US2018262326A1PendingUtilityA1

Protecting white-box feistel network implementation against fault attack

Assignee: NXP BVPriority: Nov 25, 2015Filed: May 9, 2018Published: Sep 13, 2018
Est. expiryNov 25, 2035(~9.3 yrs left)· nominal 20-yr term from priority
H04L 9/0625H04L 9/002H04L 2209/16H04L 9/004
52
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of implementing a method of mapping an input message to an output message by a keyed cryptographic operation, wherein the keyed cryptographic operation includes a plurality of rounds using a Feistel network, including: receiving an input having a first half and a second half; performing, by a basic block, a portion of a round function on the second half to produce a portion of an encoded output, and wherein the basic block provides a portion of the second half as a portion of an encoded first input to a next round; and XORing the portion of the encoded output and a portion the first half to produce a portion of an encoded second input to the next round.

Claims

exact text as granted — not AI-modified
1 . A method of mapping an input message to an output message by a keyed cryptographic operation, wherein the keyed cryptographic operation includes a plurality of rounds using a Feistel network, comprising:
 receiving an input having a first half and a second half;   performing, by a basic block, a portion of a round function on the second half to produce a portion of an encoded output, and wherein the basic block provides a portion of the second half as a portion of an encoded first input to a next round; and   XORing the portion of the encoded output and a portion the first half to produce a portion of an encoded second input to the next round.   
     
     
         2 . The method of  claim 1 , wherein the round function includes a key addition, a substitution function, a permutation function, and an expansion operation. 
     
     
         3 . The method of  claim 1 , wherein the keyed cryptographic function is the data encryption standard. 
     
     
         4 . The method of  claim 1 , wherein the basic block is a lookup table. 
     
     
         5 . The method of  claim 1 , wherein the basic block is a finite state machine. 
     
     
         6 . A non-transitory machine-readable storage medium encoded with instructions for implementing mapping an input message to an output message by a keyed cryptographic operation, wherein the keyed cryptographic operation includes a plurality of rounds using a Feistel network, comprising:
 instructions for receiving an input having a first half and a second half;   instructions for performing, by a basic block, a portion of a round function on the second half to produce a portion of an encoded output, and wherein the basic block provides a portion of the second half as a portion of an encoded first input to a next round; and   instructions for XORing the portion of the encoded output and a portion the first half to produce a portion of an encoded second input to the next round.   
     
     
         7 . The non-transitory machine-readable storage medium of  claim 6 , wherein the round function includes a key addition, a substitution function, a permutation function, and an expansion operation. 
     
     
         8 . The non-transitory machine-readable storage medium of  claim 6 , wherein the keyed cryptographic function is the data encryption standard. 
     
     
         9 . The non-transitory machine-readable storage medium of  claim 6 , wherein the basic block is a lookup table. 
     
     
         10 . The non-transitory machine-readable storage medium of  claim 6 , wherein the basic block is a finite state machine. 
     
     
         11 - 22 . (canceled)

Join the waitlist — get patent alerts

Track US2018262326A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.