Cryptographic Apparatus Using Round-Dependent MDS Matrices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional common key block encryption algorithms, such as DES, are vulnerable to differential analysis attacks due to the use of the same linear conversion matrix in each round, making key analysis easy and security low.

Innovation Solution

Implementing a Feistel type common key block encryption process with an SPN type F function that uses different MDS matrices for each round, specifically for both odd and even rounds, to perform nonlinear and linear conversion processes, thereby increasing the difficulty of key analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If the same linear conversion matrix is used in each round of the encryption process, then the device complexity is reduced and ease of manufacture is improved, but the security against differential analysis attacks deteriorates

Engineering Contradiction:
Improveease of implementing encryption algorithmVSAvoidsecurity against differential analysis
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent changes the parameter of the linear conversion matrix from being identical across all rounds to being different for each round. Specifically, it uses different MDS matrices for odd and even rounds, which fundamentally alters the encryption process to resist differential analysis while maintaining implementation feasibility through systematic matrix selection

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the encryption rounds into odd and even groups, applying different MDS matrices to each segment. This segmentation approach allows the system to use multiple matrices in a structured way, improving security without requiring complete reimplementation of the encryption algorithm

Inventive Principle:
Principle #1Segmentation

2Reliability

If different MDS matrices are used for each round of the encryption process, then the robustness against differential analysis is improved, but the device complexity increases

Engineering Contradiction:
Improverobustness against differential analysisVSAvoidcomplexity of encryption algorithm
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent modifies the encryption algorithm by changing the linear conversion matrix parameter to be round-dependent. By using different MDS matrices for odd and even rounds, it achieves enhanced security against differential analysis while controlling complexity through a systematic approach to matrix selection and application

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements periodic action by alternating between different MDS matrices for odd and even rounds. This periodic pattern of matrix application provides enhanced security while maintaining a predictable and manageable structure, preventing the complexity from becoming uncontrolled

Inventive Principle:
Principle #19Periodic action

3Reliability

If the number of active S boxes is increased to resist differential attacks, then the security is improved, but the computational overhead and processing time increase

Engineering Contradiction:
Improvesecurity against key analysisVSAvoidencryption processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent changes the parameter of the linear conversion matrix to be round-dependent, which naturally increases the number of active S boxes throughout the encryption process. This parameter change achieves enhanced security against differential analysis and key recovery attacks while the systematic approach manages the computational overhead

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7433470B2Cryptographic processing apparatus, cryptographic processing method, and computer program
Publication Date: 2008.10.07 SONY GROUP CORP
  • US7433470B2 patent drawing
  • US7433470B2 patent drawing
  • US7433470B2 patent drawing

AI summary

There is provided a highly secure cryptographic processing apparatus and method where an analysis difficulty is increased. In a Feistel type common key block encrypting process in which an SPN type F function having a nonlinear conversion section and a linear conversion section is repeatedly executed a plurality of rounds. The linear conversion process of an F function corresponding to each of the plurality of rounds is performed as a linear conversion process which employs an MDS (Maximum Distance Separable) matrix, and a linear conversion process is carried out which employs a different MDS matrix at least at each of consecutive odd number rounds and consecutive even number rounds. This structure makes it possible to increase the minimum number (a robustness index against a differential attack in common key block encryption) of the active S box in the entire encrypting function.