WO2015133687A1 - 비트 확장 방식을 이용한 암호화 장치 및 방법 - Google Patents
비트 확장 방식을 이용한 암호화 장치 및 방법 Download PDFInfo
- Publication number
- WO2015133687A1 WO2015133687A1 PCT/KR2014/007775 KR2014007775W WO2015133687A1 WO 2015133687 A1 WO2015133687 A1 WO 2015133687A1 KR 2014007775 W KR2014007775 W KR 2014007775W WO 2015133687 A1 WO2015133687 A1 WO 2015133687A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- bit
- extension
- encryption
- determining
- extended
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/002—Countermeasures against attacks on cryptographic mechanisms
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/06—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
- H04L9/065—Encryption by serially and continuously modifying data stream elements, e.g. stream cipher systems, RC4, SEAL or A5/3
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/34—Encoding or coding, e.g. Huffman coding or error correction
Definitions
- Embodiments of the present invention relate to an encryption technique, and more particularly, to an encryption apparatus and method using a bit extension scheme.
- Cryptography has been widely used in the economic and financial fields, and has been widely used for authentication of identity, key management for digital keys, digital signature, and identity verification. .
- Encryption techniques are often used to ensure the safety of message transmission.
- the encryption technique involves encrypting plaintext on the transmission side and decrypting ciphertext on the receiving side.
- DES Data Encryption Standard
- ANSI American National Standards Institute
- Other encryption protocols include 3-DES and AES (Advanced Encryption Standard).
- Decryption can also be done by neglecting the management of decryption keys, predictability of passwords, or monitoring of keyboard input on the network.
- Decryption techniques include Ciphertext Only Attack, Known Plaintext Attack, Chosen Plaintext Attack, Adaptive Chosen Plaintext Attack, and Timing attack. And DPA (or 'power analysis') attacks.
- Korean Patent Publication No. 10-0571178 name of the invention: a method for encrypting and decrypting a message, a registration date: April 07, 2006).
- An embodiment of the present invention can improve the security of the information transmission channel (main transport channel) by encrypting by extending the bit length of the message to be encrypted, thereby minimizing the transmission of information to the eavesdropping channel in various environments
- An encryption device and method using a bit extension method for guaranteeing a desired amount of information loss are provided.
- An encryption apparatus using a bit extension scheme includes a bit selector for selecting each bit value from a binary bit string of an input message; And for each of the selected bit values, generate an extended bit string by extending the length of each of the bit values using a plurality of random numbers, and combining the generated extended bit strings to encrypt the message. And a bit extension encryption unit.
- the present invention by extending and encrypting the length of the bit value of the message to be encrypted, it is possible to improve the security of the information transmission channel (main transport channel), thereby minimizing the transmission of information to the eavesdropping channel. In this way, the amount of information loss can be guaranteed in various environments.
- the bit extension multiple in consideration of the length and security of the message when the bit length is extended, it is possible to encrypt the message with bits of an extended length optimally for transmission to the information delivery channel. Therefore, the security of the message transmitted through the information transmission channel can be further improved.
- FIG. 1 is a block diagram illustrating an encryption apparatus using a bit extension method according to an embodiment of the present invention.
- FIG. 2 is a block diagram illustrating a detailed configuration of the bit extension encryption unit of FIG. 2.
- FIG. 3 is a block diagram illustrating an encryption apparatus using a bit extension method according to another embodiment of the present invention.
- 4 to 6 are flowcharts illustrating an encryption method using a bit extension method according to an embodiment of the present invention.
- FIG. 7 is a flowchart illustrating an encryption method using a bit extension method according to another embodiment of the present invention.
- An encryption apparatus using a bit extension scheme includes a bit selector for selecting each bit value from a binary bit string of an input message; And for each of the selected bit values, generate an extended bit string by extending the length of each of the bit values using a plurality of random numbers, and combining the generated extended bit strings to encrypt the message. And a bit extension encryption unit.
- the encryption apparatus using a bit extension method further includes an extension multiple determination unit for determining a bit extension multiple for extending the length of each bit value, and the bit extension encryption unit further comprising the determined bit extension multiple
- the extended bit string may be generated as a bit string having a length corresponding to the bit extension multiple using the plurality of random numbers.
- the bit extension encryption unit may include: a bit string generator configured to generate a first bit area among the extended bit strings using the plurality of random numbers; A bit determination unit configured to determine a bit value of a second bit area among the extended bit strings based on a result of performing a logical operation on each of the generated bit values of the first bit area; And a bit string combination unit that combines the extension bit strings including the first and second bit regions, respectively.
- the bit determiner may perform an exclusive OR operation on each of the bit values of the first bit area, and determine a bit value of the second bit area based on a result of performing the exclusive OR operation.
- the bit determining unit defines a result value of the exclusive OR operation as an operator and defines a bit value for performing an exclusive OR operation as an operand
- the result value of the logical operation with the operator is an original bit value.
- the bit value of the operand to be equal to may be determined as the bit value of the second bit area.
- the second bit region may be disposed at any position in the extension bit string.
- the extended multiple determination unit may determine the bit extended multiple in consideration of the length and security of the message.
- the extended multiple determination unit may determine a target information loss rate according to the security of a transmission channel for transmitting the encrypted message, and determine the bit extension multiple based on the determined target information loss rate.
- the extended multiple determining unit may determine the bit extended multiple in consideration of the number of transmission channels through which the encrypted message is to be transmitted.
- the extended multiple determination unit may determine the bit extended multiple based on a target transmission amount of a transmission channel through which the encrypted message is to be transmitted.
- the encryption apparatus using the bit extension method according to an embodiment of the present invention may further include an external encoding unit for encoding the input message using a linear encoding algorithm.
- the linear encoding algorithm may include a hamming encoding algorithm.
- An encryption method using a bit extension method includes selecting each bit value from a binary bit string of an input message in a bit selector of an encryption device; Generating, by the bit extension encryption unit of the encryption apparatus, an extension bit string by extending a length of each of the bit values using a plurality of random numbers for each of the selected bit values; And encrypting the message by combining each of the generated extension bit strings in the bit extension encryption unit of the encryption apparatus.
- the encryption method using the bit extension method further includes the step of determining, by the extension multiple determination unit of the encryption device, a bit extension multiple for extending the length of each of the bit values.
- the generating of the bit string may include generating the extension bit string as a bit string having a length corresponding to the bit extension multiple by using the plurality of random numbers based on the determined bit extension multiple.
- the generating of the extended bit string may include: generating, by the bit string generator of the bit extension encryption unit, a first bit region of the extended bit string using the plurality of random numbers; And determining, by the bit determining unit of the bit extension encryption unit, a bit value of a second bit region of the extended bit string based on a result of performing a logical operation on each of the generated bit values of the first bit region.
- the encrypting of the message may include encrypting the message by combining the extended bit strings including the first and second bit regions in the bit string combination unit of the bit extended encryption unit. .
- Determining a bit value of a second bit region of the extended bit string may include performing an exclusive OR operation on each of the bit values of the first bit region; And determining a bit value of the second bit area based on a result of performing the exclusive OR operation.
- a result value of the exclusive OR operation is defined as an operator, and a bit value for performing an exclusive OR operation as an operand, a bit of the second bit area based on a result of performing the exclusive OR operation
- the determining of the value may include determining a bit value of an operand so that a result of logical operation with the operator is equal to an original bit value, as a bit value of the second bit region.
- the second bit region may be disposed at a random position in the extension bit string.
- the determining of the bit extension multiple may include determining the bit extension multiple in consideration of the length and security of the message.
- the determining of the bit extension multiple may include determining a target information loss rate according to security of a transmission channel through which the encrypted message is to be transmitted; And determining the bit extension multiple based on the determined target information loss rate.
- the determining of the bit extension multiple may include determining the bit extension multiple by considering the number of transport channels through which the encrypted message is to be transmitted.
- the determining of the bit extension multiple may include determining the bit extension multiple based on a target transmission amount of a transmission channel through which the encrypted message is to be transmitted.
- the encryption method using the bit extension method according to an embodiment of the present invention may further include encoding, by the external encoding unit of the encryption apparatus, the input message using a linear encoding algorithm.
- the linear encoding algorithm may include a hamming encoding algorithm.
- FIG. 1 is a block diagram illustrating an encryption apparatus using a bit extension method according to an embodiment of the present invention.
- an encryption apparatus 100 using a bit extension method includes a bit selector 110, an extension multiple determination unit 120, and a bit extension encryption unit 130. can do.
- the bit selector 110 selects each bit value from the binary bit string of the input message. To this end, the bit selector 110 may extract the binary bit string by analyzing the input message, and sequentially select respective bit values from the extracted binary bit string.
- the bit selector 110 may extract a binary bit string '1100' as a result of analyzing the input message, and bit values' 1 'and' from the extracted binary bit string '1100'. 1 ',' 0 ', and' 0 'can be selected sequentially.
- the extended multiple determining unit 120 determines a bit extended multiple for extending the length of each bit value.
- the bit extension multiple is a multiple value for extending the length of each bit value.
- each of the bit values may be extended to a length of 1 bit.
- the binary bit string of the input message is '1100' as in the above example.
- the bit extension multiple is 3
- the lengths of the bit values of '1', '1', '0', and '0' are '001', '111', '110', and '101'.
- the bit extension multiple is increased as the value increases and the security is improved, whereas the smaller the value is reduced as the information amount and the less secure, it is preferable to be determined in consideration of both the amount of information and security. . That is, the extended multiple determination unit 120 may determine the bit extended multiple in consideration of the length and security of the message.
- the extended multiple determination unit 120 may determine a target information loss rate according to the security of a transmission channel for transmitting an encrypted message, and determine the bit extension multiple based on the determined target information loss rate. In addition, the extended multiple determination unit 120 may determine the bit extended multiple in consideration of the number of transmission channels for transmitting the encrypted message. In addition, the extended multiple determination unit 120 may determine the bit extended multiple based on a target transmission amount of a transmission channel for transmitting the encrypted message.
- the bit extension encryption unit 130 generates an extended bit string by extending the length of each of the bit values using a plurality of random numbers for each of the selected bit values.
- the random number may indicate a value randomly selected from 0 or 1.
- the bit extension encrypting unit 130 has a length corresponding to the bit extension multiple by using the plurality of random numbers based on the bit extension multiple L determined by the expansion multiple determination unit 120. It can be generated as a bit string of.
- the bit extension encryption unit 130 may encrypt the message by combining each of the generated extension bit strings.
- the bit extension encryption unit 130 sets the extension bit strings for the respective bit values '1', '1', '0', and '0' to '111', '010', '101',
- the message may be encrypted by generating a '110' and outputting a binary bit string such as '111010101110' by combining each of the generated extended bit strings.
- the bit extension encryption unit 130 may include a bit string generator 210, a bit determiner 220, and a bit string combiner 230.
- FIG. 2 is a block diagram illustrating a detailed configuration of the bit extension encryption unit 130 of FIG. 2.
- the bit string generator 210 may generate a first bit region of the extension bit string using the plurality of random numbers. As shown in the above example, when the bit extension multiple is 3, the first bit region may be defined as an area including a first bit and a second bit.
- the bit determiner 220 may determine a bit value of the second bit region of the extended bit string based on a result of the logical operation of each of the generated bit values of the first bit region.
- the bit determiner 220 may perform an exclusive OR operation on each of the bit values of the first bit area, and determine the bit value of the second bit area based on a result of performing the exclusive OR operation. .
- bit determiner 220 defines an operator as a result of performing the exclusive OR operation and defines a bit value for performing an exclusive OR operation as an operand.
- the bit value of the operand so that the result of the logical operation is equal to the original bit value may be determined as the bit value of the second bit region.
- the second bit area may be disposed at a random position in the extension bit string. That is, the second bit area may be disposed at an arbitrary position such as the front, middle, or rear part of the extension bit string. To this end, the bit determiner 220 may determine an arbitrary region in which the second bit region is to be located in the extended bit string using a random number table or the like.
- the second bit region is located at the end of the extended bit string.
- the present invention is not limited thereto and may be located at another position as described above.
- the second bit region may be disposed at any position within the extension bit string, thereby increasing security.
- the bit stream generation unit 210 allows the first bit and the second bit, ie, the first bit area, of the extended bit string for each of the bit values to be '11', '01', '10', ' 11 'may be generated.
- the bit determiner 220 determines the second bit area, that is, the last bit of the extended bit string, wherein an exclusive OR operation of the first bit and the second bit of the first bit area is performed. Based on the result of the operation, '1', '0', '1', and '0' may be determined as the last bits for each of '11', '01', '10', and '11'.
- the bit determiner 220 performs a result of the exclusive OR operation and a bit value of performing an exclusive OR operation so that an original bit value is obtained as a bit value of the second bit region of the extension bit string. You can decide.
- the extended bit strings for the respective bit values' 1 ',' 1 ',' 0 ', and' 0 'selected from the binary bit string of the input message are' 111 ',' 010 ',' 101 ',' 110 'may be generated.
- the bit string combiner 230 may combine an extended bit string including the first bit region and the second bit region.
- the bit string combiner 230 may combine each of the generated extended bit strings '111', '010', '101', and '110'.
- the message can be encrypted by outputting a binary bit string.
- FIG. 3 is a block diagram illustrating an encryption apparatus using a bit extension method according to another embodiment of the present invention.
- the encryption apparatus 300 using the bit extension scheme may include an external encoding unit 310 and an internal encoding unit 320.
- the external encoding unit 310 receives a message and encodes it using a linear encoding algorithm.
- the linear encoding algorithm may include a hamming encoding algorithm.
- the inner encoding unit 320 receives a message encoded by the outer encoding unit 310 and performs encryption.
- the internal encoding unit 320 may include a bit selector 322, an extended multiple determination unit 324, and a bit extended encryption unit 326.
- the bit selector 322 selects each bit value from the binary bit string of the message encoded by the external encoder 310. To this end, the bit selector 322 may analyze the encoded message to extract a binary bit string, and sequentially select respective bit values from the extracted binary bit string.
- the extended multiple determining unit 324 determines a bit extended multiple for extending the length of each bit value.
- the bit extension multiple is a multiple value for extending the length of each bit value as described above.
- the bit extension multiple is 1 (a natural number of 2 or more), each of the bit values extends to the length of 1 bit. Can be.
- the extended multiple determination unit 324 may determine the bit extended multiple in consideration of the length and security of the message.
- the extended multiple determination unit 324 may determine a target information loss rate according to the security of a transmission channel for transmitting an encrypted message, and determine the bit extension multiple based on the determined target information loss rate. In addition, the extended multiple determination unit 324 may determine the bit extended multiple in consideration of the number of transmission channels for transmitting the encrypted message. In addition, the extended multiple determination unit 324 may determine the bit extended multiple based on a target transmission amount of a transmission channel for transmitting the encrypted message.
- the bit extension encryption unit 326 generates an extended bit string by extending the length of each of the bit values using a plurality of random numbers for each of the selected bit values.
- the bit extension encrypting unit 326 has a length corresponding to the bit expansion multiple using the plurality of random numbers based on the bit extension multiple L determined by the expansion multiple determining unit 324. It can be generated as a bit string of.
- the bit extension encryption unit 326 may encrypt the message by combining each of the generated extension bit strings.
- 4 to 6 are flowcharts illustrating an encryption method using a bit extension method according to an embodiment of the present invention.
- bit selector 110 of the encryption apparatus 100 selects each bit value from a binary bit string of an input message.
- step 420 the extension multiple determination unit 120 of the encryption apparatus 100 determines a bit extension multiple for extending the length of each bit value.
- step 430 the bit extension encryption unit 130 of the encryption apparatus 100 expands the length of each of the bit values by using the plurality of random numbers based on the determined bit extension multiple. Generate heat.
- the bit extension encryption unit 130 of the encryption apparatus 110 may generate the extension bit string as a bit string having a length corresponding to the bit extension multiple using the plurality of random numbers.
- the step 430 will be described in detail with reference to FIG. 5 as follows.
- the bit string generator 210 of the bit extension encryption unit 130 may use the plurality of random numbers for the first bit region of the extension bit string. Create
- step 520 the bit determiner 220 of the bit extension encryption unit 130 based on a result of performing a logical operation on each of the generated bit values of the first bit region, selects a first one of the extended bit strings. Determines the bit value of the 2-bit area.
- bit determiner 220 of the bit extension encryption unit 130 performs an exclusive OR operation on each bit value of the first bit region.
- the bit determiner 220 of the bit extension encryptor 130 determines a bit value of the second bit area based on a result of performing the exclusive OR operation.
- the bit determination unit 220 of the bit extension encryption unit 130 is defined. ) May determine the bit value of the operand so that the result of logical operation with the operator is equal to the original bit value as the bit value of the second bit region.
- the second bit area may be disposed at any position in the extension bit string.
- the second bit area may be an area including one last bit of the extended bit string. That is, assuming that the extended bit string is '110', the first bit region generated by using a plurality of random numbers is '11', and is determined based on a result of performing an exclusive OR operation of the first bit region.
- the second bit area may be referred to as '0'.
- step 440 the bit extension encryption unit 130 of the encryption apparatus 100 encrypts the message by combining each of the generated extension bit strings.
- FIG. 7 is a flowchart illustrating an encryption method using a bit extension method according to another embodiment of the present invention.
- the external encoding unit 310 of the encryption apparatus 300 encodes an input message using a linear encoding algorithm.
- the linear encoding algorithm may include a hamming encoding algorithm.
- the internal encoding unit 320 of the encryption device 300 receives the message encoded by the external encoding unit 310 and performs encryption.
- step 720 the bit selector 322 of the internal encoder 320 selects each bit value from the binary bit string of the encoded message.
- the bit selector 322 of the internal encoder 320 may extract a binary bit string by analyzing the encoded message, and sequentially select respective bit values from the extracted binary bit string.
- step 730 the expansion multiple determiner 324 of the internal encoding unit 320 determines a bit extension multiple for extending the length of each bit value.
- bit extension multiple is a multiple value for extending the length of each bit value.
- bit extension multiple is 1 (a natural number of 2 or more)
- each of the bit values may be extended to a length of 1 bit.
- bit extension encryption unit 326 of the internal encoding unit 320 expands the length of each of the bit values using a plurality of random numbers based on the determined bit extension multiple. Generate heat.
- the extended bit string may be generated as a bit string having a length corresponding to the bit extension multiple.
- step 750 the bit extension encryption unit 326 of the internal encoding unit 320 combines each of the generated extension bit strings to encrypt the message.
- the present invention by extending and encrypting the length of the bit value of the message to be encrypted, it is possible to improve the security of the information transmission channel (main transport channel), thereby providing information transmission to the eavesdropping channel. Minimized to ensure the targeted loss of information in a variety of environments.
- the message by determining the bit extension multiple in consideration of the length and security of the message when the bit length is extended, the message can be encrypted with bits of an extended length optimally for transmission to the information delivery channel. Therefore, the security of the message transmitted through the information transmission channel can be further improved.
- the bit length is extended by using a plurality of random numbers and a bit value determined through a logical operation with the random numbers, so that encryption and recovery can be performed in a secure and limited resource and time. can do.
- Embodiments of the invention include a computer readable medium containing program instructions for performing various computer-implemented operations.
- the computer readable medium may include program instructions, local data files, local data structures, or the like, alone or in combination.
- the media may be those specially designed and constructed for the purposes of the present invention, or they may be of the kind well known and available to those having skill in the computer software arts.
- Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tape, optical recording media such as CD-ROMs, DVDs, magnetic-optical media such as floppy disks, and ROM, RAM, flash memory, and the like.
- Hardware devices specifically configured to store and execute the same program instructions are included.
- Examples of program instructions include not only machine code generated by a compiler, but also high-level language code that can be executed by a computer using an interpreter or the like.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
- Storage Device Security (AREA)
Abstract
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치는 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택하는 비트 선택부; 및 상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성하고, 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화하는 비트 확장 암호화부를 포함한다.
Description
본 발명의 실시예들은 암호화 기술에 관한 것으로, 더욱 상세하게는 비트 확장 방식을 이용한 암호화 장치 및 방법에 관한 것이다.
암호(cryptography)는 경제, 금융분야에서 널리 사용된 이래로, 동일성의 인증(Authentication), 암호화 키에 대한 관리(Key Management), 디지털 서명(Digital Signature) 및 신원 확인(Identity Verification) 등 광범위하게 사용되고 있다.
암호화 기술은 메시지 전송의 안전을 보장하기 위하여 자주 사용된다. 상기 암호화 기술은 전송측(transmission side)에서 평문(plaintext)을 부호화(encrypt)하고, 수신측(receiving side)에서 암호문(ciphertext)을 해독(decrypt)하는 것을 포함한다.
데이터 암호화 표준(Data Encryption Standard: DES)은 여러 나라들과 ANSI(American National Standards Institute)에서 표준으로 채용된 블록 단위 암호화 프로토콜이다. 이외에도 암호화 프로토콜에는 3-DES 및 AES(Advanced Encryption Standard) 등이 있다.
암호 해독은 해독키의 관리 소홀, 비밀번호의 예측 가능성, 또는 통신망에서 키보드 입력에 대한 모니터링 등으로도 가능하다. 암호를 해독하는 기술로는 단순 암호문 공격(Ciphertext Only Attack), 평문 공격(Known Plaintext Attack), 선택 평문 공격(Chosen Plaintext Attack), 최적 선택 평문 공격(Adaptively Chosen Plaintext Attack), 시간 공격(timing attack) 및 DPA(또는 '전력 분석'이라 함) 공격 등이 있다.
관련 선행기술로는 한국 등록특허공보 제10-0571178호(발명의 명칭: 메시지의 암호화 및 복호화 방법, 등록일자: 2006년 04월 07일)가 있다.
본 발명의 일 실시예는 암호화하고자 하는 메시지의 비트 길이를 확장하여 암호화함으로써 정보 전달 채널(주 전송 채널)의 보안성을 향상시킬 수 있으며, 이를 통해 도청 채널로의 정보 전달을 최소화하여 다양한 환경에서 목표된 정보 손실량을 보장할 수 있도록 하는 비트 확장 방식을 이용한 암호화 장치 및 방법을 제공한다.
본 발명이 해결하고자 하는 과제는 이상에서 언급한 과제(들)로 제한되지 않으며, 언급되지 않은 또 다른 과제(들)은 아래의 기재로부터 당업자에게 명확하게 이해될 수 있을 것이다.
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치는 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택하는 비트 선택부; 및 상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성하고, 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화하는 비트 확장 암호화부를 포함한다.
본 발명의 일 실시예에 따르면, 암호화하고자 하는 메시지의 비트 값의 길이를 확장하여 암호화함으로써 정보 전달 채널(주 전송 채널)의 보안성을 향상시킬 수 있으며, 이를 통해 도청 채널로의 정보 전달을 최소화하여 다양한 환경에서 목표된 정보 손실량을 보장할 수 있다.
본 발명의 일 실시예에 따르면, 비트 길이의 확장 시 메시지의 길이와 보안성을 고려하여 비트 확장 배수를 결정함으로써, 정보 전달 채널로의 전송에 최적으로 확장된 길이의 비트로 메시지를 암호화할 수 있으며, 이를 통해 정보 전달 채널로 전송되는 메시지에 대한 보안성을 보다 향상시킬 수 있다.
본 발명의 일 실시예에 따르면, 복수의 난수, 및 난수들과의 논리 연산을 통해 결정된 비트 값을 이용하여 비트 길이를 확장시킴으로써, 보안에 강하면서도 한정된 자원과 시간에서 효율적인 암호 및 복원이 가능하도록 할 수 있다.
도 1은 본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치를 설명하기 위해 도시한 블록도이다.
도 2는 도 2의 비트 확장 암호화부의 상세 구성을 설명하기 위해 도시한 블록도이다.
도 3은 본 발명의 다른 실시예에 따른 비트 확장 방식을 이용한 암호화 장치를 설명하기 위해 도시한 블록도이다.
도 4 내지 도 6은 본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 방법을 설명하기 위해 도시한 흐름도이다.
도 7은 본 발명의 다른 실시예에 따른 비트 확장 방식을 이용한 암호화 방법을 설명하기 위해 도시한 흐름도이다.
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치는 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택하는 비트 선택부; 및 상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성하고, 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화하는 비트 확장 암호화부를 포함한다.
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치는 상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정하는 확장 배수 결정부를 더 포함하고, 상기 비트 확장 암호화부는 상기 결정된 비트 확장 배수를 기준으로, 상기 복수의 난수를 이용하여 상기 확장 비트열을 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성할 수 있다.
상기 비트 확장 암호화부는 상기 확장 비트열 중 제1 비트 영역을 상기 복수의 난수를 이용하여 생성하는 비트열 생성부; 상기 생성된 제1 비트 영역의 비트 값 각각을 논리 연산한 결과 값에 기초하여, 상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정하는 비트 결정부; 및 상기 제1 및 제2 비트 영역을 포함하는 상기 확장 비트열을 각각 조합하는 비트열 조합부를 포함할 수 있다.
상기 비트 결정부는 상기 제1 비트 영역의 비트 값 각각에 대한 배타적 논리합 연산을 수행하고, 상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정할 수 있다.
상기 비트 결정부는 상기 배타적 논리합 연산을 수행한 결과 값을 연산자로 정의하고, 상기 연산자와 배타적 논리합 연산을 수행하는 비트 값을 피연산자로 정의할 때, 상기 연산자와 논리 연산한 결과 값이 원래의 비트 값과 동일하도록 하는 피연산자의 비트 값을 상기 제2 비트 영역의 비트 값으로 결정할 수 있다.
상기 제2 비트 영역은 상기 확장 비트열 내 임의의 위치에 배치될 수 있다.
상기 확장 배수 결정부는 메시지의 길이와 보안성을 고려하여 상기 비트 확장 배수를 결정할 수 있다.
상기 확장 배수 결정부는 상기 암호화된 메시지를 전송할 전송 채널의 보안성에 따른 목표 정보 손실률을 결정하고, 상기 결정된 목표 정보 손실률에 기초하여 상기 비트 확장 배수를 결정할 수 있다.
상기 확장 배수 결정부는 상기 암호화된 메시지를 전송할 전송 채널의 수를 고려하여 상기 비트 확장 배수를 결정할 수 있다.
상기 확장 배수 결정부는 상기 암호화된 메시지를 전송할 전송 채널의 목표 전송량에 기초하여 상기 비트 확장 배수를 결정할 수 있다.
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치는 선형 부호화 알고리즘을 이용하여 상기 입력된 메시지를 부호화하는 외부 인코딩부를 더 포함할 수 있다.
상기 선형 부호화 알고리즘은 해밍 부호화 알고리즘을 포함할 수 있다.
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 방법은 암호화 장치의 비트 선택부에서, 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택하는 단계; 상기 암호화 장치의 비트 확장 암호화부에서, 상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성하는 단계; 및 상기 암호화 장치의 비트 확장 암호화부에서, 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화하는 단계를 포함한다.
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 방법은 상기 암호화 장치의 확장 배수 결정부에서, 상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정하는 단계를 더 포함하고, 상기 확장 비트열을 생성하는 단계는 상기 결정된 비트 확장 배수를 기준으로, 상기 복수의 난수를 이용하여 상기 확장 비트열을 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성하는 단계를 포함할 수 있다.
상기 확장 비트열을 생성하는 단계는 상기 비트 확장 암호화부의 비트열 생성부에서, 상기 확장 비트열 중 제1 비트 영역을 상기 복수의 난수를 이용하여 생성하는 단계; 및 상기 비트 확장 암호화부의 비트 결정부에서, 상기 생성된 제1 비트 영역의 비트 값 각각을 논리 연산한 결과 값에 기초하여, 상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정하는 단계를 포함하고, 상기 메시지를 암호화하는 단계는 상기 비트 확장 암호화부의 비트열 조합부에서, 상기 제1 및 제2 비트 영역을 포함하는 상기 확장 비트열을 각각 조합하여 상기 메시지를 암호화하는 단계를 포함할 수 있다.
상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정하는 단계는 상기 제1 비트 영역의 비트 값 각각에 대한 배타적 논리합 연산을 수행하는 단계; 및 상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정하는 단계를 포함할 수 있다.
상기 배타적 논리합 연산을 수행한 결과 값을 연산자로 정의하고, 상기 연산자와 배타적 논리합 연산을 수행하는 비트 값을 피연산자로 정의할 때, 상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정하는 단계는 상기 연산자와 논리 연산한 결과 값이 원래의 비트 값과 동일하도록 하는 피연산자의 비트 값을 상기 제2 비트 영역의 비트 값으로 결정하는 단계를 포함할 수 있다.
상기 제2 비트 영역은 상기 확장 비트열 내 임의(random)의 위치에 배치될 수 있다.
상기 비트 확장 배수를 결정하는 단계는 메시지의 길이와 보안성을 고려하여 상기 비트 확장 배수를 결정하는 단계를 포함할 수 있다.
상기 비트 확장 배수를 결정하는 단계는 상기 암호화된 메시지를 전송할 전송 채널의 보안성에 따른 목표 정보 손실률을 결정하는 단계; 및 상기 결정된 목표 정보 손실률에 기초하여 상기 비트 확장 배수를 결정하는 단계를 포함할 수 있다.
상기 비트 확장 배수를 결정하는 단계는 상기 암호화된 메시지를 전송할 전송 채널의 수를 고려하여 상기 비트 확장 배수를 결정하는 단계를 포함할 수 있다.
상기 비트 확장 배수를 결정하는 단계는 상기 암호화된 메시지를 전송할 전송 채널의 목표 전송량에 기초하여 상기 비트 확장 배수를 결정하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 방법은 암호화 장치의 외부 인코딩부에서, 선형 부호화 알고리즘을 이용하여 상기 입력된 메시지를 부호화하는 단계를 더 포함할 수 있다.
상기 선형 부호화 알고리즘은 해밍 부호화 알고리즘을 포함할 수 있다.
기타 실시예들의 구체적인 사항들은 상세한 설명 및 첨부 도면들에 포함되어 있다.
본 발명의 이점 및/또는 특징, 그리고 그것들을 달성하는 방법은 첨부되는 도면과 함께 상세하게 후술되어 있는 실시예들을 참조하면 명확해질 것이다. 그러나, 본 발명은 이하에서 개시되는 실시예들에 한정되는 것이 아니라 서로 다른 다양한 형태로 구현될 것이며, 단지 본 실시예들은 본 발명의 개시가 완전하도록 하며, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 발명의 범주를 완전하게 알려주기 위해 제공되는 것이며, 본 발명은 청구항의 범주에 의해 정의될 뿐이다. 명세서 전체에 걸쳐 동일 참조 부호는 동일 구성요소를 지칭한다.
이하에서는 첨부된 도면을 참조하여 본 발명의 실시예들을 상세히 설명하기로 한다.
도 1은 본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치를 설명하기 위해 도시한 블록도이다.
도 1을 참조하면, 본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 장치(100)는 비트 선택부(110), 확장 배수 결정부(120), 및 비트 확장 암호화부(130)를 포함할 수 있다.
상기 비트 선택부(110)는 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택한다. 이를 위해, 상기 비트 선택부(110)는 상기 입력된 메시지를 분석하여 이진 비트열을 추출하고, 상기 추출된 이진 비트열로부터 순차적으로 각각의 비트 값을 선택할 수 있다.
예를 들어, 상기 비트 선택부(110)는 상기 입력된 메시지를 분석한 결과로서 이진 비트열 '1100'을 추출할 수 있으며, 상기 추출된 이진 비트열 '1100'으로부터 비트 값 '1', '1', '0', '0'을 각각 순차적으로 선택할 수 있다.
상기 확장 배수 결정부(120)는 상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정한다. 여기서, 상기 비트 확장 배수는 상기 비트 값 각각의 길이를 확장하기 위한 배수 값으로서, 상기 비트 확장 배수가 ℓ(2 이상의 자연수)일 경우, 상기 비트 값 각각은 ℓ비트의 길이로 확장될 수 있다.
예를 들어, 상기 입력된 메시지의 이진 비트열이 위의 예에서와 같이 '1100'인 것으로 가정한다. 이러한 경우, 상기 비트 확장 배수를 3이라 가정하면, '1', '1', '0', '0' 의 비트 값 각각의 길이는 '001', '111', '110', '101'과 같이 확장될 수 있다.
참고로, 상기 비트 확장 배수는 그 값이 클수록 정보량이 늘어나고 보안성이 향상되는 반면에, 그 값이 작을수록 정보량이 줄어들고 보안성이 떨어지기 때문에 정보량과 보안성을 모두 고려하여 결정되는 것이 바람직하다. 즉, 상기 확장 배수 결정부(120)는 메시지의 길이와 보안성을 고려하여 상기 비트 확장 배수를 결정할 수 있다.
예를 들어, 상기 확장 배수 결정부(120)는 암호화된 메시지를 전송할 전송 채널의 보안성에 따른 목표 정보 손실률을 결정하고, 상기 결정된 목표 정보 손실률에 기초하여 상기 비트 확장 배수를 결정할 수 있다. 또한, 상기 확장 배수 결정부(120)는 상기 암호화된 메시지를 전송할 전송 채널의 수를 고려하여 상기 비트 확장 배수를 결정할 수 있다. 또한, 상기 확장 배수 결정부(120)는 상기 암호화된 메시지를 전송할 전송 채널의 목표 전송량에 기초하여 상기 비트 확장 배수를 결정할 수 있다.
상기 비트 확장 암호화부(130)는 상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성한다. 여기서, 상기 난수는 0 또는 1 중에서 무작위로 선출된 값을 가리킬 수 있다.
즉, 상기 비트 확장 암호화부(130)는 상기 확장 배수 결정부(120)에 의해 결정된 비트 확장 배수 ℓ을 기준으로, 상기 복수의 난수를 이용하여 상기 확장 비트열을 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성할 수 있다.
상기 비트 확장 암호화부(130)는 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화할 수 있다.
예를 들어, 상기 입력된 메시지의 이진 비트열이 위와 같이 '1100'이고 비트 확장 배수가 3이라고 가정한다. 이러한 경우, 상기 비트 확장 암호화부(130)는 각각의 비트 값 '1', '1', '0', '0' 에 대한 확장 비트열을 각각 '111', '010', '101', '110'와 같이 생성하고, 상기 생성된 확장 비트열 각각을 조합하여 '111010101110'와 같은 이진 비트열을 출력함으로써 상기 메시지를 암호화할 수 있다.
이를 위해, 상기 비트 확장 암호화부(130)는 비트열 생성부(210), 비트 결정부(220) 및 비트열 조합부(230)를 포함할 수 있다. 참고로, 도 2는 도 2의 비트 확장 암호화부(130)의 상세 구성을 설명하기 위해 도시한 블록도이다.
상기 비트열 생성부(210)는 상기 확장 비트열 중 제1 비트 영역을 상기 복수의 난수를 이용하여 생성할 수 있다. 위의 예와 같이 상기 비트 확장 배수가 3인 경우, 상기 제1 비트 영역은 첫 번째 비트와 두 번째 비트를 포함하는 영역으로 정의될 수 있다.
상기 비트 결정부(220)는 상기 생성된 제1 비트 영역의 비트 값 각각을 논리 연산한 결과 값에 기초하여, 상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정할 수 있다.
즉, 상기 비트 결정부(220)는 상기 제1 비트 영역의 비트 값 각각에 대한 배타적 논리합 연산을 수행하고, 상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정할 수 있다.
더욱 구체적으로 설명하면, 상기 비트 결정부(220)는 상기 배타적 논리합 연산을 수행한 결과 값을 연산자로 정의하고, 상기 연산자와 배타적 논리합 연산을 수행하는 비트 값을 피연산자로 정의할 때, 상기 연산자와 논리 연산한 결과 값이 원래의 비트 값과 동일하도록 하는 피연산자의 비트 값을 상기 제2 비트 영역의 비트 값으로 결정할 수 있다.
여기서, 상기 제2 비트 영역은 상기 확장 비트열 내 임의(random)의 위치에 배치될 수 있다. 즉, 상기 제2 비트 영역은 상기 확장 비트열의 앞이나 중간, 뒷부분 등과 같이 임의의 위치에 배치될 수 있다. 이를 위해, 상기 비트 결정부(220)는 난수표 등을 이용하여 상기 확장 비트열 내에서 상기 제2 비트 영역이 위치할 임의의 영역을 결정할 수 있다.
아래의 예는 상기 제2 비트 영역이 상기 확장 비트열의 마지막에 위치한다는 가정하에 설명하고 있으나, 이에 한정되지 않고 앞서 설명한 바와 같이 다른 위치에 위치할 수도 있음은 물론이다. 이처럼 상기 제2 비트 영역이 상기 확장 비트열 내 임의의 위치에 배치됨으로써 보안성이 높아질 수 있다.
예컨대, 상기 입력된 메시지의 이진 비트열이 위와 같이 '1100'이고 비트 확장 배수가 3이라고 가정한다. 이러한 경우, 상기 비트열 생성부(210)에 의해 상기 비트 값 각각에 대한 확장 비트열 중 첫 번째 비트와 두 번째 비트, 즉 제1 비트 영역이 '11', '01', '10', '11'과 같이 생성될 수 있다. 이에 따라, 상기 비트 결정부(220)는 상기 확장 비트열의 제2 비트 영역, 즉 마지막 비트 하나를 결정하게 되는데, 이때 상기 제1 비트 영역의 첫 번째 비트와 두 번째 비트의 배타적 논리합 연산(XOR)을 수행한 결과 값에 기초하여 '11', '01', '10', '11' 각각에 대해 '1', '0', '1', '0'을 마지막 비트로 결정할 수 있다.
다시 말해, 상기 비트 결정부(220)는 상기 배타적 논리합 연산을 수행한 결과 값과 배타적 논리합 연산을 수행하여 원래의 비트 값이 나오도록 하는 비트 값을 상기 확장 비트열의 제2 비트 영역의 비트 값으로 결정할 수 있다. 이로써, 상기 입력된 메시지의 이진 비트열로부터 선택된 각각의 비트 값 '1', '1', '0', '0'에 대한 확장 비트열은 '111', '010', '101', '110'으로 생성될 수 있다.
상기 비트열 조합부(230)는 상기 제1 비트 영역 및 상기 제2 비트 영역을 포함하는 확장 비트열을 각각 조합할 수 있다.
예를 들어, 상기 비트열 조합부(230)는 상기 생성된 각각의 확장 비트열 '111', '010', '101', '110' 각각을 조합할 수 있으며, 이에 따라 '111010101110'와 같은 이진 비트열을 출력함으로써 상기 메시지를 암호화할 수 있다.
도 3은 본 발명의 다른 실시예에 따른 비트 확장 방식을 이용한 암호화 장치를 설명하기 위해 도시한 블록도이다.
도 3을 참조하면, 본 발명의 다른 실시예에 따른 비트 확장 방식을 이용한 암호화 장치(300)는 외부 인코딩부(310), 및 내부 인코딩부(320)를 포함할 수 있다.
상기 외부 인코딩부(310)는 메시지를 입력받아 선형 부호화 알고리즘을 이용하여 부호화하는 역할을 한다. 여기서, 상기 선형 부호화 알고리즘은 해밍 부호화 알고리즘을 포함할 수 있다.
상기 내부 인코딩부(320)는 상기 외부 인코딩부(310)에 의해 부호화된 메시지를 입력받아 암호화를 수행하는 역할을 한다. 이를 위해, 상기 내부 인코딩부(320)는 비트 선택부(322), 확장 배수 결정부(324) 및 비트 확장 암호화부(326)를 포함할 수 있다.
상기 비트 선택부(322)는 상기 외부 인코딩부(310)에 의해 부호화된 메시지의 이진 비트열로부터 각각의 비트 값을 선택한다. 이를 위해, 상기 비트 선택부(322)는 상기 부호화된 메시지를 분석하여 이진 비트열을 추출하고, 상기 추출된 이진 비트열로부터 순차적으로 각각의 비트 값을 선택할 수 있다.
상기 확장 배수 결정부(324)는 상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정한다. 여기서, 상기 비트 확장 배수는 앞서 설명한 바와 같이 상기 비트 값 각각의 길이를 확장하기 위한 배수 값으로서, 상기 비트 확장 배수가 ℓ(2 이상의 자연수)일 경우, 상기 비트 값 각각은 ℓ비트의 길이로 확장될 수 있다.
이때, 상기 확장 배수 결정부(324)는 메시지의 길이와 보안성을 고려하여 상기 비트 확장 배수를 결정할 수 있다.
예컨대, 상기 확장 배수 결정부(324)는 암호화된 메시지를 전송할 전송 채널의 보안성에 따른 목표 정보 손실률을 결정하고, 상기 결정된 목표 정보 손실률에 기초하여 상기 비트 확장 배수를 결정할 수 있다. 또한, 상기 확장 배수 결정부(324)는 상기 암호화된 메시지를 전송할 전송 채널의 수를 고려하여 상기 비트 확장 배수를 결정할 수 있다. 또한, 상기 확장 배수 결정부(324)는 상기 암호화된 메시지를 전송할 전송 채널의 목표 전송량에 기초하여 상기 비트 확장 배수를 결정할 수 있다.
상기 비트 확장 암호화부(326)는 상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성한다.
즉, 상기 비트 확장 암호화부(326)는 상기 확장 배수 결정부(324)에 의해 결정된 비트 확장 배수 ℓ을 기준으로, 상기 복수의 난수를 이용하여 상기 확장 비트열을 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성할 수 있다.
상기 비트 확장 암호화부(326)는 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화할 수 있다.
도 4 내지 도 6은 본 발명의 일 실시예에 따른 비트 확장 방식을 이용한 암호화 방법을 설명하기 위해 도시한 흐름도이다.
먼저 도 1 및 도 4를 참조하면, 단계(410)에서 상기 암호화 장치(100)의 비트 선택부(110)는 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택한다.
다음으로, 단계(420)에서 상기 암호화 장치(100)의 확장 배수 결정부(120)는 상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정한다.
다음으로, 단계(430)에서 상기 암호화 장치(100)의 비트 확장 암호화부(130)는 상기 결정된 비트 확장 배수를 기준으로, 상기 복수의 난수를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성한다.
즉, 상기 암호화 장치(110)의 비트 확장 암호화부(130)는 상기 복수의 난수를 이용하여 상기 확장 비트열을 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성할 수 있다.
상기 단계(430)에 대해 도 5를 참조하여 상세히 설명하면 다음과 같다.
즉, 도 2 및 도 5를 참조하면, 단계(510)에서 상기 비트 확장 암호화부(130)의 비트열 생성부(210)는 상기 확장 비트열 중 제1 비트 영역을 상기 복수의 난수를 이용하여 생성한다.
이후, 단계(520)에서 상기 비트 확장 암호화부(130)의 비트 결정부(220)는 상기 생성된 제1 비트 영역의 비트 값 각각을 논리 연산한 결과 값에 기초하여, 상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정한다.
상기 단계(520)에 대해 도 6을 참조하여 상세히 설명하면 다음과 같다.
즉, 도 2 및 도 6을 참조하면, 단계(610)에서 상기 비트 확장 암호화부(130)의 비트 결정부(220)는 상기 제1 비트 영역의 비트 값 각각에 대한 배타적 논리합 연산을 수행한다.
이어서, 단계(620)에서 상기 비트 확장 암호화부(130)의 비트 결정부(220)는 상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정한다.
다시 말해서, 상기 배타적 논리합 연산을 수행한 결과 값을 연산자로 정의하고, 상기 연산자와 배타적 논리합 연산을 수행하는 비트 값을 피연산자로 정의할 때, 상기 비트 확장 암호화부(130)의 비트 결정부(220)는 상기 연산자와 논리 연산한 결과 값이 원래의 비트 값과 동일하도록 하는 피연산자의 비트 값을 상기 제2 비트 영역의 비트 값으로 결정할 수 있다.
여기서, 상기 제2 비트 영역은 상기 확장 비트열 내 임의의 위치에 배치될 수 있다. 예를 들어 상기 제2 비트 영역은 상기 확장 비트열 중 마지막 비트 하나를 포함하는 영역일 수 있다. 즉, 상기 확장 비트열이 '110'이라 가정하면, 복수의 난수를 이용하여 생성되는 상기 제1 비트 영역은 '11'이고, 상기 제1 비트 영역의 배타적 논리합 연산 수행 결과에 기초하여 결정되는 상기 제2 비트 영역은 '0'이라 할 수 있다.
다시 도 1 및 도 4를 참조하면, 단계(440)에서 상기 암호화 장치(100)의 비트 확장 암호화부(130)는 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화한다.
도 7은 본 발명의 다른 실시예에 따른 비트 확장 방식을 이용한 암호화 방법을 설명하기 위해 도시한 흐름도이다.
도 3 및 도 7을 참조하면, 단계(710)에서 상기 암호화 장치(300)의 외부 인코딩부(310)는 선형 부호화 알고리즘을 이용하여 입력된 메시지를 부호화 한다. 여기서, 상기 선형 부호화 알고리즘은 해밍 부호화 알고리즘을 포함할 수 있다.
다음으로, 상기 암호화 장치(300)의 내부 인코딩부(320)는 상기 외부 인코딩부(310)에 의해 부호화된 메시지를 입력받아 암호화를 수행한다.
즉, 먼저 단계(720)에서 상기 내부 인코딩부(320)의 비트 선택부(322)는 상기 부호화된 메시지의 이진 비트열로부터 각각의 비트 값을 선택한다.
이를 위해, 상기 내부 인코딩부(320)의 비트 선택부(322)는 상기 부호화된 메시지를 분석하여 이진 비트열을 추출하고, 상기 추출된 이진 비트열로부터 순차적으로 각각의 비트 값을 선택할 수 있다.
이후, 단계(730)에서 상기 내부 인코딩부(320)의 확장 배수 결정부(324)는 상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정한다.
여기서, 상기 비트 확장 배수는 상기 비트 값 각각의 길이를 확장하기 위한 배수 값으로서, 상기 비트 확장 배수가 ℓ(2 이상의 자연수)일 경우, 상기 비트 값 각각은 ℓ비트의 길이로 확장될 수 있다.
이후, 단계(740)에서 상기 내부 인코딩부(320)의 비트 확장 암호화부(326)는 상기 결정된 비트 확장 배수를 기준으로, 복수의 난수를 이용하여 상기 비트 값 각각의 길이를 확장하여 상기 확장 비트열을 생성한다.
여기서, 상기 확장 비트열은 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성될 수 있다.
이후, 단계(750)에서 상기 내부 인코딩부(320)의 비트 확장 암호화부(326)는 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화한다.
이와 같이, 본 발명의 일 실시예에서는 암호화하고자 하는 메시지의 비트 값의 길이를 확장하여 암호화함으로써 정보 전달 채널(주 전송 채널)의 보안성을 향상시킬 수 있으며, 이를 통해 도청 채널로의 정보 전달을 최소화하여 다양한 환경에서 목표된 정보 손실량을 보장할 수 있다.
또한, 본 발명의 일 실시예에서는 비트 길이의 확장 시 메시지의 길이와 보안성을 고려하여 비트 확장 배수를 결정함으로써, 정보 전달 채널로의 전송에 최적으로 확장된 길이의 비트로 메시지를 암호화할 수 있으며, 이를 통해 정보 전달 채널로 전송되는 메시지에 대한 보안성을 보다 향상시킬 수 있다.
또한, 본 발명의 일 실시예에서는 복수의 난수, 및 난수들과의 논리 연산을 통해 결정된 비트 값을 이용하여 비트 길이를 확장시킴으로써, 보안에 강하면서도 한정된 자원과 시간에서 효율적인 암호 및 복원이 가능하도록 할 수 있다.
본 발명의 실시예들은 다양한 컴퓨터로 구현되는 동작을 수행하기 위한 프로그램 명령을 포함하는 컴퓨터 판독 가능 매체를 포함한다. 상기 컴퓨터 판독 가능 매체는 프로그램 명령, 로컬 데이터 파일, 로컬 데이터 구조 등을 단독으로 또는 조합하여 포함할 수 있다. 상기 매체는 본 발명을 위하여 특별히 설계되고 구성된 것들이거나 컴퓨터 소프트웨어 당업자에게 공지되어 사용 가능한 것일 수도 있다. 컴퓨터 판독 가능 기록 매체의 예에는 하드 디스크, 플로피 디스크 및 자기 테이프와 같은 자기 매체, CD-ROM, DVD와 같은 광기록 매체, 플롭티컬 디스크와 같은 자기-광 매체, 및 롬, 램, 플래시 메모리 등과 같은 프로그램 명령을 저장하고 수행하도록 특별히 구성된 하드웨어 장치가 포함된다. 프로그램 명령의 예에는 컴파일러에 의해 만들어지는 것과 같은 기계어 코드뿐만 아니라 인터프리터 등을 사용해서 컴퓨터에 의해서 실행될 수 있는 고급 언어 코드를 포함한다.
지금까지 본 발명에 따른 구체적인 실시예에 관하여 설명하였으나, 본 발명의 범위에서 벗어나지 않는 한도 내에서는 여러 가지 변형이 가능함은 물론이다. 그러므로, 본 발명의 범위는 설명된 실시예에 국한되어 정해져서는 안 되며, 후술하는 특허 청구의 범위뿐 아니라 이 특허 청구의 범위와 균등한 것들에 의해 정해져야 한다.
이상과 같이 본 발명은 비록 한정된 실시예와 도면에 의해 설명되었으나, 본 발명은 상기의 실시예에 한정되는 것은 아니며, 이는 본 발명이 속하는 분야에서 통상의 지식을 가진 자라면 이러한 기재로부터 다양한 수정 및 변형이 가능하다. 따라서, 본 발명 사상은 아래에 기재된 특허청구범위에 의해서만 파악되어야 하고, 이의 균등 또는 등가적 변형 모두는 본 발명 사상의 범주에 속한다고 할 것이다.
[부호의 설명]
110, 322: 비트 선택부
120, 324: 확장 배수 결정부
130, 326: 비트 확장 암호화부
210: 비트열 생성부
220: 비트 결정부
230: 비트열 조합부
310: 외부 인코딩부
320: 내부 인코딩부
Claims (24)
- 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택하는 비트 선택부; 및상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성하고, 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화하는 비트 확장 암호화부를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제1항에 있어서,상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정하는 확장 배수 결정부를 더 포함하고,상기 비트 확장 암호화부는상기 결정된 비트 확장 배수를 기준으로, 상기 복수의 난수를 이용하여 상기 확장 비트열을 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제2항에 있어서,상기 비트 확장 암호화부는상기 확장 비트열 중 제1 비트 영역을 상기 복수의 난수를 이용하여 생성하는 비트열 생성부;상기 생성된 제1 비트 영역의 비트 값 각각을 논리 연산한 결과 값에 기초하여, 상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정하는 비트 결정부; 및상기 제1 및 제2 비트 영역을 포함하는 상기 확장 비트열을 각각 조합하는 비트열 조합부를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제3항에 있어서,상기 비트 결정부는상기 제1 비트 영역의 비트 값 각각에 대한 배타적 논리합 연산을 수행하고, 상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제4항에 있어서,상기 비트 결정부는상기 배타적 논리합 연산을 수행한 결과 값을 연산자로 정의하고, 상기 연산자와 배타적 논리합 연산을 수행하는 비트 값을 피연산자로 정의할 때, 상기 연산자와 논리 연산한 결과 값이 원래의 비트 값과 동일하도록 하는 피연산자의 비트 값을 상기 제2 비트 영역의 비트 값으로 결정하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제3항 내지 제5항 중 어느 한 항에 있어서,상기 제2 비트 영역은상기 확장 비트열 내 임의의 위치에 배치되는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제2항에 있어서,상기 확장 배수 결정부는메시지의 길이와 보안성을 고려하여 상기 비트 확장 배수를 결정하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제7항에 있어서,상기 확장 배수 결정부는상기 암호화된 메시지를 전송할 전송 채널의 보안성에 따른 목표 정보 손실률을 결정하고, 상기 결정된 목표 정보 손실률에 기초하여 상기 비트 확장 배수를 결정하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제7항에 있어서,상기 확장 배수 결정부는상기 암호화된 메시지를 전송할 전송 채널의 수를 고려하여 상기 비트 확장 배수를 결정하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제7항에 있어서,상기 확장 배수 결정부는상기 암호화된 메시지를 전송할 전송 채널의 목표 전송량에 기초하여 상기 비트 확장 배수를 결정하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제1항에 있어서,선형 부호화 알고리즘을 이용하여 상기 입력된 메시지를 부호화하는 외부 인코딩부를 더 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 제11항에 있어서,상기 선형 부호화 알고리즘은해밍 부호화 알고리즘을 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 장치.
- 암호화 장치의 비트 선택부에서, 입력된 메시지의 이진 비트열로부터 각각의 비트 값을 선택하는 단계;상기 암호화 장치의 비트 확장 암호화부에서, 상기 선택된 비트 값 각각에 대해서, 복수의 난수(random number)를 이용하여 상기 비트 값 각각의 길이를 확장하여 확장 비트열을 생성하는 단계; 및상기 암호화 장치의 비트 확장 암호화부에서, 상기 생성된 확장 비트열 각각을 조합하여 상기 메시지를 암호화하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제13항에 있어서,상기 암호화 장치의 확장 배수 결정부에서, 상기 비트 값 각각의 길이를 확장하기 위한 비트 확장 배수를 결정하는 단계를 더 포함하고,상기 확장 비트열을 생성하는 단계는상기 결정된 비트 확장 배수를 기준으로, 상기 복수의 난수를 이용하여 상기 확장 비트열을 상기 비트 확장 배수에 대응하는 길이의 비트열로 생성하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제14항에 있어서,상기 확장 비트열을 생성하는 단계는상기 비트 확장 암호화부의 비트열 생성부에서, 상기 확장 비트열 중 제1 비트 영역을 상기 복수의 난수를 이용하여 생성하는 단계; 및상기 비트 확장 암호화부의 비트 결정부에서, 상기 생성된 제1 비트 영역의 비트 값 각각을 논리 연산한 결과 값에 기초하여, 상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정하는 단계를 포함하고,상기 메시지를 암호화하는 단계는상기 비트 확장 암호화부의 비트열 조합부에서, 상기 제1 및 제2 비트 영역을 포함하는 상기 확장 비트열을 각각 조합하여 상기 메시지를 암호화하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제15항에 있어서,상기 확장 비트열 중 제2 비트 영역의 비트 값을 결정하는 단계는상기 제1 비트 영역의 비트 값 각각에 대한 배타적 논리합 연산을 수행하는 단계; 및상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제16항에 있어서,상기 배타적 논리합 연산을 수행한 결과 값을 연산자로 정의하고, 상기 연산자와 배타적 논리합 연산을 수행하는 비트 값을 피연산자로 정의할 때,상기 배타적 논리합 연산의 수행 결과에 기초하여 상기 제2 비트 영역의 비트 값을 결정하는 단계는상기 연산자와 논리 연산한 결과 값이 원래의 비트 값과 동일하도록 하는 피연산자의 비트 값을 상기 제2 비트 영역의 비트 값으로 결정하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제15항 내지 제17항 중 어느 한 항에 있어서,상기 제2 비트 영역은상기 확장 비트열 내 임의의 위치에 배치되는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제14항에 있어서,상기 비트 확장 배수를 결정하는 단계는메시지의 길이와 보안성을 고려하여 상기 비트 확장 배수를 결정하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제19항에 있어서,상기 비트 확장 배수를 결정하는 단계는상기 암호화된 메시지를 전송할 전송 채널의 보안성에 따른 목표 정보 손실률을 결정하는 단계; 및상기 결정된 목표 정보 손실률에 기초하여 상기 비트 확장 배수를 결정하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제19항에 있어서,상기 비트 확장 배수를 결정하는 단계는상기 암호화된 메시지를 전송할 전송 채널의 수를 고려하여 상기 비트 확장 배수를 결정하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제19항에 있어서,상기 비트 확장 배수를 결정하는 단계는상기 암호화된 메시지를 전송할 전송 채널의 목표 전송량에 기초하여 상기 비트 확장 배수를 결정하는 단계를 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제13항에 있어서,암호화 장치의 외부 인코딩부에서, 선형 부호화 알고리즘을 이용하여 상기 입력된 메시지를 부호화하는 단계를 더 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
- 제23항에 있어서,상기 선형 부호화 알고리즘은해밍 부호화 알고리즘을 포함하는 것을 특징으로 하는 비트 확장 방식을 이용한 암호화 방법.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2014-0026104 | 2014-03-05 | ||
| KR1020140026104A KR101553148B1 (ko) | 2014-03-05 | 2014-03-05 | 비트 확장 방식을 이용한 암호화 장치 및 방법 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2015133687A1 true WO2015133687A1 (ko) | 2015-09-11 |
Family
ID=54055466
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2014/007775 Ceased WO2015133687A1 (ko) | 2014-03-05 | 2014-08-21 | 비트 확장 방식을 이용한 암호화 장치 및 방법 |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR101553148B1 (ko) |
| WO (1) | WO2015133687A1 (ko) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR102653018B1 (ko) | 2019-01-16 | 2024-03-29 | 삼성전자주식회사 | 랜덤 넘버를 이용하여 나머지 연산을 수행하는 보안 프로세서 및 이의 동작 방법 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20000016261A (ko) * | 1997-04-02 | 2000-03-25 | 알렉산드르 안드레비치 몰도비안 | 이진 코드 정보의 암호화 방법_ |
| KR20020005438A (ko) * | 2001-07-03 | 2002-01-17 | 남궁석 | 암호화 처리장치 그 방법 |
| KR20040088352A (ko) * | 2003-04-01 | 2004-10-16 | 마이크로소프트 코포레이션 | 확장형 멀티미디어에 대한 완전 확장형 암호화 방법 및 장치 |
-
2014
- 2014-03-05 KR KR1020140026104A patent/KR101553148B1/ko not_active Expired - Fee Related
- 2014-08-21 WO PCT/KR2014/007775 patent/WO2015133687A1/ko not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20000016261A (ko) * | 1997-04-02 | 2000-03-25 | 알렉산드르 안드레비치 몰도비안 | 이진 코드 정보의 암호화 방법_ |
| KR20020005438A (ko) * | 2001-07-03 | 2002-01-17 | 남궁석 | 암호화 처리장치 그 방법 |
| KR20040088352A (ko) * | 2003-04-01 | 2004-10-16 | 마이크로소프트 코포레이션 | 확장형 멀티미디어에 대한 완전 확장형 암호화 방법 및 장치 |
Non-Patent Citations (1)
| Title |
|---|
| RYU, DONG RYEOL ET AL.: "Bit-sliced Modular Multiplication Algorithm and Implementation", JOURNAL OF THE KOREA INSTITUTE OF INFORMATION SECURITY AND CRYPTOLOGY, vol. 10, no. 3, September 2000 (2000-09-01) * |
Also Published As
| Publication number | Publication date |
|---|---|
| KR101553148B1 (ko) | 2015-09-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2016039556A1 (en) | Apparatus and method for data encryption | |
| WO2014069778A1 (ko) | 아이디 기반 암호화, 복호화 방법 및 이를 수행하기 위한 장치 | |
| WO2020022598A1 (ko) | 암호문에 대한 근사 연산을 수행하는 장치 및 방법 | |
| US10740497B2 (en) | System and method for cryptographic processing in a time window | |
| CN114520727B (zh) | 安全芯片数据防护方法及系统 | |
| KR100991222B1 (ko) | 암호화 및 복호를 위한 장치, 방법 및 기록 매체 | |
| WO2024077857A1 (zh) | 数据传输方法和装置、设备及存储介质 | |
| CN110071943A (zh) | 密钥真随机变化的复合型高安全ip保密通信方法 | |
| JPH0728407A (ja) | 暗号における暗号化前処理装置および復号後処理装 置 | |
| CN108494554A (zh) | 一种基于双明文的数据对称加密方法 | |
| JP2024545040A (ja) | リンク暗号化のための自動鍵ローリング | |
| US20060126827A1 (en) | Encryption methods and apparatus | |
| WO2015133687A1 (ko) | 비트 확장 방식을 이용한 암호화 장치 및 방법 | |
| WO2011111981A2 (ko) | 데이터 자동 암복호화 방법 및 장치 | |
| WO2021025185A1 (ko) | 안티-인버전 함수를 이용한 화이트박스 암호 인코딩 장치 및 방법 | |
| CN117592071A (zh) | 数据加密、数据解密、异常定位方法以及装置 | |
| Madani et al. | Enhancement of A5/1 Stream Cipher Overcoming its Weaknesses | |
| CN113852456A (zh) | 一种基于Matlab的混沌映射和特征提取的图像加密系统 | |
| CN112235789A (zh) | 一种中断可恢复保密通信处理方法、装置和系统 | |
| CN111934864A (zh) | 基于密钥熔合变换的秘密通信方法 | |
| CN117675328B (zh) | Mipi报文加解密的方法和装置 | |
| WO2019050343A1 (ko) | 화이트박스 암호가 적용된 블록 암호 기반의 난수 생성 방법 및 장치 | |
| Huang et al. | A block cipher mode of operation with two keys | |
| Ahmad et al. | Attack Robustness and Security Enhancement with Improved Wired Equivalent Protocol | |
| WO2024034733A1 (ko) | 영상 패킷의 암호화를 지원하는 네트워크 시스템, 장치 및 그 방법 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 14884776 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 14884776 Country of ref document: EP Kind code of ref document: A1 |