WO2019014336A1 - Entwined encryption and error correction - Google Patents

Entwined encryption and error correction Download PDF

Info

Publication number
WO2019014336A1
WO2019014336A1 PCT/US2018/041623 US2018041623W WO2019014336A1 WO 2019014336 A1 WO2019014336 A1 WO 2019014336A1 US 2018041623 W US2018041623 W US 2018041623W WO 2019014336 A1 WO2019014336 A1 WO 2019014336A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
polynomials
transformed
entwined
cipher
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2018/041623
Other languages
French (fr)
Inventor
Anna M. Johnston
Bishara SHAMEE
Steven R. Wilkinson
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Raytheon Co
Original Assignee
Raytheon Co
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Raytheon Co filed Critical Raytheon Co
Publication of WO2019014336A1 publication Critical patent/WO2019014336A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • H04L9/0625Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation with splitting of the data block into left and right halves, e.g. Feistel based algorithms, DES, FEAL, IDEA or KASUMI
    • HELECTRICITY
    • H03ELECTRONIC CIRCUITRY
    • H03MCODING; DECODING; CODE CONVERSION IN GENERAL
    • H03M13/00Coding, decoding or code conversion, for error detection or error correction; Coding theory basic assumptions; Coding bounds; Error probability evaluation methods; Channel models; Simulation or testing of codes
    • H03M13/03Error detection or forward error correction by redundancy in data representation, i.e. code words containing more digits than the source words
    • HELECTRICITY
    • H03ELECTRONIC CIRCUITRY
    • H03MCODING; DECODING; CODE CONVERSION IN GENERAL
    • H03M13/00Coding, decoding or code conversion, for error detection or error correction; Coding theory basic assumptions; Coding bounds; Error probability evaluation methods; Channel models; Simulation or testing of codes
    • H03M13/03Error detection or forward error correction by redundancy in data representation, i.e. code words containing more digits than the source words
    • H03M13/05Error detection or forward error correction by redundancy in data representation, i.e. code words containing more digits than the source words using block codes, i.e. a predetermined number of check bits joined to a predetermined number of information bits
    • H03M13/13Linear codes
    • H03M13/15Cyclic codes, i.e. cyclic shifts of codewords produce other codewords, e.g. codes defined by a generator polynomial, Bose-Chaudhuri-Hocquenghem [BCH] codes
    • H03M13/151Cyclic codes, i.e. cyclic shifts of codewords produce other codewords, e.g. codes defined by a generator polynomial, Bose-Chaudhuri-Hocquenghem [BCH] codes using error location or error correction polynomials
    • HELECTRICITY
    • H03ELECTRONIC CIRCUITRY
    • H03MCODING; DECODING; CODE CONVERSION IN GENERAL
    • H03M13/00Coding, decoding or code conversion, for error detection or error correction; Coding theory basic assumptions; Coding bounds; Error probability evaluation methods; Channel models; Simulation or testing of codes
    • H03M13/63Joint error correction and other techniques
    • HELECTRICITY
    • H03ELECTRONIC CIRCUITRY
    • H03MCODING; DECODING; CODE CONVERSION IN GENERAL
    • H03M13/00Coding, decoding or code conversion, for error detection or error correction; Coding theory basic assumptions; Coding bounds; Error probability evaluation methods; Channel models; Simulation or testing of codes
    • H03M13/65Purpose and implementation aspects
    • H03M13/6508Flexibility, adaptability, parametrability and configurability of the implementation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/008Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols involving homomorphic encryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/065Encryption by serially and continuously modifying data stream elements, e.g. stream cipher systems, RC4, SEAL or A5/3
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0861Generation of secret information including derivation or calculation of cryptographic keys or passwords
    • H04L9/0869Generation of secret information including derivation or calculation of cryptographic keys or passwords involving random numbers or seeds
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • H04L9/3006Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters
    • H04L9/3026Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters details relating to polynomials generation, e.g. generation of irreducible polynomials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • H04L9/3006Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters
    • H04L9/3033Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy underlying computational problems or public-key parameters details relating to pseudo-prime or prime number generation, e.g. primality test
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/30Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy
    • H04L9/3093Public key, i.e. encryption algorithm being computationally infeasible to invert or user's encryption keys not requiring secrecy involving Lattices or polynomial equations, e.g. NTRU scheme
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/34Encoding or coding, e.g. Huffman coding or error correction
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/46Secure multiparty computation, e.g. millionaire problem

Definitions

  • Embodiments discussed herein regard devices, systems, and methods for encrypting and encoding data.
  • One or more embodiments can include error correction and/or data verification abilities.
  • Encrypting data obfuscates data to an entity that intercepts the data.
  • the intended information is generally referred to as plaintext.
  • the encrypted inforniation is ciphertext.
  • An authorized receiver of the ciphertext can generally decrypt the ciphertext to recover the plaintext,
  • Error detection is an ability to determine whether the plaintext recovered at the receiver is the intended plaintext.
  • Error correction is the ability to determine the intended plaintext if an error is present in the recovered plaintext.
  • FIG. 1 illustrates, by way of example, a schematic diagram of an embodiment of a system.
  • FIG. 2 illustrates, by way of example, a schematic diagram of an embodiment of data being split into words.
  • FIG. 3 illustrates, by way of example, a diagram of an
  • FIG. 4 illustrates, by way of example, a diagram of an
  • FIG. 5 illustrates, by way of example, a graph 500 of error rate versus energy for a variety of encoding techniques.
  • FIG. 6 illustrates, by way of example, a block diagram of an embodiment of a machine on which one or more of the methods as discussed herein can be implemented.
  • Embodiments in this disclosure generally relate to encoding schemes that provide error correction and/or error detection and encryption capabilities, sometimes referred to as entwined encryption.
  • the encodings discussed herein encrypt data and allow portions of the encrypted data to be lost or altered between a sender and a receiver, such as in a medium, while still being able to recreate the original data at the receiver.
  • ECE Entwined Cryptographic Encoding
  • a stream cipher e.g., a cipher from the e STREAM collection, from the European Network of Excellence in
  • ECE is flexible, allowing for different word sizes, plaintext and ciphertext block sizes, and varying error correction capabilities.
  • the system can be designed with no, minimal, and large error correction capabilities.
  • An amount of overhead required per error is about equivalent to the overhead in Reed- Solomon encoding.
  • ECE was designed so that not all ciphertext is needed for decryption. If a minimum number of ciphertext words are recovered, plaintext can be recovered.
  • 2r text words and 2s key words represent a reduction of a degree v(n - 1) polynomial over F2, modulo 2(r + s) relatively prime polynomials in M of degree v.
  • the key stream determines the moduli as well as the 2s key words.
  • Encryption and encoding are accomplished by swapping one set of moduli for another, leaving the underlying v(n - J) degree polynomial unchanged.
  • Entwined encryption even if a cryptography key is broken, the data remains secure unless enough data blocks (of the original data) are recovered. Entwined encryption may improve diffusion of data in a
  • FIG. 1 illustrates, by way of example, a schematic diagram of an embodiment of a system 100
  • the system 100 can be used for implementing encoding and decoding using an ECE technique. All the items upstream from encrypted encoded data 1 11 are part of ECE encryption. All the items downstream from encrypted encoded data 1 13 are part of ECE decryption. Key syncing can help the performance (in terms of an ability to decipher correct plaintext from ciphertext) of the system 100.
  • Data 101 is received at an entwined cryptographic encoder 102.
  • the data 101 is sometimes referred to as plaintext.
  • Other inputs to the entwined cryptographic encoder 102 include a crypto stream 105 and polynomials 109.
  • a key 103 is received at a key generator 104.
  • the key 103 is a seed variable or other initializing data that causes the key generator 104 to produce a stream of ciphertext.
  • the stream of ciphertext may be used to select polynomials from a polynomial table 106 (as indicated by polynomial selection 107) and as extra cipher words provided to the entwined cryptographic encoder 102 (as indicated by crypto stream 105).
  • the key generator 104 produces a cipher stream, such as using a cipher technique from eSTREAM or AES previously discussed, or another cipher stream.
  • the polynomial table 106 includes v-degree relatively prime polynomials in F2.
  • the polynomials in the polynomial table 106 can be indexed by root, with a primitive having index zero, and the remaining polynomials ordered by ascending root. The root and primitive notion is discussed further elsewhere herein.
  • the polynomial selector 107 provides the indexes of polynomials that are provided to the entwined cryptographic encoder 102 as polynomials 109.
  • the entwined cryptographic encoder 102 transforms the data 101 based on the polynomials 109 and the crypto stream 105. The result of the transform is encrypted encoded data 1 1 1. At least some of the operations performed by the entwined cryptographic encoder are discussed with regard to FIG. 3 and elsewhere herein.
  • a summary of the operations performed by the entwined cryptographic encoder 102 includes: receiving the data 101, the crypto stream 105, and the polynomials 109; creating data relations based on the data 101 and the polynomials 109; creating key relations based on the crypto stream 105 and the polynomials 109; initializing return relations based on the data 101, the crypto stream 105, and/or the polynomials 109; transforming data relations, weave extracting cipher words; and/or performing a weave transform to create the encrypted encoded data 111.
  • the encrypted encoded data 111 is provided to a receiver, such as through a medium 108.
  • the medium 108 can include a wired or wireless medium.
  • a wired medium includes a non-air medium (e.g., an optical fiber or conductive medium).
  • a wireless medium includes a signal provided through an air medium.
  • the signal provided to the medium (the encrypted encoded data J 11) may be different than the signal provided to the entwined encrypted decoder 112, as indicated by the encrypted encoded data 1 13.
  • the medium 108 can interact with and alter the encrypted encoded data 1 11, such as to drop a portion of the encrypted encoded data 1 1 1 and/or alter a value represented by the encrypted encoded data 111.
  • an entity may intercept the encrypted encoded data 1 1 as it is being transmitted through the medium 108 and alter the encrypted encoded data 1 1.
  • Each of the hosts 150A-150B can receive at least a portion of the encrypted encoded data 1 1 1.
  • Each of the hosts 150A-150B can fonvard their portion of the encrypted encoded data 1 1 1 as the encrypted encoded data 113.
  • the portions of the encrypted encoded data 11 1 can comprise disjoint subsets of the data 101, such as to include the entirety of the data 101 in encrypted encoded form. In such an embodiment, an entity would need to intercept all of the data from all of the hosts 150A-150B to recreate the data 101, assuming the keys and other encryption steps could be determined.
  • An entwined crypto decoder 112 can receive the encrypted encoded data 113, polynomials 121, and crypto stream 1 17.
  • the crypto stream 1 17 and polynomial selection 1 19 can be provided by a key generator 114.
  • the key generator 114 is another instantiation of the key generator 104, such that if a key 1 15 is the same as the key 103, the output of the key generator 104 is the same as the output of the key generator 14.
  • the polynomial table 116 similarly, is another instantiation of the polynomial table 106, such as to include polynomials indexed in the same manner.
  • the entwined cryptographic decoder 112 transforms the encrypted encoded data 1 13 into data 123 based on the polynomials 121 and the crypto stream 105.
  • the data 123 is the same as the data 101 if there are less than (or equal to) a maximum number of errors in the encrypted encoded data 1 13, The maximum number of errors is configurable and discussed elsewhere herein.
  • the result of the transform is the data 123.
  • the operations performed by the entwined cryptographic decoder 112 are discussed with regard to FIG. 4 and elsewhere herein.
  • a summary of the operations performed by the entwined cryptographic decoder 112 includes: receiving the encrypted encoded data 13, the crypto stream 117, and the polynomials 121; creating key relations based on the crypto stream 1 17 and the polynomials 121 ; initializing return relations based on the encrypted encoded data 1 3, the crypto stream 1 17, and/or the polynomials 121; performing a weave transform to create a possible version of the data 123; checking the created data 123 to determine if it is correct; if not correct, swapping words in the transformed encrypted encoded data; checking the swapped data to determine if correct; and if correct, providing the data 123 as plaintext to a receiver.
  • the 115 can be synced, such as to produce consistent keys.
  • the consistent keys can help ensure that the crypto streams 105 and 117 are consistent and/or the polynomial select data 1 19 and 107 are consistent. That is, for decoding the encrypted encoded data 111 that is encrypted based on the polynomial select data 107 and the crypto stream 105, the key generator 114, in providing a decryption process cipher stream, produces the same polynomial select data 1 19 as the polynomial seiect data 107 and crypto stream 1 17 as the crypto stream 105.
  • Syncing the keys can include providing a key generator sync signal 125, such as may indicate a start time, an acknowledge or the like, to indicate that each of the key generators 104 and 114 will produce the same bits for their respective cipher streams.
  • a key generator sync signal 125 such as may indicate a start time, an acknowledge or the like, to indicate that each of the key generators 104 and 114 will produce the same bits for their respective cipher streams.
  • One or more of the hosts 150A-150B may be similarly synced with the encoding device 130 and/or the decoding device 140.
  • FIG. 2 illustrates, by way of example, a schematic diagram of an embodiment of data 101 being split into words.
  • the data 101 is split into data blocks 203 A, 203B, 203C...203N.
  • Each of the data blocks 203A-203N can include 2r words.
  • Each of the data blocks 203 A-N is split into 2r words 205A, 205B, ... , and 205C.
  • Each of the words 205 A-C includes v bits including the bits 207 A, 207B, ... ,207V.
  • the entwined cryptographic encoder 102 can perform these data splitting operations to portion the data 101 to the proper level for processing.
  • FIG. 3 illustrates, by way of example, a diagram of an
  • the method 300 can be performed by the entwined cryptographic encoder 102.
  • the method 300 includes receiving data (to be encrypted and/or encoded), at operation 302; transforming the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomials stored on the memory; at operation 304;
  • the method 300 can further include producing, by key generator circuitry, a cipher stream of data based on a key.
  • the method 300 can further include, wherein the entwined encryption encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received cipher stream.
  • the method 300 can further include, wherein another portion of the cipher stream provides an index to the respective polynomials.
  • the method 300 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials.
  • the method can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoder circuitry, based on data from the cipher stream.
  • the method 300 can further include splitting the received data into blocks of v- bit words.
  • the operation 304 can further include transformation of the blocks of v-bits words individually.
  • the method 300 can further include, wherein v is a maximum degree of the polynomials in the memory.
  • the method 300 can further include, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be corrected, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and
  • FIG. 4 illustrates, by way of example, a diagram of an
  • the method 400 includes receiving encrypted, encoded data, at operation 402; performing a Da Yen weave transform on a portion the encrypted, encoded data, at operation 404, comparing the
  • the method 400 can further include providing the plaintext to a receiver.
  • the method 400 can further include in response to a
  • the method 400 can further include comparing the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version.
  • the method 400 can further include producing, by key generator circuitry, a cipher stream of data based on a key.
  • the operation 404 can include transforming the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received cipher stream.
  • the method 400 can further include, wherein another portion of the cipher stream provides an index to respective polynomials represented by respective polynomial integers.
  • the method 400 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials.
  • the method 400 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream.
  • the method 400 can further include, wherein, wherein, wherein v is a maximum degree of the polynomials in the memory, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, v-bit words from the cipher stream, wherein the number of polynomial s in the memoiy is 2*.
  • the methods 300 and 400 include encoding and decoding, respectively, and may be used together.
  • One or more of the methods 300 and 400 may include the following operations:
  • A) receive input word size, v, in bits wherein v is a power of two, such as ⁇ 8, 16, 32, 64, ... ⁇ (at entwined cryptographic encoder 102 and/or key generator 104).
  • C) generate 2sv bits (e.g., by key generator 104).
  • Each v-bit pointer is kj and points to a polynomial in the polynomial table. No two kj are equal.
  • a maximum value of kj includes a value less than (or equal to) 2 V -1.
  • 2n polynomials e.g., irreducible polynomials
  • K) receive cipher words Ci (e.g., by the entwined cryptographic decoder 112).
  • L) receive input word size, v, in bits wherein v is a power of two, such as ⁇ 8, 16, 32, 64, ... ⁇ (at entwined cryptographic decoder 1 12 and/or key generator 104).
  • M) generate 2sv bits (e.g., by key generator 114).
  • Each v-bit key is k ⁇ .
  • Each v-bit pointer is kj and points to a polynomial in the polynomial table. No two kj are equal.
  • a maximum value of kj includes a value less than (or equal to) 2 V -1.
  • ECE uses a Da Yen weave transform, and for that a few detimtions and some theory may be helpful.
  • a theorem used for the weave i s the Da Yen.
  • the Da Y ' en maps a set of relations to a single relation and back again.
  • a relation (d mod m) refers to a coset, or set of elements of the Euclidean domain. Because ECE considers real data and integers, unless stated otherwise, the relations here will always be in reduced form (e.g., ⁇ d ⁇ ⁇ ⁇ m ⁇ ).
  • may provide stability uniqueness of data as it moves between different rings (moduli).
  • the Da Yen (Chinese Remainder Theorem ) is an isomorphism between the direct product of factor rings and a single factor ring.
  • R and (R) R .
  • the general ring version of the Da Yen and its proof can be found elsewhere.
  • the following i s a presentation of Da Yen using relations. Let R be a set of relatively prime relations. Then there exists a mapping (and its inverse) from R to a relation (i? such that:
  • the Da Yen weave transform may compute the inner relations w t _ l5 such as without computing the large relation (jR t -i). After the w t ⁇ have been computed, the full relation can be computed with the result already in reduced form
  • A- R w 0 + w 0 (w, (... (w n __, + w n _ 2 w n . , .)) .
  • the weave encoding can use this relation evaluation process to convert a set of distinct relations I to a set J.
  • Equivalent sets enable decoding and the independence of encoded blocks. As long as an error free set of 2r encoded relations is recovered, the original plain text can be recovered. Any added relations can be used for error checking and correction.
  • a computational cost in serial is "divide" operations over i' 7 crank , Paralieiization can
  • Order does not matter in the set of relations R, but order does matter in the transformed set of Wj values.
  • Order can be important during the decoding process. For at least this reason, the ordering of the relations in R will be specified for each transform,
  • Input: i? ⁇ ui j 0 ⁇ j ⁇ n ⁇ , an ordered set of relatively prime relations and ⁇ a permutation on ⁇ 0, 1, 1 ⁇
  • ECE detects and corrects errors by assuming a col lection of 2r received relations are correct, computing the unused 2s relations and comparing them to the received values. If at least half of these relations are correct and at most s errors exist, then plain text can be extracted from the set.
  • R ⁇ 1 ⁇ 2 ⁇ , ⁇ + 3 ⁇ 4
  • 0 ⁇ k ⁇ n] be the set of n received values and their key-determined moduli
  • K [ ⁇ ,- j O ⁇ j ⁇ 2s ⁇ the set of 2s key relations.
  • the Da Yen weave transform of different sets of 2r elements can be computed using the weave transform, the swapping pairs of elements in and out, until either a set passes the checks or there are no more sets to check. If no good set is found, then too many errors exist to recover the plaintext.
  • Pairing relations can reduce a maximal number of sets to check from
  • Adjacent weave terms may be swapped with one multiply and one "divide” (e.g., compute an inverse and then multiply), and the permutation keeps track of swaps performed.
  • Swapping weave terms j and (j + 1) converts R n to R a where
  • W T ords of key may be generated using a stream cipher (e.g., a key used for encryption and/or encoding is the stream ciphers output).
  • a set of 2n or q irreducible polynomials of degree v over F2 may be determined.
  • ECE performs a ya den weave encoding using a mix of plaintext and key relations, in embodiments discussed herein, moduli of the relation sets can be determined from the stream cipher. Alternatively, keys and/or moduli may be otherwise randomly chosen.
  • A Generate 2v(s + n) bits of key stream from the supplied key generator.
  • the decoding process in ECE is like encoding in that a Da Yen weave transform is performed in decoding. If there are no errors and at least 2r correct relations, decoding can be performed. If (2r + 1) relations were received with at most t/2 errors, an error free set of 2r relations can be found and error free plaintext extracted.
  • a decoding technique can exhaust subsets of the received relations, such as by pairing adjacent relations. Such a technique may reduce computation time per subset, such as by performing the full transform only once and modifying the transform to match the new subset by performing a weave swap.
  • A Generate 2v(s + n) bits of key stream from the supplied key generator. Label the kev bits * ⁇ k t ⁇ 0 ⁇ j ⁇ 2s) , where k. is a v-h ⁇ t word of key;
  • nV etted nV etted — lvlVetted[lvl]
  • Example 4 Polynomial Ya Den Weave Transform
  • the swapped transform can be computed using the weave swap technique. Using the original weave:
  • Entwined encryption provides an implementer more freedom in implementation than other systems, which require a standard data block size. Many encoding schemes have rather strict restrictions on block size, but entwined encryption allows a user to vary a block size, such as based on their needs. [00136] Entwined encryption may provide a foundation for a quantum resistant public key cryptosystem. This is a new, important area of cryptography as all currently used public key systems are vulnerable to quantum attacks.
  • Multiplicative inverses (e.g., division) modulo these polynomials is a component of the ECE.
  • Inverses can be computed in several ways which are not covered here. These include many variants of the Euclidean algorithm as well as the Da Yen.
  • the following example encrypts/encodes a block of 24 bits (e.g., three 8-bit words) into five, 8-bit words. Plaintext bits are used as coefficients to a binary polynomial (an element of ⁇ ixj) with degree less than 24.
  • a key stream is provided by a key generator (e.g., a stream cipher), such as can include a randomizer with a seed (e.g., an internal secret seed). This key stream provides integers in the range of the id of the set of irreducible polynomials. In this
  • Decrypting and decoding using the given key integers uses a Da Yen weave transform.
  • the second technique can include an iterative technique, such as can be more computationally efficient than the first technique.
  • the iterative technique can follow these three formulas:
  • ffae2a0flc c3ba8b51 mod 1 13b9e5fd (Mo removed, S0 M2M3M4)
  • ffae2a0flc 23ab lf mod 101Oe905 (Mi removed, so 3 ⁇ 44W 4 )
  • FIG. 5 illustrates, by way of example, a graph 500 of error rate versus energy for a variety of encoding techniques.
  • the graph 500 includes uncoded data with added white Gaussian noise (AWGN) represented by line 506, data encoded using a Reed Solomon technique, represented by line 504, and data encoded using ECE, represented by line 502.
  • AWGN white Gaussian noise
  • FIG. 6 illustrates, by way of example, a block diagram of an embodiment of a machine 600 on which one or more of the methods, such as those discussed with regard to FIGS. 3 and 4 and elsewhere herein can be implemented.
  • one or more items of the system 100 can be implemented by the machine 600.
  • the machine 600 operates as a standalone device or may be connected (e.g., networked) to other machines.
  • the entwined cryptographic encoder 102, the poly table 106, the key generator 104, the entwined cryptographic decoder 112, the poly table 116, the key generator 1 14, the medium 108, the encoding device 130 (the transmitter device), and/or the decoding device 140 (the receiver device) can include one or more of the items of the machine 600.
  • the machine 600 may operate in the capacity of a server or a client machine in server-client network
  • the machine 600 may be a personal computer (PC), a tablet PC, a set-top box (STB), a Personal Digital Assistant (PDA), a cellular telephone, a web appliance, a network router, switch or bridge, or any machine capable of executing instructions (sequential or otherwise) that specify actions to be taken by that machine.
  • PC personal computer
  • PDA Personal Digital Assistant
  • STB set-top box
  • web appliance web appliance
  • network router switch or bridge
  • the example machine 800 includes processing circuitry 902 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an application specific integrated circuit, circuitry, such as one or more transistors, resistors, capacitors, inductors, diodes, logic gates, multiplexers, oscillators, buffers, modulators, regulators, amplifiers, demodulators, radios (e.g., transmit or receive radios or transceivers), sensors 621 (e.g., a transducer that converts one form of energy (e.g., light, heat, electrical, mechanical, or other energy) to another form of energy), or the like, or a combination thereof), a main memory 604 and a static memory 606, which communicate with each other via a bus 608,
  • the machine 600 e.g., computer system
  • the machine 600 also includes an al
  • the disk drive unit 616 includes a machine-readable medium 622 on which is stored one or more sets of instructions and data structures (e.g., software) 624 embodying or utilized by any one or more of the methodologies or functions described herein.
  • the instructions 624 may also reside, completely or at least partially, within the main memory 604 and/or within the processor 602 during execution thereof by the machine 600, the main memory 604 and the processor 602 also constituting machine-readable media.
  • the machine 600 as illustrated includes an output controller 628.
  • the output controller 628 manages data flow to/from the machine 600.
  • the output controller 628 is sometimes called a device controller, with software that directly interacts with the output controller 628 being called a device driver.
  • machine-readable medium 622 is shown in an example embodiment to be a single medium, the term “machine-readable medium” may include a single medium or multiple media (e.g., a centralized or distributed database, and/or associated caches and servers) that store the one or more instructions or data structures.
  • the term “machine-readable medium” shall also be taken to include any tangible medium that is capable of storing, encoding or carrying instructions for execution by the machine and that cause the machine to perform any one or more of the methodologies of the present invention, or that is capable of storing, encoding or carrying data structures utilized by or associated with such instructions.
  • the term “machine-readable medium” shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media.
  • machine-readable media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), and flash memory devices; magnetic disks such as internal hard disks and removable disks;
  • semiconductor memory devices e.g., Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), and flash memory devices
  • EPROM Erasable Programmable Read-Only Memory
  • EEPROM Electrically Erasable Programmable Read-Only Memory
  • flash memory devices e.g., electrically Erasable Programmable Read-Only Memory (EEPROM), and flash memory devices
  • EPROM Erasable Programmable Read-Only Memory
  • EEPROM Electrically Erasable Programmable Read-Only Memory
  • flash memory devices e.g., electrically Erasable Programmable Read-Only Memory (EEPROM), and flash memory devices
  • magneto-optical disks and CD-ROM and DVD-ROM disks.
  • the instructions 624 may further be transmitted or received over a communications network 626 using a transmission medium.
  • the instructions 624 may be transmitted using the network interface device 620 and any one of several well-known transfer protocols (e.g., HTTP).
  • Examples of communication networks include a local area network ("LAN”), a wide area network (“WAN”), the Internet, mobile telephone networks, Plain Old Telephone (POTS) networks, and wireless data networks (e.g., WiFi and WiMax networks).
  • LAN local area network
  • WAN wide area network
  • POTS Plain Old Telephone
  • WiFi and WiMax networks wireless data networks
  • transmission medium shall be taken to include any intangible medium that is capable of storing, encoding or carrying instructions for execution by the machine, and includes digital or analog communications signals or other intangible media to facilitate communication of such software.
  • Example 1 can include an entwined cryptographic encode device comprising a memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table, entwined cryptographic encoding circuitry to receive data, transform the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomial table, and perform a Da Yen weave on the transformed data based on received cipher data, and provide the weaved transformed data to a medium .
  • an entwined cryptographic encode device comprising a memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table, entwined cryptographic encoding circuitry to receive data, transform the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomial table, and perform a Da Yen weave on the transformed data based
  • Example 1 can further include ke generator circuitry to produce a cipher stream of data based on a key, and wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received cipher stream.
  • Example 2 can further include, wherein another portion of the cipher stream provides an index to the respective polynomials.
  • Example 4 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials.
  • Example 5 at least one of Examples 1-4 can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoding circuitry, based on data from the cipher stream.
  • Example 6 at l east one of Exampl es 1-5 can further include, wherein the entwined cryptographic encoding circuitry is further configured to split the received data into blocks of v-bit words, wherein the transformation of the data includes transformation of the blocks of v-bits words individually, and wherein v is a maximum degree of the polynomials in the memory.
  • Example 7 at least one of Example 1-6 can further include, wherein a number of r-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, v- bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
  • Example 8 includes an entwined cryptographic decode device comprising a memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table, entwined cryptographic decoding circuitry to receive encrypted, encoded data, perform a Da Yen weave transform on a portion the encrypted, encoded data, compare the transformed data to another portion of the encrypted, encoded data to determine if errors exist in the transformed data, in response to a
  • Example 9 further includes, wherein the entwined cryptographic decoding circuitry is further configured to in response to a determination that errors exist, perform a weave swap on two words of the transformed data, and compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version.
  • Example 9 can further include key generator circuitry to produce a cipher stream of data based on a key, and wherein the entwined cryptographic decoding circuitry is further configured to transform the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received cipher stream.
  • Example 10 can further include, wherein another portion of the cipher stream provides an index to respective polynomials represented by respective polynomial integers.
  • Example 1 1 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials.
  • Example 13 at least one of Examples 8-12 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream.
  • Example 14 at least one of Examples 8-13 can further include, wherein v is a m aximum degree of the polynomials in the memory, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, -bit words from the cipher stream, wherein the number of polynomials in the memor is 2 f .
  • an encryption and decryption system includes an entwined cryptographic encode device comprising a first memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a first polynomial table, entwined cryptographic encoding circuitry to receive data, transform the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomial table, perform a Da Yen weave on the transformed data based on received cipher data, and provide the weaved transformed data to a medium, and an entwined cryptographic decode device compri sing a second memory including data indicating the set of relatively prime, irreducible polynomials stored and indexed thereon in a second polynomial table, entwined cryptographic decoding circuitry to receive the encrypted, encoded data from the medium, perform a Da Yen weave transform on a first portion the encrypted, encoded data, compare the transformed data to a second
  • Example 15 may further include, wherein the entwined cryptographic encode device further includes first key generator circuitry to produce a first cipher stream of data based on a first key, and wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received first cipher stream, and the entwined cryptographic decode device further includes second key generator circuitry to produce a second cipher stream of data based on a second key, and wherein the entwined cryptographic decoding circuitry is further configured to transform the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received second cipher stream.
  • Example 16 can further include, wherein the first and second key generator circuitry are synced.
  • Example 18 at least one of Examples 16-17 can further include, wherein a portion of the first cipher stream provides an index to the respective polynomials on the first memory and wherein a portion of the second cipher stream provides an index to the respective polynomials on the second memory.
  • Example 18 can further include, wherein the polynomials on the first and second memories are indexed based on a respective root and primitive of the polynomials.
  • Example 20 at least one of Examples 16-19 can further include, wherein the entwined cryptographic decoding circuitry is further configured to, in response to a determination that errors exist, perform a weave swap on two words of the transformed data, and compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version.
  • Example 21 at least one of Examples 16-20 can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoder circuitry, based on data from the cipher stream.
  • Example 22 at least one of Examples 16-21 can further include, wherein the entwined encryption circuitry is further to split the received data into blocks of v-bit words, and transformation of the data includes transformation of the blocks of v-bits words individually, wherein v is a maximum degree of the polynomials in the memory.
  • Example 23 at least one of Examples 16-22 can further include, wherein a number of t-bit cipher words provided by the first and second cipher streams includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and
  • Example 24 at least one of Examples 16-23 can further include, wherein another portion of the first cipher stream provides an index to first respective polynomials represented by respective polynomial integers.
  • Example 25 at least one of Examples 16-24 can further include, wherein the first polynomials are indexed based on a respective root and primitive of the polynomials.
  • Example 26 at least one of Examples 16-25 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream.
  • Example 27 can include a method for entwined cryptographic encoding storing, on a memory, data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table, receiving data, at entwined cryptographic encoding circuitry, transforming the data to a set of data integers modulo respective polynomial integers
  • Example 27 can further include producing, using key generator circuitry, a cipher stream of data based on a key, and wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received cipher stream.
  • Example 29 can further include, wherein another portion of the cipher stream provides an index to the respective polynomials.
  • Example 30 at least one of Examples 27-29 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials.
  • Example 31 at least one of Examples 27-30 can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoding circuitry, based on data from the cipher stream .
  • Example 32 at least one of Examples 27-31 can further include splitting the received data into blocks of v-bit words, wherein the transformation of the data includes transformation of the blocks of v-bits words individually, and wherein v is a maximum degree of the polynomials in the memory.
  • Example 33 at least one of Example 27-32 can further include, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 25, v- bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
  • Example 34 includes a method of entwined cryptographic decoding including storing, on a memory, data indicating a set of relati vely prime, irreducible polynomials stored and indexed thereon in a polynomial table, receiving, at entwined cryptographic decoding circuitry, encrypted, encoded data, performing a Da Yen weave transform on a portion the encrypted, encoded data, comparing the transformed data to another portion of the encrypted, encoded data to determine if errors exist in the transformed data, in response to a determination that no errors exist, converting the error-free version of data to plaintext, and providing the plaintext to a receiver.
  • Example 34 further includes, in response to a determination that errors exi st, performing a weave swap on two words of the transformed data, and compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exi st in the weave swapped version.
  • Example 35 can further include producing, using key generator circuitiy, a cipher stream of data based on a key, and transforming the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received cipher stream.
  • Example 36 can further include, wherein another portion of the cipher stream provides an index to respective polynomials represented by respective polynomial integers.
  • Example 37 can further include, wherein the polynomials are indexed based on a respective root and primitivei ve of the polynomials.
  • Example 39 at least one of Examples 34-38 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream.
  • Example 40 at least one of Examples 34-39 can further include, wherein v is a maximum degree of the polynomials in the memory, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, v-bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
  • Example 41 can include a non-transitory machine-readable medium including instructions that, when executed by a machine, configure the machine to perform operations of the method of at least one of Examples 27-40.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • Probability & Statistics with Applications (AREA)
  • Mathematical Physics (AREA)
  • Pure & Applied Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Algebra (AREA)
  • Mathematical Optimization (AREA)
  • Mathematical Analysis (AREA)
  • Error Detection And Correction (AREA)
  • Storage Device Security (AREA)

Abstract

D'une manière générale, la présente invention concerne des systèmes, des dispositifs et des procédés de chiffrement entrelacé et de correction d'erreur et/ou de détection d'erreur. Un dispositif de codage cryptographique entrelacé peut consister à : une mémoire comprenant des données indiquant un ensemble de polynômes irréductibles relativement premiers stockés et indexés sur celui-ci, des circuits de codage de chiffrement entrelacés pour recevoir des données, transformer les données en un ensemble de nombres entiers de données modulo des entiers polynomiaux respectifs représentatifs de polynômes respectifs des polynômes stockés sur la mémoire, et effectuer un tissage Da Yen sur les données transformées sur la base de données de chiffrement reçues, et fournir les données transformées tissées à un support.In general, the present invention relates to systems, devices and methods for interleaving encryption and error correction and / or error detection. An interleaved cryptographic coding device may consist of: a memory comprising data indicating a set of relatively early irreducible polynomials stored and indexed thereto, interleaved encryption coding circuits for receiving data, transforming the data into a set of integers of modulo data of the respective polynomial integers representative of respective polynomials of the polynomials stored on the memory, and weaving Da Yen on the transformed data on the basis of received cipher data, and providing the woven transformed data to a medium.

Description

ENTWINED ENCRYPTION AND ERROR CORRECTION
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This patent application claims the benefit of priority to U. S.
Application Serial No. 15/667,111, filed August 2, 2017, which application claims the benefit of priority to U.S. Provisional Patent Application No.
62/532,563, filed July 14, 2017, entitled "ENTWINED ENCRYPTION AND ERROR C RRECTION", which are incorporated by reference herein in their entirety.
TECHNICAL FIELD
[0002] Embodiments discussed herein regard devices, systems, and methods for encrypting and encoding data. One or more embodiments can include error correction and/or data verification abilities.
BACKGROUND
[0003] Encrypting data obfuscates data to an entity that intercepts the data. The intended information is generally referred to as plaintext. The encrypted inforniation is ciphertext. An authorized receiver of the ciphertext can generally decrypt the ciphertext to recover the plaintext,
[0004] Error detection is an ability to determine whether the plaintext recovered at the receiver is the intended plaintext. Error correction is the ability to determine the intended plaintext if an error is present in the recovered plaintext.
[0005] Previous encryption techniques do not provide an inherent and flexible ability to detect and/or correct errors in recovered plaintext.
BRIEF DESCRIPTION OF THE DRAWINGS
[0006] In the drawings, which are not necessarily drawn to scale, like numerals can describe similar components in different views. Like numerals having different letter suffixes can represent different instances of similar components. The drawings illustrate generally, by way of example, but not by way of limitation, various embodiments or examples discussed in the present document.
[0007] FIG. 1 illustrates, by way of example, a schematic diagram of an embodiment of a system.
[0008] FIG. 2 illustrates, by way of example, a schematic diagram of an embodiment of data being split into words.
[0009] FIG. 3 illustrates, by way of example, a diagram of an
embodiment of a method for performing an entwined cryptographic encoding.
[0010] FIG. 4 illustrates, by way of example, a diagram of an
embodiment of a method for performing an entwined cryptographic decoding.
[0011] FIG. 5 illustrates, by way of example, a graph 500 of error rate versus energy for a variety of encoding techniques.
[0012] FIG. 6 illustrates, by way of example, a block diagram of an embodiment of a machine on which one or more of the methods as discussed herein can be implemented.
DETAILED DESCRIPTION
[0013] Embodiments in this disclosure generally relate to encoding schemes that provide error correction and/or error detection and encryption capabilities, sometimes referred to as entwined encryption. The encodings discussed herein encrypt data and allow portions of the encrypted data to be lost or altered between a sender and a receiver, such as in a medium, while still being able to recreate the original data at the receiver.
[0014] Some cryptographic systems convert data from plaintext to equally sized ciphertext (equal in number of bits occupied by the plaintext and ciphertext). These systems may offer no integrity for lost or corrupted data, generally have no secondary protection in case of compromised cryptovariable (key), and are not generally homomorphic. That is, operations on plaintext are not possible in their encrypted form. Entwined Cryptographic Encoding (ECE), a cryptographic technique discussed herein takes a different path, with more flexibility, homomorphic properties, and the ability to add data integrity (e.g., error detection and/or error correction abilities). [0015] ECE converts a block of data into many independent words of cipher. On their own these pieces are secure; even if the piece of data and the cryptographic key were compromised, no information about the plaintext data would be revealed. Further, the system has error detection and/or error correction capabilities; errors can be detected and/or corrected. In ECE individual ciphertext pieces may be lost without any loss to the original data.
[0016] This is possible by Da Yen, sometimes referred to as the Chinese
Remainder Theorem, and implemented using a stream cipher (e.g., a cipher from the e STREAM collection, from the European Network of Excellence in
Cryptology (ECRYPT), Advanced Enciyption Standard (AES) in counter mode, from the United States Institute of Standards and Technology (NIST), or other stream cipher) and a data transformation technique referred to as a weave,
[0017] ECE is flexible, allowing for different word sizes, plaintext and ciphertext block sizes, and varying error correction capabilities. The system can be designed with no, minimal, and large error correction capabilities. An amount of overhead required per error is about equivalent to the overhead in Reed- Solomon encoding. ECE was designed so that not all ciphertext is needed for decryption. If a minimum number of ciphertext words are recovered, plaintext can be recovered.
[0018] The following variables are used to tailor the system to a users' needs; a set, M, of irreducible polynomials of degree v, 2r plaintext words in a block of data, a maximal number of errors that may be corrected, s, and n cipher words, where // ------ 2(r ÷ s).
[0019] 2r text words and 2s key words represent a reduction of a degree v(n - 1) polynomial over F2, modulo 2(r + s) relatively prime polynomials in M of degree v. The key stream determines the moduli as well as the 2s key words.
Encryption and encoding are accomplished by swapping one set of moduli for another, leaving the underlying v(n - J) degree polynomial unchanged.
[0020] Using the Da Yen weave transform (discussed elsewhere), words of data can be efficiently mixed with key and moduli into cipher words. Only operations in Fzv are necessary. Decoding/decryption can use the same transformation as encoding but with different moduli. Using theoretical tools similar to those used in Reed-Solomon coding, the overdetermined nature of the system allows errors to be detected and corrected.
[0021] Using entwined encryption, even if a cryptography key is broken, the data remains secure unless enough data blocks (of the original data) are recovered. Entwined encryption may improve diffusion of data in a
cryptosystem. If any bit of input data is modified, every bit of the resulting output has about a fifty percent chance of flipping (e.g., from a logical "1" to a logical "0" or vice versa). Other encryption techniques have no such diffusion. By entwining error correction and encryption in a manner discussed herein, the security of the cryptosystem may be improved.
[0022] FIG. 1 illustrates, by way of example, a schematic diagram of an embodiment of a system 100, The system 100 can be used for implementing encoding and decoding using an ECE technique. All the items upstream from encrypted encoded data 1 11 are part of ECE encryption. All the items downstream from encrypted encoded data 1 13 are part of ECE decryption. Key syncing can help the performance (in terms of an ability to decipher correct plaintext from ciphertext) of the system 100.
[0023] Data 101 is received at an entwined cryptographic encoder 102.
The data 101 is sometimes referred to as plaintext. Other inputs to the entwined cryptographic encoder 102 include a crypto stream 105 and polynomials 109.
[0024] A key 103 is received at a key generator 104. The key 103 is a seed variable or other initializing data that causes the key generator 104 to produce a stream of ciphertext. The stream of ciphertext may be used to select polynomials from a polynomial table 106 (as indicated by polynomial selection 107) and as extra cipher words provided to the entwined cryptographic encoder 102 (as indicated by crypto stream 105). The key generator 104 produces a cipher stream, such as using a cipher technique from eSTREAM or AES previously discussed, or another cipher stream.
[0025] The polynomial table 106 includes v-degree relatively prime polynomials in F2. The polynomials in the polynomial table 106 can be indexed by root, with a primitive having index zero, and the remaining polynomials ordered by ascending root. The root and primitive notion is discussed further elsewhere herein. The polynomial selector 107 provides the indexes of polynomials that are provided to the entwined cryptographic encoder 102 as polynomials 109.
[0026] The entwined cryptographic encoder 102 transforms the data 101 based on the polynomials 109 and the crypto stream 105. The result of the transform is encrypted encoded data 1 1 1. At least some of the operations performed by the entwined cryptographic encoder are discussed with regard to FIG. 3 and elsewhere herein. A summary of the operations performed by the entwined cryptographic encoder 102 includes: receiving the data 101, the crypto stream 105, and the polynomials 109; creating data relations based on the data 101 and the polynomials 109; creating key relations based on the crypto stream 105 and the polynomials 109; initializing return relations based on the data 101, the crypto stream 105, and/or the polynomials 109; transforming data relations, weave extracting cipher words; and/or performing a weave transform to create the encrypted encoded data 111.
[0027] The encrypted encoded data 111 is provided to a receiver, such as through a medium 108. The medium 108 can include a wired or wireless medium. A wired medium includes a non-air medium (e.g., an optical fiber or conductive medium). A wireless medium includes a signal provided through an air medium. The signal provided to the medium (the encrypted encoded data J 11) may be different than the signal provided to the entwined encrypted decoder 112, as indicated by the encrypted encoded data 1 13. The medium 108 can interact with and alter the encrypted encoded data 1 11, such as to drop a portion of the encrypted encoded data 1 1 1 and/or alter a value represented by the encrypted encoded data 111. In one or more instances, an entity may intercept the encrypted encoded data 1 1 as it is being transmitted through the medium 108 and alter the encrypted encoded data 1 1 1.
[0028] There may be one or more hosts 150A-150B in the medium 108.
Each of the hosts 150A-150B can receive at least a portion of the encrypted encoded data 1 1 1. Each of the hosts 150A-150B can fonvard their portion of the encrypted encoded data 1 1 1 as the encrypted encoded data 113. The portions of the encrypted encoded data 11 1 can comprise disjoint subsets of the data 101, such as to include the entirety of the data 101 in encrypted encoded form. In such an embodiment, an entity would need to intercept all of the data from all of the hosts 150A-150B to recreate the data 101, assuming the keys and other encryption steps could be determined.
[0029] An entwined crypto decoder 112 can receive the encrypted encoded data 113, polynomials 121, and crypto stream 1 17. The crypto stream 1 17 and polynomial selection 1 19 can be provided by a key generator 114. The key generator 114 is another instantiation of the key generator 104, such that if a key 1 15 is the same as the key 103, the output of the key generator 104 is the same as the output of the key generator 14. The polynomial table 116, similarly, is another instantiation of the polynomial table 106, such as to include polynomials indexed in the same manner.
[0030] The entwined cryptographic decoder 112 transforms the encrypted encoded data 1 13 into data 123 based on the polynomials 121 and the crypto stream 105. The data 123 is the same as the data 101 if there are less than (or equal to) a maximum number of errors in the encrypted encoded data 1 13, The maximum number of errors is configurable and discussed elsewhere herein. The result of the transform is the data 123. The operations performed by the entwined cryptographic decoder 112 are discussed with regard to FIG. 4 and elsewhere herein. A summary of the operations performed by the entwined cryptographic decoder 112 includes: receiving the encrypted encoded data 13, the crypto stream 117, and the polynomials 121; creating key relations based on the crypto stream 1 17 and the polynomials 121 ; initializing return relations based on the encrypted encoded data 1 3, the crypto stream 1 17, and/or the polynomials 121; performing a weave transform to create a possible version of the data 123; checking the created data 123 to determine if it is correct; if not correct, swapping words in the transformed encrypted encoded data; checking the swapped data to determine if correct; and if correct, providing the data 123 as plaintext to a receiver.
[0031] To perform accurate and consistent decoding, the keys 103 and
115 can be synced, such as to produce consistent keys. The consistent keys can help ensure that the crypto streams 105 and 117 are consistent and/or the polynomial select data 1 19 and 107 are consistent. That is, for decoding the encrypted encoded data 111 that is encrypted based on the polynomial select data 107 and the crypto stream 105, the key generator 114, in providing a decryption process cipher stream, produces the same polynomial select data 1 19 as the polynomial seiect data 107 and crypto stream 1 17 as the crypto stream 105. Syncing the keys can include providing a key generator sync signal 125, such as may indicate a start time, an acknowledge or the like, to indicate that each of the key generators 104 and 114 will produce the same bits for their respective cipher streams. One or more of the hosts 150A-150B may be similarly synced with the encoding device 130 and/or the decoding device 140.
[0032] FIG. 2 illustrates, by way of example, a schematic diagram of an embodiment of data 101 being split into words. The data 101 is split into data blocks 203 A, 203B, 203C...203N. Each of the data blocks 203A-203N can include 2r words. Each of the data blocks 203 A-N is split into 2r words 205A, 205B, ... , and 205C. Each of the words 205 A-C includes v bits including the bits 207 A, 207B, ... ,207V. The entwined cryptographic encoder 102 can perform these data splitting operations to portion the data 101 to the proper level for processing.
[0033] FIG. 3 illustrates, by way of example, a diagram of an
embodiment of a method 300 for performing an entwined cryptographic encoding. The method 300 can be performed by the entwined cryptographic encoder 102. The method 300, as illustrated, includes receiving data (to be encrypted and/or encoded), at operation 302; transforming the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomials stored on the memory; at operation 304;
performing a Da Yen weave on the transformed data based on received cipher data, at operation 306; and providing the weaved transformed data to a medium, at operation 308.
[0034] The method 300 can further include producing, by key generator circuitry, a cipher stream of data based on a key. The method 300 can further include, wherein the entwined encryption encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received cipher stream. The method 300 can further include, wherein another portion of the cipher stream provides an index to the respective polynomials. [0035] The method 300 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials. The method can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoder circuitry, based on data from the cipher stream. The method 300 can further include splitting the received data into blocks of v- bit words. The operation 304 can further include transformation of the blocks of v-bits words individually. The method 300 can further include, wherein v is a maximum degree of the polynomials in the memory. The method 300 can further include, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be corrected, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and
transformed v ersions of the 2s, v-bit words from the cipher stream, wherein the number of polynomials in the memory is 2*.
[0036] FIG. 4 illustrates, by way of example, a diagram of an
embodiment of a method 400 for performing an entwined cryptographic decoding. The method 400 can be performed by the entwined cryptographic decoder 112. The method 400, as illustrated, includes receiving encrypted, encoded data, at operation 402; performing a Da Yen weave transform on a portion the encrypted, encoded data, at operation 404, comparing the
transformed data to another portion of the encrypted, encoded data (to determine if errors exist in the transformed data), at operation 406; and in response to a determination that no errors exist, convert the error-free version of data to plaintext, at operation 408. The method 400 can further include providing the plaintext to a receiver.
[0037] The method 400 can further include in response to a
determination that errors exist, perform a weave swap on two words of the transformed data. The method 400 can further include comparing the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version. The method 400 can further include producing, by key generator circuitry, a cipher stream of data based on a key. The operation 404 can include transforming the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received cipher stream.
[0038] The method 400 can further include, wherein another portion of the cipher stream provides an index to respective polynomials represented by respective polynomial integers. The method 400 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials. The method 400 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream. The method 400 can further include, wherein, wherein v is a maximum degree of the polynomials in the memory, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, v-bit words from the cipher stream, wherein the number of polynomial s in the memoiy is 2*.
[0039] A summary of operations that may be performed using the method 400 is now provided in more mathematical terms.
[0040] The methods 300 and 400 include encoding and decoding, respectively, and may be used together. One or more of the methods 300 and 400 may include the following operations:
[0041] A) receive input word size, v, in bits wherein v is a power of two, such as {8, 16, 32, 64, ... } (at entwined cryptographic encoder 102 and/or key generator 104).
[0042] B) receive 2r plain words to be encrypted (at entwined cryptographic encoder 01).
[0043] C) generate 2sv bits (e.g., by key generator 104).
[0044] D) split 2sv bits into 2s v-bit keys (e.g., at entwined cryptographic encoder 102). Each v-bit key is k}. [0045] E) generate 2vn bits (e.g., by key generator 104).
[0046] F) split 2vn bits into 2n v-bit pointers (e.g., at entwined cryptographic encoder 102). Each v-bit pointer is kj and points to a polynomial in the polynomial table. No two kj are equal. A maximum value of kj includes a value less than (or equal to) 2V-1.
[0047] G) generate 2n polynomials (e.g., irreducible polynomials) of degree 2V-1, where q=2n>v (at polynomial table 106), based on kj. Each polynomial is indicated by Mkj.
[0048] H) create data relations ¾ = dj mod (Mkj) (e.g., by the entwined cryptographic encoder 102).
[0049] I) produce n, Ci, cipher words by performing Da Yen weave transform (e.g., by the entwined cryptographic encoder 102).
[0050] J) transmit cipher words (e.g., by the entwined cryptographic encoder 102 over the medium 108),
[0051] K) receive cipher words Ci (e.g., by the entwined cryptographic decoder 112).
[0052] L) receive input word size, v, in bits wherein v is a power of two, such as {8, 16, 32, 64, ... } (at entwined cryptographic decoder 1 12 and/or key generator 104).
[0053] M) generate 2sv bits (e.g., by key generator 114).
[0054] N) split 2sv bits into 2s v-bit keys (e.g., at entwined cryptographic encoder 1 12). Each v-bit key is k}.
[0055] O) generate 2vn bits (e.g., by key generator 1 14).
[0056] P) split 2vn bits into 2n v-bit pointers (e.g., at entwined cryptographic encoder 112). Each v-bit pointer is kj and points to a polynomial in the polynomial table. No two kj are equal. A maximum value of kj includes a value less than (or equal to) 2V-1.
[0057] Q) generate 2n polynomials (e.g., irreducible polynomials) of degree 2V-1, where q=2n>v (at polynomial table 1 16), based on kj. Each polynomial is indicated by Mkj.
0058] R) create key relations: v , = (k Ί mo&mk ) .
0059] S) create the cipher relations: v,s+ ;. = (c , modffi,. ) . [0060] T) Initialize return relations: δ/' =:: (0 mod mk ) for 0 <j < 2r.
[0061 ] U) Perform Da Yen weave transform to extract plain words (do,
Figure imgf000013_0001
[0062] The next section details more specifics regarding operations of the system 100. The next section begins with some definitions and basics, on which proofs and further discussion of ECE relies.
[0063] ECE uses a Da Yen weave transform, and for that a few detimtions and some theory may be helpful. A theorem used for the weave i s the Da Yen. The Da Y'en maps a set of relations to a single relation and back again.
[0064] Let E be a Euclidean domain. A relation μ, is a pair of elements
|X μ e £, μ ≠ 0 and a non— unit, <|μ| with μ representing μ mod μ
[0065] In general, a relation (d mod m) refers to a coset, or set of elements of the Euclidean domain. Because ECE considers real data and integers, unless stated otherwise, the relations here will always be in reduced form (e.g., \d\ < \m\).
[0066] The size (Euclidean norm) restriction | μ| <|μ| may provide stability uniqueness of data as it moves between different rings (moduli).
[0067] Equally sized, relatively prime moduli do not exist over the integers, but can be found if the Euclidean domain is a polynomial ring over a finite field. In ECE the Euclidean domain will be F2[x]. The pair of elements (μ, μ) in a relation μ with polynomials over F2 with | μ| = |μ| = deg(fi),
[0068] Relations are a component of ECE, therefore a simplified way to compare and combine relations and data may be convenient.
Let be two relations with x e E, Uj, i are relatively prime if their respective moduli μ^, μ^ are relatively prime. W/, ½ are equivalent if respective moduli are the same size (|/L- | = and fij = ½. x = ,u implies x = μ mod μ, x + μ = μ + x represents the relation (x + μ mod μ).
[0069] The Da Yen (Chinese Remainder Theorem ) is an isomorphism between the direct product of factor rings and a single factor ring. The Da Yen provides a foundation of the Da Yen weave transform equating a set of relations R to a single relation (i? . Shorthand for the modulus and value of (R is (R ) =
R and (R) = R . The general ring version of the Da Yen and its proof can be found elsewhere. The following i s a presentation of Da Yen using relations. Let R be a set of relatively prime relations. Then there exists a mapping (and its inverse) from R to a relation (i? such that:
1 : R = Σμείΐ β-
2: R — μ for all μ e R,
3. (homomorphic) For any two relation sets R = {μ;- j 0 < j < n}, (? = {i'fc | 0i < n] with equal size and moduli (e.g., μ - = Vj for 0 < / < n),
(R> + ( = ({/ , + mod /) , 0 ./ /? (R)(Q) = ("./ ^- mod ; ! 0 < / <
[0070] The Da Yen weave transform, in part, may convert a set of relations R to the relation (R} , one relation at a time. Operations of the weave transform may create the relation (Rt) where Rt = {μ;· j 0 < y < tj, with Rt in reduced form . Let R = {μ^ \ 0 < j < n} be a set of relatively prime relations, th subsets Rt = j/i; J 0 < j < t} and (Rj) = μ0 and ?t = J" 1 , for 1 < t < n.
Figure imgf000014_0001
for 1 < t < n.
[0071] The Da Yen weave transform may compute the inner relations wt_l5 such as without computing the large relation (jRt-i). After the wt→ have been computed, the full relation can be computed with the result already in reduced form |A- R = w0 + w0 (w,
Figure imgf000014_0002
(... (wn__, + wn_2 wn . , .)) . (3)
[0072] Because this result is already in reduced form and the w relations can be computed within their own factor rings, the relation may be computed and reduced modulo μ, such as by using small moduli and relation μ operations. 73] Let R = (μ;· | 0 < j < n} be a set of relatively prime relations with combined relation ^Z? . For any relation a, define the relation R(a) = (R mod «) :
?(a) = w0 + voCWi + w^... ( n_2 + w ...2wil..,1))moii 6c. (4)
[0074] The weave encoding can use this relation evaluation process to convert a set of distinct relations I to a set J. Let I, J be sets of relatively prime relations with J I encoded into J is the set of relations I ( ) = {/(«) | o E
/}. Two sets of relations, I, J are called equivalent if: 2. {/) = (J)
[0075] Notice that encoded set I(J) is equivalent by definition to I.
Equivalent sets enable decoding and the independence of encoded blocks. As long as an error free set of 2r encoded relations is recovered, the original plain text can be recovered. Any added relations can be used for error checking and correction.
[0076] The weave transform converts an ordered set of relatively prime relations R = ( ^ j 0 < j < n}, to equivalent weave terms, A computational cost in serial is "divide" operations over i'7„ , Paralieiization can
Figure imgf000015_0001
reduce the time to (n-1 ) operations.
[0077] Order does not matter in the set of relations R, but order does matter in the transformed set of Wj values. The w,- value computed during the iterative Da Yen depends on the relations in the subset Rj = { ;· j 0 < i < j], to obtain (Rj), and μ;- itself, but not on any μέ with i > j . Order can be important during the decoding process. For at least this reason, the ordering of the relations in R will be specified for each transform,
[0078] Da Yen Weave Transform and Permutations
[0079] Let π be a permutation on the integers 0 ≤j < n, defaulting to the identit : jt ) = j for 0 ≤j < n. Then for any 0 < t < n,
Figure imgf000015_0002
Rr = ^(0) + W <0 > < <1> + W,(l) ( · ( M^(/-2)
Figure imgf000016_0001
= mod ά (7) and Γζ (£ΐπ(/)) = / ;.0) for all 0 ≤j < t.
[0080] Da Yen Weave Transform Technique
[0081] Input: i?={ ui j 0≤j < n }, an ordered set of relatively prime relations and π a permutation on {0, 1, 1 }
[0082] Output: W= {wj \ 0≤j < n } an ordered set of relatively prime relations satisfying equation (6).
[0083] /: Initialize:
[0084] Α νπφ) = μ 0)
[0085] B: for k \ to (// - 1): = μπ(!() ;
[0086] II: For /' = 1 to./ = (n - 1):
[0087] .,4 : =
[0088] 5: For k = (/ + 1) to k = (// - 1):
[0089] w]! ] - (i¾ ( v^ " 0 - v^;)) modwk)
[0090] End of Weave Transform Technique
[00 1] ECE detects and corrects errors by assuming a col lection of 2r received relations are correct, computing the unused 2s relations and comparing them to the received values. If at least half of these relations are correct and at most s errors exist, then plain text can be extracted from the set.
[0092] Let R = { ½<,·+¾ | 0 < k < n] be the set of n received values and their key-determined moduli, K = [μ ,- j O < j < 2s} the set of 2s key relations. Decoding begins by transforming K U R = μ^, ^s+fc | 0≤ j < 2s; 0 < k < n] to R71. If less than half the 2s computed values match the unused received values, then errors exist in the current collection of 2r values. Other sets may be tested until one is found that passes the test.
[0093] The Da Yen weave transform of different sets of 2r elements can be computed using the weave transform, the swapping pairs of elements in and out, until either a set passes the checks or there are no more sets to check. If no good set is found, then too many errors exist to recover the plaintext.
[0094] Weave swapping may help efficiency, requiring only a few- operations in the base field instead of a re-computation of the entire transform.
(r + s)
Pairing relations can reduce a maximal number of sets to check from
2r to , reducing expected computational work to approximately a square
Figure imgf000017_0001
root of the time required swapping individuals.
[0095] Weave swapping is now explained. Order in the weave transform may help extract values.
Figure imgf000017_0002
j 0≤j < n } be its transform with permutation π. Recall that WK ) value computed during the iterative Da Yen depends on the relations of the unordered subset {/½(¾ j 0 < i < /} and /½ /) itself, but not on any ½ Qwith i > j, and low order weave terms can be combined to compute an extracted weave value. Weave swapping allows swapping of the order of two adjacent relations in a woven transform without recomputing the entire transform. Adjacent weave terms may be swapped with one multiply and one "divide" (e.g., compute an inverse and then multiply), and the permutation keeps track of swaps performed. Swapping weave terms j and (j + 1) converts Rn to Ra where
ff(fe) = 7r(fc) 0 < k < j; (j + 1) < k < n
a(j) = n j + 1)
a( + 1) = n(j).
[0096] The moduli, Wj = Uj are constant and not effected by swapping relations. Recall that the Da Yen weave transform has intermediate results
W3T(J) ~ nQ )(wn(j) ~ W7t(ji))m°dfin(j) with Wr[{ j ) = w^n . The swapped values in terms of these intermediate values is:
Figure imgf000017_0003
1. w (j) = therefore
Wff(j = WnU+ fi'rtU) +
Figure imgf000017_0004
(9)
2, Wff(/+i)0) = and for one term higher:wffQ-+1) = (W/TQ) —
Wa(j V)mo d a(j+l (10) These equations simplify for the relation sets used in ECE. All moduli have the same degree over F2 with μ,≡ jiik Θ /}, mod/4 ·
wff ") = ^πα÷1)σωΦβσα+1-)Φ}νπω7ηοάβσω (11) [0097] Weave Swap Technique
[0098] Input: RK, 0≤ / < (w - 1), with w, = (x @ c, )
[0099] Output: Ra as described elsewhere herein
[00100] l: waij) = w:;(r.. l }i r;(j )- : w j )nwduir( j)
[00101] //: wn( 0 ■■■■■■■ (\νπ( - ^ίΤί /))( AT{ / · : i (S■■ s )) " 1 motl®nl i.. , ;
[00102] /!/: σ = π
[00103] IV: σ(/) = π(/ + 1)
[00104] : σ( · ! ) π(/)
[00105] VI: ?' is now ./?0
[00106] End Weave Swap Technique
[00107] Encoding Technique
[00108] WTords of key may be generated using a stream cipher (e.g., a key used for encryption and/or encoding is the stream ciphers output). A set of 2n or q irreducible polynomials of degree v over F2 may be determined. ECE performs a ya den weave encoding using a mix of plaintext and key relations, in embodiments discussed herein, moduli of the relation sets can be determined from the stream cipher. Alternatively, keys and/or moduli may be otherwise randomly chosen.
[00109] Encoding Technique
Input:
Figure imgf000018_0001
Output: {q I 0 < i < n], v— bit cipher words
I: Generate key and set up system (assumes key generator is initialized with cryptovariable (e.g., long term key)),
A: Generate 2v(s + n) bits of key stream from the supplied key generator.
Label the key bits
® {ki \ 0 < j < 2s} , where kf. is a v-bit word of key;
• {kj \0≤ j, n}, where k, is less than q \M\ and k,≠ Ay for al /'≠ j.
B: Create the data relations: δ/' = ( δ/' mod mk .) for 0 < j < 2r.
C: Create the key relations: v . = (kj raodm^ )for 0 <j < 2s.
D: Initialize return relations: Uj ::= (0 modmfcn+ .) for 0 < j < n.
//: Transform R = [Sj, δ2τ+κ
Figure imgf000019_0001
into with π equal to the identity permutation.
///: Weave extract cipher words q = Rn (uj) for 0 < < n.
[00110] End Encoding Technique
[00111] The decoding process in ECE is like encoding in that a Da Yen weave transform is performed in decoding. If there are no errors and at least 2r correct relations, decoding can be performed. If (2r + 1) relations were received with at most t/2 errors, an error free set of 2r relations can be found and error free plaintext extracted.
[00112] Check Decoding Weave Techni que
[00113] Input:
Figure imgf000019_0002
00114] Output: true, if weave is correct; false, if fails correct check
00115] /: FailCotmt = Q
00116] //: i r ; 0 io (/ - A: Weave extract modulus R,T (v„(+ ) = τ
B: If τ does not equal r-.,:, . ! ail( "own ::= FaiiCount + I ,
0119] ///: return : i f FaiiCount≤ return true; else return false
[00120] End Check Decoding Weave Technique
[00121] Because there can be at most t/2 errors, not all (2r + t) choose 2r subsets of the received relations need to be tried. If t/2 errors exist and relations were paired with an adjacent relation (e.g., pair 0 is μ0, μν pair 1 is μ2, μ3 and so on), then there would be t/2 pairs not used in the extraction process. If each of these unused pairs contained at least one error, then the used pairs are error free. In other words, one of the these (r + t/2) choose r pair subsets would be an error free transformation.
[00122] A decoding technique can exhaust subsets of the received relations, such as by pairing adjacent relations. Such a technique may reduce computation time per subset, such as by performing the full transform only once and modifying the transform to match the new subset by performing a weave swap.
[00123] Decoding Technique
Input:
Figure imgf000020_0001
/: Generate key and set up system (assumes key generator is initialized with cryptovariable - i.e., long term key), such as the same was as was done for the encoding, using the same cryptovariable.
A: Generate 2v(s + n) bits of key stream from the supplied key generator. Label the kev bits * {kt \ 0 < j < 2s) , where k. is a v-h\t word of key;
• {kj j 0 < , ft], where k< is less than q = \ M\ and k,≠ k for ai /≠ j
B: Create the key relations: v, = (k . mod/ ) for 0 <j < 2s.
C: Create the cipher relations: v2s÷J - μπ( n ~ (ρ„υ) modmk t ) for 0 <j
< (2r + 1).
D: Initialize return relations: δ/' = (0 mod mk ) for 0 <j < 2r.
II; Let σ be a permutation on the integers 0 <j < (2s + ri), initialized with the identity permutation: a(J) =j.
Ill: Let
Figure imgf000021_0001
TV Perform weave transform to map R = \ \ 0 < / < (2(5 + f) + t)} into ?0".
V: While Ivl < halfSpares and the current R° fails check decoding weave:
A: for/' = 2(r + 5 + M) down to 2(nV etted + s):
1 : Weave Swap Ra at/' and (j - 1)
2 : Weave Swap Ra at (/ - 1 ) and/
i?: lvlVetted[lvl] = lvlVetted [lvl] + l; nV etted = nV 'etted + 1 C: if nVetted > r and Ivl < halfSpares /*
go to a more significant level, as this level is exhausted */
nV etted = nV etted — lvlVetted[lvl]
lvlVetted[lvl] = 0
Ivl = lvl + l
Ό: else if {Ivl > 0) /*else if not at lowest level, go down to least significant level*/
1 : lvl = 0
VI: Weave Extract Modulus to get plain words ό) = βπ(<5/) for 0 < j < 2r.
End Decoding Technique ® ε = Z: Let
R = {(2 mod 7); (5 mod 13); (1 mod 2)}
Q = {(5 mod 7); (1 mod 13); (0 mod 2)}.
Then <R> = (135 mod 182), with R = 135 and R ==: 182 and (Q) = (40 mod 182) Notice that R + O = {(0 mod 7); (6 mod 13); (1 mod 2)}, <R + Q) = (175 mod 182) and RQ = {(3 mod 7); (5 mod 13); (0 mod 2)} and (RQ) ==: (122 mod 182).
® = f" 2 [xj: Let R = {{x3 + x + 1 mod x4 + x3 + 1); (x mod x2 + x + 1); (1 mod x + 1)},
Then (R) = fx5 mod x7 + x6 + x4 + 1) with R = x5 and R = x7 + x6 + x* + 1.
[00128] End of Example 1 .
[00129] Example 2: Equivalent Relation Subsets
Figure imgf000022_0001
The set / maps to the relation (I) = 2x2 + 6x mod ( 3 + 9x + 0) while (R) = 3x4 + 8r- + 7x2 + 9x2 + 3 mod (x5 + 5x4 + 3 3 + 7 l + 6).
Notice Λ3ΐ /(μι) = μ1. This, along with the fact that the size of all moduli in R are identical (degree 1), gives us that the following relation sets are equivalent:
End of Example 2.
Example 3 : Integer Ya Den Weave Transform
Let ? = {(2 mod 3)(3 mod 5)(1 mod 1 1)(7 mod 13)}, find R mod 7.
Ai :::: 3 <i :::: 5 / - 1 1 3 1 7
3"1 (3 - 2) 3-j (l - 2) 3"1 (7 - 2)
- 2(1) 4(-l) 9(5)
2 7 6
5-1 (7 - 2) 5"1 (6 - 2)
- 9(5) 8(4)
1 6
l r1 (6 - 1)
- 6(5)
4
R71 (2 mod 3) (2 mod 5) (1 mod 11) (4 mod 13)
The full value of <R> would be <R> = (2 + 3(2 + 5(1 + 11(4))) = 683 mod 2145, but R mod 7 can be computed without the full value:
R 2 + 3(2 + 5(1 + 1 (4))) mod 7
- 2 + 3(2 + 5(1 + 4(4))) mod 7
≡ 2 + 3(2 + 5(3)) mod 7
≡ 2 + 3(3) mod 7
≡ 4 mod 7
Now divide R by 7 and return the quotient modulo 3, 5, 11, and 13. The reminder is already known: r = 4, To find the quotient, subtract r and multiply by
7"1. The inverses of 7 mod ut are:
[ 1 mod 3 3 mod 5 8 mod 11 2 mod 13 ].
Finally, the quotient is equivalent to:
I ' ik 4 1(2
Figure imgf000023_0001
683 - 4
The integer form ot the quotient is——— = 97. Notice that
/
97≡[ lmod3 2 mod 5 9modl l 6 mod 13 ]
[00132] End Example 3.
[00133] Example 4: Polynomial Ya Den Weave Transform Let ε = / 'Ixi, represent polynomials in hexadecimal: x5 + x3x2 --> 0x2c, and R ==: {(0x6 mod 0x25), (Ox la mod 0x29), (Oxc mod 0x2f), (0x3 mod 0x37)} and find R mod 0x3b:
Figure imgf000024_0001
R contains four degree 6 polynomials, therefore i = 20, but we can compute R mod 0x3b with the w values and operations mod 0x3b (note: all moduli have the same degree, therefore w,≡ (ws Θ 0x3^) mod 0x36) :
R≡ 0x6 Θ 0x25 (Ox l a ® 0x29 (0x13 ® 0x2f 0x13)) mod 0x b
≡ 0x6 ® Oxle (Oxla Θ 0x12 (0x13 Θ 0x14 0x13)) mod 0x b
≡ 0x6 ® Oxle (Oxla Θ 0x12 · 0x16) mod 0x3b
≡ 0x6 ® Oxle · 0x14 mod 0x3b
To illustrate how a change in order effects the weave transform, use the same R but swap the order of μ-, μ?:
R = {(0x6 mod 0x25), (Oxla mod 0x29), (Oxc mod 0x2f), (0x3 mod 0x37)} and find R mod 0x3b: μ0 = 0x25 μΊ 0x2f /, = 0x29 L = 0x37
0x6 Oxc Oxla 0x3
- 0x1 Ox la Oxf
- 0x10 0x4
- 0x13
(0x6 mod (0x1 mod (Ox 10 mod (0x13 mod 0x25) 0x20 0x29) 0x37)
Notice that swapping the order of μι, μ:? changes the intermediate results for μ3, but not the final value or the result
R≡ 0x6 ® 0x25 (Ox l a Θ 0x2f (0x10 Θ 0x29 · 0x13)) mod 0\3 b
Oxb
The swapped transform can be computed using the weave swap technique. Using the original weave:
Figure imgf000025_0001
It is known that Μ½(0), H½(3>, where π(0) = 0, π(3) = 3, don't change. For the swapped values:
M½(i) = W2 (0x29 ® 0x2f) ® w i π( 1 ) = 2
------ 0x1 mod 0x21"
Wn(2) == (¼' i θ w (0x29 Θ 0x2f)-1 π(2) === 1
== 0x10 mod 0x29
[00134] End of Example 4.
[00135] Entwined encryption provides an implementer more freedom in implementation than other systems, which require a standard data block size. Many encoding schemes have rather strict restrictions on block size, but entwined encryption allows a user to vary a block size, such as based on their needs. [00136] Entwined encryption may provide a foundation for a quantum resistant public key cryptosystem. This is a new, important area of cryptography as all currently used public key systems are vulnerable to quantum attacks.
[00137] An example that works with polynomials over F2 or modulo 2: f(x = ∑ί=ο ^ί χ1 where bt £ {0,1} and x is a variable/placeholder, Arithemetic in this example is standard polynomial addition and multiplication, except coefficient addition and multiplication is done modulo 2: 1 + 1 = 1 Θ 1 = 0. As the coefficients are restricted to { 1 ,0}, polynomials can be written in short hand as hexadecimal numbers. For example, Ox 1 1 d = 0b 100011101 = x8 + x4 + x3 + x2 + l .
[00138] Modular reduction using polynomials over F2 as the moduli is used in this example. If M(x) is the polynomial modulus, then 0 = M(x) mod M(x). This may seem like an obvious statement, but it may be used to simplify polynomial reduction. Let (x)
Figure imgf000026_0001
(e.g., a degree n polynomial over Fi). Starting with the obvious relation, then adding xn to both sides (addition being the same as subtraction mod 2), gives: xn =
bjxi mod M(x). To reduce a polynomial P(x) mod M(x), simply replace n-th powers with the lower terms of M( ) of add left shifted versions of (x) until the degree is less than n. The following table, the polynomial, P(x) = 0x37f6 is reduced modulo, (x), Ox 1 1 d.
1 1 0 1 1 1 1 1 1 1 0 1 1 0
1 0 0 0 1 1 1 0 1 0 0 0 0 0
1 0 1 0 0 0 1 0 1 0 1 1 0
I 0 0 0 1 1 1 0 1 0 0 0 0
1 0 1 1 0 0 0 0 1 1 0
1 0 0 0 1 1 1 0 1 0 0
I 1 1 1 1 0 0 1 0
1 0 0 0 1 1 1 0 1
1 1 1 0 1 1 1 1
which equals Oxef.
[00139] Multiplicative inverses (e.g., division) modulo these polynomials is a component of the ECE. The inverse of a mod m ' is b such that ah = 1 mod m, and it is written b = a 1" mod ///. Inverses can be computed in several ways which are not covered here. These include many variants of the Euclidean algorithm as well as the Da Yen.
[00140] Table 1 includes irreducible polynomials of degree 8 (in hexadecimal short-hand notation). Note that polynomial (j=0) is primitive. This means that every non-zero element of i7? is generated by a root of the polynomial in the algebraic completion of ¥'2. If a is a root of p0(x), then a root of polynomial pj(x) is aexp In the example encryption/encoding scheme below, these polynomials are referred to as ίί(χ
Figure imgf000027_0001
TABLE 1 : Irreducible Polynomials of Degree 8
[00141] The following example encrypts/encodes a block of 24 bits (e.g., three 8-bit words) into five, 8-bit words. Plaintext bits are used as coefficients to a binary polynomial (an element of ^ixj) with degree less than 24. A key stream is provided by a key generator (e.g., a stream cipher), such as can include a randomizer with a seed (e.g., an internal secret seed). This key stream provides integers in the range of the id of the set of irreducible polynomials. In this
9 <? example the key stream provides integers in the range 0 < /<,- < 30. Thus, these keys serve as indices for the irreducible polynomials, Mj(x) in Table 1.
[00142] Consider P(x) = ∑jio bt xl where ht G {0, 1}. ECE converts (x) into five 8-bit words Cj where Cj = P(x)mod Mk .(x) for 0 < j < 5.
Decrypting and decoding using the given key integers uses a Da Yen weave transform.
[00143] There are at least two construction techniques to determine Cj. Assume there are n Cj values mod Mj for j =:: 0, 1 , 2, . . . , (n-1). These may be the entire set of just a sub-set (if the product of / has a degree at least as large as the initial modulus (24 in this example)). The first technique can include using the following formula: P(x) = ∑] o Ui≠j Mi(.x)
Figure imgf000028_0001
ix)]
[00144] The second technique can include an iterative technique, such as can be more computationally efficient than the first technique. The iterative technique can follow these three formulas:
/¾(*) = Co j-l 7-1
: (x) - Pi .. . (x)® ® Pj...1 (xy)modMj (x)]
Figure imgf000028_0002
P(x) - Pn^ (x)
[00145] For this example, let P(xj 0x23 ab If and the key integers be as shown in Table 2:
Figure imgf000028_0004
Figure imgf000028_0003
C4 == 73 mod la3 [00147] If only Ci, Ci, and C4 are recovered, and the keys are known, the full plain text can be recovered:
P(x) = (17b · la3)[(17b · la3)"j86 mod la9] Θ (la9 · Ia3)[(la9 · l a3Yl 3 1 mod 17b] (la9 · 17b)[(la9 · 17b)"1 73 mod la3]
= lea6d (39-186 mod la9) Θ 14a5b(ad"!31 mod 17b) Φ le343 (5f ] 73 mod la3) = lea6d (fD- 86 mod la9) Φ 14a5b(d2- 31 mod 17b) Θ le343 (6d-73 mod l a3) = (lea6d · b5) Φ (14a5b 2) Φ (le343 · 80)
= d09e29 Φ 294b6 Φ flal 80
[00148] In this example, if all cipher words are known, an error may be corrected. For example, let the Cj received after tra smission be {8b, 96, 31, e9, 73 } (note the error in Ci = 96; Ci was determined to be 86).
P(x) = 1 13b9e5fd (4b_1Co mod lb l) Θ 101f3e905 (%?lCi mod la9) Θ 111x182883 (55¾2 mod 17b) Φ 18c8b0e55 (Ι4¾ mod 139) Φ 10cd8495b (89-xC4 mod la3)
= 1 13b9e5fd (7c-Co mod lb l) Θ 101f3e905 (4a- i mod l a9) Φ lfbd82883
(c9 C? mod 17b) Φ 18c8b0e55 (16-C3 mod 139) Φ 10cd8495b (a6- C4 mod la3) = 89dcf2fe8 Φ I fl 57a4763 e 2afb4e07el Φ 8eab0882cf Φ 4c76d9e299
= ffae2a0fl c mod MsMiMiMiMt.
[00149] In only one error is in the blocks, then reducing this result modulo a smaller product (in this case 0M2M3 1) can produce a polynomial with degree less than 24, the corrected plain text. Using a product containing C\ mod returns a polynomial with a higher degree. The value reduced modulo the product of all moduli but one of (in order) Mo, Mi, . . . 4, is provided:
ffae2a0flc = c3ba8b51 mod 1 13b9e5fd (Mo removed, S0 M2M3M4) ffae2a0flc = 23ab lf mod 101Oe905 (Mi removed, so ¾4W4)
ffae2a0flc = 4e563719 mod lfbd82883 (M2 removed, S0 0 1 3 4)
ftae2a0flc
Figure imgf000029_0001
ffae2a()flc == dl3bdbb9 mod 10cd8495b (M4 removed, so MQMIMIM )
[00150] As can be seen, removing i from the modulus recovers the original data 0x23 ab 1 f .
[00151] FIG. 5 illustrates, by way of example, a graph 500 of error rate versus energy for a variety of encoding techniques. The graph 500, as illustrated, includes uncoded data with added white Gaussian noise (AWGN) represented by line 506, data encoded using a Reed Solomon technique, represented by line 504, and data encoded using ECE, represented by line 502.
[00152] FIG. 6 illustrates, by way of example, a block diagram of an embodiment of a machine 600 on which one or more of the methods, such as those discussed with regard to FIGS. 3 and 4 and elsewhere herein can be implemented. In one or more embodiments, one or more items of the system 100 can be implemented by the machine 600. In alternative embodiments, the machine 600 operates as a standalone device or may be connected (e.g., networked) to other machines. In one or more embodiments, the entwined cryptographic encoder 102, the poly table 106, the key generator 104, the entwined cryptographic decoder 112, the poly table 116, the key generator 1 14, the medium 108, the encoding device 130 (the transmitter device), and/or the decoding device 140 (the receiver device) can include one or more of the items of the machine 600. In a networked deployment, the machine 600 may operate in the capacity of a server or a client machine in server-client network
environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The machine 600 may be a personal computer (PC), a tablet PC, a set-top box (STB), a Personal Digital Assistant (PDA), a cellular telephone, a web appliance, a network router, switch or bridge, or any machine capable of executing instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term "machine" shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein.
[00153] The example machine 800 includes processing circuitry 902 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an application specific integrated circuit, circuitry, such as one or more transistors, resistors, capacitors, inductors, diodes, logic gates, multiplexers, oscillators, buffers, modulators, regulators, amplifiers, demodulators, radios (e.g., transmit or receive radios or transceivers), sensors 621 (e.g., a transducer that converts one form of energy (e.g., light, heat, electrical, mechanical, or other energy) to another form of energy), or the like, or a combination thereof), a main memory 604 and a static memory 606, which communicate with each other via a bus 608, The machine 600 (e.g., computer system) may further include a video display unit 610 (e.g., a liquid crystal display (LCD) or a cathode ray tube (CRT)), The machine 600 also includes an alphanumeric input device 612 (e.g., a keyboard), a user interface (UI) navigation device 614 (e.g., a mouse), a disk drive or mass storage unit 616, a signal generation device 6 8 (e.g., a speaker) and a network interface device 620.
[00154] The disk drive unit 616 includes a machine-readable medium 622 on which is stored one or more sets of instructions and data structures (e.g., software) 624 embodying or utilized by any one or more of the methodologies or functions described herein. The instructions 624 may also reside, completely or at least partially, within the main memory 604 and/or within the processor 602 during execution thereof by the machine 600, the main memory 604 and the processor 602 also constituting machine-readable media.
[00155] The machine 600 as illustrated includes an output controller 628.
The output controller 628 manages data flow to/from the machine 600. The output controller 628 is sometimes called a device controller, with software that directly interacts with the output controller 628 being called a device driver.
[00156] While the machine-readable medium 622 is shown in an example embodiment to be a single medium, the term "machine-readable medium" may include a single medium or multiple media (e.g., a centralized or distributed database, and/or associated caches and servers) that store the one or more instructions or data structures. The term "machine-readable medium" shall also be taken to include any tangible medium that is capable of storing, encoding or carrying instructions for execution by the machine and that cause the machine to perform any one or more of the methodologies of the present invention, or that is capable of storing, encoding or carrying data structures utilized by or associated with such instructions. The term "machine-readable medium" shall accordingly be taken to include, but not be limited to, solid-state memories, and optical and magnetic media. Specific examples of machine-readable media include nonvolatile memory, including by way of example semiconductor memory devices, e.g., Erasable Programmable Read-Only Memory (EPROM), Electrically Erasable Programmable Read-Only Memory (EEPROM), and flash memory devices; magnetic disks such as internal hard disks and removable disks;
magneto-optical disks; and CD-ROM and DVD-ROM disks.
[00157] The instructions 624 may further be transmitted or received over a communications network 626 using a transmission medium. The instructions 624 may be transmitted using the network interface device 620 and any one of several well-known transfer protocols (e.g., HTTP). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), the Internet, mobile telephone networks, Plain Old Telephone (POTS) networks, and wireless data networks (e.g., WiFi and WiMax networks). The term
"transmission medium" shall be taken to include any intangible medium that is capable of storing, encoding or carrying instructions for execution by the machine, and includes digital or analog communications signals or other intangible media to facilitate communication of such software.
[00158] Examples and Additional Notes.
[00159] Example 1 can include an entwined cryptographic encode device comprising a memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table, entwined cryptographic encoding circuitry to receive data, transform the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomial table, and perform a Da Yen weave on the transformed data based on received cipher data, and provide the weaved transformed data to a medium .
[00160] In Example 2, Example 1 can further include ke generator circuitry to produce a cipher stream of data based on a key, and wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received cipher stream.
[00161] In Example 3, Example 2 can further include, wherein another portion of the cipher stream provides an index to the respective polynomials.
[00162] In Example 4, Example 3 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials. [00163] In Example 5, at least one of Examples 1-4 can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoding circuitry, based on data from the cipher stream.
[00164] In Example 6, at l east one of Exampl es 1-5 can further include, wherein the entwined cryptographic encoding circuitry is further configured to split the received data into blocks of v-bit words, wherein the transformation of the data includes transformation of the blocks of v-bits words individually, and wherein v is a maximum degree of the polynomials in the memory.
[00165] In Example 7, at least one of Example 1-6 can further include, wherein a number of r-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, v- bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
[00166] Example 8 includes an entwined cryptographic decode device comprising a memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table, entwined cryptographic decoding circuitry to receive encrypted, encoded data, perform a Da Yen weave transform on a portion the encrypted, encoded data, compare the transformed data to another portion of the encrypted, encoded data to determine if errors exist in the transformed data, in response to a
determination that no errors exist, convert the error-free version of data to plaintext, and provide the plaintext to a receiver,
[00167] In Example 9, Example 8 further includes, wherein the entwined cryptographic decoding circuitry is further configured to in response to a determination that errors exist, perform a weave swap on two words of the transformed data, and compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version. [00168] In Example 10, Example 9 can further include key generator circuitry to produce a cipher stream of data based on a key, and wherein the entwined cryptographic decoding circuitry is further configured to transform the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received cipher stream.
[00169] In Example 11, Example 10 can further include, wherein another portion of the cipher stream provides an index to respective polynomials represented by respective polynomial integers.
[00170] In Example 12, Example 1 1 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials.
[00171] In Example 13, at least one of Examples 8-12 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream.
[00172] In Example 14, at least one of Examples 8-13 can further include, wherein v is a m aximum degree of the polynomials in the memory, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, -bit words from the cipher stream, wherein the number of polynomials in the memor is 2f.
[00173] In Example 15, an encryption and decryption system includes an entwined cryptographic encode device comprising a first memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a first polynomial table, entwined cryptographic encoding circuitry to receive data, transform the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomial table, perform a Da Yen weave on the transformed data based on received cipher data, and provide the weaved transformed data to a medium, and an entwined cryptographic decode device compri sing a second memory including data indicating the set of relatively prime, irreducible polynomials stored and indexed thereon in a second polynomial table, entwined cryptographic decoding circuitry to receive the encrypted, encoded data from the medium, perform a Da Yen weave transform on a first portion the encrypted, encoded data, compare the transformed data to a second portion of the encrypted, encoded data to determine if errors exist in the transformed data, in response to a determination that no errors exist, convert the error-free version of data to plaintext, and provide the plaintext to a receiver.
[00174] In Example 16, Example 15 may further include, wherein the entwined cryptographic encode device further includes first key generator circuitry to produce a first cipher stream of data based on a first key, and wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received first cipher stream, and the entwined cryptographic decode device further includes second key generator circuitry to produce a second cipher stream of data based on a second key, and wherein the entwined cryptographic decoding circuitry is further configured to transform the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received second cipher stream.
[00175] In Example 17, Example 16 can further include, wherein the first and second key generator circuitry are synced.
[00176] In Example 18, at least one of Examples 16-17 can further include, wherein a portion of the first cipher stream provides an index to the respective polynomials on the first memory and wherein a portion of the second cipher stream provides an index to the respective polynomials on the second memory.
[00177] In Example 19, Example 18 can further include, wherein the polynomials on the first and second memories are indexed based on a respective root and primitive of the polynomials.
[00178] In Example 20, at least one of Examples 16-19 can further include, wherein the entwined cryptographic decoding circuitry is further configured to, in response to a determination that errors exist, perform a weave swap on two words of the transformed data, and compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version.
[00179] In Example 21, at least one of Examples 16-20 can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoder circuitry, based on data from the cipher stream.
[00180] In Example 22, at least one of Examples 16-21 can further include, wherein the entwined encryption circuitry is further to split the received data into blocks of v-bit words, and transformation of the data includes transformation of the blocks of v-bits words individually, wherein v is a maximum degree of the polynomials in the memory.
[00181] In Example 23, at least one of Examples 16-22 can further include, wherein a number of t-bit cipher words provided by the first and second cipher streams includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and
transformed v ersions of the 2s, v-bit words from the cipher stream, wherein the number of first and second polynomials in the first and second memories is 2*.
[00182] In Example 24, at least one of Examples 16-23 can further include, wherein another portion of the first cipher stream provides an index to first respective polynomials represented by respective polynomial integers.
[00183] In Example 25, at least one of Examples 16-24 can further include, wherein the first polynomials are indexed based on a respective root and primitive of the polynomials.
[00184] In Example 26, at least one of Examples 16-25 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream. [00185] Example 27 can include a method for entwined cryptographic encoding storing, on a memory, data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table, receiving data, at entwined cryptographic encoding circuitry, transforming the data to a set of data integers modulo respective polynomial integers
representative of respective polynomials of the polynomial table, performing a Da Yen weave on the transformed data based on received cipher data, and providing the weaved transformed data to a medium.
[00186] In Example 28, Example 27 can further include producing, using key generator circuitry, a cipher stream of data based on a key, and wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received cipher stream.
[00187] In Example 29, Example 28 can further include, wherein another portion of the cipher stream provides an index to the respective polynomials.
[00188] In Example 30, at least one of Examples 27-29 can further include, wherein the polynomials are indexed based on a respective root and primitive of the polynomials.
[00189] In Example 31, at least one of Examples 27-30 can further include, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoding circuitry, based on data from the cipher stream .
[00190] In Example 32, at least one of Examples 27-31 can further include splitting the received data into blocks of v-bit words, wherein the transformation of the data includes transformation of the blocks of v-bits words individually, and wherein v is a maximum degree of the polynomials in the memory.
[00191] In Example 33, at least one of Example 27-32 can further include, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 25, v- bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
[00192] Example 34 includes a method of entwined cryptographic decoding including storing, on a memory, data indicating a set of relati vely prime, irreducible polynomials stored and indexed thereon in a polynomial table, receiving, at entwined cryptographic decoding circuitry, encrypted, encoded data, performing a Da Yen weave transform on a portion the encrypted, encoded data, comparing the transformed data to another portion of the encrypted, encoded data to determine if errors exist in the transformed data, in response to a determination that no errors exist, converting the error-free version of data to plaintext, and providing the plaintext to a receiver.
[00193] In Example 35, Example 34 further includes, in response to a determination that errors exi st, performing a weave swap on two words of the transformed data, and compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exi st in the weave swapped version.
[00194] In Example 36, Example 35 can further include producing, using key generator circuitiy, a cipher stream of data based on a key, and transforming the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received cipher stream.
[00195] In Example 37, Example 36 can further include, wherein another portion of the cipher stream provides an index to respective polynomials represented by respective polynomial integers.
[00196] In Example 38, Example 37 can further include, wherein the polynomials are indexed based on a respective root and primiti ve of the polynomials.
[00197] In Example 39, at least one of Examples 34-38 can further include, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream. [00198] In Example 40, at least one of Examples 34-39 can further include, wherein v is a maximum degree of the polynomials in the memory, wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, v-bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
[00199] Example 41 can include a non-transitory machine-readable medium including instructions that, when executed by a machine, configure the machine to perform operations of the method of at least one of Examples 27-40.
[00200] Although an embodiment has been described with reference to specific example embodiments, it will be evident that various modifications and changes may be made to these embodiments without departing from the broader spirit and scope of the invention. Accordingly, the specification and drawings are to be regarded in an illustrative rather than a restrictive sense. The accompanying drawings that form a part hereof, show by way of illustration, and not of limitation, specific embodiments in which the subject matter may be practiced. The embodiments illustrated are described in sufficient detail to enable those skilled in the art to practice the teachings disclosed herein. Other embodiments may be utilized and derived therefrom, such that structural and logical substitutions and changes may be made without departing from the scope of this disclosure. This Detailed Description, therefore, is not to be taken in a limiting sense, and the scope of various embodiments is defined only by the appended claims, along with the full range of equivalents to which such claims are entitled.

Claims

What is claimed is: 1. An entwined cryptographic encode device comprising:
a memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table;
entwined cryptographic encoding circuitry to:
receive data;
transform the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the polynomial table; and
perform a Da Yen weave on the transformed data based on received cipher data; and
provide the weaved transformed data to a medium .
2. The device of claim 1, further comprising:
key generator circuitry to produce a cipher stream of data based on a key; and
wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received cipher stream.
3. The device of claim 2, wherein another portion of the cipher stream provides an index to the respective polynomials.
4. The device of claim 3, wherein the polynomials are indexed based on a respective root and primitive of the polynomials,
5. The device of claim 4, wherein the weaved transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic encoding circuitry, based on data from the cipher stream.
6. The device of claim 5, wherein the entwined cryptographic encoding circuitry is further configured to:
split the received data into blocks of v-bit words;
wherein the transformation of the data includes transformation of the blocks of v-bits words individually; and
wherein v is a maximum degree of the polynomials in the memory.
7. The device of claim 6, wherein a number of /-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, v-bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
8. An entwined cryptographic decode device comprising:
a memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a polynomial table;
entwined cryptographic decoding circuitry to:
receive encrypted, encoded data;
perform a Da Yen weave transform on a portion the encrypted, encoded data;
compare the transformed data to another portion of the encrypted, encoded data to determine if errors exist in the transformed data;
in response to a determination that no errors exist, convert the error-free version of data to plaintext; and
provide the plaintext to a receiver.
9. The device of claim 8, wherein the entwined cryptographic decoding circuitry is further configured to:
in response to a determination that errors exist, perform a weave swap on two words of the transformed data; and
compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version.
10. The device of claim 9, further comprising:
key generator circuitry to produce a cipher stream of data based on a key; and
wherein the entwined cryptographic decoding circuitry is further configured to transform the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received cipher stream.
11. The device of claim 10, wherein another portion of the cipher stream provides an index to respective polynomials represented by respective polynomial integers,
12. The device of claim 11, wherein the polynomials are indexed based on a respective root and primitive of the polynomials,
13. The device of claim 12, wherein the weave transformed data includes the transformed received data and transformed cipher data transformed, by the entwined cryptographic decoding circuitry, based on data from the cipher stream,
14. The device of claim 3, wherein v is a maximum degree of the polynomials in the mem or}', wherein a number of t-bit cipher words provided by the cipher stream includes the number of words in a block of the blocks, 2r, plus two times a maximum number of errors to be correctd, s, and a number of v-bit cipher words provided by the cipher stream includes two times the maximum number of errors to be correctd, wherein the weaved transformed data includes transformed versions of each of the v-bit words of the data block and transformed versions of the 2s, -bit words from the cipher stream, wherein the number of polynomials in the memory is 2'.
15. An encryption and decryption system comprising:
an entwined cryptographic encode device comprising:
a first memory including data indicating a set of relatively prime, irreducible polynomials stored and indexed thereon in a first polynomial table; entwined cryptographic encoding circuitry to:
receive data;
transform the data to a set of data integers modulo respective polynomial integers representative of respective polynomials of the first polynomial table; and
perform a Da Yen weave on the transformed data based on received cipher data; and
provide the weaved transformed data to a medium; and an entwined cryptographic decode device comprising:
a second memory including data indicating the set of relatively prime, irreducible second polynomials stored and indexed thereon in a second polynomial table;
entwined cryptographic decoding circuitry to:
receive the encrypted, encoded data from the medium;
perform a Da Yen weave transform on a first portion the encrypted, encoded data;
compare the transformed data to a second portion of the encrypted, encoded data to determine if errors exist in the transformed data,
in response to a determination that no errors exist, convert the error-free version of data to plaintext; and
provide the plaintext to a receiver.
16. The system of claim 5, wherein:
the entwined cryptographic encode device further includes: first key generator circuitry to produce a first cipher stream of data based on a first key; and
wherein the entwined cryptographic encoding circuitry is further configured to transform the data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave based on the received first cipher stream; and
the entwined cryptographic decode device further includes:
second key generator circuitry to produce a second cipher stream of data based on a second key; and
wherein the entwined cryptographic decoding circuitry is further configured to transform the encrypted encoded data to a set of data integers modulo respective polynomial integers and perform the Da Yen weave transform based on the received second cipher stream.
17. The system of claim 16, wherein the first and second key generator ci cuitry are synced,
18. The system of claim 16, wherein a portion of the first cipher stream provides an index to the respective polynomials on the first memory and wherein a portion of the second cipher stream provides an index to the respective polynomials on the second memory.
19. The system of claim 18, wherein the polynomials on the first and second memories are indexed based on a respective root and primitive of the polynomials.
20. The system of claim 16, wherein the entwined cryptographic decoding circuitry is further configured to:
in response to a determination that errors exist, perform a weave swap on two words of the transformed data; and
compare the weave swapped data to a different portion of the encrypted, encoded data to determine if errors exist in the weave swapped version.
PCT/US2018/041623 2017-07-14 2018-07-11 Entwined encryption and error correction Ceased WO2019014336A1 (en)

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
US201762532563P 2017-07-14 2017-07-14
US62/532,563 2017-07-14
US15/667,111 US10333698B2 (en) 2017-07-14 2017-08-02 Entwined encryption and error correction
US15/667,111 2017-08-02

Publications (1)

Publication Number Publication Date
WO2019014336A1 true WO2019014336A1 (en) 2019-01-17

Family

ID=64999270

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2018/041623 Ceased WO2019014336A1 (en) 2017-07-14 2018-07-11 Entwined encryption and error correction

Country Status (3)

Country Link
US (1) US10333698B2 (en)
TW (1) TWI673992B (en)
WO (1) WO2019014336A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110995734A (en) * 2019-12-12 2020-04-10 深圳大学 Cloud storage auditing method and system based on error correcting code and computer equipment

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10333698B2 (en) 2017-07-14 2019-06-25 Raytheon Company Entwined encryption and error correction
US11032061B2 (en) * 2018-04-27 2021-06-08 Microsoft Technology Licensing, Llc Enabling constant plaintext space in bootstrapping in fully homomorphic encryption
US11057186B1 (en) * 2019-05-17 2021-07-06 Juniper Networks, Inc. Generating cryptographic random data from raw random data
US12099997B1 (en) 2020-01-31 2024-09-24 Steven Mark Hoffberg Tokenized fungible liabilities
US12225126B2 (en) 2021-12-21 2025-02-11 Silicon Motion, Inc. Apparatus and method for detecting errors during data encryption
CN116318644A (en) * 2021-12-21 2023-06-23 慧荣科技股份有限公司 Error detecting device for data encryption
US12348630B2 (en) 2021-12-21 2025-07-01 Silicon Motion, Inc. Apparatus and method for detecting errors during data encryption
US12580731B2 (en) 2022-06-02 2026-03-17 Cryptography Research, Inc. Encryption of error correction data using symbol-level ciphers
CN118677599A (en) 2023-03-20 2024-09-20 慧荣科技股份有限公司 Round key expansion device for data encryption

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160112197A1 (en) * 2014-10-16 2016-04-21 Dyce, Llc Method and apparatus for storing encrypted data files across distributed storage media

Family Cites Families (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3873047B2 (en) * 2003-09-30 2007-01-24 株式会社東芝 Identification information embedding device, identification information analysis device, identification information embedding method, identification information analysis method, and program
US8817974B2 (en) * 2011-05-11 2014-08-26 Nxp B.V. Finite field cryptographic arithmetic resistant to fault attacks
US8925075B2 (en) * 2011-11-07 2014-12-30 Parallels IP Holdings GmbH Method for protecting data used in cloud computing with homomorphic encryption
WO2014035146A2 (en) * 2012-08-28 2014-03-06 서울대학교산학협력단 Homomorphic encryption method and decryption method using ring isomorphism, and device using same
US9306738B2 (en) * 2012-12-21 2016-04-05 Microsoft Technology Licensing, Llc Managed secure computations on encrypted data
US20150095747A1 (en) * 2013-09-30 2015-04-02 Itzhak Tamo Method for data recovery
US9425961B2 (en) * 2014-03-24 2016-08-23 Stmicroelectronics S.R.L. Method for performing an encryption of an AES type, and corresponding system and computer program product
US10116437B1 (en) * 2015-12-14 2018-10-30 Ingram Micro, Inc. Method for protecting data used in cloud computing with homomorphic encryption
US20170293913A1 (en) * 2016-04-12 2017-10-12 The Governing Council Of The University Of Toronto System and methods for validating and performing operations on homomorphically encrypted data
US10742413B2 (en) * 2017-04-25 2020-08-11 International Business Machines Corporation Flexible verifiable encryption from lattices
US10333698B2 (en) 2017-07-14 2019-06-25 Raytheon Company Entwined encryption and error correction

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160112197A1 (en) * 2014-10-16 2016-04-21 Dyce, Llc Method and apparatus for storing encrypted data files across distributed storage media

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
ANNA JOHNSTON: "Dispersed Cryptography and the Quotient Ring Transform", INTERNATIONAL ASSOCIATION FOR CRYPTOLOGIC RESEARCH,, vol. 20170220:143702, 14 February 2017 (2017-02-14), pages 1 - 27, XP061022816 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110995734A (en) * 2019-12-12 2020-04-10 深圳大学 Cloud storage auditing method and system based on error correcting code and computer equipment
CN110995734B (en) * 2019-12-12 2020-12-15 深圳大学 Error-correcting code-based cloud storage auditing method, system and computer equipment

Also Published As

Publication number Publication date
TWI673992B (en) 2019-10-01
US20190020470A1 (en) 2019-01-17
US10333698B2 (en) 2019-06-25
TW201909594A (en) 2019-03-01

Similar Documents

Publication Publication Date Title
WO2019014336A1 (en) Entwined encryption and error correction
Trappe Introduction to cryptography with coding theory
Bösch et al. Efficient helper data key extractor on FPGAs
CA2723319C (en) A closed galois field cryptographic system
CN104871477B (en) Encryption system, re-encrypted private key generating means, re-encryption device, encryption method
EP2569884A1 (en) Format-preserving encryption via rotating block encryption
JP2008203548A (en) Key generating method using quadric hyperbolic curve group, decoding method, signature verification method, key stream generating method and device
JP6229714B2 (en) Ciphertext verification system, method and program
Saarinen Ring-LWE ciphertext compression and error correction: Tools for lightweight post-quantum cryptography
Sokouti et al. Medical image encryption: an application for improved padding based GGH encryption algorithm
Diekert et al. Discrete algebraic methods: Arithmetic, cryptography, automata and groups
Shcherbacov Quasigroup based crypto-algorithms
AU2020275902A1 (en) A computer-implemented method of performing Feistel-network-based block-cipher encryption of plaintext
Dumas et al. Foundations of coding: compression, encryption, error correction
CN104881838B (en) One kind is based on GF (23) (K, N) significant point deposited without expansion image and reconstructing method
CN103095449A (en) Dynamic encryption and decryption method based on stream ciphers
CN103354984B (en) Encryption processing system, key generating device, encryption device, decryption device, key handover apparatus and cipher processing method
CN107078900B (en) Cryptosystems based on reproducible random sequences
Kuang Quantum permutation pad for quantum secure symmetric and asymmetric cryptography
CN109639423B (en) Constituent device of decryption algorithm
Niebuhr Attacking and defending code-based cryptosystems
Fathimala et al. K out of N secret sharing scheme for gray and color images
CN117150536B (en) Anti-counterfeiting method, device and equipment for document and readable storage medium
Naresh et al. QR verification system using RSA algorithm
Wen et al. An information hiding scheme using magic squares

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18752660

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18752660

Country of ref document: EP

Kind code of ref document: A1