Cipher Structure Resistance Evaluation Method

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for evaluating and optimizing cipher structures in terms of resistance to differential and linear cryptanalysis, particularly for those using differently-sized substitution boxes, as existing methods lack efficiency and effectiveness in assessing their cryptographic strength.

Innovation Solution

A method and apparatus for evaluating resistance to differential and linear cryptanalysis by determining the generalized minimum number of non-zero symbols in a diffusion element, dividing the input into subset inputs, calculating the maximum differential or linear characteristic probability using specific equations, and selecting transformations or confusion elements to enhance resistance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If differently-sized S-boxes are used in a cipher structure, then cryptographic strength may be improved, but the ability to evaluate resistance to differential and linear cryptanalysis becomes insufficient

Engineering Contradiction:
Improveresistance to differential and linear cryptanalysisVSAvoidevaluation technique complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the evaluation process by dividing the cipher structure into diffusion elements and confusion elements, and further dividing the input into subset inputs corresponding to each confusion element. This segmentation allows the complex evaluation of differently-sized S-boxes to be broken down into manageable calculations of generalized minimum numbers and subset numbers, making the evaluation feasible while maintaining comprehensive cryptographic analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces new evaluation parameters including the generalized minimum number NG of non-zero symbols, subset numbers NSi for each subset input, and the derived quantity NW = NG - SN. These parameters transform the complex cryptographic evaluation into systematic calculations that can assess resistance to differential and linear cryptanalysis for differently-sized S-boxes in a structured manner.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If identically-sized S-boxes are used, then design simplicity is maintained, but cryptographic optimization for differently-sized S-boxes cannot be achieved

Engineering Contradiction:
Improvedesign simplicityVSAvoidcryptographic strength
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent enables the evaluation and optimization of differently-sized S-boxes by introducing the generalized minimum number NG and subset numbers NSi as calculable parameters. These parameters allow cryptographers to systematically assess and compare different S-box configurations, making it possible to optimize cryptographic strength while maintaining design feasibility through structured evaluation procedures.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8098816B2Apparatus and method for evaluating a cipher structure's resistance to cryptanalysis
Publication Date: 2012.01.17 QUALCOMM INC
  • US8098816B2 patent drawing
  • US8098816B2 patent drawing
  • US8098816B2 patent drawing

AI summary

Disclosed is a method for evaluating resistance to cryptanalysis of a cipher structure having a diffusion element including a linear transformation placed between differently-sized confusion elements at an input and an output of the diffusion element. A generalized minimum number of non-zero symbols at the diffusion element's input and output is determined. The diffusion element's input is divided into subset inputs, each having a size corresponding to the size of each confusion element at the diffusion element input. For each subset input, a subset number of non-zero symbols at the subset input and the diffusion element output is determined. Each subset number is summed to generate a summed subset number. The summed subset number is subtracted from the generalized minimum number to generate a worst-case number. An upper bound of a maximum differential characteristic probability is calculated and used to evaluate the cipher structure.