to synchronise between authenticator (vehicle) and supplicant (key fob), which is achieved using counters. If some key fob transmissions do not make it to the vehicle, the key fob counter will be increased, but not the vehicle's counter. If the RKE system deals with this by resetting to the lower counter number, then an attacker can potentially unlock the vehicle, since the reset system assumes that as long as the counter number on the fob is higher than the vehicle, it can't be a replay attack. But this means that codes captured before the reset occurred, and which never made it to the car, would be accepted in the RollBack attack. If the counters are not reset, the result could be that the key fob is locked out and will not work to unlock the vehicle.

[0079] Both of the aforementioned potential problems are eliminated using the present embodiments, since no synchronisation is required, and the chance an attacker will come across two or more equal random words is considered impossible, given the order (k) of the system is high enough.

[0080] Other, potentially more serious, attacks can be carried out on prior art authentication systems which use a ‘secret key’, such as the Keeloq cipher which is commonly used in authenticating vehicle remote controls. Various attacks, such as brute force, which may be combined with other methods, for example slide- algebraic or side channel attacks (SCA), can be employed to recover the secret key, thus breaking the system. Some of the prior art Keeloq system use a serial number, or part thereof, to seed the system making cryptographic analysis trivial. Those Keeloq systems which use a randomly generated seed, are the most secure, but can still be cracked using various methods, some of which are mentioned above.

[0081] The encryption system 30 does not share keys between different supplicants, so if a single supplicant’s key was cracked, it would not affect the security of other supplicants. Whilst it is not thought possible that the keys could be cryptographically retrieved using known methods, a brute force attack could be carried out to obtain all possible input word 31 / output codeword 32 pairs. Such an attack could be rendered essentially useless, by increasing the order of the encryption system 30. For example, a 1 Kb system, if sampled at 1 ps, would require 5.7E294 years to iterate all possible input words.

[0082] It is well known that side-channel attacks on hardware systems become much more difficult as the number of stages increases. The encryption system 30 will always have many more stages than prior art systems.

[0083] In some cases, the encryption system 30 may also include additional components or features to further enhance the security of the encryption process. For example, the system may include a mechanism for handling invalid numbers, such as an invalid number handler authenticator 34 in the authenticator 10 or an invalid number handler supplicant 35 in the supplicant 20, as mentioned before and explained in more detail later. These components can check the shift register polynomial 41 and the output codeword 32 for certain undesirable conditions, and adjust them as necessary e.g. to avoid generation of so-called "catastrophic codes" as output codewords 32, which are present in much greater numbers than would be expected if they were random. In general, for the encryption system 30 under consideration, the only two catastrophic codes of interest are all zeros or all ones. It should be known to those conversant with the art that an LFSR will only output a zero word 43 if the input word 41 is zero. However, this only holds if the generator polynomial constant (go) of the generator polynomial 42 is one, as is always the case in prior art LFSRs as seen in FIGS. 3 and 4. In contrast, for the LFSR 40 encryption system 30 under consideration, the generator polynomial constant (go) is determined by an input bit, as shown in FIGS. 5 and 7, according to the mapping carried out by the generator encryption key 52. In this case, go will be set to zero in half of all possible input words 31 , which will result in the possibility of all zero outputs. Outputs consisting of all ones cannot be predicted, and should also preferably be handled.

[0084] The invalid number handlers 34 / 35 can deal with these situations by checking the shift register contents at initialisation, and thereafter at each shift. If the shift register polynomial 41 equals zero, then a one is inputted into the highest order shift register. Conversely, if each bit in the shift register word 41 equals one, a zero is inputted into the highest order shift register. FIG. 9 shows these operations in a flowchart, whilst FIG. 7 shows their implementation using logic gates. It can be seen in FIG. 7 that if all inputs to the NOR gate 101 are zero, it will output a one which is used to Set the highest order shift register, after which it will contain one. If, on the other hand, all inputs to the AND gate 100 are one, it will output a one to clear the highest order shift register, after which it will contain zero.

[0085] Referring back to FIG. 2, the final stages of the encryption process involve the transformation of the output polynomial 43 into the output codeword 32. This transformation is achieved by obfuscating the output polynomial 43 using an output encryption key 53. The output encryption key 53, like the shift register encryption key 51 and the generator encryption key 52, may comprise a polarity key 54 and a position key 55. The polarity key 54 selectively inverts the bits of the output polynomial 43, while the position key 55 maps the resulting bits to their final positions in the output codeword 32.

[0086] In some aspects, the output encryption key 53, similar to the rest of the encryption keys 50 used in the encryption system 30, may be randomly generated and stored securely within the authenticator 10 and the supplicant 20. The output encryption key 53 may be unique to each pair of authenticator 10 and supplicant 20, thereby enhancing the security of the authentication process.

[0087] The output codeword 32, which is the final output of the encryption system 30, represents the encrypted version of the original input word 31. The output codeword 32 is used for device authentication. In some cases, the output codeword 32 may be transmitted from the supplicant 20 to the authenticator 10, where it is compared with the expected codeword generated by the authenticator 10. If the received codeword matches the expected codeword, the supplicant 20 is authenticated and access to the protected system or resource is granted.

[0088] There are two methods of implementing the LFSR, the Fibonacci implementation shown in FIG. 3 and the Galois implementation shown in FIG. 4. Either of these two forms may be used in the present encryption system 30, though the Fibonacci form is generally used herein as it is easier to illustrate in the figures than the Galois form.

[0089] Both LFSR 40 operates by shifting data through the registers from left to right. At each clock cycle, the contents of each register are moved to the next register in sequence. The feedback paths create new input bits based on the XOR combination of selected register outputs called ‘taps’, as determined by the generator polynomial.

[0090] Referring now to FIG. 3, the generator polynomial is fully realized and each stage is fed back to the modulo 2 adders. Equivalently stated, each bit in the generator word is set to one. This would be unlikely to happen in prior art LFSRs where k>2, since the object is often to produce maximal length generator polynomials which will output all 2k-1 states. The '-T in the preceding equation accounts for the disallowed state when all k bits are zero. The maximal length generator polynomials will (for k>2) require at least one generator coefficient to be turned off. It can also be seen that the generator polynomial constant T means the feedback from the lowest order stage (go) is always allowed. Similarly, the highest order polynomial (gm) is always one, since this allows the output of the modulo 2 adders to be fed back into the LFSR.

[0091] A common prior art use of the LFSR is in making maximal length pseudorandom generators, which after seeding, or initializing, the shift register stages, the LFSR runs continually while producing all possible non-zero outputs. The output words thus produced have excellent random properties, however they are not cryptographically secure, since the generator polynomial can be retrieved using the Berlekamp-Massey algorithm, or derivatives thereof. The Berlekamp-Massey algorithm needs 2*k (where k is the order) consecutive output bits, in order to derive the generator polynomial.

[0092] Referring to FIG. 4, the Galois-configured Linear Feedback Shift Register (LFSR) 40 is depicted. In some aspects, the Galois configuration of the LFSR 40 may be preferred over the Fibonacci configuration, as shown in FIG. 3, due to its efficiency in both hardware as well as software and firmware implementations.

[0093] Referring to FIG. 5, the encryption system 30 is shown in a more detailed block diagram. The encryption system 30 includes an input word 31 , a shift register encryption key 51 , a generator encryption key 52, a Linear Feedback Shift Register (LFSR) 40, an output encryption key 53, and an output codeword 32.

[0094] As described before, the input word 31 is the initial data that is to be encrypted. In some aspects, the input word 31 may be a random number generated by a random number generator, such as the random number generator 11 in the authenticator 10. In other cases, the input word 31 may be an encrypted pseudorandom number generated by a pseudorandom number generator such as in the form shown in FIG 11 . The shift register encryption key 51 and the generator encryption key 52 are applied to the input word 31 to generate a shift register polynomial 41 and a generator polynomial 42, respectively. These polynomials are then used in the LFSR 40 to generate an output polynomial 43.

[0095] The LFSR 40 is a key component of the encryption system 30. The LFSR 40 can be implemented in various ways, such as in a Fibonacci configuration or a Galois configuration, depending on the specific requirements of the application. The LFSR 40 operates by shifting data through the registers from left to right. At each clock cycle, the contents of each register are moved to the next register in sequence. The feedback paths create new input bits based on the XOR combination of selected register outputs, as determined by the generator polynomial.

[0096] As depicted in FIG. 5, LFSR 40 of the encryption system 30 according to the disclosure does not directly output the initialization bits, as is generally the case in prior art. In contrast, the initialization bits (x?...xo) are fed back via the taps to the modulo- 2 adders, as is the case in prior art implementations; however, unlike the prior art forms shown in FIG. 3 and 4, the initialization bits are not directly outputted, rather they are discarded. Another difference with the forms shown in FIGS. 3 and 4 is that the generator polynomial constant (go) is controlled by the input word, instead of always being set to one. This is explained in more detail in the sections regarding the encryption system 30.

[0097] When implemented in the encryption system 30, the generator polynomial will change according to the input word 31 , meaning it will be impossible to obtain the 2*k consecutive output bits necessary for the Berlekamp-Massey algorithm to work. Furthermore, the Berlekamp-Massey algorithm requires access to the output of the LFSR, whereas the encryption system 30 obfuscates the LFSR output via the output encryption key 53.

[0098] Both prior art LFSRs and the encryption system 30, may use the XNOR function instead of the XOR, with corresponding inversion in logic.

[0099] After the output polynomial 43 is generated by the LFSR 40, it is further obfuscated using the output encryption key 53. This final obfuscation step transforms the output polynomial 43 into a secure output codeword 32. The output codeword 32 is the final output of the encryption system 30 and represents the encrypted version of the original input word 31 .

[0100] In some aspects, the encryption system 30 may also include additional components or features to further enhance the security of the encryption process. For example, the system may include a mechanism for handling invalid numbers. These components can check the shift register polynomial 41 and the output codeword 32 for certain undesirable conditions, and adjust them as necessary to avoid generation of so-called "catastrophic codes" as output codewords 32, which are present in much greater numbers than would be expected if they were random.

[0101] In conjunction with the LFSR 40, three encryption keys 50 are used to create an output codeword 32. The three keys are named herein as shift register encryption key 51 , generator encryption key 52 and output encryption key 53. For the purposes of describing the function of the encryption keys, the word 'obfuscate' is used to define the combined action of the two specified methods employed by the encryption keys. The first of the aforementioned methods is to change the position of the bits between the input and output words, which will be referred to herein as 'mapping'. The second method either inverts the bit or not, and will be referred to as 'polarity'. Noting that the order of operation in which the mapping key 55 and polarity key 54 are applied is irrelevant, though of course should be similar for both authenticator 10 and supplicant 20. Together, when applied to an input word, the mapping and polarity keys will output an obfuscated word.

[0102] FIG. 6 shows a block diagram for each of the encryption keys, and their resultant action on the specified input. Both the shift register encryption key 51 and generator encryption key 52 act on the input word (m) 31 . As an example, the shift register encryption key 51 first inverts the input word 31 according to the polarity key 54 which in FIG. 6 is the word 10010011. If the particular bit of the polarity key is a one, then the corresponding message bit is inverted, which is shown pictorially by a bar over the bit designation. Therefore, for example, the lowest message bit mo is inverted and mo is shown with a bar over it in FIG. 6. If a polarity key bit is zero the corresponding message bit is not inverted, for example m2 which passes through the polarity key without inversion. Noting that this could be inverted such that it is a zero which causes a polarity inversion and a one allows pass through with no change. The resulting word outputted by the polarity key is then mapped to its final position in the output word, which for the shift register encryption key 51 is the shift register input(x) 41 , using the position key 55. FIG. 6 uses arrows to depict this mapping, for example the inverted lowest order message bit mo is mapped to output bit X3.

[0103] Similarly, the generator encryption key 52 obfuscates the input message word (m) 31 , resulting in the generator polynomial 42. Using the key 52 in FIG. 6, it can be seen that the lowest generator bit (go) is controlled by the inverse of message bit one, mi . Likewise, the generator bit g4 is set the same as the value of message bit, m 7. The output encryption key 53 then takes the shift register output 43 as the input, and outputs the output codeword 32. If implemented in firmware / software each position key 55 will require k*log2(k) bits of memory, whilst the polarity key 54 will use k bits of memory. For k=512 bits, this translates to 4. 608e+3 bits per position key, giving a total of 5. 12e+3 bits per encryption key. If implemented in hardware, the connections and inversions will be physically made, and so require no memory storage.

[0104] The encryption keys can be randomly created by the manufacturer, and randomness tests could be performed on the resultant system by inputting incremental input message words 31 , in order to eliminate key combinations returning the most deterministic pattern of output codewords 32.

[0105] Referring to FIG. 7, the encryption system 30 is shown with the implementation of the LFSR 40 and the invalid number handlers 34 / 35 using logic gates. The invalid number handlers 34 / 35 are designed to handle certain undesirable conditions that may arise during the operation of the LFSR 40.

[0106] If all inputs to the NOR gate 101 are zero, it will output a one which is used to Set the highest order shift register, after which it will contain one. If, on the other hand, all inputs to the AND gate 100 are one, it will output a one to Clear the highest order shift register, after which it will contain zero.

[0107] This mechanism of handling invalid numbers enhances the security of the encryption process by ensuring that the output codeword 32 does not consist of all zeros or all ones. This further obfuscates the output codeword 32, making it more difficult for potential attackers to reverse-engineer the original input word 31 or predict the output codeword 32.

[0108] Referring to FIG. 8, the flowchart illustrates an authentication process involving an Authenticator 10 and a Supplicant 20. The process begins with the Authenticator 10 waiting to receive a request. Depending on the embodiment, the request may contain ID and / or control data, as determined by the ID and Data Handler 15, which could be used by the authenticator 10 to determine the correct encryption keys 50 as shown in FIG. 6, given multiple supplicants are supported. If no ID data are used, then the authenticator 10 would have to run the subsequently received codeword 32 through the encryption system 30 as shown in FIG. 2, for each possible set of encryption keys 50 as utilized by the multiple supplicants, in order to determine if a valid codeword 32 was received. In cases where the device has just one function, i.e. opening a garage door, a specific ID does not have to be sent with the request, and neither control data, it is only necessary for the supplicant 20 to send some type of request so the authenticator 10 knows to send the random number.

[0109] If no request is received, the Authenticator 10 continues to wait. Upon receiving the request, the Authenticator 10 generates a random message and inputs it into an encryption system 30. The process checks if the generated word is invalid. If valid, the random message is transmitted.

[0110] In some aspects, the Authenticator 10 may be a device such as a computer or a remote keyless entry (RKE) system. The Authenticator 10 may be configured to generate a random message using a random number generator 11 . The generated random message then serves as the input word 31 for the encryption system 30.

[0111] The encryption system 30 of the Authenticator 10 processes the input word 31 to generate an output codeword 32. This involves obfuscating the input word 31 using a shift register encryption key 51 and a generator encryption key 52 to obtain a shift register polynomial 41 and a generator polynomial 42, respectively. These polynomials are then processed through a Linear Feedback Shift Register (LFSR) 40 to obtain an output polynomial 43. The output polynomial 43 is further obfuscated using an output encryption key 53 to produce the output codeword 32, as described before.

[0112] The Authenticator 10 transmits the random message to the Supplicant 20 using a transmitter 13. The random message will not be transmitted until it had successfully passed through the encryption system 30. The transmitter 13 may use various methods for transmitting the random message, such as direct electrical contact, inductive coupling, wireless technologies like Bluetooth or near field contact (NFC), or light transmissions using infra-red or other suitable electromagnetic frequency ranges. The Authenticator 10 also stores the codeword outputted from the encryption system 30. A timeout check is performed. If no timeout occurs, the Authenticator 10 waits to receive a codeword.

[0113] Upon receiving a response codeword from the Supplicant 20, the Authenticator 10 compares the response codeword with the stored output codeword 32 using a compare codewords 16 module. If the response codeword matches the stored output codeword 32, the Supplicant 20 is authenticated and access to the protected system or resource is granted. If the response codeword does not match the stored output codeword 32, the system remains locked.

[0114] Referring to FIG. 8, the flowchart illustrates the steps performed by the Supplicant 20 in the authentication process. The process begins with the Supplicant 20 transmitting a request to the Authenticator 10. The request may include identification or control data, depending on the specific requirements of the authentication process. In some cases, the Supplicant 20 may transmit a simple request signal to initiate the authentication process.

[0115] Upon transmitting the request, the Supplicant 20 enters a waiting state to receive a random message from the Authenticator 10. The random message is received by the receiver 23 of the Supplicant 20. The receiver 23 may use various methods for receiving the random message, such as direct electrical contact, inductive coupling, wireless technologies like Bluetooth or near field contact (NFC), or light transmissions using infra-red or other suitable electromagnetic frequency ranges.

[0116] Once the random message is received, it is processed by the second encryption system 30 of the Supplicant 20. The received random message serves as the input word 31 for the encryption system 30. The encryption system 30 obfuscates the input word 31 using a shift register encryption key 51 and a generator encryption key 52 to obtain a shift register polynomial 41 and a generator polynomial 42, respectively. These polynomials are then processed through a Linear Feedback Shift Register (LFSR) 40 to obtain an output polynomial 43. The output polynomial 43 is further obfuscated using an output encryption key 53 to produce a response codeword. In some aspects, the Supplicant 20 may also include an invalid number handler supplicant 35. This component checks the response codeword and, if necessary, adjusts it to avoid certain undesirable conditions, such as all bits being zero or all bits being one. In general, this would only be necessary in case of an attack, since the authenticator 10 would never send out a random word which would cause such an output. This additional layer of processing enhances the security of the authentication process by further obfuscating the response codeword.

[0117] Once the response codeword is generated, it is transmitted back to the Authenticator 10 using the transmitter 22 of the Supplicant 20. The transmitter 22 may use various methods for transmitting the response codeword, such as direct electrical contact, inductive coupling, wireless technologies like Bluetooth or near field contact (NFC), or light transmissions using infra-red or other suitable electromagnetic frequency ranges.

[0118] In some cases, the Supplicant 20 may also transmit additional data along with the response codeword. This additional data may include information related to specific functions that may be performed by the Authenticator 10, such as starting a vehicle engine or opening a door. This data is managed by the ID and Data Handler 25 of the Supplicant 20.

[0119] In some aspects, the Authenticator 10 is configured to compare the response codeword with the output codeword 32 by a compare codewords 16 module within the Authenticator 10. The compare codewords 16 module may use various methods for comparing the codewords, such as bitwise comparison or other suitable comparison methods. If the response codeword matches the output codeword 32, the Supplicant 20 is authenticated and access to the protected system or resource is granted. If the response codeword does not match the output codeword 32, the system remains locked.

[0120] FIG. 9 shows a software program flowchart, with generally corresponding block diagrams in FIG. 2, FIG. 5 and FIG. 7. The process begins with the input word 31 , which may be a random number generated by a random number generator, such as the random number generator 11 in the authenticator 10. The input word 31 is then processed by two encryption keys: a shift register encryption key 51 and a generator encryption key 52. The shift register encryption key 51 obfuscates the input word 31 to obtain a shift register polynomial 41 , while the generator encryption key 52 obfuscates the input word 31 to obtain a generator polynomial 42.

[0121] In some aspects, the generator polynomial 42 undergoes a circular shift 33 based on information derived from the input word 31 prior to shifting the shift register polynomial 41 through the LFSR 40. The function of generator polynomial shifting 33 may be employed in various embodiments for the purpose of further 'randomizing' the outputs from the LFSR 40. Specifically, a certain percentage of key combinations will fail the general randomness tests with very low p values, indicating a deterministic pattern. This is not thought to be problematic, since any such non- randomness will not help an attacker retrieve the encryption keys 50, else be able to predict the output code 32 for a given input 31 . Nonetheless, the p values can be exponentially increased, indicating a much less deterministic pattern, by shifting the generator polynomial 42 in one direction according to information derived from the input word 31. Such information may be the number of ones in the input message 31 , as also shown in the flowchart of FIG. 9. For an illustrative, but not practical, example the eight-bit input number 31 11001000 would circularly right shift the generator polynomial 42 by three bits. In this aspect, other deterministic information from the input word 31 could be used to determine the number of shifts, such as number of zeros in the input word 31 .

[0122] The shift register polynomial 41 and the generator polynomial 42 are then processed through the LFSR 40. As can be seen in FIG. 9, in the illustrated embodiment this means that the shift register polynomial 41 and the generator polynomial 42 are bitwise multiplied, using a AND operation or equivalent. The resulting word from the aforementioned operation is modulo-2 added, using a XOR operation or equivalent, which results in a single bit which is stored. The shift register contents are then bitwise shifted, causing the lowest shift register bit to be discarded, whilst the stored bit from the modulo-2 addition is added to the highest order bit of the shift register. These operations are repeated k times, where k is the order of the system, after which the highest order initialization bit x7 (FIG. 5) will have shifted through the shift register and been discarded after the last shift operation. The contents of the shift register 41 , are finally obfuscated using the output encryption key 53.

[0123] In some cases, the shift register polynomial 41 is checked at initialization and after each shift. This may be performed by an invalid number handler supplicant 35 in the supplicant 20. If all bits in the shift register polynomial 41 are zero, a one is inputted into the highest order bit of the shift register polynomial 41 . Conversely, if all bits in the shift register polynomial 41 are one, a zero is inputted into the highest order bit of the shift register polynomial 41. This mechanism for handling invalid numbers enhances the security of the encryption process by ensuring that the output polynomial 43 does not consist of all zeros or all ones.

[0124] Referring back to FIG. 9, the flowchart further illustrates the invalid number handling processes and the final stages of the encryption system 30. The invalid number handling processes are designed to handle certain undesirable conditions that may arise during the operation of the LFSR 40. These conditions include situations where all bits in the shift register polynomial 41 are zero or all bits are one.

[0125] In some aspects, if all bits in the shift register polynomial 41 are zero, a one is inputted into the highest order bit of the shift register polynomial 41. This adjustment ensures that the shift register polynomial 41 does not consist of all zeros, which could potentially compromise the security of the encryption process.

[0126] Conversely, if all bits in the shift register polynomial 41 are one, a zero is inputted into the highest order bit of the shift register polynomial 41. This adjustment ensures that the shift register polynomial 41 does not consist of all ones, which could also potentially compromise the security of the encryption process.

[0127] The output codeword 32 is also checked for certain undesirable conditions. Specifically, if the output codeword 32 is all zeros or all ones, it is rejected and a new input word 31 is generated. This mechanism for handling invalid numbers enhances the security of the encryption process by ensuring that the output codeword 32 does not consist of all zeros or all ones.

[0128] In some cases, the authenticator 10 is configured to process the random message through the first encryption system 30 as an input word 31 to generate an output codeword 32. The authenticator 10 may use various methods for processing the random message, such as bitwise operations, modulo-2 addition, and obfuscation using encryption keys. The output codeword 32 represents the encrypted version of the original random message.

[0129] Similarly, the supplicant 20 is configured to process the received random message through the second encryption system 30 as an input word 31 to generate a response codeword. The supplicant 20 may use various methods for processing the received random message, such as bitwise operations, modulo-2 addition, and obfuscation using encryption keys. The response codeword represents the encrypted version of the received random message.

[0130] Referring to FIG. 10, a hardware implementation of the Fibonacci configured Linear Feedback Shift Register (LFSR) circuit is depicted. The encryption keys 51 and 52 shown in FIG. 6 are used in FIG. 10, and it can be seen that the lowest order shift register, in this example a D Type Flip Flop 106, is initialized according to the value of the input word 31 at position five, shown as ms in FIG 10. If this value is one, the shift register is set to one, if the value is zero, the shift register is cleared to zero. The corresponding lowest order generator bit, go, is set according to the inverse of message bit one, mi . The inverse function is performed by a NOT gate 105. After initialization, the contents of the flip flops 106 are shifted to the right, as controlled by the clock generator 107, and the contents of the lowest order flip flop is discarded. The outputs from the AND gates 100 are modulo-2 added using XOR gates 103, and the bit result fed back into the highest order flip flop x?. After k shifts, the flip flops will contain the output word 43. The final obfuscation using encryption key 53 is not shown in FIG. 10.

[0131] This circuit configuration allows for the implementation of the encryption system described in the invention, where the LFSR is used in conjunction with encryption keys to generate output codewords from input words. In some aspects, the LFSR circuit may be implemented using other types of flip-flops or logic gates, depending on the specific requirements of the application.

[0132] Referring to FIG. 11 , an 8-bit PRNG 71 is shown, together with the generator polynomial necessary for creating a maximal length sequence. The pseudorandom number generator 71 includes multiple stages, labeled xi through xs, connected in series. Feedback connections are shown from stages xs, xe, xs, and X4 to XOR gates, implementing the generator polynomial xA8+xA6+xA5+xA4+1 . The output of the pseudorandom number generator 71 , labeled as Random Number 72, is then used as the input word 31 for the encryption system 30. The resulting output codeword 32 can then be considered an encrypted random number 73. Unlike the random outputs 72, the encrypted random numbers 73 will protect the system from being cracked using known algorithms such as the Berkely-Massey.

[0133] In some aspects, the PRNG Encryption System 70 may be used to secure the outputs of a pseudorandom number generator against algorithmic based cryptographic attacks. By applying the encryption system 30 to the output of the pseudorandom number generator 71 , the output can no longer be predicted, thereby enhancing the security of the generated random numbers.

[0134] In some cases, the PRNG Encryption System 70 may be implemented in a hardware device, such as an integrated circuit or a field-programmable gate array (FPGA). In other cases, the PRNG Encryption System 70 may be implemented in a software or firmware environment, using a digital signal processor (DSP) or a general-purpose processor. The specific implementation of the PRNG Encryption System 70 may depend on various factors, such as the order (k) of the system, the performance requirements of the application, the available resources, and the desired level of security.

[0135] Referring to FIG. 12, the authentication system comprises an authenticator 10 and a supplicant 20, both configured for one-way transmission authentication. The authenticator 10 includes a first encryption system 30, a counter 18, an invalid number handler authenticator 34, and a receiver 14. The supplicant 20 includes a second encryption system 30, a counter 26, an invalid number handler supplicant 35, and a transmitter 22.

[0136] In some aspects, the authenticator 10 is configured to generate an input word 31 using the counter 18. The counter 18 may be a digital counter that increments its count value at each clock cycle or upon receiving a specific signal. The count value from the counter 18 serves as the input word 31 for the first encryption system 30 in the authenticator 10.

[0137] The first encryption system 30 in the authenticator 10 processes the input word 31 to generate an output codeword 32. This involves obfuscating the input word 31 using a shift register encryption key 51 and a generator encryption key 52 to obtain a shift register polynomial 41 and a generator polynomial 42, respectively. The shift register polynomial 41 is then processed through a Linear Feedback Shift Register (LFSR) 40 using the generator polynomial 42 to obtain an output polynomial 43. The output polynomial 43 is further obfuscated using an output encryption key 53 to produce the output codeword 32.

[0138] The authenticator 10 is also configured to check the output codeword 32 using the invalid number handler authenticator 34. The invalid number handler authenticator 34 checks the output codeword 32 for certain undesirable conditions, such as all bits being zero or all bits being one. If the output codeword 32 is all zeros or all ones, it is rejected and a new input word 31 is generated.

[0139] On the other hand, the supplicant 20 is configured to generate an input word 31 using its counter 26. Similar to the counter 18 in the authenticator 10, the counter 26 in the supplicant 20 may be a digital counter that increments its count value after each operation or upon receiving a specific signal. The count value from the counter 26 serves as the input word 31 for the second encryption system 30 in the supplicant 20.

[0140] The second encryption system 30 in the supplicant 20 processes the input word 31 to generate a response codeword. This involves obfuscating the input word 31 using a shift register encryption key 51 and a generator encryption key 52 to obtain a shift register polynomial 41 and a generator polynomial 42, respectively. These polynomials are then processed through a Linear Feedback Shift Register (LFSR) 40 to obtain an output polynomial 43. The output polynomial 43 is further obfuscated using an output encryption key 53 to produce the response codeword.

[0141] The supplicant 20 is also configured to check the response codeword using the invalid number handler supplicant 35. The invalid number handler supplicant 35 checks the response codeword for certain undesirable conditions, such as all bits being zero or all bits being one. If the response codeword is all zeros or all ones, it is adjusted to avoid these conditions.

[0142] Once the response codeword is generated, it is transmitted back to the authenticator 10 using the transmitter 22 of the supplicant 20. The transmitter 22 may use various methods for transmitting the response codeword, such as direct electrical contact, inductive coupling, wireless technologies like Bluetooth or near field contact (NFC), or light transmissions using infra-red or other suitable electromagnetic frequency ranges.

[0143] Referring to FIG. 12, the authentication system is shown in a configuration that allows for one-way transmission from the supplicant 20 to the authenticator 10. In this configuration, the authenticator 10 includes a first encryption system 30, a counter 18, an invalid number handler authenticator 34, and a receiver 14. The supplicant 20 includes a second encryption system 30, a counter 26, an invalid number handler supplicant 35, and a transmitter 22.

[0144] In some aspects, the authenticator 10 is configured to generate an input word 31 using either the counter 18 or a counter value received from the supplicant 20. The counter 18 may be a digital counter that increments its count value at each operation. The count value obtained serves as the input word 31 for the first encryption system 30 in the authenticator 10.

[0145] The first encryption system 30 in the authenticator 10 processes the input word 31 to generate an output codeword 32. This involves obfuscating the input word 31 using a shift register encryption key 51 and a generator encryption key 52 to obtain a shift register polynomial 41 and a generator polynomial 42, respectively. These polynomials are then processed through a Linear Feedback Shift Register (LFSR) 40 to obtain an output polynomial 43. The output polynomial 43 is further obfuscated using an output encryption key 53 to produce the output codeword 32.

[0146] The authenticator 10 is also configured to check the output codeword 32 using the invalid number handler authenticator 34. The invalid number handler authenticator 34 checks the output codeword 32 for certain undesirable conditions, such as all bits being zero or all bits being one. If the output codeword 32 is all zeros or all ones, it is rejected and a new input word 31 is generated.

[0147] On the other hand, the supplicant 20 is configured to generate an input word 31 using its counter 26. Similar to the counter 18 in the authenticator 10, the counter 26 in the supplicant 20 may be a digital counter that increments its count value after each operation. The count value from the counter 26 serves as the input word 31 for the second encryption system 30 in the supplicant 20.

[0148] The second encryption system 30 in the supplicant 20 processes the input word 31 to generate a response codeword. This involves obfuscating the input word 31 using a shift register encryption key 51 and a generator encryption key 52 to obtain a shift register polynomial 41 and a generator polynomial 42, respectively. These polynomials are then processed through a Linear Feedback Shift Register (LFSR) 40 to obtain an output polynomial 43. The output polynomial 43 is further obfuscated using an output encryption key 53 to produce the response codeword.

[0149] The supplicant 20 is also configured to check the response codeword using the invalid number handler supplicant 35. The invalid number handler supplicant 35 checks the response codeword for certain undesirable conditions, such as all bits being zero or all bits being one. If the response codeword is all zeros or all ones, it is adjusted to avoid these conditions.

[0150] Once the response codeword is generated, it is transmitted back to the authenticator 10, optionally the supplicant 20 may also transmit its counter 26 value in plaintext, using the transmitter 22 of the supplicant 20. The transmitter 22 may use various methods for transmitting the response codeword, such as direct electrical contact, inductive coupling, wireless technologies like Bluetooth or near field contact (NFC), or light transmissions using infra-red or other suitable electromagnetic frequency ranges.

[0151] It should be understood that the descriptions and figures herein are meant as a guide for constructing the device on a number of different platforms, such as can be followed by those of ordinary skill in the art. Specifically, the System and Method for LFSR Based Authentication may be implemented in hardware, firmware or software, else a combination thereof.

[0152] In some aspects, the method for authenticating devices as described above may be implemented as a computer program product. The computer program product may comprise a computer-readable storage medium having computer-readable instructions stored thereon. The computer-readable instructions may be executable by a computerized device comprising a computer processor to cause the computerized device to perform the methods as described above. This includes receiving an input word 31 , obfuscating the input word 31 using multiple encryption keys 50 to obtain polynomials, shifting the shift register polynomial 41 through a Linear Feedback Shift Register (LFSR) 40 to obtain an output polynomial 43, obfuscating the output polynomial 43 using an output encryption key 53 to obtain an output codeword 32, and outputting the output codeword 32 for device authentication.

[0153] In some cases, the encryption system 30 may be implemented in hardware. This could involve the use of physical components such as logic gates, flip-flops, and other electronic components to perform the operations of the encryption system 30. For example, the LFSR 40 could be implemented using a series of flip-flops arranged in a shift register configuration, with feedback paths created using logic gates to implement the generator polynomial. Depending on various factors, especially the order (k) of the system, implementing certain embodiments in hardware may become overly complex. As an example, a 1024-bit system would need a method by which to implement the encryption keys 50 obfuscations. In this case, the position key 55 will result in k! (where k is the order of the system and '!' is the factorial operator) possible connections. For k=1 Kb, this would result in 5. 41A2639 possible connections per key. The encryption keys 50 could be implemented using physical connections and inversions made on a chip. For instance, the connections could be made using wire bonding to the chip or on-chip connections. In addition to the aforementioned position key 55, the input signal may be inverted according to the polarity key 54, which would require up to k inverter devices. However, it is important that these connections are hidden in such a way as to make them unobtainable from attacks aimed at discovering the encryption keys.

[0154] Peripheral components necessary to the working of the particular embodiments are largely omitted from this disclosure. For a hardware embodiment, these components may include, but are not limited to, the power supply, the clock signal generator required to provide a clocking pulse to the correct logic devices, such as the flip flop devices which comprise the shift register 45, as well as the logic devices themselves as would be known to those skilled in the art.

[0155] In other cases, the encryption system 30 may be implemented in firmware. This could involve the use of a microprocessor or similar device capable of executing binary code, together with memory storage capabilities for both the binary code and the encryption keys 50. The encryption keys 50 could be stored in non-volatile memory, which may reside on the microprocessor itself, or on a separate device such as an EEPROM.

[0156] In yet other cases, the encryption system 30 may be implemented in software. This could involve the use of a general-purpose computer processor to execute binary code, with the binary code and the encryption keys 50 stored on a disk or other storage medium. The encryption keys 50 could be stored in non-volatile memory, which may reside on the computer or device itself, or on removable memory such as a USB stick or similar.

[0157] In some aspects, the encryption keys 50 could be implemented using a combination of hardware, firmware, and software. For example, the encryption keys 50 could be stored in hardware or firmware, while the operations of the encryption system 30 are performed by software running on a computer processor. This could provide a balance between the security advantages of hardware or firmware implementations and the flexibility and ease of update provided by software implementations.

[0158] In some cases, the encryption keys 50 could be dynamically altered in both software and hardware implementations. This could involve the use of switching devices to implement the connections, such that the keys can be changed without physically altering the hardware. However, larger order systems would likely be too complex for dynamic switching. Therefore, the choice of implementation platform for the encryption keys 50 may depend on various factors, such as the order of the system, the specific requirements of the application, and the desired level of security.

[0159] In some aspects, the authenticator 10 and / or the supplicant 20 may include user interface elements, such as an LCD screen or similar display, to relay information to the user. For example, the LCD screen may display the status of the authentication process, error messages, or other relevant information. This could provide the user with real-time feedback about the operation of the authentication system, enhancing the user experience and facilitating troubleshooting.

[0160] Whichever of the technological platforms is chosen, the connections and mathematical operations necessary to implement the authentication system are equivalent.

[0161] In some cases, the authentication system may incorporate two-factor authentication data into the encryption process. Two-factor authentication is a security process in which the user provides two different authentication factors to verify themselves. This process is designed to provide an additional layer of security, reducing the risk of fraudulent access or data breaches.

[0162] The two-factor authentication handler will generally be implemented using the same platform as the encryption system 30, for example in hardware, firmware or software, else a combination thereof. In the context of the present disclosure, the two-factor authentication data could be incorporated into the encryption process by using the polarity key 54. For example, a Personal Identification Number (PIN) or other identification data could be directly XORed with the output codeword 32 by the supplicant 20 which, in the case of a PIN is usually a four-digit number, would need a keypad or similar in order to input the data. The authenticator 10 would perform the same operation, and given the PIN used by the authenticator 10 matches that used by the supplicant 20, the codewords will match, and the system will be unlocked.

[0163] Alternatively, the binary representation of the PIN or other two-factor authentication data could be either XORed with a polarity key 54, XORed with the output codeword 32, or used directly in the polarity key 54. This would allow the two-factor authentication data to be seamlessly integrated into the encryption process, enhancing the security of the authentication system without significantly increasing its complexity.

[0164] In some aspects, the two-factor authentication data could be entered by the user via a keypad or similar input device connected to the supplicant 20. The entered data would then be processed by the encryption system 30 in the supplicant 20, and the resulting output codeword 32 would be transmitted to the authenticator 10 for verification. This could provide a secure and user-friendly method for incorporating two-factor authentication into the authentication system.

[0165] It is to be appreciated that the concepts, systems, circuits and techniques sought to be protected herein are not limited to use in the example applications described herein (e.g., automotive or building access control), but rather may be useful in substantially any application where it is desired to authenticate devices or secure communications between devices. While particular embodiments and applications of the present disclosure have been illustrated and described in connection with remote keyless entry systems and computer login authentication, it is to be understood that embodiments of the disclosure are not limited to the precise construction and compositions disclosed herein and that various modifications, changes, and variations can be apparent from the foregoing descriptions without departing from the spirit and scope of the disclosure as defined in the appended claims. The authentication system and method described herein may find industrial application in a wide range of fields including, but not limited to, Internet of Things (loT) device authentication, financial transaction security, industrial control system access, healthcare device authentication, smart home security systems, and secure wireless communication protocols across various industries.

[0166] INDEX OF ELEMENTS

[0167] 10: Authenticator

[0168] 11 : Random Number Generator

[0169] 12: Repeat Random Number Handler

[0170] 13: Transmitter

[0171] 14: Receiver

[0172] 15: ID and Data Handler (authenticator)

[0173] 16: Compare Codewords

[0174] 17: Repeat Output Codeword Handler

[0175] 18: Counter

[0176] 20: Supplicant

[0177] 21 : Invalid Random Number Handler

[0178] 22: Transmitter

[0179] 23: Receiver

[0180] 24: Delay

[0181] 25: ID and Data Handler (supplicant)

[0182] 26: Counter

[0183] 30: Encryption System

[0184] 31 : Input Word (m)

[0185] 32: Output Codeword (c):

[0186] 33: Generator Polynomial Shifting

[0187] 34: Invalid Number Handler Authenticator : Invalid Number Handler Supplicant : Linear Feedback Shift Register : Shift Register Polynomial (x) : Generator Polynomial (g) : Output Polynomial (y) : Modulo 2 Addition : Shift Register : Encryption Keys : Shift Register Encryption Keys : Generator Encryption Keys : Output Encryption Keys : Polarity Key : Position Key : PRNG Encryption System : Maximal Length Pseudorandom Number Generator (PRNG): Random Number : Encrypted Random Number

Claims

CLAIMS1. A computer-implemented method for generating an encrypted codeword using an encryption system (30) for authenticating devices, the method comprising: receiving an input word (31 ); obfuscating the input word (31 ) using a shift register encryption key (51 ) to obtain a shift register polynomial (41 ), wherein the shift register polynomial (41 ) initializes a Linear Feedback Shift Register, LFSR, (40); obfuscating the input word (31 ) using a generator encryption key (52) to obtain a generator polynomial (42), determining feedback taps for the LFSR (40) based on the generator polynomial (42); shifting the shift register polynomial (41 ) through the LFSR (40) for at least one cycle using the feedback taps to obtain an output polynomial (43); obfuscating the output polynomial (43) using an output encryption key (53) to obtain an output codeword (32); and outputting the output codeword (32).

2. The method according to claim 1 , wherein at least one of the steps of obfuscating the input word (31 ) using the shift register encryption key (51 ), or obfuscating the input word (31 ) using the generator encryption key (52), or obfuscating the output polynomial (43) using the output encryption key (53) comprises the sub-steps of: selectively inverting the polarity of each bit of the input word (31 ) or the output polynomial (43) as applicable, based on corresponding bits of a polarity key (54); and mapping resulting bits to final positions based on corresponding position values of a position key (55) to obtain the shift register polynomial (41 ), the generator polynomial (42) or the output codeword (32) as applicable.

3. The method according to any one of claims 1 or 2, further comprising: circularly shifting the generator polynomial (42) based on information derived from the input word (31 ) prior to shifting the shift register polynomial (41 ) through the LFSR (40), such as circularly shifting the generator polynomial (42) by a number of bits equal to the number of ones or zeros in the input word (31 ).

4. The method according to any one of claims 1 to 3, wherein shifting the shift register polynomial (41 ) through a LFSR (40) comprises: bitwise multiplying the generator polynomial (42) with the shift register polynomial (41 ) to obtain a multiplied polynomial; performing a modulo-2 addition on the multiplied polynomial to obtain a single bit; bitwise shifting the contents of the shift register causing the lowest order bit to be discarded, and adding the single bit from the modulo-2 addition to the highest order bit; and repeating these operations k times, where k is the order of the system to obtain the output polynomial (43).

5. The method according to any one of claims 1 to 4, wherein the LFSR (40) is implemented in a Fibonacci configuration or a Galois configuration.

6. The method according to any one of claims 1 to 5, further comprising: checking the shift register polynomial (41 ) at initialization and after each shift, such as by using an invalid number handler supplicant (35); and if all bits in the shift register polynomial (41 ) are zero, inputting a one into the highest order bit of the shift register polynomial (41 ); orif all bits in the shift register polynomial (41 ) are one, inputting a zero into the highest order bit of the shift register polynomial (41 ).

7. The method according to any one of claims 1 to 6, further comprising: checking the output codeword (32), such as by using an invalid number handler authenticator (34); and if the output codeword (32) is all zeros or all ones, rejecting the output codeword (32) and generating a new input word (31 ).

8. A computer-implemented method for authenticating devices, wherein the method is performed by an authenticator (10) and a supplicant (20) and comprises: receiving by the authenticator (10) a request from a supplicant (20), the request preferably comprising at least one of an identification or control data; in response to the request, generating a random message by the authenticator (10); performing by the authenticator (10) a method according to any one of claims 1 to 7 using the generated random message as the input word (31 ) to generate and store an output codeword (32); transmitting by the authenticator (10) the random message to the supplicant (20); performing by the supplicant (20) a method according to any one of claims 1 to 7 using the received random message as the input word (31 ) to generate an output codeword (32); transmitting by the supplicant (20) the output codeword (32) to the authenticator (10) as a response codeword; comparing (16) by the authenticator (10) the response codeword with the stored output codeword (32); andinitiating by the authenticator (10) a preset action, such as an unlock procedure, if the response codeword matches the stored output codeword (32).

9. A computer-implemented method for generating encrypted random numbers using a PRNG Encryption System (70), the method comprising: generating a random number using a maximal length pseudorandom number generator (71 ); inputting the generated random number as an input word (31 ) into an encryption system (30); processing the input word (31 ) through the encryption system (30) to generate an output codeword (32) according to the method of any one of claims 1 to 7; and outputting the output codeword (32) as an encrypted random number (73).

10. A system for authenticating devices, comprising: an authenticator (10) comprising: a first encryption system (30); a random number generator (11 ); a first transmitter (13); and a first receiver (14); a supplicant (20) comprising: a second encryption system (30) corresponding to the first encryption system (30); a second transmitter (22); and a second receiver (23); wherein the authenticator (10) is configured to: generate a random message using the random number generator (11 );process the random message through the first encryption system (30) as an input word (31 ) to generate an output codeword (32) according to the method of any one of claims 1 to 7; transmit the random message to the supplicant (20) using the first transmitter (13); receive a response codeword from the supplicant (20) using the first receiver (14); and compare (16) the response codeword with the output codeword (32); and wherein the supplicant (20) is configured to: receive the random message from the authenticator (10) using the second receiver (23); process the received random message through the second encryption system (30) as an input word (31 ) to generate the response codeword according to the method of any one of claims 1 to 7; and transmit the response codeword to the authenticator (10) using the second transmitter (22).11 . A system for authenticating devices, comprising: an authenticator (10) comprising: a first encryption system (30); a first counter (18); an invalid number handler authenticator (34); a first receiver (14); and a supplicant (20) comprising: a second encryption system (30); a second counter (26); an invalid number handler supplicant (35);a second transmitter (22); wherein the supplicant (20) is configured to: generate an input word (31 ) using the second counter (26); process the input word (31 ) through the second encryption system (30) to generate a response codeword according to the method of any one of claims 1 to 7; check the response codeword using the invalid number handler supplicant (35); and transmit the response codeword to the authenticator (10) using the second transmitter (22), optionally also transmitting the value of the second counter (26) in order to synchronise with the first counter (18); and wherein the authenticator (10) is configured to: receive the response codeword, with the optional value of the second counter (26), from the supplicant (20) using the first receiver (14); generate an input word (31 ) using either the value of the first counter (18) or the second counter (26) received by the supplicant (20); process the input word (31 ) through the first encryption system (30) to generate an output codeword (32) according to the method of any one of claims 1 to 7; and compare (16) the response codeword with the output codeword (32); wherein if the first counter (18) was used for generating the input word (31 ), the authenticator (10) is further configured to increment the first counter (18) if the compare operation (16) fails.

12. A computer program product comprising a computer-readable storage medium having computer-readable instructions stored thereon, the computer-readable instructions being executable by a computerized device comprising a computerprocessor to cause the computerized device to perform the method of any one of claims 1 to 9.

Citation Information

Patent Citations

  • Methods and apparatus for keystream generation

    EP1232603A2

  • Pseudorandom number generator and pseudorandom number generation program

    US20070174374A1

  • Linear feedback shift register (LFSR)

    US20140258721A1

  • Tamper detector with hardware-based random number generator

    US20160026829A1

  • Cryptographic processing device and cryptographic processing method

    US20160173275A1