Sign In to Follow Application
View All Documents & Correspondence

"Cryptographic Processing Apparatus, Cryptographic Processing Algorithm Constructing Method, And Cryptographic Processing Method, And Computer Program"

Abstract: It is possible to realize an extended Feistel-type common key block encryption process configuration for realizing a diffusion matrix switching mechanism (DSM). In an encryption process configuration using the extended Feistel structure in which a data sequence number d is an integer not smaller than 2, a plurality of different matrixes are selectively applied in the linear conversion process of the F function unit by selecting a plurality of different matrixes which satisfy the condition that the minimum branching number in all the data sequence selected from the minimum branching number corresponding to a data sequence based on the linear conversion matrix contained in the F function inputted to each data sequence of the extended Feistel ...

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
01 January 2009
Publication Number
21/2009
Publication Type
INA
Invention Field
COMPUTER SCIENCE
Status
Email
Parent Application

Applicants

SONY CORPORATION
1-7-1 KONAN, MINATO-KU, TOKYO, JAPAN.

Inventors

1. TAIZO SHIRAI
C/O SONY CORPORATION 1-7-1 KONAN, MINATO-KU, TOKYO, JAPAN.

Specification

DESCRIPTION CRYPTOGRAPHIC PROCESSING APPARATUS, CRYPTOGRAPHIC-PROCESSING-ALGORITHM CONSTRUCTING METHOD, AND CRYPTOGRAPHIC PROCESSING METHOD, AND COMPUTER PROGRAM Technical Field [0001]
The present invention relates to a cryptographic processing apparatus, a cryptographic-processing-algorithm constructing method, and a cryptographic processing method, and a computer program. More specifically, the present invention relates to a cryptographic processing apparatus, a cryptographic-processing-algorithm constructing method, and a cryptographic processing method which perform Feistel-type common-key block-cipher processes, and a computer program. Background Art [0002]
Nowadays, with the development of network communication and electronic commerce, security ensuring in communication has become an important issue. One method for ensuring security is cryptographic technology, and communication using various encryption techniques is currently done in actuality. [0003]
For example, a system has been put into practical use, in which a cryptographic processing module is embedded in a
compact device such as an IC card, and in which data transmission and reception is performed between the IC card and a reader/writer serving as a data reading and writing apparatus, thereby performing an authentication process or encryption and decryption of transmitted and received data. [0004]
There are various cryptographic processing algorithms, which are broadly classified into a public-key cryptographic scheme in which an encryption key and a decryption key are set as different keys, for example, a public key and a secret key, and a common-key cryptographic scheme in which an encryption key and a decryption key are set as a common key. [0005]
The common key cryptographic scheme has various algorithms. One of them is a scheme in which a plurality of keys are generated on the basis of a common key, and in which a data transformation process in units of blocks (such as 64-bit or 128-bit) is repeatedly performed using the plurality of generated keys. A typical algorithm to which such a key generation scheme and a data transformation process are applied is a common-key block-cipher scheme. [0006]
As a typical common-key block-cipher algorithm, for example, a DES (Data Encryption Standard) algorithm, which
is a U.S. standard cryptography, is broadly used in various
fields.
[0007]
The common-key block-cipher algorithm, typified by the DES, can be mainly divided into round-function sections that perform transformation of input data, and a key scheduling section that generates round keys applied in respective rounds of the round-function (F-function) sections. Round keys (sub-keys) that are to be applied in the respective rounds of the round-function sections are generated on the basis of one master key (a main key) that is input to the key scheduling section, and are applied in the respective round-function sections. [0008]
A Feistel structure has been known as a specific structure for executing an algorithm to which such round functions are applied. The Feistel structure has a structure that transforms plaintext into ciphertext by simply repeating transformation functions which are called round functions. Examples of documents describing cryptographic processes to which Feistel structures are applied include Non-Patent Document 1 and Non-Patent Document 2. [0009]
However, for example, a common-key cryptographic
process to which a Feistel structure is applied has a problem of leakage of keys due to cryptanalysis. Differential analysis (also called differential cryptanalysis or differential attack), in which keys applied in respective round functions are analyzed by analyzing multiple pieces of input data (plaintext) having a certain difference and pieces of output data (ciphertext) for the input data, and linear analysis (also called linear cryptanalysis or linear attack) , in which analysis based on plaintext and corresponding ciphertext is performed, have been known as typical techniques of cryptanalysis or attack techniques. [0010]
Easy analysis of keys due to cryptanalysis implies low security of a cryptographic process using the keys. In cryptographic algorithms of the prior art, because processes (transformation matrices) that are applied in linear transformation sections of round-function (F-function) sections are equal to one another in rounds of respective stages, analysis is feasible, resulting in easy analysis of keys. [0011]
As a configuration for dealing with such a problem, a configuration has been proposed, m which two or more different matrices are arranged in linear transformation
sections of round-function (F-function) sections in a Feistel structure. This technique is called a diffusion-matrix switching mechanism (DSM: Diffusion Switching Mechanism, hereinafter, referred to as "DSM"). Resistance to differential attacks or linear attacks can be enhanced using this DSM. [0012]
The diffusion-matrix switching mechanism (DSM) is provided as a configuration that can be applied to a typical Feistel structure having two data lines. In contrast, there is an extended-type Feistel structure having three or more data lines, which is different from the typical Feistel structure having two data lines. However, no configuration has been disclosed, m which the above-mentioned diffusion-matrix switching mechanism (DSM) is applied in such an extended-type Feistel structure having three or more data lines so that resistance to differential attacks or linear attacks is enhanced.
Non-Patent Document 1: K. Nyberg, "Extended Feistel structures", ASIACRYPT'96, SpringerVerlag, 1996, pp.91—104. Non-Patent Document 2: Yuliang Zheng, Tsutomu Matsumoto, Hideki Imai: On the Construction of Block Ciphers Provably Secure and Not Relying on Any Unproved Hypotheses. CRYPTO 1989: 461-480 Disclosure of Invention
Technical Problem [0013]
The present invention has been made in view of the foregoing problems, and aims to provide a cryptographic processing apparatus, a cryptographic-processing-algorithm constructing method, and a cryptographic processing method which realize common-key block-cipher algorithms with a high resistance to linear analysis and differential analysis, and a computer program. [0014]
More specifically, round-function sections to which a plurality of different linear transformation matrices are applied are set in a Feistel structure obtained by expanding a Feistel structure having two data lines, i.e., in an extended-type Feistel structure having any number of data lines that is equal to or more than two, such as three or four, thereby aiming to provide a cryptographic processing apparatus, a cryptographic-processing-algorithm constructing method, and a cryptographic processing method which realize common-key block-cipher algorithms with a high resistance to linear analysis and differential analysis, and a computer program.
Technical Solution [0015]
A first aspect of the present invention resides in:
a cryptographic processing apparatus characterized by including
a cryptographic processing section that performs a Feistel-type common-key block-cipher process of repeating an SP-type F-function m a plurality of rounds, the SP-type F-function performing a data transformation process including a non-linear transformation process and a linear transformation process,
wherein the cryptographic processing section
is configured to perform a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, is configured to selectively apply a plurality of at least two or more different matrices to linear transformation processes that are performed in F-functions in respective rounds,
the plurality of two or more different matrices being a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are
input to a corresponding data line in the extended Feistel structure,
and is configured so that the plurality of different matrices are repeatedly arranged in the F-functions that are input to the respective data lines in the extended Feistel structure. [0016]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is characterized in that the plurality of different matrices, which are utilized in the cryptographic processing section, are a plurality of different matrices satisfying a condition in which a minimum number of branches [BkD] for all of the data lines is equal to or more than three, the minimum number of branches [BkD] for all of the data lines being selected from among minimum numbers of branches [BkD(s(i))] corresponding to the data lines, each of the minimum numbers of branches [BkD(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in k (where k is an integer equal to or more than two) continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure. [0017]
Furthermore, in an embodiment of the cryptographic
processing apparatus of the present invention, it is characterized in that the plurality of different matrices, which are utilized in the cryptographic processing section, are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2D] for all of the data lines is equal to or more than three, the minimum number of branches [B2D] for all of the data lines being selected from among minimum numbers of branches [B2D(s(i))] corresponding to the data lines, each of the minimum numbers of branches [B2D(s(i))j corresponding to the data lines being calculated on the basis of linear transformation matrices included in two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure. [0018]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is characterized in that the plurality of different matrices, which are utilized in the cryptographic processing section, are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2L] for all of the data lines is equal to or more than three, the minimum number of branches [B2L] for all of the data lines being selected from among minimum numbers of branches [B2L(s(i))] corresponding to the data lines, each of the minimum numbers
of branches [B2L(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure. [0019]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is characterized in that, when the plurality of different matrices are denoted by n (where n is an integer equal to or more than two) different matrices, i.e., M0, Mlf .. Mn_1, the cryptographic processing section is configured so that the different matrices M0, Mlr -Mn_1 are repeatedly arranged in an order in the F-functions that are input to the respective data lines in the extended Feistel structure. [0020]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is characterized in that the cryptographic processing section is configured to perform a cryptographic process to which an extended Feistel structure that performs only one F-function in one round is applied. [0021]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is
characterized in that the cryptographic processing section is configured to perform a cryptographic process to which an extended Feistel structure that performs a plurality of F-functions in parallel in one round is applied. [0022]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is characterized in that the cryptographic processing section is configured to perform, when a is any integer satisfying a > 2 and x is any integer satisfying x > 1, a cryptographic process to which an extended Feistel structure that utilizes a types of F-functions and that has the number of data lines: d which is set as d = 2ax is applied, the a types of F-functions performing different linear transformation processes using the plurality of different matrices, and configured to perform equally x pieces of each of the types (the a types) of F-functions in one round. [0023]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is characterized in that the cryptographic processing section is configured by including: an F-function performing unit that performs ax F-functions which are performed in parallel in one round; and a control unit that performs data input/output control for the F-function performing unit.
[0024]
Furthermore, in an embodiment of the cryptographic processing apparatus of the present invention, it is characterized in that the cryptographic processing section includes: a plurality of F-function performing units that perform different linear transformation processes using the plurality of different matrices; and a control unit that changes a sequence of utilizing the plurality of F-function performing units in accordance with a setting,
wherein the control unit is configured to selectively perform any of cryptographic processes (a), (bl), and (b2), i.e.,
(a) a cryptographic process using a Feistel structure having the number of data lines d that is set as d = 2,
(bl) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and m which only one F-function is allowed to be performed in each round, or
(b2) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which a plurality of F-functions are allowed to be performed in parallel in each round. [0025]
Furthermore, in an embodiment of the cryptographic
processing apparatus of the present invention, it is characterized in that the control unit is configured to select a processing mode to be performed in accordance with a bit length of data that is to be subjected to an encryption or decryption process. [0026]
A second aspect of the present invention resides in: a cryptographic processing method for performing a cryptographic process in a cryptographic processing apparatus, the method characterized by including
a cryptographic processing step of performing a Feistel-type common-key block-cipher process of repeating an SP-type F-function in a plurality of rounds in a cryptographic processing section, the SP-type F-function performing a data transformation process including a nonlinear transformation process and a linear transformation process,
wherein the cryptographic processing step is a step of performing a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, and includes an operation step of performing operations in which a plurality of at least two or more different matrices are selectively applied to linear transformation processes that are performed in F-functions
in respective rounds,
wherein the plurality of different matrices, which are applied in the operation step, are a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure, and
wherein the operation step
is a step of performing linear transformation operations based on the plurality of different matrices in the F-functions that are input to the respective data lines in the extended Feistel structure. [0027]
Furthermore, in an embodiment of the cryptographic processing method of the present invention, it is characterized in that the plurality of different matrices are a plurality of different matrices satisfying a condition in which a minimum number of branches [BkD] for all of the data lines is equal to or more than three, the minimum number of branches [BkD] for all of the data lines being
selected from among minimum numbers of branches [BkD(s(i))] corresponding to the data lines, each of the minimum numbers of branches [BkD(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in k (where k is an integer equal to or more than two) continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure. [0028]
Furthermore, in an embodiment of the cryptographic processing method of the present invention, it is characterized in that the plurality of different matrices are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2D] for all of the data lines is equal to or more than three, the minimum number of branches [B2D] for all of the data lines being selected from among minimum numbers of branches [B2D(s(i))] corresponding to the data lines, each of the minimum numbers of branches [B2D(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure. [0029]
Furthermore, in an embodiment of the cryptographic
processing method of the present invention, it is characterized m that the plurality of different matrices are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2L] for all of the data lines is equal to or more than three, the minimum number of branches [B2L] for all of the data lines being selected from among minimum numbers of branches [B2L(s(i))] corresponding to the data lines, each of the minimum numbers of branches [B2L(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included m two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure. [0030]
Furthermore, in an embodiment of the cryptographic processing method of the present invention, it is characterized in that, when the plurality of different matrices are denoted by n (where n is an integer equal to or more than two) different matrices, i.e., M0, Mlf •••Mn_1, the operation step is a step of repeatedly performing the different matrices M0, Mx, .. Mn_1 in an order in the F-functions that are input to the respective data lines in the extended Feistel structure. [0031]
Furthermore, in an embodiment of the cryptographic
processing method of the present invention, it is characterized in that the cryptographic processing step is a step of performing a cryptographic process to which an extended Feistel structure that performs only one F-function in one round is applied. [0032]
Furthermore, in an embodiment of the cryptographic processing method of the present invention, it is characterized in that the cryptographic processing step is a step of performing a cryptographic process to which an extended Feistel structure that performs a plurality of F-functions in parallel in one round is applied. [0033]
Furthermore, in an embodiment of the cryptographic processing method of the present invention, it is characterized in that the cryptographic processing step is a step of performing, when a is any integer satisfying a > 2 and x is any integer satisfying x > 1, a cryptographic process to which an extended Feistel structure that utilizes a types of F-functions and that has the number of data lines: d which is set as d = 2ax is applied, the a types of F-functions performing different linear transformation processes using the plurality of different matrices, and a step of performing equally x pieces of each of the types (the a types) of F-functions in one round.
[0034]
Furthermore, m an embodiment of the cryptographic processing method of the present invention, it is characterized in that the cryptographic processing step is a step of performing a cryptographic process, in which an F-function performing unit that performs ax F-functions performed in parallel in one round is applied, in accordance with control performed by a control unit that performs data input/output control for the F-function performing unit. [0035]
Furthermore, in an embodiment of the cryptographic processing method of the present invention, it is characterized in that the cryptographic processing step is a step of performing a cryptographic process by using a plurality of F-function performing units that perform different linear transformation processes using the plurality of different matrices, and by using a control unit that changes a sequence of utilizing the plurality of F-function performing units in accordance with a setting,
wherein the cryptographic processing step is a step of, in accordance with control performed by the control unit, selectively performing any of cryptographic processes (a), (bl), and (b2), i.e.,
(a) a cryptographic process using a Feistel structure having the number of data lines d that is set as d = 2,
(bl) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which only one F-function is allowed to be performed in each round, or
(b2) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which a plurality of F-functions are allowed to be performed in parallel in each round. [0036]
Furthermore, in an embodiment of the cryptographic processing method of the present invention, it is characterized in that the control unit selects a processing mode to be performed in accordance with a bit length of data that is to be subjected to an encryption or decryption process. [0037]
A third aspect of the present invention resides in:
a cryptographic-processing-algorithm constructing method for constructing a cryptographic processing algorithm in an information processing apparatus, the method characterized by including:
a matrix-determining step in which, in a cryptographic-processing-algorithm configuration to which an extended Feistel structure having a number of data lines: d that is
set to an integer satisfying d > 2 is applied, a control unit provided in the information processing apparatus determines a plurality of at least two or more different matrices that are to be applied to linear transformation processes performed in F-functions in respective rounds; and
a matrix-setting step in which the control unit repeatedly arranges the plurality of different matrices, which are determined in the matrix-determining step, in the F-functions that are input to the respective data lines m the extended Feistel structure,
wherein the matrix-determining step
is a step of performing a process of determining, as the plurality of two or more different matrices, as matrices to be applied, a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure. [0038]
A fourth aspect of the present invention resides m:
a computer program that causes a cryptographic processing apparatus to perform a cryptographic process, the program characterized by including
a cryptographic processing step of causing a cryptographic processing section to perform a Feistel-type common-key block-cipher process of repeating an SP-type F-function in a plurality of rounds, the SP-type F-function performing a data transformation process including a nonlinear transformation process and a linear transformation process,
wherein the cryptographic processing step
is a step of causing the cryptographic processing section to perform a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, and includes an operation step of performing operations in which a plurality of at least two or more different matrices are selectively applied to linear transformation processes that are performed in F-functions in respective rounds,
wherein the plurality of different matrices, which are applied in the operation step, are a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum
numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure, and
wherein the operation step
is a step of performing linear transformation operations based on the plurality of different matrices in the F-functions that are input to the respective data lines in the extended Feistel structure. [0039]
A fifth aspect of the present invention resides in:
a computer program that causes an information processing apparatus to construct a cryptographic processing algorithm, the program characterized by including:
a matrix-determining step of causing, in a cryptographic-processing-algorithm configuration to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, a control unit provided in the information processing apparatus to determine a plurality of at least two or more different matrices that are to be applied to linear transformation processes performed in F-functions in respective rounds; and
a matrix-setting step of causing the control unit to
repeatedly arrange the plurality of different matrices, which are determined in the matrix-determining step, in the F-functions that are input to the respective data lines in the extended Feistel structure,
wherein the matrix-determining step
is a step of performing a process of determining, as the plurality of two or more different matrices, as matrices to be applied, a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line m the extended Feistel structure. [0040]
Note that the computer program of the present invention is a computer program that can be provided using a storage medium or a communication medium, for example, a recording medium such as a CD, a FD, or an MO, or a communication medium such as a network, that provides a program in a computer-readable format for a computer system capable of executing various program codes. Such a program is provided
in a computer-readable format, whereby a process according to the program is realized m the computer system.
[0041]
Further other objects, features, and advantages of the present invention will become apparent from more detailed descriptions based on embodiments of the present invention, which will be described below, or the attached drawings. Note that a "system" mentioned in the specification is configured as a logical set of a plurality of apparatuses, and is not limited to a system in which the apparatuses having respective configurations are contained in the same casing. Advantageous Effects
[0042]
According to a configuration in an embodiment of the present invention, in a Feistel-type common-key block-cipher process in which SPN-type F-functions including non-linear transformation sections and linear transformation sections are repeatedly performed in a plurality of rounds, round-function sections to which a plurality of different linear transformation matrices are applied are set in a Feistel structure obtained by expanding a Feistel structure having two data lines, i.e., in a Feistel structure having any number of data lines that is equal to or more than two, such as three or four, thereby realizing the diffusion-matrix

switching mechanism (DSM), so that a common-key block-cipher algorithm can be constructed and a cryptographic process can be performed with a high resistance to linear analysis and differential analysis. [0043]
According to a configuration in an embodiment of the present invention, a configuration is provided, in which a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied is performed, and the configuration is provided as a configuration in which a plurality of at least two or more different matrices are selectively applied to linear transformation processes performed m F-functions in respective rounds. A plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value are set as the plurality of two or more different matrices, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure, thereby realizing the diffusion-matrix switching
mechanism (DSM), so that a common-key block-cipher algorithm can be constructed and a cryptographic process can be performed with a high resistance to linear analysis and differential analysis. [0044]
Furthermore, according to a configuration in an embodiment of the present invention, a configuration is provided, in which a (a > 2) types of F-functions perform different linear transformation processes using a plurality of different matrices, in which an extended Feistel structure (x > 1) that utilizes the F-functions and that has the number of data lines: d that is set as d = 2ax, and in which a cryptographic process to which the extended Feistel structure is applied is performed. The configuration is provided a configuration in which equally x pieces of each of the types (the a types) of F-functions are performed m one round, whereby a compact cryptographic processing apparatus in which no useless circuit is provided is realized. [0045]
Furthermore, according to a configuration in an embodiment of the present invention, a plurality of F-function performing units are configured to perform different linear transformation processes using a plurality of different matrices, and a configuration is provided, in
which a sequence of utilizing the plurality of F-function performing units is changed in accordance with a setting,
whereby a cryptographic processing apparatus is realized, which can selectively perform any of cryptographic processes (a), (bl), and (b2), i.e.,
(a) a cryptographic process using a Feistel structure having the number of data lines d that is set as d = 2,
(bl) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which only one F-function is allowed to be performed in each round, or
(b2) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which a plurality of F-functions are allowed to be performed in parallel in each round.
Brief Description of Drawings [0046]
[Fig. 1] Fig. 1 is a diagram showing a typical common-key block-cipher configuration having a Feistel structure.
[Fig. 2] Fig. 2 is a diagram describing a configuration of an F-function that is set as a round-function section.
[Fig. 3] Fig. 3 is a diagram describing a Feistel-type cryptographic algorithm in which two different liner transformation matrices are utilized.
[Fig. 4] Fig. 4 is a diagram describing a Feistel-type cryptographic algorithm in which three different liner transformation matrices are utilized.
[Fig. 5] Fig. 5 is a diagram describing definitions of an extended Feistel structure.
[Fig. 6] Fig. 6 is a diagram showing an example of an extended Feistel structure having seven data lines (d = 7).
[Fig. 7] Fig. 7 is a diagram describing definitions of respective constituent sections and input/output data of the respective constituent sections of an extended Feistel structure.
[Fig. 8] Fig. 8 is a diagram describing application of DSM to an extended Feistel structure or a type 1.
[Fig. 9] Fig. 9 is a diagram describing application of the DSM to an extended Feistel structure or a type 2.
[Fig. 10] Fig. 10 is a diagram describing application of the DSM to the extended Feistel structure or the type 1.
[Fig. 11] Fig. 11 is a diagram describing application of the DSM to the extended Feistel structure or the type 2.
[Fig. 12] Fig. 12 is a diagram describing a configuration in which implementation efficiency is improved in an extended Feistel structure.
[Fig. 13] Fig. 13 is a diagram describing an example of a hardware configuration in which implementation efficiency is improved in an extended Feistel structure.
[Fig. 14] Fig. 14 is a diagram describing an example of an arrangement for efficiently implementing three types of F-functions.
[Fig. 15] Fig. 15 is a diagram showing a 2mn-bit block-cipher configuration which is provided as a Feistel structure having the number of data lines that is set as d = 2.
[Fig. 16] Fig. 16 is a diagram showing an extended Feistel structure which satisfies the diffusion-matrix switching mechanism (DSM), and which has the number of data lines that is set as d = 4.
[Fig. 17] Fig. 17 is a diagram describing a circuit sharing configuration in which block cipher using different numbers of bits can be performed.
[Fig. 18] Fig. 18 is a diagram describing a Feistel structure to which F-functions, i.e., three types of F-functions Fl, F2, and F3, are applied, and which has the number of data lines that is set as d = 2.
[Fig. 19] Fig. 19 is a diagram describing an example of a configuration of a cryptographic processing apparatus that performs the three types of F-functions Fl, F2, and F3.
[Fig. 20] Fig. 20 is a diagram showing an example of a configuration of an IC module serving as a cryptographic processing apparatus, which performs a cryptographic process, according to the present invention.
Best Modes for Carrying Out the Invention [0047]
A cryptographic processing apparatus and a cryptographic processing method, and a computer program will be described below in details. The description is made in the order of section headings as follows:
1. Feistel Structure Having SP-Type F-Functions
2. Operation Function of Number of Branches and Evaluation Function of Resistance
2-1. Operation Function of Number of Branches: Branch() 2-2. Evaluation Index of Resistance to Differential Attacks
2-3. Evaluation Index of Resistance to Linear Attacks
3. Method for Setting DSM for Feistel Structure Having
Two Data Lines
4. Setting of DSM in Extended Feistel Structure
4-1. Regarding Extended Feistel Structure
4-2. Configuration for Enhancing Resistance to Differential Attacks in Extended Feistel Structure
4-2-1. Configuration for Selecting Matrices, Which Is to Be Set in F-Functions, That Make Value of Minimum Number of Branches B2D Equal To or More Than Three
4-2-2. Configuration for Selecting Matrices, Which Is to Be Set in F-Functions, That Make Value of Minimum Number of Branches BkD Equal To or More Than Three
4-3. Configuration for Enhancing Resistance to Linear Attacks in Extended Feistel Structure
4-3-1. Configuration for Selecting Matrices, Which Is to Be Set m F-Functions, That Make Value of Minimum Number B2L of Branches Equal To or More Than Three
5. Configuration in Which DSM Is Utilized for Extended
Feistel Structure Having Specific Form
5-1. Application of DSM to Extended Feistel Structure of Type 1
5-2. Application of DSM to Extended Feistel Structure of Type 2
6. Proof of Relationships Between Numbers of Active S-
Boxes in Extended Feistel Structure of Each Type and Minimum
Numbers of Branches Based on Linear Transformation Matrices
in F-Functions
6-1. Proof of Relationships between Numbers of Active S-Boxes in Extended Feistel Structure of Type 1 and Minimum Numbers of Branches Based on Linear Transformation Matrices in F-Functions
6-2. Proof of Relationships between Numbers of Active S-Boxes in Extended Feistel Structure of Type 2 and Minimum Numbers of Branches Based on Linear Transformation Matrices in F-Functions
7. Improved Configuration for Implementation Based on
Contrivance of Setting of F-Functions and Process of
Utilizing F-Functions
7-1. Method for Efficiently Arranging F-Functions in Extended Feistel Structure of Type 2
7-2. Commonality of Components in Feistel Structure and Extended Feistel Structure
8. Summary of Cryptographic Processes and Cryptographic Algorithm Constructing Processes of Present Invention
9. Example of Configuration of Cryptographic Processing Apparatus
[0048]
[1. Feistel Structure Having SP-Type F-Functions] First, a Feistel structure having SP-type F-functions will be described. A Feistel structure is known as a common-key block-cipher design. The Feistel structure has a structure which transforms plaintext into ciphertext by repeating a basic unit of processing that is referred to as a round function. [0049]
A basic configuration of the Feistel structure will be described with reference to Fig. 1. Fig. 1 shows an example of a Feistel structure having two data lines having a number of rounds = r that indicates r rounds. Note that the number of rounds r is a parameter that is determined at a design stage, and that it is a value which can be changed in accordance with, for example, the length of an input key.
[0050]
In the Feistel structure shown in Fig. 1, it is supposed that the length of plaintext which is input as a target to be encrypted is 2mn bits, where m and n are both integers. First, the 2mn-bit plaintext is divided into two pieces of mn-bit input data PL (Plain-Left) 101 and PR
(Plain-Right) 102, and the input data PL (Plain-Left) 101 and PR (Plain-Right) 102 are provided as input values.
[0051]
The Feistel structure is represented using repetition of the basic unit of processing, which is referred to as a round function, and a data transformation function included in each round is referred to as an F-function 120. In the configuration shown in Fig. 1, an example of a configuration m which the F-function (round function) 120 is repeated m r stages is shown.
[0052]
For example, in the first round, mn-bit input data X and an mn-bit round key K± 103, which is input from a key generating section (not illustrated), are input to the F-function 120, and, after a data transformation process is performed in the F-function 120, mn-bit data Y is output. An exclusive OR operation is performed in an exclusive-OR section 104 using the output data Y and the other input data that is input from the previous stage (in a case of the
first stage, input data PL) , and an mn-bit operation result is output to the next round function. This process, i.e., an encryption process in which the F-function is applied so as to be repeated only times corresponding to a determined number of rounds (r) , is completed, and pieces of divided data CL (Cipher-Left) and CR (Cipher-Right), which are ciphertext, are output. With the above-described configuration, as a decryption process in the Feistel structure, it is only necessary to reverse the order of inserting round keys, and it is concluded that it is not necessary to configure inverse functions. [0053]
A configuration of the F-function 120 that is set as a function m each round is described with reference to Fig. 2. Part (a) of Fig. 2 is a diagram showing inputs and an output of the F-function 120 in one round, and part (b) of Fig. 2 is a diagram showing the detailed configuration of the F-function 120. As shown in part (b) of Fig. 2, the F-function 120 has a so-called SP-type configuration in which a non-linear transformation layer (an S layer) and a linear transformation layer (a P layer) are connected to each other. [0054]
The F-function 120 shown in Fig. 2 is a function having a setting in which the length of input/output bits is m x n bits (m, n: integers). In the SP-type F-function, first,
exclusive OR is performed using key data K≠ and data X1. Next, the non-linear transformation layer (the S layer) is applied, and then the linear transformation layer (the P layer) is applied. [0055]
Specifically, the non-linear transformation layer (the S layer) is a layer in which m non-linear transformation tables with n-bit inputs and n-bit outputs, which are referred to as S-boxes 121, are arranged, and mn-bit data is divided into n-bit pieces. The n-bit pieces are input to the corresponding S-boxes 121, and data is transformed. In each of the S-boxes 121, a non-linear transformation process, for example, in which a transformation table is applied is performed. [0056]
The linear transformation layer (the P layer) is configured using a linear transformation section 122. The linear transformation section 122 takes an mn-bit output value Z, which is data output from the S-boxes 121, as an input, and performs linear transformation for the input to output an mn-bit result. The linear transformation section 122 performs a linear transformation process such as a process of permutating positions of input bits, and outputs an mn-bit output value Y. Exclusive OR is performed using this output value Y and input data that is provided from the
previous stage, and the result of exclusive OR is provided as an input value for an F-function of the next round. [0057]
Note that, in a configuration of an embodiment described below, linear transformation performed in the linear transformation section 122 serving as the linear transformation layer (the P layer) is defined as linear transformation which is performed so that an mn x mn matrix defined over GF(2) is applied, and that, in addition, a matrix included in the i-th round is referred to as Mx. Note that it is supposed that both the S-boxes, which serve as non-linear transformation sections, and linear transformation in the configuration described in the present invention are bijective. [0058]
[2. Operation Function of Number of Branches and Evaluation Function of Resistance]
Next, an operation function of the number of branches and an evaluation function of resistance, which are necessary to understand the present invention, will be described.
(2-1. Operation Function of Number of Branches: Branch())
An operation function of the number of branches: Branch() for optimal diffusion transform (Optimal Diffusion
Mappings), which is provided as an example of linear transformation that is performed in the linear transformation section 122 serving as the linear transformation layer (the P layer) included in the above-described F-function, is defined as follows. [0059]
A mapping describing linear transformation from nxa-bit data to nxb-bit data is represented as follows:
: {0, l}na → {0, l}nb
The number of branches: Branchn() is defined for the mapping as follows:
Branchn() = mina * 0{hwn (α) + hwn((α))}
Note that minα ≠0{Xα} represents the minimum value among all Xα satisfying a ≠ 0, and that hwn(Y) represents a function of returning the number of (non-zero) elements in which all of n bit pieces of data are not zero when a bit column Y is delimited and represented in units of n bits.
Note that, in this case, a mapping 0 that is provided so that Branchn() is b + 1 is defined as an optimal diffusion transform. [0060]
(2-2. Evaluation Index of Resistance to Differential Attacks)
A common-key cryptographic process in which a Feistel structure is applied has a problem of leakage of keys due to
cryptanalysis. Differential analysis (also called differential cryptanalysis or differential attack), in which keys applied in respective round functions are analyzed by analyzing multiple pieces of input data (plaintext) having a certain difference (AX) and pieces of output data
(ciphertext) for the input data, and linear analysis (also called linear cryptanalysis or linear attack), in which analysis based on plaintext and corresponding ciphertext is performed, have been known as typical techniques of cryptanalysis or attack techniques.
[0061]
The minimum number of differential active S-boxes included in a differential path that represents connection relationships of differences can be applied as an index for evaluating resistance to differential attacks.
A differential path is a path in which specific differential values are designated for all pieces of data excluding pieces of key data in encryption functions. The differential values are not arbitrarily determined, and the differential values obtained before/after transformation processes are related to one another. Before/after linear transformation processes, the relationships between input differences and output differences are determined as one-to-one relationships. Although, before/after non-linear transformation, the relationships between input differences
and output differences are not determined as one-to-one relationships, a concept of probabilities is introduced. It is supposed that probabilities for an input difference and output differences can be calculated in advance. The sum of all probabilities for all outputs is one. [0062]
In a Feistel structure having SP-type F-functions, nonlinear transformation is performed only in a portion of processes using S-boxes. Accordingly, in this case, a differential path having a probability other than zero represents a set of pieces of differential data that are provided as differential values starting with a differential value for plaintext (input) and ending with a differential value for ciphertext (output), and differential values that are provided before/after all S-boxes are differential values having probabilities other than zero. An S-box which is included in a differential path having a probability other than zero, and to which a differential value that is not zero is input is referred to as a "differential active S-box". The minimum number among the numbers of active S-boxes in all differential paths having probabilities other than zero is referred to as a "minimum number of differential active S-boxes", and the value of this number is known as a safety index for differential attacks. Note that there is no point in attacking a differential path in
which all differential values are zero because the probability of the path becomes one. Thus, the path will not be considered below.
[0063]
In an embodiment of the present invention, a configuration is provided, in which the minimum number of differential active S-boxes is ensured to be large, thereby enhancing safety for differential attacks.
[0064]
(2-3. Evaluation Index of Resistance to Linear Attacks) Furthermore, the minimum number of linear active S-boxes included in a linear path that represents connection relationships of linear masks (although it is referred to as a "linear approximation" in most cases, herein, a word "path" is used in order to correspond to difference) can be applied as an index for evaluating resistance to linear attacks.
[0065]
A linear path is a path in which specific linear mask values are designated for all pieces of data excluding pieces of key data in encryption functions. The linear mask values are not arbitrarily determined, and the linear values obtained before/after transformation processes are related to one another. Before/after linear transformation processes, the relationships between input linear mask
values and output linear mask values are determined as one-to-one relationships. Although, before/after non-linear transformation, the relationships between input linear mask values and output linear mask values are not determined as one-to-one relationships, a concept of probabilities is introduced. A set of one or more linear mask values that can be output exists for an input linear mask value, and probabilities that the respective linear mask values are output can be calculated in advance. The sum of all probabilities for all outputs is one. [0066]
In a Feistel structure having SP-type F-functions, nonlinear transformation is performed only in a portion of processes using S-boxes. Accordingly, in this case, a linear path having a probability other than zero represents a set of pieces of linear-mask-value data that are provided as linear values starting with a linear value for plaintext (input) and ending with a linear value for ciphertext (output), and linear values that are provided before/after all S-boxes are linear values having probabilities other than zero. An S-box which is included in a linear path having a probability other than zero, and to which a linear value that is not zero is input is referred to as a "linear active S-box". The minimum number among the numbers of active S-boxes in all linear paths having probabilities
other than zero is referred to as a "minimum number of linear active S-boxes", and the value of this number is known as a safety index for linear attacks. Note that there is no point m attacking a linear path in which all linear mask values are zero because the probability of the path becomes one. Thus, the path will not be considered below. [0067]
In an embodiment of the present invention, a configuration is provided, in which the minimum number of linear active S-boxes is ensured to be large, thereby enhancing safety for linear attacks. [0068]
[3. Method for Setting DSM for Feistel Structure Having Two Data Lines]
As described previously, a configuration m which the diffusion-matrix switching mechanism (DSM: Diffusion Switching Mechanism, hereinafter, referred to as "DSM") is applied has been proposed as a configuration for enhancing resistance to the above-described differential attacks or linear attacks in a cryptographic process in which a Feistel structure is applied. The DSM has a configuration in which two or more different matrices are arranged m linear transformation sections of round-function (F-function) sections in a Feistel structure. With the DSM, the minimum number of linear active S-boxes can be ensured to be large,
whereby resistance to the differential attacks or linear
attacks can be enhanced.
[0069]
An outline of the DSM will be described. When the diffusion-matrix switching mechanism (DSM) is applied in a Feistel structure, a plurality of different matrices are provided as matrices that are applied in linear transformation sections (P layers) of round-function (F-function) sections constituting the Feistel structure. For example, all of the matrices applied in the respective rounds in the Feistel structure having r rounds as shown in Fig. 1 are not set as the same linear transportation matrices, and at least two or more types of matrices are arranged in accordance with a specific rule. [0070]
For example, Fig. 3 shows an example of a Feistel structure in which the diffusion-matrix switching mechanism (DSM) is realized using two linear transformation matrices M0 and Ml7 and Fig. 4 shows an example of a Feistel structure in which the diffusion-matrix switching mechanism (DSM) is realized using three linear transformation matrices M0, Mlr and M2. [0071]
In the example of the Feistel structure shown in Fig. 3, the two linear transformation matrices M0 and Mx are
configured as different matrices. Additionally, in the example of the Feistel structure shown in Fig. 4, the three linear transformation matrices M0, Mx, and M2 are configured as different matrices. [0072]
In order to realize the diffusion-matrix switching mechanism (DSM), it is necessary that applied matrices satisfy predetermined conditions. One of the conditions is a constraint concerning the above-described number of branches (Branch). This constraint will be described below. [0073]
Regarding the number of branches in each of a plurality of different matrices M0 to Mn applied to linear transformation performed in round-function sections of a Feistel structure,
the minimum number of branches in an applied matrix: B≠, and
the minimum numbers of branches corresponding to incidence matrices of a plurality of applied matrices : B2D, B3D, and B2L
are defined as follows: [Equation 1] (Equation Removed)
[0074]
In the equations,
Mi denotes a linear transformation matrix applied to a linear transformation process in the i-th round in the Feistel structure,
[M1 |M1+2 ] •] denotes an incidence matrix obtained by concatenating respective matrices M1|M1+2|--,
fcM denotes a transposed matrix of a matrix M, and M~x denotes an inverse matrix of the matrix M. [0075]
In the above-described equations, specifically,: B2D, B3D, and B2L denote the minimum values of the numbers of branches in matrices obtained by connecting matrices included in F-functions in two or three rounds that are consecutively provided every other round in the Feistel structure to one another. [0076]
For example, it is known that the respective matrices are set so that the above-described respective numbers of branches satisfy the following conditions, i.e.,
B2D > 3, B3D > 3, and B2L > 3,
whereby the resistance to differential attacks or
linear attacks can be enhanced in the Feistel structure.
Note that the respective subscripts and superscripts of B1D B2D B3D and B2L have the following meanings.
That is, n of BnD denotes the number of matrices that are connected to one another, D of BnD denotes a condition for having resistance to differential attacks, and L of BnL denotes a condition for having resistance to linear attacks. [0077]
[4. Setting of DSM in Extended Feistel Structure]
In the present invention, a configuration is proposed, in which the diffusion-matrix switching mechanism (DSM) is realized in a Feistel structure having any number of data lines that are two or more data lines, for example, three lines or four lines, instead of in the Feistel structure having two data lines. The configuration will be described below in detail. [0078]
A Feistel structure to be described in the present invention is an extended Feistel structure in which the number of divisions that is the number of data lines is denoted by d for generalization although it is the same as the above-described Feistel structure having two data lines in that SP-type F-functions are used, where d is an integer that is equal to or more than two. [0079]
Although the configuration in which the diffusion-matrix switching mechanism (DSM) is applied to the Feistel structure in the limited case m which the number of data lines = 2 holds has been proposed as described above, a method has not been known, in which resistance is enhanced by applying the DSM to an extended Feistel structure having the number of data lines d that is set to any number d satisfying d > 2. In the present invention, a configuration is realized, in which resistance to differential attacks or linear attacks is enhanced by applying the diffusion-matrix switching mechanism (DSM) to an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2.
Specific configurations and process examples of the present invention will be described below. [0080]
(4-1. Regarding Extended Feistel Structure)
Definitions of an extended Feistel structure will be described with reference to Fig. 5. In the specification, an extended Feistel structure is defined as follows:
1. Has d (d is egual or more than two) data lines, and the size of each of the data lines is mn bits.
2. The input/output size of an F-function is mn bits.
3. Has rounds that are referred to as units of processing. One data line or a plurality of data lines are
subjected to a transformation process using an F-function in a round. The result is subjected to exclusive-OR using another data line. However, when two or more F-functions are included in one round, duplicated data lines do not exist as data lines that serve as inputs/outputs of all of the F-functions. [0081]
An example of the extended Feistel structure that is constructed in accordance with the above-described definitions will be described with reference to Fig. 5.
The above-mentioned definition 1. Has d (d is egual to or more than two) data lines, and the size of each of the data lines is mn bits.
The definition is described with reference to Fig. 5. The definition means that, in Fig. 5, the input/output size of each data line that is each of data lines 1 to d is mn bits, and that the total number of bits for an input/output is dmn bits. [0082]
The above-described definition 2. The input/output size of an F-function is mn bits.
The definition is described with reference to Fig. 5. For example, mn bits that are output as an operation result from an exclusive-OR (XOR) operation section 201 serving as an upper stage are input to an F-function 202 via a data
line 2. Furthermore, a round key K is input, and an operation process is performed. This operation process is the process that has been described with reference to part
(b) of Fig. 2, and includes non-linear transformation performed in the S-boxes and a linear transformation process, in which the linear transformation matrix Mi is applied, that is performed in the linear transformation section. The output of the F-function 202 is mn bits, and is input to an exclusive-OR (XOR) operation section 203 of a data line 4.
[0083]
The above-described definition 3. Has rounds that are referred to as units of processing. One data line or a plurality of data lines are subjected to a transformation process using an F-function in a round. The result is subjected to exclusive-OR using another data line. However, when two or more F-functions are included in one round, duplicated data lines do not exist as data lines that serve as inputs/outputs of all of the F-functions.
The definition is described with reference to Fig. 5. Fig. 5 shows an extended Feistel structure having an r-round configuration. One or more F-functions are included in each rount, and the result is subjected to exclusive OR using another data line. Regarding a round n shown in Fig. 5, a plurality of F-functions are included in one round, and are an F-function 211 and an F-function 212 shown in Fig. 5.
[0084]
As described above, when a plurality of F-functions are included in one round, input/output lines of the respective F-functions are data lines different from one another, and are set so that duplicated data lines are not applied as the input/output data lines.
An input data line of the F-function 211 shown in Fig. 5 is a data line 1, and an output data line of the F-function 211 is a data line 2.
An input data line of the F-function 212 is any one of data lines 5 or more, and an output data line of the F-function 212 is a data line 3.
The input/output data lines are set so as not to be duplicated. [0085]
Note that, as shown also m Fig. 5, in the specification, an F-function is denoted by [F], and a round key is denoted by [K]. Subscripts and superscripts that are set for the respective identifiers F and K have the following meanings:
That is, i of Fxn or Kxn denotes a round, and n denotes an identification number of an F-function or a round key in the same round.
Note that a linear transformation matrix that is applied in a linear transformation section of an F-function

in each round is denoted by [M] in the description given below although it is not illustrated. As in the above-described case, a subscript and a superscript that are set for M have the following meanings.
That is, 1 of M1n denotes a round, and n denotes an identification number of a linear transformation matrix for a corresponding one of a plurality of F-functions that are set in the same round. [0086]
Fig. 6 shows an example of an extended Feistel structure that satisfies the above-described definitions and that has seven data lines (d = 7). Note that, in Fig. 6, although symbols of exclusive-OR operation (XOR) sections for outputs of respective F-functions and respective data lines are omitted, the extended Feistel structure has a configuration in which exclusive-OR operations (XOR) using corresponding inputs are performed at respective intersection points of the outputs of the respective F-functions and the respective data lines, and in which the results of the exclusive-OR operations (XOR) are output in a downward direction of the same data lines. In the example shown in Fig. 6, a round 1+4, a round i+5, a round i+9, and a round i+10 are rounds that are provided in such a manner that two or more F-functions are included m one round. Regarding F-functions [F] and round keys [K] provided m

these rounds, numbers denoting identification numbers of the F-functions or the round keys in the same rounds are provided at the top right corners. [0087]
When a Feistel structure having the number of lines d that is set as d = 2 is constructed in accordance with the above-described definitions 1 to 3, it is provided as a Feistel structure having two data lines, i.e., the Feistel structure that has been previously described with reference to Fig. 1. In other words, a connection structure m which F-functions are input alternately to two respective lines is provided. However, in a case of an extended Feistel structure having three or more data lines, a connection structure is not uniquely determined since a plurality of data lines that can be selected as inputs and outputs of F-functions exist. In other words, the larger the d in an extended Feistel structure, the higher the number of places at which F-functions can be set. The flexibly with which F-functions can be set is exponentially increased. [0088]
In the present invention, a configuration is proposed, in which the diffusion-matrix switching mechanism (DSM: Diffusion Switching Mechanism) that enhances resistance to differential attacks or linear attacks is realized in such an extended Feistel structure.
[0089]
In a Feistel structure in which the number of lines d is set as d = 2, for example, as shown in Fig. 3 or Fig. 4, two different linear transformation matrices M0 and Mx, or three different linear transformation matrices M0, Mx, and M2 are provided as matrices applied in linear transformation sections (P layers) of round-function (F-function) sections constituting a Feistel structure, whereby the DSM is realized. However, in order to realize the DSM, it is necessary that applied matrices satisfy predetermined conditions. One of the conditions is a constraint concerning the above-described number of branches (Branch) . [0090]
In an extended Feistel structure having the number of data lines d that is set as
d: any integer satisfying d > 2,
before a description of a configuration for realizing the DSM, definitions of respective constituent sections and input/output data of the respective constituent sections of an extended Feistel structure used in the description given below will be described with reference to Fig. 7.
Fig. 7 is a diagram in which only one data line is extracted and shown from among data lines constituting an extended Feistel structure, for example, as shown in Fig. 6. As shown in Fig. 7, it can be understood that data which is
input to one data line is subjected to exclusive-OR (XOR) using one or more outputs of F-functions, and that, then, it is output. This is applied to any data line included in the extended Feistel structure. [0091]
In Fig. 7, a state is shown, in which outputs of a plurality of F-functions [FS(D, I, Fs(1)# 2, . .] are added using exclusive-OR operations (XOR) for one data line [s(i)].
Note that, each of d data lines included in the extended Feistel structure is referred to as S(i) (1 < 1 < d) . The F-functions that are input to the data line S(i) are referred as Fs(1)/ x, Fs(l)/ 2r in the order in which they are input to the data line S(i) from earlier ones.
Additionally, input data that is input to the data line s(i) is denoted by Ws(1), 0-
Data obtained after an output of an F-function Fs(l)/ -, is subjected to exclusive OR is denoted by Ws(l)/ 3.
In addition, input data that is input to the F-function Fs(1), -, is denoted by Xs(1), -,.
Although each Xs(1), -, is data that belongs to another line other than the data line s(i), herein, it is supposed that which line each Xs(1)/ -, belongs to does not matter.
In this case, it can be considered that the extended Feistel structure has a configuration in which the d data lines are connected to one another.
[0092]
A configuration for realizing the DSM in an extended Feistel structure, i.e., hereinafter, a configuration for realizing the DSM in an extended Feistel structure having the following d, will be described below, d: any integer satisfying d > 2
The description is made in the order of section headings as follows:
(4-2. Configuration for Enhancing Resistance to Differential Attacks in Extended Feistel Structure)
(4-3. Configuration for Enhancing Resistance to Linear Attacks in Extended Feistel Structure)
The respective configurations will be sequentially described. [0093]
(4-2. Configuration for Enhancing Resistance to Differential Attacks in Extended Feistel Structure)
First, a configuration for enhancing resistance to differential attacks m an extended Feistel structure will be described.
As described above, differential attacks are attacks in which keys applied in respective round functions are analyzed by analyzing multiple pieces of input data (plaintext) having a certain difference (AX) and pieces of output data (ciphertext) for the input data. The minimum
number of differential active S-boxes included in a differential path that represents connection relationships of differences can be applied as an index for evaluating resistance to differential attacks. A differential path includes differential values in pieces of data excluding pieces of key data in encryption functions. Before/after linear transformation processes, the relationships between input differences and output differences are determined as one-to-one relationships. Although, before/after non-linear transformation processes, the relationships between input differences and output differences are not determined as one-to-one relationships, probabilities of occurrence of output differences for an input difference are calculated. The sum of all probabilities for all outputs is one. [0094]
In a Feistel structure having SP-type F-functions, nonlinear transformation is performed using only S-boxes. In this case, a differential path having a probability other than zero represents a set of pieces of differential data that are provided as differential values starting with a differential value for plaintext (input) and ending with a differential value for ciphertext (output), and differential values that are provided before/after all S-boxes have probabilities other than zero. An S-box which is included in a differential path having a probability other than zero,
and to which a differential value that is not zero is input is referred to as a "differential active S-box". The minimum number among the numbers of active S-boxes in all differential paths having probabilities other than zero is referred to as a "minimum number of differential active S-boxes", and the value of this number is used as a safety index for differential attacks. [0095]
Making the minimum number of differential active S-boxes large leads to enhancement of resistance to differential attacks. A technique for constructing a DSM structure for making the minimum number of differential active S-boxes large m an extended Feistel structure having the number of data lines d that is set to any integer satisfying d > 2 will be described below. [0096]
A linear transformation matrix used in a F-function [FS(i), x] included in an extended Feistel structure is denoted by [Ms(1)/ x] . In this case, an equation B2D(s(i)) for calculating the number of branches, in which the operation function of the number of branches: Branch() is applied, is defined as follows: [Equation 2]
(Equation Removed)
[0097]
The above-mentioned equation is an equation for calculating the minimum value of the number of branches in an incidence matrix [Ms(l)( |Ms(l); : + 1] of two linear transformation matrices [Ms(l)f , Ms(1); 3+1] that are used in two F-functions [Fs(l)( 2, Fs(l)/ J+1] which are adjacent to each other, and which are input to any data line s(i) constituting the extended Feistel structure. [0098]
In any data line s(i) constituting the extended Feistel structure, []] that corresponds to the number of F-functions, which are input to the data line s(i), from the top stage is set to any j, and data [Ws(l)/ -, ] on the data line s(i) will be considered.
Input/output data [Ws(1)r 3] and [Ws(1)/ ]+2] sandwich input portions of the two F-functions [Fs(1)≠ J+1] and [Fs{l); 3+2] , which are input to the data line s(i), for the data line s(i) . Regarding the input/output data [W3(1), -, ] and [Ws(1), -,+2] on the data line s(i), the following case is considered.
Ws(i), D = 0 WS(x), D+2 = 0
[0099]
In this case,
between respective input differential values [AXS(1), ]+i] and [AXS(1), -,+2] for the F-functions [Fs(l)r 3+1] and [Fs(l)f J+2] adjacent to each other from among the F-functions, which are input to the data line s(i),
the following relationship holds: [Equation 3]
(Equation Removed) [0100]
Note that, in the above-mentioned relationship, hw denotes hamming weight, and the left-hand side of the above-mentioned relationship represents the number of non-zero elements in input differential data of the F-functions, i.e., the sum of the numbers of active S-boxes. Ensuring this number to be a large value is a condition in which enhancement of resistance to differential attacks can be expected. Accordingly, if other conditions other than the condition are the same, it is concluded that it is preferable that matrices in the respective F-functions constituting the extended Feistel structure be selected so as to make B2D(s(i)) as large as possible.
[0101]
In extended Feistel-type cryptography in the prior art, a configuration in which one linear transformation matrix is utilized in linear transformation sections in all F-functions is a general configuration.
However, when the two linear transformation matrices tMs(i), j ] and tMs(1), 3+1] that are used in the two F-functions t≠sd), 3' ≠s(1), j+1] adjacent to each other, which are input to the data line s(i), are the same matrices, the above-described equation for calculating the number of branches, in which the operation function of the number of branches: Branch() is applied, i.e.,
B2D(s(i)), becomes two, which is the minimum value. Thus, an effect of enhancement of resistance cannot be expected. [0102]
Additionally, even in a case in which different matrices are used, when two matrices are carelessly selected, there is a case in which B2D(s(i)) becomes two.
B2D(s(i)), which is defined by the above-described equation for calculating the number of branches, is made to be a much larger number of branches, whereby a localized minimum number of differential active S-boxes is ensured to be large, so that resistance to differential attacks can be enhanced. Accordingly, for example, matrices are selected so as to make B2D(s(i)) equal to or more than three, whereby
resistance to differential attacks can be enhanced. [0103]
B2D(s(i)) is calculated for each of the data lines in the extended Feistel structure. The minimum value from among the calculated values is denoted by B2D. A method for selecting matrices m the F-functions so as to make B2D equal to or more than three will be described. [0104]
(4-2-1. Configuration for Selecting Matrices, Which Is to Be Set in F-Functions, That Make Value of Minimum Number of Branches B2D Equal To or More Than Three)
First, it will be described below that making the minimum number of branches [B2D] , which is the minimum number among the minimum numbers of branches [B2D(s(i))J calculated for all of the data lines m the extended Feistel structure, equal to or more than three can be realized by providing at least two types of matrices. [0105]
First, two different matrices [A0] and [A-J are prepared, which make the number of branches in an incidence matrix [A0|A1] of the two different matrices [A0] and [A-J equal to or more than three, i.e., which satisfy as follows:
Branchn( [AQIAJ) > 3 [0106]
Next, linear transformation matrices of the linear
transformation sections of the plurality of F-functions, which are input to the data line s(i) in the extended Feistel structure, are set as follows:
A0 is set as the linear transformation matrix that is set in the linear transformation section of the first F-function Fs(1), x.
A1 is set as the linear transformation matrix that is set in the linear transformation section of the second F-function Fs(1)/ 2-
A0 is set as the linear transformation matrix that is set in the linear transformation section of the third F-function Fs(1), 3.
In this manner, the two different matrices [A0] and [Ax] are alternately arranged in this order from the top for the plurality of F-functions, which are input to the data line
s(i) -[0107]
When the linear transformation matrices are set m this manner, the above-described equation for calculating the minimum value of the number of branches in the incidence matrix [Ms(l)/ -,IMs{l)/ D+1] of the two linear transformation matrices [Ms(l)f , Ms(l)f 3+1] that are used in the two F-functions [Fg(;L)f 3, Fs(1)( +1] adjacent to each other, which are input to any data line s(i), is provided as follows:
[Equation 4]
(Equation Removed)
In other words, it is ensured that the minimum number of branches is equal to or more than three. [0108]
As a matter of course, when the matrices [A0] and [A-J are permuted, the same effect is obtained. Additionally, when the matrices are similarly set for each of the data lines s(i) in the extended Feistel structure, B2D can be made equal to or more than three simply by using the two matrices. [0109]
Branchn( [AQIAJ ) > 3
In this manner, the two different matrices [A0] and [A±] satisfying the relationship given above are prepared, and the respective matrices are set so as to be alternately arranged in the F-functions that are input to the respective data lines s(i) in the extended Feistel structure, whereby the value of the minimum number of branches B2D can be made equal to or more than three. Enhancement of resistance to differential attacks by using the diffusion-matrix switching mechanism (DSM) can be realized. [0110]
An example in which the two different matrices [A0] and [A-J are applied has been described above.
Next, an example will be described below, in which different matrices are generalized using any number [k] that is equal to or more than two. [0111]
A linear transformation matrix used m an F-function [Fs(1)/ D] included m an extended Feistel structure is denoted by [Ms(x)/ -, ] . In this case, an equation B2D(s(i)) for calculating the number of branches, in which the operation function of the number of branches: Branch () is applied, is defined as follows: [Equation 5] (Equation Removed)
[0112]
The above-mentioned equation is an equation for calculating the minimum value of the number of branches m an incidence matrix [Ms(l)f -,|Ms(l)f D + 1|.. |MsU)f J+k_x] of k linear transformation matrices [Ms(l)( , Ms(l)≠ -.+l, .. , Ms(1) -]+k-i] that are used in k F-functions [Fs(l)( , Fs(1)> 3+1, . ., Fs(i), -,+k-iJ which are adjacent to one another, and which are input to any data line s(i) constituting the extended
Feistel structure. [0113]
In any data line s(i) constituting the extended Feistel structure, [j] that corresponds to the number of F-functions, which are input to the data line s(i), from the top stage is set to any j, and data [Ws(1), -, ] on the data line s(i) will be considered.
Input/output data [Ws(1), -, ] and [Ws(1), -,+k] sandwich input portions of the k F-functions [Fs(l)> :+1] . . [Fs(l)f -,+jJ , which are input to the data line s(i), for the data line s(i). Regarding the input/output data [Ws{1)i -, ] and [Ws(1); ]+k] on the data line s(i), the following case is considered.
Wsd), j = 0
WS(x), :+k = 0 [0114]
In this case,
between respective input differential values [AXs(l), 3+1] .. [AXS(X), D+k] for the k F-functions [Fs(l)f :+1] .. [Fs(l)/ -,+k] adjacent to one another from among the F-functions, which are input to the data line s(i),
the following relationship is obtained: [Equation 6](Equation Removed)
[0115]
In addition, in the above-mentioned relationship, hw denotes hamming weight, and the left-hand side of the above-mentioned relationship represents the number of non-zero elements in input differential data of the F-functions, i.e., the sum of the numbers of active S-boxes. Ensuring this number to be a large value is a condition m which enhancement of resistance to differential attacks can be expected. Accordingly, if other conditions other than the condition are the same, it is concluded that it is preferable that matrices in the respective F-functions constituting the extended Feistel structure be selected so as to make BkD(s(i)) as large as possible.
[0116]
However, when even only one pair of same matrices exists in the k linear transformation matrices [Ms(l) ,] ...
[Ms(l)> -,+k-1] that are used in the k F-functions [Fs(l)≠ 3 ] ...
[Fs(l)f j+k-1] adjacent to one another, which are input to the data line s(i) , the above-described equation for calculating the number of branches, in which the operation function of the number of branches: Branch() is applied, i.e.,
BkD(s(i)), becomes two, which is the minimum value. Thus, an effect of enhancement of resistance cannot be expected.
[0117]
Additionally, even in a case in which different matrices are used as the k linear transformation matrices
[Ms (1)), ]] "• [Ms(1), J+k-j] , when matrices are carelessly selected, there is a case in which BkD(s(i)) becomes two.
[0118]
BkD(s(i)), which is defined by the above-described equation for calculating the number of branches, is made to be a much larger number of branches, whereby a localized minimum number of linear active S-boxes is ensured to be large, so that resistance to differential attacks can be enhanced. Accordingly, for example, matrices are selected so as to make BkD(s(i)) equal to or more than three, whereby resistance to differential attacks can be enhanced.
[0119]
BkD(s(i)) is calculated for each of the data lines in the extended Feistel structure. The minimum value from among the calculated values is denoted by BkD. A method for selecting matrices in the F-functions so as to make BkD equal to or more than three will be described.
[0120]
(4-2-2. Configuration for Selecting Matrices, Which Is to Be Set in F-Functions, That Make Value of Minimum Number of Branches BkD Equal To or More Than Three)
It will be described below that making the minimum
number of branches [BkD] , which is the minimum number among the minimum.numbers of branches [BkD(s(i))] calculated for all of the data lines in the extended Feistel structure, equal to or more than three can be realized by providing at least k types of matrices. [0121]
First, k different matrices [A0] , [A-J , [A2] , ... [Ak_x] are prepared, which make the number of branches of an incidence matrix [AQIA-JJ.. |Ak_x] of the k different matrices [A0] , [A1] , [A2] , ... [Ak_1] equal to or more than three, i.e., which satisfy as follows:
Branchn( [AQIA≠ |Ak_2] ) > 3 [0122]
Next, linear transformation matrices of the linear transformation sections of the plurality of F-functions, which are input to the data line s(i) in the extended Feistel structure, are set as follows:
A0 is set as the linear transformation matrix that is set m the linear transformation section of the first F-function Fs(l), i.
Ax is set as the linear transformation matrix that is set m the linear transformation section of the second F-function Fs(l), 2-
A2 is set as the linear transformation matrix that is set in the linear transformation section of the third F-
function Fs(l)/ 3.
Ak_1 is set as the linear transformation matrix that is set in the linear transformation section of the k-th F-function Fsu), k-
A0 is set as the linear transformation matrix that is set in the linear transformation section of the k+l-th F-function Fs(1)/ k+1.
Ax is set as the linear transformation matrix that is set in the linear transformation section of the k+2-th F-f unction Fs(l), k+2 .
In this manner, the k different matrices [A0] , [A-J , [A2] , .. [Ak_1] are repeatedly arranged in this order from the top for the plurality of F-functions, which are input to the data line s(1). [0123]
When the linear transformation matrices [A0] , [Ax] , [A2] , ... [Ak_1] are set in this manner, the above-described equation for calculating the minimum value of the number of branches in the incidence matrix [Ms(l)≠ :IMs(l)/ 3+11 ...Ms (1) t -,+k-il of the k linear transformation matrices [Ms(l)j , Ms(l) ,+1, . -Ms(1) -1+k_1] that are used in the k F-functions [Fs(l)( , Fs(i)( 3+i---≠s(i), -,-i-k-i] adjacent to one another, which are input to any data line s(i), is provided as follows:
[Equation 7] (Equation Removed)
In other words, it is ensured that the minimum number of branches is equal to or more than three. [0124]
As a matter of course, when the matrices [A0] , [A-J, [A2] , ... [Ak_;i_] are permuted, the same effect is obtained. Additionally, when the matrices are similarly set for each of the data lines s(i) in the extended Feistel structure, B can be made equal to or more than three simply by using the k matrices. [0125]
Branchn ([Ao]lAi]. . |Ak_x] ) > 3
In this manner, the k different matrices [A0] , [A-J , [A2] , ... [Ak-1] satisfying the relationship given above are prepared, and the respective matrices are set so as to be repeatedly arranged m an order in the F-functions that are input to the respective data lines s(i) in the extended Feistel structure, whereby the value of the minimum number of branches BkD can be made equal to or more than three. Enhancement of resistance to differential attacks by using the diffusion-matrix switching mechanism (DSM) can be
realized. [0126]
Note that, regarding selection of a value of k, when k is at least equal to or more than two, an effect can be expected. The larger the k is, the larger the guaranteed range. Thus, enhancement of resistance can be more expected. However, in contrast, because the minimum number of types of necessary matrices is increased, there is a probability that such k is not suitable for an efficient implementation. Thus, the value of k is a value that should be selected in accordance with a situation at a design stage. [0127]
(4-3. Configuration for Enhancing Resistance to Linear Attacks in Extended Feistel Structure)
Next, a configuration for enhancing resistance to linear attacks xn an extended Feistel structure will be described.
As previously described, the minimum number of linear active S-boxes included in a linear path that represents connection relationships of linear masks (although it is referred to as a "linear approximation" in most cases, herein, a word "path" is used in order to correspond to difference) can be applied as an index for evaluating resistance to linear attacks. A linear path is a path m which specific linear mask values are designated for all
pieces of data excluding pieces of key data in encryption functions. Before/after linear transformation processes, the relationships between input linear mask values and output linear mask values are determined as one-to-one relationships. Although, before/after non-linear transformation processes, the relationships between input linear mask values and output linear mask values are not determined as one-to-one relationships, probabilities of occurrence of output linear masks for an input linear mask are calculated. The sum of all probabilities for all outputs is one. [0128]
In a Feistel structure having SP-type F-functions, nonlinear transformation is performed only in a portion of processes using S-boxes. Accordingly, in this case, a linear path having a probability other than zero represents a set of pieces of lmear-mask-value data that are provided as linear values starting with a linear value for plaintext (input) and ending with a linear value for ciphertext (output), and linear values that are provided before/after all S-boxes are linear values having probabilities other than zero. An S-box which is included in a linear path having a probability other than zero, and to which a linear value that is not zero is input is referred to as a "linear active S-box". The minimum number among the numbers of
active S-boxes in all linear paths having probabilities other than zero is referred to as a "minimum number of linear active S-boxes", and the value of this number is used as a safety index for linear attacks. [0129]
Making the minimum number of linear active S-boxes large leads to enhancement of resistance to linear attacks. A technique for constructing a DSM structure for making the minimum number of linear active S-boxes large in an extended Feistel structure having the number of data lines d that is set to any integer satisfying d > 2 will be described below. [0130]
A linear transformation matrix used in a F-function [FsU), x] included m an extended Feistel structure is denoted by [Ms(1)/ x] . In this case, an equation B2L(s(i)) for calculating the number of branches, in which the operation function of the number of branches: Branch() is applied, is defined as follows: [Equation 8] (Equation Removed)
[0131]
The above-mentioned equation is an equation for

calculating the minimum value of the number of branches in an incidence matrix [tM~1s(1)/ -,ltM"1S(i), 3+1] °f transposed matrices [tM_1s(l)( ] and [tM"1s(l)/ :+1] of inverse matrices of two respective linear transformation matrices [Ms(l)( ] and tMs{i), -j+il that are used in two F-functions [Fs(l)≠ -,, ≠s(i), -,+iJ which are adjacent to each other, and which are input to any data line s(i) constituting the extended Feistel structure. [0132]
In any data line s(i) constituting the extended Feistel structure, [j] that corresponds to the number of F-functions, which are input to the data line s(i), from the top stage is set to any j, and, for a certain j, the followings are defined:
an input to the j-th F-function: Xs(x), -,
a result obtained by exclusive OR (XOR) of an output of the j-th F-function and data on the data line s(i) : Ws(1), -,
an input to the j + l-th F-function: Xs(1)/ -,+1
Linear masks for these respective data pieces are defined as follows:
rxs(1), 3 rws(1), 3 rxSd), -j+i
In this case, if at least any one of the linear masks is not zero, the following relationship is satisfied.
[Equation 9] (Equation Removed)
[0133]
In other word, the above-mentioned relationship is satisfied. It means that, the larger the value of the left-hand side of the above-mentioned relationship, the larger the localized number of linear active S-boxes. Accordingly, it is concluded that it is preferable that matrices be selected so as to make B2L(s(i)) large.
[0134]
However, when the two linear transformation matrices
C≠s(i), -j ] and [ ≠s(i), -j+i] that are used in the two F-functions [Fs(l)/ , Fs(1) ,+1] adjacent to each other, which are input to the data line s(i), are the same matrices, the above-described equation for calculating the number of branches, i.e.,
B2L(s(i) ), becomes two, which is the minimum value. Thus, an effect of enhancement of resistance cannot be expected. B2L(s(i)) is made to be a much larger of branches, whereby a minimum number of linear active S-boxes is ensured to be large, so that resistance to liner attacks can be enhanced. Thus, for
example, matrices are selected so as to make B2L(s(i)) equal to or more than three, whereby resistance to linear attacks can be enhanced. [0135]
B2L(s(i)) is calculated for each of the data lines in the extended Feistel structure. The minimum value from among the calculated values is denoted by B2L. A method for selecting matrices in the F-functions so as to make B2L equal to or more than three will be described. [0136]
(4-3-1. Configuration for Selecting Matrices, Which Is to Be Set in F-Functions, That Make Value of Minimum Number B2L of Branches Equal To or More Than Three)
It will be described below that making the minimum number of branches [B2L] , which is the minimum number among the minimum numbers of branches [B2L(s(i))] calculated for all of the data lines in the extended Feistel structure, equal to or more than three can be realized by providing at least two types of matrices. [0137]
First, two different matrices [A0] and [A1] are prepared, which make the number of branches in an incidence matrix ≠AQ-1 I tA1_1] of the two different matrices [A0] and [A1] equal to or more than three, i.e., which satisfy as follows:
Branchn( ["AQ"1!≠!"1] ) > 3
[0138]
Next, linear transformation matrices of the linear transformation sections of the plurality of F-functions, which are input to the data line s(i) in the extended Feistel structure, are set as follows:
A0 is set as the linear transformation matrix that is set in the linear transformation section of the first F-function Fs(1), \.
Ax is set as the linear transformation matrix that is set in the linear transformation section of the second F-function Fs(l)/ 2-
A0 is set as the linear transformation matrix that is set m the linear transformation section of the third F-function Fs(1), 3.
In this manner, the two different matrices [A0] and [A-J are alternately arranged in this order from the top for the plurality of F-functions, which are input to the data line s(i) • [0139]
When the linear transformation matrices are set in this manner, the above-described equation for calculating the minimum value of the number of branches in the incidence matrix [tM~1s(l)f |tM"1s(l)j J+1] of the transposed matrices [tM~ 1s(i), 3] anc* [tM~1s(1)/ 3+1] °f the inverse matrices of the two
respective linear transformation matrices [Ms(l)f 3 ] and [Ms{l)( +1] that are used in the tw.o F-functions [Fs(l)j , Fs(1)/ -,+1] adjacent to each other, which are input to any data line s(i), is provided as follows: [Equation 10] (Equation Removed)
In other words, it is ensured that the minimum number of branches is equal to or more than three. [0140]
As a matter of course, when the matrices [A0] and [A-J are permuted, the same effect is obtained. Additionally, when the matrices are similarly set for each of the data lines s(i) in the extended Feistel structure, B2L can be made equal to or more than three simply by using the two matrices. [0141]
BranchnU≠VAf1]) > 3
In this manner, the two different matrices [A0] and [A1] satisfying the relationship given above are prepared, and the respective matrices are set so as to be alternately arranged in the F-functions that are input to the respective data lines s(i) in the extended Feistel structure, whereby the value of the minimum number of branches B2L can be made
equal to or more than three. Enhancement of resistance to linear attacks by using the diffusion-matrix switching mechanism (DSM) can be realized. [0142]
[5. Configuration in Which DSM Is Utilized for Extended Feistel Structure Having Specific Form]
As described above, the DSM technology is applied in the extended Feistel structures having the number of data lines d that is set to any integer satisfying d > 2, whereby resistance to differential attacks or linear attacks can be enhanced. Specific extended Feistel structures in which a safety index for differential attacks or linear attacks can be ensured at a high level will be described below. [0143]
As previously described with reference to Figs. 5 and 6, the extended Feistel structures having the number of data lines d that is set to any integer satisfying d > 2 have various configurations, such as a configuration in which inputs from various other data lines can be provided as inputs to one data line, and a configuration in which a plurality of F-functions can be performed in parallel in one round. The extended Feistel structures will be largely classified into two types (a type 1 and a type 2), and a specific extended Feistel structure in which a safety index for differential attacks or linear attacks can be ensured at
a high level will be described below for each type. [0144]
(5-1. Application of DSM to Extended Feistel Structure of Type 1)
First, application of the DSM to an extended Feistel structure of a type 1 will be described with reference to Fig. 8.
It is supposed that the extended Feistel structure of the type 1 has the following parameters.
Parameters:
(a) The number of divisions for a piece of data: d
(where d is equal to or more than three)
(b) The length of a piece of input/output data: dmn bits
(c) The length of pieces of divided data: mn bits
(d) The number of F-functions per round: 1
[0145]
As shown in Fig. 8, an F-function is applied to mn-bit data on a data line provided on the left end shown m Fig. 8 in each round, and the process result of the F-function is output to an immediately adjacent data line and subjected to exclusive-OR. Note that the operators of exclusive-OR are omitted in Fig. 8. [0146]
As shown in Fig. 8, a configuration is provided, m
which the data line provided on the left end is used to perform data input for the F-functions in each .round, and in which the data line provided on the left end is moved to the right end and the other data lines other than the data line are shifted to the left by one in the next round.
[0147]
A configuration for enhancing resistance to differential attacks and linear attacks by applying the DSM to the extended Feistel structure in which one F-function is performed in each round in this manner will be described.
[0148]
In (4-2. Configuration for Enhancing Resistance to Differential Attacks in Extended Feistel Structure) that has been previously described, it has been described that B2D(s(i)) is calculated for each data line in an extended Feistel structure, that the minimum value among the calculated values is defined as B2D, and that matrices in F-functions are selected so as to make B2D equal to or more than three, whereby resistance to differential attacks can be enhanced.
Furthermore, in (4-3. Configuration for Enhancing Resistance to Linear Attacks in Extended Feistel Structure) that has been previously described, it has been described that B2L(s(i)) is calculated for each data line m an extended Feistel structure, that the minimum value among the

calculated values is defined as B2L, and that matrices in F-func.tions are selected so as to make B2L equal to or more than three, whereby resistance to linear attacks can be enhanced. [0149]
In addition to B2D and B2L, furthermore,
the minimum number of branches among the number of branches in linear transformation matrices m F-functions included in the extended Feistel structure of the type 1 as shown in Fig. 8 is denoted by B≠. [0150]
In this case, when the number of differential active S-boxes included in p continuous rounds in the extended Feistel structure of the type 1 as shown in Fig. 8 is denoted by ActD(p) and the number of linear active S-boxes is denoted by ActL(p), the following relationships exist:
ActD(3d) > B≠ + B2D
ActL(3d) > 2B2L
In the above-mentioned relationships,
ActD(3d) denotes the number of differential active S-boxes included in 3d continuous rounds, and
ActL(3d) denotes the number of linear active S-boxes included in 3d continuous rounds.
Proof that these relationships hold will be described below.
[0151]
As described above, by utilizing matrices that make B≠, B2D, and B2L large, the number of active S-boxes can be ensured to be large, and, consequently, resistance to differential attacks and linear attacks can be enhanced.
Note that it is known that a theoretical maximum value of B≠, B2D, or B2L is m + 1. [0152]
Regarding the above-mentioned relationships, i.e.,
ActD(3d) > B-L0 + B2D and
ActL(3d) > 2B2L,
the minimum number of branches B2D or B2L, which has been previously described, is included in the right-hand sides of the relationships. Making the minimum numbers of branches large contributes to ensuring the number of active S-boxes to be large, and is effective in enhancing resistance to differential attacks and linear attacks. Accordingly, in the configuration of the extended Feistel structure of the type 1 as shown in Fig. 8, a configuration in which the minimum number of branches B2D or B2L, which has been previously described, is made equal to or more than three is effective, and, with the configuration, resistance to differential attacks and linear attacks can be ensured at a level higher than that in the prior art. [0153]
(5-2. Application of DSM to Extended Feistel Structure of Type 2)
Next, application of the DSM to an extended Feistel structure of a type 2 will be described with reference to Fig. 9.
It is supposed that the extended Feistel structure of the type 2 has the following parameters.
Parameters:
(a) The number of divisions for a piece of data: d
(where d is an even number equal to or more than four)
(b) The length of a piece of input/output data: dmn bits
(c) The length of pieces of divided data: mn bits
(d) The number of F-functions per round: d/2 [0154]
As shown in Fig. 9, F-functions are applied to mn-bit data lines provided as odd-numbered data lines from the left end in each round, and the process results of the F-functions are output to immediately adjacent data lines and subjected to exclusive-OR. Note that the operators of exclusive-OR are omitted in Fig. 9. [0155]
As shown in Fig. 9, a configuration is provided, in which the data line provided on the left end is used to perform data input for the F-functions in each round, and in
which the data line provided on the left end is moved to the right end and the other,data lines other than the data line are shifted to the left by one in the next round.
[0156]
A configuration for enhancing resistance to differential attacks and linear attacks by applying the DSM to the extended Feistel structure in which d/2 F-functions are performed in each round in this manner will be described.
[0157]
In (4-2. Configuration for Enhancing Resistance to Differential Attacks in Extended Feistel Structure) that has been previously described, it has been described that B2D(s(i)) is calculated for each data line in an extended Feistel structure, that the minimum value among the calculated values is defined as B2D, and that matrices in F-functions are selected so as to make B2D equal to or more than three, whereby resistance to differential attacks can be enhanced.
Furthermore, in (4-3. Configuration for Enhancing Resistance to Linear Attacks in Extended Feistel Structure) that has been previously described, it has been described that B2L(s(i)) is calculated for each data line m an extended Feistel structure, that the minimum value among the calculated values is defined as B2L, and that matrices in F-functions are selected so as to make B2L equal to or more
than three, whereby resistance to linear attacks can be
enhanced.
[0158]
In addition to B2D and B2L, furthermore,
the minimum number of branches among the number of branches in linear transformation matrices in F-functions included in the extended Feistel structure of the type 2 as shown in Fig. 9 is denoted by B1D. [0159]
In this case, when the number of differential active S-boxes included in p continuous rounds in the extended Feistel structure of the type 2 as shown in Fig. 9 is denoted by ActD(p) and the number of linear active S-boxes is denoted by ActL(p), the following relationships exist:
ActD(6) > B-L0 + B2D
ActL(6) > 2B2L
In the above-mentioned relationships,
ActD(6) denotes the number of differential active S-boxes included in six continuous rounds, and
ActL(6) denotes the number of linear active S-boxes included in six continuous rounds.
Proof that these relationships hold will be described below. [0160]
As described above, by utilizing matrices that make B-LD,
B2D, and B2L large, the number of active S-boxes can be ensured to be large, and, consequently, resistance to differential attacks and linear attacks can be enhanced.
Note that it is known that a theoretical maximum value of B-L0, B2D, or B2L is m + 1. [0161]
Regarding the above-mentioned relationships, i.e.,
ActD(6) > BXD + B2D and
ActL(6) > 2B2L,
the minimum number of branches B2D or B2L, which has been previously described, is included in the right-hand sides of the relationships. Making the minimum numbers of branches large contributes to ensuring the number of active S-boxes to be large, and is effective in enhancing resistance to differential attacks and linear attacks. Accordingly, in the configuration of the extended Feistel structure of the type 2 as shown m Fig. 9, a configuration in which the minimum number of branches B2D or B2L, which has been previously described, is made equal to or more than three is effective, and, with the configuration, resistance to differential attacks and linear attacks can be ensured at a level higher than that in the prior art. [0162]
[6. Proof of Relationships Between Numbers of Active S-Boxes in Extended Feistel Structure of Each Type and Minimum
Numbers of Branches Based on Linear Transformation Matrices m F-Functions]
Next, the proof of relationships between the numbers of active S-boxes and the minimum numbers of branches based on linear transformation matrices in F-functions, which have been described m the section headings
(5-1. Application of DSM to Extended Feistel Structure of Type 1) and
(5-2. Application of DSM to Extended Feistel Structure of Type 2), which are given above, will be described. [0163]
(6-1. Proof of Relationships between Numbers of Active S-Boxes in Extended Feistel Structure of Type 1 and Minimum Numbers of Branches Based on Linear Transformation Matrices in F-Functions)
First, the proof of relationships between the numbers of active S-boxes in the extended Feistel structure of the type 1, which has been previously described with reference to Fig. 8, and the minimum numbers of branches based on linear transformation matrices in F-functions will be described. [0164]
In other words, in a case in which the number of differential active S-boxes included in p continuous rounds
in the extended Feistel structure of the type 1 is denoted by ActD(p), and in which the number of linear active S-boxes is denoted by ActL(p), the following relationships exist:
ActD(3d) > B≠ + B2D
ActL(3d) > 2B2L
Proof that these relationships hold will be described below. [0165]
When the configuration of the extended Feistel structure of the type 1, which has been previously described with reference to Fig. 8, is shown in another form, it can be shown as a configuration shown in Fig. 10. Although the configuration is shown in Fig. 8 m such a manner that respective data lines are permuted on a round-by-round basis so that a data line which is used to perform input to an F-function is placed on the left end, permutation of the data lines on a round-by-round basis is not performed m Fig. 10, and each of the data lines is shown as one line. In Fig. 10, rounds 1 to 6d are shown. Although d rounds (rounds 1 to d, d+1 to 2d, .. , 5d+l to 6d) are shown in such a manner that they are arranged in one horizontal line, these rounds are not performed in parallel, and the respective rounds, for example, the rounds 1 to d, are sequentially performed. [0166]
Additionally, although exclusive-OR (XOR) operations
that are performed at intersections of outputs of F-
functions and the respective data lines are omitted in Fig.
10, the exclusive-OR (XOR) operations are performed at the
intersections of outputs of F-functions and the respective
data lines, and the results are provided as inputs to F-
functions of the next round.
[0167]
In the configuration of the extended Feistel structure of the type 1, it will be proved that the following relationships, which have been previously described in (5-1, Application of DSM to Extended Feistel Structure of Type 1), hold:
ActD(3d) > BXD + B2D
ActL(3d) > 2B2L
In the relationships,
ActD(3d) and ActL(3d) denote the number of differential active S-boxes and the number of linear active S-boxes, respectively, included in 3d continuous rounds in the extended Feistel structure of the type 1, which is shown Fig. 8 or Fig. 10.
BiD denotes the minimum number of branches among the number of branches in the linear transformation matrices in the F-functions included in the extended Feistel structure of the type 1.
B2D and B2L denote the minimum number of branches m an
incidences matrix of linear transformation matrices, and the minimum number of branches in an incidence matrix of transposed matrices of inverse matrices of the linear transformation matrices, respectively, which have been previously described in (4-2) and (4-3), in continuous F-functions that are input to one data line included in an extended Feistel structure. [0168]
BiD, B2D, and B2L are defined as follows: [Equation 11] (Equation Removed)
[0169]
Note that, in the above-mentioned definitions, the following relationship holds:
B±D > B2D
Additionally, the number of differential active S-boxes included in the k-th F-function in the extended Feistel structure of the type 1, which is shown in Fig. 8 or Fig. 10
is denoted by Dk, and the number of linear active S-boxes is
denoted by Lk.
[0170]
(Proof 1. Proof of ActD(3d) > B≠ + B2D) First, it will be proved that ActD(3d) > B≠ + B2D holds. In other words, it will be proved that the number of differential active S-boxes included in 3d continuous rounds in the extended Feistel structure of the type 1, which is shown in Fig. 8 or Fig. 10, is equal to or more than B±D +
[0171]
A case is considered, in which a difference (AX) obtained using an input that is not zero is provided m the extended Feistel structure of the type 1. In this case, the extended Feistel structure of the type 1 has the following four characteristics:
(Characteristic 1) A differential active S-box that is not zero exists in at least one round from among d continuous rounds.
(Characteristic 2) If Dk = 0 holds, Dk_d+1 = Dk + 1 holds.
(Characteristic 3) If Dk / 0 holds, Dk_d+1 + Dk + Dk + 1 > B-L0 holds.
(Characteristic 4) If Dk + Dk+d * 0 holds, Dk_d+1 + Dk +
Dk+d + Dk+d+i ≠ B2D holds. [0172]
By utilizing the four characteristics given above, it will be proved that
ActD(3d) > B≠ + B2D
holds, i.e.,
it will be proved that "the number of differential active S-boxes included in 3d continuous rounds is equal to or more than BXD + B2D". [0173]
It is supposed that the i+l-th to the i+3d-th rounds are targets rounds.
Case 1: a case is supposed, m which an active S-box that is not zero exists in the i+d+2-th to i+2d-l-th rounds.
When it is supposed that a round in which an active S-box that is not zero exists is the k-th round, it is indicated that Dk ≠ 0 holds. [0174]
Case 1-1: m addition to Case 1, when Dk+d_x & 0 holds, the followings hold:
in accordance with Characteristic 3, Dk + Dk+1 + Dk_
d+l - Bl
in accordance with Characteristic 4, Dk+d_1 + Dk_2d +
°k-l + Dk+d ≠ B2D
Thus, the following is obtained: [Equation 12]
(Equation Removed)
[0175]
Case 1-2: in addition to Case 1, when Dk+1 * 0 holds, the followings hold:
in accordance with Characteristic 3, Dk+1 + Dk+2 + Dk_d+2 > BXD
in accordance with Characteristic 4, Dk + Dk_d+1 + Dk+d + Dk+d+i > B2D
Thus, the following is obtained: [Equation 13] (Equation Removed)
[0176]
Case 1-3: in addition to Case 1, when Dk+d_1 = 0 and Dk+1 = 0 hold, the followings hold:
in accordance with Characteristic 2, Dk = Dk+d * 0
in accordance with Characteristic 3, Dk + Dk+1 + Dk_
d+l - al
in accordance with Characteristic 3, Dk+d + Dk+d+1 + Dk+1
> B2D
Because Dk+1 = 0 holds, the following is obtained: [Equation 14] (Equation Removed)
[0177]
Case 2: a case is supposed, in which no active S-box that is not zero exists m the i-fd+2 to i+2d-l rounds.
In accordance with Characteristic 1, D1+d+1 ≠= 0 or D1+2d * 0 holds. [0178]
Case 2-1: when D1+2d = 0 holds although D1+d+1 ≠ 0 holds, the followings hold:
in accordance with Characteristic 2, D1+d+1 = D1+2d+1 * 0 in accordance with Characteristic 3, D1+d+1 + D1+d+2 + D1+2 >
BiD
in accordance with Characteristic 3, D1+2d+1 + D1+2d+2 + D1+d+2 >
BiD
Because D1+d+2 = 0 holds, the following is obtained: [Equation 15]
(Equation Removed)
[0179]
Case 2-2: when D1+2d ≠ 0 holds although D1+d+1 = 0 holds, the followings hold:
in accordance with Characteristic 2, D1+2d = D1+d ≠ 0 in accordance with Characteristic 3, D1+d + D1+d+1 + D1+1 > B≠ in accordance with Characteristic 3, D1+2d + D1+2d+i + D1+d+1 >
BiD
Because D1+d+1 = 0 holds, the following is obtained: [Equation 16] (Equation Removed)
[0180]
Case 2-3: when D1+d+1 ≠ 0 and D1+2d ≠ 0 hold, the followings hold:
in accordance with Characteristic 3, D1+d+1 + D1+d+2 + D1+2 > BXD
In accordance with Characteristic 3, D1+2d + D1+2d+1 + D1+d + D1+1 > B2D
Thus, the following is obtained: [Equation 17]
(Equation Removed) [0181]
When Case 1 and Case 2 given above are summarized, it is proved that the following holds: [Equation 18] (Equation Removed)
In other words, the following holds:
ActD(3d) > B≠ + B2D
It has been proved that the number of differential active S-boxes included in 3d continuous rounds in the extended Feistel structure of the type 1, which is shown in Fig. 8 or Fig. 10, is equal to or more than BXD + B2D-[0182]
(Proof 2. Proof of ActL(3d) > 2B2L)
Next, it will be proved that ActL(3d) > 2B2L holds.
In other words, it will be proved that the number of linear active S-boxes included m 3d continuous rounds in the extended Feistel structure of the type 1, which is shown
m Fig. 8 or Fig. 10, is equal to or more than 2B2L.
Note that, as described above, B2L is defined as follows: [Equation 19] (Equation Removed)
Additionally, the number of linear active S-boxes included in the k-th F-function is denoted by Lk. [0183]
When a linear mask obtained using an input that is not zero is provided in the extended Feistel structure of the type 1, the extended Feistel structure of the type 1 has the following two characteristics:
(Characteristic 5) A linear active S-box that is not zero exists in at least one round from among d continuous rounds.
(Characteristic 6) Lk + Lk+1 + Lk+d > B2L or Lk + Lk+1 + Lk+d = 0 holds. Note that, when Lk + Lk+1 + i≠+d - B2L holds, two or more terms included in the left-hand side do not become simultaneously zero.
By utilizing the two characteristics given above, it will be proved that
ActL(3d) > 2B2L,
holds, i.e.,
it will be proved that "the number of linear active S-boxes included in 3d continuous rounds is equal to or more than 2B2L". [0184]
It is supposed that the i+1-th to the i+3d-th rounds are targets rounds.
Case 1: a case is supposed, m which an active S-box that is not zero exists in the i+d+2-th to i+2d-th rounds.
When it is supposed that a round in which an active S-box that is not zero exists is the k-th round, it is indicated that Lk ≠ 0 holds. [0185]
Case 1-1: in addition to Case 1, when Lk+d ≠ 0 or Lk_x ≠ 0 holds, the followmgs hold:
in accordance with Characteristic 6, Lk + Lk+d + Lk. > B2L
in accordance with Characteristic 6, Lk_1 + Lk_x_d + Lk-d ≠ B2L
Thus, the following is obtained: [Equation 20] (Equation Removed) [0186]
Case 1-2: in addition to Case 1, when Lk+d = 0 and Lk_x =
0 hold, the followings hold:
in accordance with Characteristic 6, Lk_d+1 ≠ 0
m accordance with Characteristic 6, Lk + Lk-1 + Lk+d_1 >
B2L
in accordance with Characteristic 6, Lk_d+1 + Lk+1 + Lk_d+2 > B2L [0187]
In this case, if d > 4 holds, the following is obtained. [Equation 21]
(Equation Removed) [0188]
If d = 3 holds, it has already been known that Lk_x = 0 holds although Lk_x is duplicated.
Thus, similarly, the following is obtained: [Equation 22]
(Equation Removed) [0189]
Case 2: a case is supposed, in which an active S-box that is not zero does not exist in the i+d+2-th to i+2d-l-th rounds. The followings hold:
in accordance with Characteristic 1, L1+d+1 ≠ 0
in accordance with Characteristic 6, L1+d ≠ 0
in accordance with Characteristic 6, L1+cH1 + L1+d+2 +
Lx+2d+l - B2
in accordance with Characteristic 6, L1+d + L1+d_1_ + L1+2d_ 1 > B2L [0190]
In this case, if d > 4 holds, the following is obtained. [Equation 23] (Equation Removed) [0191]
If d =3 holds, it has already been known that L1+5 = 0 holds although L1+5 is duplicated.
Thus, similarly, the following is obtained: [Equation 24]
(Equation Removed) [0192]
When Case 1 and Case 2 given above are summarized, it is proved that the following holds: [Equation 25]
i+3d j=i+In other words, the following holds:
ActL(3d) > 2B2L,
It has been proved that the number of linear active S-boxes included in 3d continuous rounds in the extended Feistel structure of the type 1, which is shown m Fig. 8 or Fig. 10, is equal to or more than 2B2L. [0193]
(6-2. Proof of Relationships between Numbers of Active S-Boxes in Extended Feistel Structure of Type 2 and Minimum Numbers of Branches Based on Linear Transformation Matrices in F-Functions)
Next, the proof of relationships between the numbers of active S-boxes in the extended Feistel structure of the type 2, which has been described with reference to Fig. 9, and the minimum numbers of branches based on linear transformation matrices in F-functions will be described. [0194]
In other words, in a case m which the number of differential active S-boxes included in p continuous rounds in the extended Feistel structure of the type 2 is denoted by ActD(p), and in which the number of linear active S-boxes is denoted by ActL(p), the following relationships exist:
ActD(6) > Bi0 + B2D
ActL(6) > 2B2L
It will be proved that these relationships hold. [0195]
When the configuration of the extended Feistel structure of the type 2, which has been previously described with reference to Fig. 9, is shown in another form, it can be shown as a configuration shown in Fig. 11. Although the configuration is shown in Fig. 9 in such a manner that respective data lines are permuted on a round-by-round basis, permutation of the data lines is not performed in Fig. 11, and each of the data lines is shown as one line. In Fig. 11, rounds 1 to 12 are shown. F-functions in two rounds (1 to 2, 3 to 4, . ) are shown in such a manner that they are arranged m one horizontal line. For example, Fi, Q, FI, 2, , and Fi, d-2 selected from among F-functions FI, 0 to Fl, d-1 that are shown in a horizontal line for the rounds 1 to 2 shown in Fig. 11, which are every-other-selected F-functions (output arrows are directed upward), are performed in the first round in parallel. In the next second round, the
remaining Fi, i, Fi, 3, .. , and Fi, d_i, which are every-other-selected F-functions (output arrows are directed downward), are performed in parallel. [0196]
In Fig. 11, numbers used to identify each of the F-functions are newly introduced in order to easily understand the proof, and a position of the F-function is determined using the two numbers.
That is, i of F1# -, denotes a round number (1 = 1 and 2 rounds, 2 = 3 and 4 rounds . .) , and y denotes - of an F-function in two rounds. Note that, when j is an even number, which is 0, 2, or 4, the F-function is provided for a preceding round, and that, when j is an odd number, which is 1, 3, or 5, the F-function is provided for the following round. Note that, when a linear transformation matrix included in the F-function F1# -, is referred to as [Mlf 3]. [0197]
In the configuration of the extended Feistel structure of the type 2, it will be proved that the following relationships, which have been previously described in (5-2, Application of DSM to Extended Feistel Structure of Type 2), hold:
ActD(6) > B≠ + B2D
ActL(6) > 2B2L
In the relationships,
ActD(6) and ActL(6) denote the number of differential active S-boxes and the number of linear active S-boxes, respectively, included in six continuous rounds in the extended Feistel structure of the type 2, which is shown Fig. 9 or Fig. 11.
BXD denotes the minimum number of branches among the number of branches in the linear transformation matrices in the F-functions included m the extended Feistel structure of the type 2.
B2D and B2L denote the minimum number of branches in an incidences matrix of linear transformation matrices, and the minimum number of branches in an incidence matrix of transposed matrices of inverse matrices of the linear transformation matrices, respectively, which have been previously described m (4-2) and (4-3), in continuous F-functions that are input to one data line included in an extended Feistel structure. [0198]
BiD' B2D' anc* B2L are defined as follows: [Equation 26] (Equation Removed) [0199]
Note that, in the above-mentioned definitions, the following relationship holds: BXD > B2D
Additionally, the number of active S-boxes included in Fpi q is denoted by Dp( q. Note that, in the following description, when a portion denoted by the subscript q has a negative value or a value equal to or more than d, a residue operation (q mode d) is performed using d, thereby correcting the portion so that 0 < q < d always holds. [0200]
(Proof 3. Proof of ActD(6) > B±D + B2D)
First, it will be proved that ActD(6) > B±D + B2D holds.
In other words, it will be proved that the number of differential active S-boxes included m six continuous rounds in the extended Feistel structure of the type 2, which is shown in Fig. 9 or Fig. 11, is equal to or more than B-L0 + B2D. [0201]
A case is considered, m which a difference (AX) obtained using an input that is not zero is provided m the extended Feistel structure of the type 2. In this case, the
extended Feistel structure of the type 2 has the following four characteristics:
(Characteristic 1) A differential active S-box that is not zero exists in FP/ q (p = i, q e {0, ...d-1}) for a certain i.
(Characteristic 2) If Dp/ = 0 holds,
Dp-i, q+1 = Dp< +1 holds (where q is an even number) , and
Dp, q+1 = DP+I, q+1 holds (where q is an odd number) . (Characteristic 3) If Dp; q ≠ 0 holds,
Dp/ q + Dp.-L≠ q+1 + Dpi q+1 > BXD holds (where q is an even number), and
DP, q + DP, q+1 + DP+1 q+1 * B1D holds (where q is an odd number).
(Characteristic 4) If D + Dp+1/ ≠ 0 holds,
DP, q + DP+i, q + Dp-1, q+1 + Vi, q+1 - B2° holds (where q is an even number), and
Dp, q + Dp+1< q + Dp/ q+1 + Dp+2i q+1 > B2D holds (where q is an odd number). [0202]
By utilizing the four characteristics given above, it will be proved that
ActD(6) > Bi0 + B2D,
holds, i.e.,
it will be proved that "the total number of
differential active S-boxes included in 3d continuous F-functions Fp, q satisfying p e {1, l + l, i + 2}, q e {0, 1, .. d-1} for any integer i that is equal to or more than one is equal to or more than BXD + B2D". [0203]
It is supposed that, when an element that is not zero is arbitrarily selected from among Dpi q (p = I + 1, q e {0, ...d-1}), it satisfies D≠ k = 0. It is indicated in accordance with the above-mentioned (Characteristic 1) that it always exists. [0204]
Case 1: when D.≠ k_1 ≠ 0 holds, the followings hold: m accordance with Characteristic 3,
D k + D-,-1, k+1 + DJ, k+1 - B1D (where k is an even number)
DD; k + D3i k+1 + D3+1, k+1 - B1D (where k is an odd number)
in accordance with Characteristic 4,
D3_lt k-1 + DD/ k_x + D3_X/ k + DJ+1/ k > B2D (where k is an even number)
D3, k-i + DD+1/ k_x + DD_lf k + D]+lr k > B2D (where k is an odd number)
Thus, the following holds: [Equation 27] (Equation Removed) [0205]
Case 2: when D k+1 * 0 holds, the followings hold: in accordance with Characteristic 3,
D3, k+1 + D], k+2 + DJ+1, k+2 ≠ BiD (where k is an even number)
D3, k+1 + DD-i, k+2 + D3, k+2 ≠ BiD (where k is an odd number)
in accordance with Characteristic 4,
DD, k + DJ+1, k + D:-i, k+1 + D3+li k+1 > B2D (where k is an even number)
D:-i, k + D:/ k + DJ-1 k+1 + D:+lf k+1 > B2D (where k is an odd number)
Thus, the following holds: [Equation 28] (Equation Removed) [0206]
Case 3: when D≠ k_1 = 0 and D k+1 = 0 hold, the followings hold:
in accordance with Characteristic 2, because D k_x = 0
holds,
D3+1, k = Dj, k = 0 (where k is an even number)
D3-i, k = D], k * 0 (where k is an odd number)
in accordance with Characteristic 3,
D:/ k + DD_1/ k+1 + D3i k+1 > B-t0 (where k is an even
number)
DJr k + D-j≠ k+1 + DJ+li k+1 > B1D (where k is an odd
number)
further in accordance with Characteristic 3,
D:+i, k + D], k+1 + DD+i, k+1 ≠ BiD (where k is an even number)
Dn-i, k + Dj-1, k+1 + DD, k+1 - BiD (where k is an odd number)
Thus, because DJ k+1 = 0 holds, the following holds: [Equation 29] (Equation Removed) [0207]
When the cases given above are summarized, the following is proved: [Equation 30]
(Equation Removed)In other words, the following holds:
ActD(6) > B-L0 + B2D
It has been proved that the number of differential active S-boxes included in six continuous rounds in the extended Feistel structure of the type 2, which is shown in Fig. 9 or Fig. 11, is equal to or more than B1D + B2D. [0208]
(Proof 4. Proof of ActL(6) > 2B2L)
Next, it will be proved that ActL(6) > 2B2L holds.
In other words, it will be proved that the number of linear active S-boxes included in six continuous rounds in the extended Feistel structure of the type 2, which is shown in Fig. 9 or Fig. 11, is equal to or more than 2B2L.
Note that, as described above, B2L is defined as follows: [Equation 31] (Equation Removed)Additionally, the number of linear active S-boxes included in the F„ n-th F-function is denoted by L„ „.
[0209]
When a linear mask obtained using an input that is not zero is provided in the extended Feistel structure of the type 2, the extended Feistel structure of the type 2 has the following two characteristics:
(Characteristic 5) A differential active S-box that is not zero exists in Fp, q (p = i, q e {0, ...d-1}) for a certain I .
(Characteristic 6)
L3, k + LD+i, k + LD, k+1 ≠ B2L or L3r k + LD+1/ k + L]f k+1 = 0 holds (where k is an even number), and
LD, k + L3 + l, k + L3 + l, k+l - B2L or Lj, k + L:+l, k + LD+1, k+1 = 0
holds (where k is an odd number). [0210]
Note that, when a relationship is represented in a form La + Lb + Lc > B2L, two or more terms included in the left-hand side do not become simultaneously zero.
By utilizing the two characteristics given above, it will be proved that
ActL(6) > 2B2L,
holds, i.e.,
it will be proved that "the number of linear active S-boxes included in 3d F-functions Fp, q satisfying p e {i, l+l, 1+2}, q e {0, 1, ...d-1} for any integer i that is equal to or more than one is equal to or more than 2B2L".
[0211]
It is supposed that, when an element that is not zero is arbitrarily selected from among Lp/ q (p = 1 + 1, q e {0, ...d-1}), it satisfies L, k ≠ 0. It is indicated in accordance with Characteristic 5 that such L k always exists. [0212]
The followings hold:
in accordance with Characteristic 6,
L-,-1, k + L3i k + l>3-ir k+1 - B2L (where k is an even number)
L3i k + L-j+1/ k + L-j+lf k+1 > B2L (where k is an odd number) [0213]
Case 1: when L k_1 & 0 holds, the followings hold:
in accordance with Characteristic 6,
L3i k-1 + L.[ + lf k_1 + L-,+1 k > B2L (where k is an even number)
kJ-1, k-1 + kj, k_ + L3_1( k - B2L (where k is an odd number)
Thus, in this case, the following holds: [Equation 32] (Equation Removed) [0214]
Case 2: when L≠ k_x = 0 holds, the followmgs hold: in accordance with Characteristic 6,
L:-i, k_1 = 0 (where k is an even number) ≠D+I, k-i = 0 (where k is an odd number) Thus, the followings hold:
L.j-1, k_2 + Lj, k-2 + LD-I, k-i - B2L (where k is an even number)
L3i k_2 + L + 1, k-2 + LD + I, k-1 - B2L (where k is an odd number)
Because d > 4 holds in this case, m such case, the following holds: [Equation 33] (Equation Removed) [0215]
When Case 1 and Case 2 given above are summarized, it is proved that the following holds:
[Equation 34] (Equation Removed)In other words, the following holds:
ActL(6) > 2B2L,
It has been proved that the number of linear active S-boxes included in six continuous rounds in the extended Feistel structure of the type 2, which is shown in Fig. 9 or Fig. 11, is equal to or more than 2B2L. [0216]
[7. Improved Configuration for Implementation Based on Contrivance of Setting of F-Functions and Process of Utilizing F-Functions]
As described above, in the present invention, at least two or more different matrices are selectively applied to linear transformation processes performed in F-functions in respective rounds, i.e., the so-called diffusion-matrix switching mechanism (DSM) is applied, in the extended Feistel structure having the number of data lines: d that is set to an integer satisfying d > 2, thereby realizing a configuration in which resistance to linear analysis or differential analysis is enhanced.
[0217]
when a configuration in which operation processes in which a plurality of different matrices are selectively applied are performed in this manner is to be realized as hardware, different F-function processing sections having hardware configurations for performing operations corresponding to the respective matrices are necessary. Particularly, when a plurality of F-functions are to be performed in parallel in one round, a plurality of circuits for the plurality of F-functions for performing parallel processing are necessary. [0218]
In other words, the extended Feistel structure of the type 2, which has been previously described with reference to Fig. 9 or Fig. 11, has a configuration in which data transformation processes to which a plurality of F-functions are applied in the same round are performed in parallel. When the processes according to the configuration of the type 2 are to be performed with hardware, it is necessary to implement the number of pieces of F-function hardware that corresponds to the number of F-functions that are performed in parallel in one round. Regarding F-functions that are required to be performed m parallel as mentioned above, a plurality of F-functions having the same configuration need to be provided even when they has the same configuration.
[0219]
As described above, a cryptographic process configuration of the present invention is a configuration in which a plurality of at least two or more different matrices are selectively applied to linear transformation processes that are performed m F-functions in respective rounds, whereby it is provided as a configuration in which resistance to various types of attacks is enhanced. In other words, it is provided as a configuration provided with the diffusion-matrix switching mechanism (DSM: Diffusion Switching Mechanism).
[0220]
In order to satisfy the diffusion-matrix switching mechanism (DSM), it is only necessary that a condition is satisfied, for example, in which a plurality of different matrices satisfying a condition m which a minimum number of branches [BkD] for all of the data lines is equal to or more than three are set, the minimum number of branches [BkD] for all of the data lines being selected from among minimum numbers of branches [BkD(s(i))] corresponding to the data lines, each of the minimum numbers of branches [BkD(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in k (where k is an integer equal to or more than two) continuous F-functions that are input to a corresponding data line s(i)
in the extended Feistel structure. There is no particular constraint of the F-functions that are performed in parallel in each round. [0221]
An example of a configuration in which implementation efficiency is improved while maintaining resistance based on the diffusion-matrix switching mechanism (DSM) in an extended Feistel structure on the basis of these characteristics will be described below. [0222]
(7-1. Method for Efficiently Arranging F-Functions in Extended Feistel Structure of Type 2)
First, to begin with, a configuration for efficiently arranging F-functions in the extended Feistel structure of the type 2, which has been described with reference to Fig. 9 or Fig. 11, will be described. As mentioned in the section heading (5-2. Application of DSM to Extended Feistel Structure of Type 2) that has been previously described, the extended Feistel structure of the type 2 has the following parameters.
Parameters:
(a) The number of divisions for a piece of data: d
(where d is an even number equal to or more than four)
(b) The length of a piece of input/output data: dmn
bits
(c) The length of pieces of divided data: mn bits
(d) The number of F-functions per round: d/2 [0223]
In other words, as shown in Fig. 9, F-functions are applied to mn-bit data lines provided as odd-numbered data lines from the left end in each round, and the process results of the F-functions are output to immediately adjacent data lines and subjected to exclusive-OR. Note that the operators of exclusive-OR are omitted in Fig. 9. [0224]
A configuration will be described below, in which implement efficiency for the extended Feistel structure of the type 2 having such a configuration is enhanced. As one example, a case in which the number of data lines (the number of divisions) is set as d = 4 will be described with reference to Fig. 12. In Fig. 12, two different F-functions that perform linear transformation using two different linear transformation matrices Ml and M2 are denoted by Fl and F2, respectively. [0225]
A Feistel structure shown in Fig. 12 is the extended Feistel structure of the type 2 in which the two F-functions, i.e., the F-functions Fl and F2, are used, and in which d = 4 holds. In other words, it has a configuration having the followings:
(a) The number of divisions for a piece of data: four
(b) The length of a piece of input/output data: 4mn bits
(c) The length of pieces of divided data: mn bits
(d) The number of F-functions per round: 4/2 = 2 [0226]
In a case of the configuration shown in Fig. 12, in order to satisfy conditions for the DSM by using the two F-functions, some arrangements can be considered. In other words, in order to satisfy conditions for the DSM, as described above, it is only necessary that a condition is satisfied, for example, in which a plurality of different matrices satisfying a condition in which a minimum number of branches [BkD] for all of the data lines is equal to or more than three are set, the minimum number of branches [BkD] for all of the data lines being selected from among minimum numbers of branches [BkD(s(i))] corresponding to the data lines, each of the minimum numbers of branches [BkD(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in k (where k is an integer equal to or more than two) continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure. There is no particular constraint of the F-functions that are performed in parallel in each round.
[0227]
Accordingly, as manners in which F-functions, are set, the following two manners can be used:
(a) Setting a plurality of F-functions that are to be set in one round as the same F-functions
(b) Setting a plurality of F-functions that are to be set in one round as different F-functions
[0228]
Here, as shown in Fig. 12, a configuration is provided, m which two F-functions that exist m one round are selected so that they are a pair of Fl and F2. An advantage of this configuration markedly appears when hardware (H/W) implementation is performed on the basis of processes for one round. [0229]
In other words, hardware (H/W) implementation is performed to set hardware having a configuration in which only processes for one round can be performed, i.e., a configuration m which the F-function Fl and the function F2 can be performed in parallel as shown in Fig. 13. Fig. 13 is a block diagram showing a cryptographic processing apparatus 250 having a hardware configuration m which the cryptographic process according to the extended Feistel structure shown in Fig. 12 is performed. [0230]
The cryptographic processing apparatus 250 includes a first ,F-function (Fl) dedicated processing circuit 251 that performs the F-function Fl, a second F-function (F2) dedicated processing circuit 252 that performs the F-function F2, a control circuit 253, and an auxiliary circuit 254. The first F-function (Fl) dedicated processing circuit 251 and the second F-function (F2) dedicated processing circuit 252 are configured so that they can operate in parallel, and data transformation based on the two different F-functions is performed by applying these two circuit in each round. [0231]
The control circuit 253 performs control of input/output data for the respective F-function dedicated processing circuits 252 and 252 and the auxiliary circuit 254. The auxiliary circuit 254 performs operation processes other than the F-functions or the like. [0232]
With application of this configuration, the first F-function (Fl) dedicated processing circuit 251 and the second F-function (F2) dedicated processing circuit 252 are applied only times corresponding to the required number of rounds so that round operations can be performed. The two F-function dedicated circuits are operated m parallel in all rounds, and implementation m which no useless circuit
is provided can be performed. [0233]
When the number of F-functions that are performed in parallel in each round is two as shown m Fig. 12, all round operations can be performed using hardware implementation shown in Fig. 13 with a setting in which the F-functions are set as different F-functions. In addition, when a configuration in which F-functions that are performed in one round are set as the same F-functions, e.g., a configuration m which Fl and Fl are performed in parallel in the first round and F2 and F2 are performed in the second round, is provided, two pieces of each of an Fl performing circuits and an F2 performing circuit need to be provided as hardware, so that a configuration having circuits whose scale is larger than that of circuits included in the configuration shown in Fig. 13 is required. [0234]
As shown in Fig. 12, with a setting in which all of combinations of the F-functions that are performed in respective rounds are set as the pairs of Fl and F2, the hardware shown in Fig. 13 is applied, and Fl and F2 can be always simultaneously performed in each of the rounds. A compact apparatus in which the scale of circuits is reduced without providing any useless circuit is realized. [0235]
Although the configuration shown m Fig. 12 corresponds to a case in which the number of data lines is set as d = 4, efficient implementation can be performed using a similar setting also in a case in which the number of data lines is set to another number. For example, although four F-functions are set in one round in a case in which the number of data lines is set as d = 8, a configuration is provided, in which two pieces of each of the two different F-functions Fl and F2 are set as these four F-functions. [0236]
In an implement configuration in this case, two pieces of each of the F-functions Fl and F2 are provided, whereby a configuration in which the four F-functions (Fl, Fl, F2, F2) can be performed in parallel is provided. With this configuration, all of the four F-functions are performed in parallel in all rounds, and implementation without providing any useless circuit can be performed. [0237]
Additionally, when the number of data lines is set as d = 16, four pieces of each of Fl and F2 are set as eight F-functions that exist in one round. For further generalization, when the number of data lines is set as d = 4x, a configuration in which x pieces of the F-functions Fl and F2 are utilized m each round. In a case in which hardware implementation is performed, if a configuration in
which x pieces of each of the F-functions Fl and F2 are set is provided, the numbers of pieces of Fl and F2 that are required in each round are the same. Thus, Fl and F2 can be performed without excess or deficiency, and the implementation efficiency can be improved. [0238]
Although the above-described process example is an example m which two different F-functions to which two different linear transformation matrices are applied are set in order to satisfy the diffusion-matrix switching mechanism (DSM), a similar thing can be applied also in a case in which three or more F-functions are set by using three or more linear transformation matrices. [0239]
An example of an arrangement for efficiently implementing three types of F-functions is shown in Fig. 14. Fig. 14 is an example of the extended Feistel structure of the type 2 having the number of data lines that is set as d = 6. A configuration shown in Fig. 14 is set to a configuration in which one piece of each of three F-functions Fl, F2, and F3 that exist m one round is assuredly utilized. [0240]
With this configuration, when hardware (H/W) implementation is performed, a configuration in which the F-
functions can be performed in parallel m each round can be provided using simple implementation of one piece of each of Fl, F2, and F3, and a circuit configuration that does not include useless circuits in terms of H/W is realized. [0241]
Furthermore, when the number of data lines is set as d = 12, two pieces of each of Fl, F2, and F3 are set as six F-functions that exist in one round. Additionally, when the number of data lines is set as d = 18, three pieces of each of Fl, F2, and F3 are set as nine F-functions that are to be set in one round. In a case in which the above-mentioned cases are generalized, when the number of data lines is set as d = 6x, x pieces of each of Fl, F2, and F3 are provided as F-functions that are to be set in each round. In other words, a configuration is provided, in which different F-functions are equally utilized. [0242]
With a configuration in which the F-functions are set in this manner, the numbers of pieces of Fl, F2, and F3 that are required in each round can be set to the same number. When hardware implantation is performed, circuits can be set so as to be utilized without excess or deficiency, so that the implementation efficiency can be improved. In a case in which software is used, because utilizing manners in which tables for obtaining input/output values are utilized are
the same in respective rounds, a table can be set m accordance with one utilizing manner without configuring tables for various supposed cases, and be stored in a memory. [0243]
When the above-described respective process examples are further generalized, the following can be said:
(1) In a case in which the extended Feistel structure of the type 2 in which a types of F-functions are utilized is configured, when the number of data lines (the number of divisions) is set as d = 2ax, where a is an integer equal to or more than two and x is an integer equal to or more than one, a configuration in which x pieces of each of the types of F-functions are equally set as ax F-functions that are to be set in one round is used, so that implementation efficiency can be improved. [0244]
Note that, regarding the above-described setting of F-functions, the F-functions that are input in respective data lines are set so that the above-described conditions for DSM are satisfied. With this setting, resistance can be maintained. [0245]
(7-2. Commonality of Components in Feistel Structure and Extended Feistel Structure)
As described above, the DSM mechanism is utilized for
any of the Feistel structures, the extended Feistel structure of the type 1, and the extended Fei.stel structure of the type 2, which have been previously described, thereby providing an advantage in that resistance to attacks is enhanced. [0246]
In other words, when the Feistel structures are broadly classified into the followings:
(a) A Feistel structure having the number of data lines
(the number of divisions) that is set as d = 2
(b) An extended Feistel structure having the number of
data lines (the number of divisions) that is set to any
number satisfying d > 2
Further, the extended Feistel structure can be classified into the followings:
(bl) A type 1 in which one F-function is allowed to be performed in each round
(b2) A type 2 in which a plurality of F-functions are allowed to be performed in parallel in each round
The Feistel structures can be classified into these three types (a), (bl), and (b2).
Enhancement of resistance is realized with application of the DSM mechanism in any of the three types of Feistel structures. [0247]
For application of the DSM mechanism, it is necessary to, implement different F-functions that perform at least two or more different linear transformation matrices. With an implement configuration having this plurality of different F-functions, an apparatus that can selectively perform the above-mentioned plurality of different Feistel structures
(a), (bl), and (b2) can be realized. Such an apparatus that performs a selection process will be described below.
[0248]
A plurality of different F-functions that perform linear transformation matrices satisfying the diffusion-matrix switching mechanism (DSM) are determined, and it is supposed that the data size of input/output data of the respective F-functions is mn bits. With application of such F-functions, for example, 2mn-bit block cipher is performed in a Feistel structure, as shown in Fig. 15, having the number of data lines that is set as d = 2.
[0249]
The size of input/output data of the respective F-functions Fl and F2 in the Feistel structure having the number of data lines that is set as d = 2, which is shown in Fig. 15, is mn bits. The Feistel structure having the number of data lines that is set as d = 2 performs a process of transforming 2mn-bit plaintext into 2mn-bit ciphertext, or a decryption process that is the reverse of the process,
thereby performing 2mn-bit block cipher. [0250]
Additionally, by utilizing the F-functions Fl and F2 whose input/output data size is mn bits, which are shown in Fig. 15, an extended Feistel structure that satisfies the diffusion-matrix switching mechanism (DSM) and that has the number of data lines that is set as d = 4 can be configured. A configuration of the extended Feistel structure is shown in Fig. 16. [0251]
The size of input/output data of respective F-functions Fl and F2 in the Feistel structure having the number of data lines that is set as d = 4, which is shown in Fig. 16, is mn bits, and the F-functions Fl and F2 shown in Fig. 15 are applied as they are. The Feistel structure having the number of data lines that is set as d = 4 performs a process of transforming 4mn-bit plaintext into 4mn-bit ciphertext, or a decryption process that is the reverse of the process, thereby performing 4mn-bit block cipher. [0252]
Furthermore, for generalization, when the number of data lines is set as d = x where x is an integer equal to or more than two, a block-cipher configuration in which an xmn-bit encryption or decryption process is performed can be structured using the same configuration for performing F-
functions.
[0253]
For example, an apparatus capable of selectively performing an input/output 128-bit block-cipher process and a 256-bit block-cipher process in which the DSM mechanism is realized by using only different F-functions Fl and F2 whose input/output bits is 64 bits.
[0254]
In other words, the two different F-functions Fl and F2 whose input/output bits is 64 bits are implemented as F-functions, and a manner for utilizing the F-functions Fl and F2 is controlled. For example, when a cryptographic process based on the Feistel structure having the number of data lines that is set as d = 2 (Fig. 15) is to be performed, a configuration is provided, in which one of the respective F-functions Fl and F2 is performed in each round. In contrast, when a cryptographic process based on the Feistel structure having the number of data lines that is set as d = 4 (Fig. 16) is to be performed, a configuration is provided, in which the respective F-functions Fl and F2 are performed m parallel in each round. In this manner, by installing the two types of F-functions, an apparatus capable of selectively performing input/output 128-bit block cipher and 256-bit block cipher is realized. In other words, although the same F-functions are used, the connection method is
changed, whereby block cipher having the different numbers of bits can be performed, so that it can be expected that implementation efficiency will be improved by the commonality of circuits and/or codes or the like in both S/W and H/W. [0255]
An example of a configuration of a cryptographic processing apparatus having such a configuration is shown in Fig. 17. A cryptographic processing apparatus 270 that is shown in Fig. 17 includes a first F-function (Fl) dedicated processing circuit 271 that performs the F-function Fl, a second F-function (F2) dedicated processing circuit 272 that performs the F-function F2, a control circuit 273, and an auxiliary circuit 274. The first F-function (Fl) dedicated processing circuit 271 and the second F-function (F2) dedicated processing circuit 272 are configured so that they can operate in parallel. The control circuit 273 performs control of input/output data for the respective processing units, and performs a process of selecting a Feistel structure. The auxiliary circuit 274 performs operation processes other than the F-functions or the like. [0256]
The control circuit 273 performs the process of selecting a Feistel structure, i.e., selects any one of the following structures to perform a cryptographic process
based on the structure:
(a) A Feistel structure having the number of date lines (the number of divisions) that is set as d = 2
(bl) An extended Feistel structure of a type 1 which has the number of data lines (the number of divisions) that is set as any number satisfying d > 2, and m which one F-function is allowed to be performed in each round
(b2) An extended Feistel structure of a type 2 which has the number of data lines (the number of divisions) that is set as any number satisfying d > 2, and in which a plurality of F-functions is allowed to be performed in parallel in each round
Note that, setting information is input, for example, from the outside. Alternatively, a configuration may be provided, m which a processing mode to be performed is selected in accordance with the bit length of data that is to be subjected to an encryption or decryption process. The control circuit 273 performs control of changing a sequence of application of the respective F-function dedicated circuits in accordance with the selection, and control of performing round functions according to the respective Feistel structures. [0257]
With application of this configuration, the first F-function (Fl) dedicated processing circuit 251 and the
second F-function (F2) dedicated processing circuit 252 are applied so, that cryptographic processes to which various Feistel structures are applied can be performed. Cryptographic processes supporting various bits, in which bits to be processed in an encryption process or a decryption process are different, can be performed. [0258]
Additionally, although an example in which two F-functions are used is shown in Fig. 17, the configuration is not limited to that provided in the example in which two F-functions are used, and a similar result can be expected also with a configuration in which any number of F-functions are used. For example, the extended Feistel structure that has been previously described with reference to Fig. 14 is configured as an extended Feistel structure which satisfies the diffusion-matrix switching mechanism (DSM), and which has the number of data lines d = 6 with application of the three different F-functions Fl, F2, and F3. A cryptographic process configuration having a Feistel structure having the number of data lines that is set as d = 2, which is shown in Fig. 18, can be constructed with application of the same three types of F-functions, i.e., the F-functions Fl, F2, and F3. Also in the configuration in which the number of data lines is set as d = 2, the respective matrices Fl, F2, and F3 are arranged with a setting in which they satisfy the
DSM mechanism. [0259]
An example of a configuration of a cryptographic processing apparatus that performs the three types of F-functions, i.e., Fl, F2, and F3, is shown in Fig. 19. A cryptographic processing apparatus 280 that is shown in Fig. 19 includes a first F-function (Fl) dedicated processing circuit 281 that performs the F-function Fl, a second F-function (F2) dedicated processing circuit 282 that performs the F-function F2, a third F-function (F3) dedicated processing circuit 283 that performs the F-function F3, a control circuit 274, and an auxiliary circuit 275. The first F-function (Fl) dedicated processing circuit 281, the second F-function (F2) dedicated processing circuit 282, and the third F-function (F3) dedicated processing circuit 283 are configured so that they can operate in parallel. The control circuit 284 performs control of input/output data for the respective processing units, and performs a process of selecting a Feistel structure. The auxiliary circuit 285 performs operation processes other than the F-functions or the like. [0260]
The control circuit 284 performs the process of selecting a Feistel structure, i.e., selects any one of the following structures to perform a cryptographic process
based on the structure:
(a) A Feistel structure having the number of data lines (the number of divisions) that is set as d = 2
(bl) An extended Feistel structure of a type 1 which has the number of data lines (the number of divisions) that is set as any number satisfying d > 2, and in which one F-function is allowed to be performed in each round
(b2) An extended Feistel structure of a type 2 which has the number of data lines (the number of divisions) that is set as any number satisfying d > 2, and m which a plurality of F-functions is allowed to be performed in parallel in each round
Note that, setting information is input, for example, from the outside. The control circuit 284 performs control of changing a sequence of application of the respective F-function dedicated circuits in accordance with the setting, and control of performing round functions according to the respective Feistel structures. [0261]
With application of this configuration, the first F-function (Fl) dedicated processing circuit 281 to the third F-function (F3) dedicated processing circuit 283 are applied so that cryptographic processes to which various Feistel structures are applied can be performed. Cryptographic processes supporting various bits, in which bits to be
processed in an encryption process or a decryption process are different, can be performed. Note that a configuration having four or more F-function performing sections can be provided. [0262]
As described above, a plurality of different F-functions that perform linear transformation matrices satisfying the diffusion-matrix switching mechanism (DSM) are determined, and the respective F-functions are implemented. A sequence of processes to which the F-functions are applied is changed, thereby realizing a configuration in which a cryptographic process based on any one of the following structures is selectively performed:
(a) A Feistel structure having the number of data lines (the number of divisions) that is set as d = 2
(bl) An extended Feistel structure of a type 1 which has the number of data lines (the number of divisions) that is set as any number satisfying d > 2, and in which one F-function is allowed to be performed in each round
(b2) An extended Feistel structure of a type 2 which has the number of data lines (the number of divisions) that is set as any number satisfying d > 2, and in which a plurality of F-functions is allowed to be performed in parallel in each round
An apparatus capable of changing the number of bits to

be processed in an encryption process or a decryption
process.
[0263]
For example, cryptographic processes with a high resistance can be performed using a process configuration in which a (a is an integer equal to or more than two) types of F-functions are configured, in which cryptographic processes based on the above-mentioned three types of Feistel structures are performed, and in which the diffusion-matrix switching mechanism (DSM) is satisfied. [0264]
[8. Summary of Cryptographic Processes and Cryptographic Algorithm Constructing Processes of Present Invention]
Finally, the cryptographic processes and cryptographic algorithm constructing processes of the present invention, which have been described above, will be described together. [0265]
As described with reference to Figs. 1 and 2, the cryptographic processing apparatus of the present invention has the cryptographic processing section that performs a Feistel-type common-key block-cipher process of repeating an SP-type F-function, which performs a data transformation process including a non-linear transformation process and a linear transformation process, in a plurality of rounds.
Furthermore, as described with reference to Fig. 5 and the followings, the cryptographic processing section is configured to perform a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, and configured to selectively apply a plurality of at least two or more different matrices to linear transformation processes that are performed in F-functions in respective rounds. [0266]
The plurality of at least two or more different matrices are set so as to realize the diffusion-matrix switching mechanism (DSM: Diffusion Switching Mechanism), and the cryptographic process in which resistance to differential attacks or linear attacks is enhanced is realized by using the DSM. In order to realize enhancement of resistance by using the DSM, selection and arrangement of matrices are performed in accordance with specific conditions. [0267]
In other words, a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value are set as the plurality of matrices that are applied to the linear transformation processes
which are performed in the F-functions, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure. The plurality of different matrices are repeatedly arranged in the F-functions that are input to the respective data lines in the extended Feistel structure. [0268]
More specifically, the plurality of different matrices that are utilized in the cryptographic processing section are a plurality of different matrices satisfying a condition in which a minimum number of branches [BkD] is equal to or more than three, the minimum number of branches [BkD] for all of the data lines being selected from among minimum numbers of branches [BkD(s(i))] corresponding to the data lines, each of the minimum numbers of branches [BkD(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included m k (where k is an integer equal to or more than two) continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure.
Alternatively, the plurality of different matrices that

are utilized in the cryptographic processing section are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2L] for all of the data lines is equal to or more than three, the minimum number of branches [B2L] for all of the data lines being selected from among minimum numbers of branches [B2L(s(i))] corresponding to the data lines, each of the minimum numbers of branches
[B2L(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure.
[0269]
When the plurality of different matrices are denoted by n (where n is an integer equal to or more than two) different matrices, i.e., M0, M1, Mn-1 the encryption processing section of the encryption processing apparatus of the present invention is configured so that the different matrices M0, Mlr . Mn_x are repeatedly arranged in an order in the F-functions that are input to the respective data lines m the extended Feistel structure. As an example of a specific extended Feistel structure, for example, the extended Feistel structure of the type 1 that performs only one F-function in one round, which has been described with reference to Figs. 8 and 10, and the extended Feistel structure that performs a plurality of F-functions in
parallel in one round are provided. [0270]
Note that the present invention includes the cryptographic processing apparatus and method that perform the cryptographic process to which the above-described extended Feistel structure are applied, and a computer program that performs the cryptographic process, and further includes an information processing apparatus and method that constructs a cryptographic processing algorithm for performing the cryptographic process to which the above-described extended Feistel structure are applied, and a computer program. [0271]
An information processing apparatus, such as a general PC, can be applied as the information processing apparatus that constructs a cryptographic processing algorithm, and the information processing apparatus has a control unit that can perform the following processing steps. In other words, the steps are:
a matrix-determining step of, in a cryptographic-processing-algorithm configuration to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, determining a plurality of at least two or more different matrices that are to be applied to linear transformation processes which
are performed in F-functions m respective rounds; and a matrix-setting step of repeatedly arranging the plurality of different matrices, which are determined in the matrix-determining step, in the F-functions that are input in the respective data lines in the extended Feistel structure. [0272]
The matrix-determining step is performed as a step of performing a process of determining, as the plurality of two or more different matrices, as matrices to be applied, a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure. [0273]
The diffusion-matrix switching mechanism (DSM: Diffusion Switching Mechanism) is realized in the cryptographic process to which the extended Feistel structure that is set using such a processing algorithm is
applied, whereby the cryptographic process m which resistance to differential attacks or linear attacks is enhanced is realized. [0274]
[9. Example of Configuration of Cryptographic Processing Apparatus]
Finally, Fig. 20 shows an example of a configuration of an IC module 300 serving as the cryptographic processing apparatus that performs the cryptographic process according to the above-described embodiment. The above-described process can be performed in, for example, PCs, IC cards, readers/writers, or various other information processing apparatuses. The IC module 300 shown m Fig. 20 can be configured in such various devices. [0275]
A CPU (Central processing Unit) 301 shown in Fig. 20 is a processor which performs control of start or end of the cryptographic process, which performs control of transmission and reception of data, which performs control of data transfer among respective constituent units, and which executes other various types of programs. A memory 302 includes a ROM (Read-Only-Memory) that stores a program executed by the CPU 301 or fixed data such as operation parameters, a RAM (Random Access Memory) used as a storage area or work area for a program executed in a process
performed by the CPU 301 and parameters that appropriately change in processing of the program, and so forth. The memory 302 can be also used as a storage area for key data necessary for the cryptographic process, a transformation table (permutation table) applied to the cryptographic process, data applied to transformation matrices, or the like. Note that it is preferable that the data storage area is configured as a memory having a tamper resistant structure. [0276]
A cryptographic processing unit 303 performs, for example, a cryptographic process and decryption process according to the above-described extended-Feistel-type common-key block-cipher processing algorithm. Note that, here, an example in which the cryptographic processing means is provided as a separate module is shown. However, a configuration may be provided, in which, instead of providing such an independent cryptographic processing module, for example, a cryptographic processing program is stored in the ROM, and in which the CPU 301 reads and executes the program stored in the ROM. [0277]
A random-number generator 304 performs a process of generating random numbers necessary for generation of keys which are necessary for the cryptographic process or the
like. [0278]
A transmitting/receiving unit 305 is a data communication processing unit that performs data communication with outside. For example, the transmitting/receiving unit 705 performs data communication with an IC module such as a reader/writer, and performs output of ciphertext generated in the IC module, input of data from an external device such as a reader/writer, etc. [0279]
The IC module 300 performs, for example, the extended-Feistel-type cryptographic process in which the number of data lines d is set to an integer satisfying d > 2 in accordance with the above-described embodiment. Different linear transformation matrices are set as linear transformation matrices in F-functions m an extended Feistel structure m a manner according to the above-described embodiment, whereby the diffusion-matrix switching mechanism (DSM: Diffusion Switching Mechanism) is realized, so that resistance to differential attacks or linear attacks can be enhanced. [0280]
The present invention has been described in detail with reference to the specific embodiment. However, it is obvious that a person skilled in the art could make
modifications or alternatives to the embodiment without departing from the scope of the present invention. In other words, the present invention has been disclosed in a form of illustration, and should not be restrictively construed. The section of CLAIMS should be referred in order to determine the scope of the present invention.
[0281]
The series of processes described in the specification can be performed by hardware or software, or a combination configuration of both hardware and software. In a case in which the processes are performed by software, a program in which a sequence of processes is recorded can be installed into a memory provided in a computer incorporated in dedicated hardware, and can be executed. Alternatively, the program can be installed into a general-purpose computer capable of performing various processes, and can be executed.
[0282]
For example, the program can be recorded in advance on a hard disk or ROM (Read Only Memory) serving as a recording medium. Alternatively, the program can be stored (recorded) temporarily or permanently on a removable recording medium such as a flexible disc, a CD-ROM (Compact Disc Read Only Memory), an MO (Magneto optical) disc, a DVD (Digital Versatile Disc), a magnetic disc, or a semiconductor memory. Such a removable recording medium can be provided as so-
called packaged software. [0283]
Note that the program can be installed from a removable recording medium as described above into a computer. In addition, the program can be transferred wirelessly from a download site to a computer, or be transferred by wire to a computer via a network such as a LAN (Local Area Network) or the Internet, and the computer can receive the program transferred m such a manner and install it into a built-in recording medium such as a hard disk. [0284]
Note that various processes described in the specification may be performed sequentially in the order described, or may also be performed in parallel or individually in accordance with processing capabilities of an apparatus that performs the processes or on an as needed basis. In addition, a "system" mentioned in the specification is configured as a logical set of a plurality of apparatuses, and is not limited to a system in which the apparatuses having respective configurations are contained in the same casing. Industrial Applicability [0285]
As described above, according to a configuration in an embodiment of the present invention, in a Feistel-type
common-key block-cipher process in which SPN-type F-functions including non-linear transformation sections and linear transformation sections are repeatedly performed m a plurality of rounds, round-function sections to which a plurality of different linear transformation matrices are applied are set in a Feistel structure obtained by expanding a Feistel structure having two data lines, i.e., in a Feistel structure having any number of data lines that is equal to or more than two, such as three or four, thereby realizing the diffusion-matrix switching mechanism (DSM), so that a common-key block-cipher algorithm can be constructed and a cryptographic process can be performed with a high resistance to linear analysis and differential analysis. [0286]
According to a configuration in an embodiment of the present invention, a configuration is provided, in which a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied is performed, and the configuration is provided as a configuration in which a plurality of at least two or more different matrices are selectively applied to linear transformation processes performed in F-functions in respective rounds. A plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is
equal to or more than a predetermined value are set as the plurality of two or more different matrices, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure, thereby realizing the diffusion-matrix switching mechanism (DSM), so that a common-key block-cipher algorithm can be constructed and a cryptographic process can be performed with a high resistance to linear analysis and differential analysis. [0287]
Furthermore, according to a configuration in an embodiment of the present invention, a configuration is provided, m which a (a > 2) types of F-functions perform different linear transformation processes using a plurality of different matrices, in which an extended Feistel structure (x > 1) that utilizes the F-functions and that has the number of data lines: d that is set as d = 2ax, and in which a cryptographic process to which the extended Feistel structure is applied is performed. The configuration is provided a configuration m which equally x pieces of each of the types (the a types) of F-functions are performed in
one round, whereby a compact cryptographic processing apparatus in which no useless circuit is provided is realized. [0288]
Furthermore, according to a configuration in an embodiment of the present invention, a plurality of F-function performing units are configured to perform different linear transformation processes using a plurality of different matrices, and a configuration is provided, in which a sequence of utilizing the plurality of F-function performing units is changed in accordance with a setting,
whereby a cryptographic processing apparatus is realized, which can selectively perform any of cryptographic processes (a), (bl), and (b2), i.e.,
(a) a cryptographic process using a Feistel structure having the number of data lines d that is set as d = 2,
(bl) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which only one F-function is allowed to be performed in each round, or
(b2) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which a plurality of F-functions are allowed to be performed in parallel in each round.

CLAIMS
1. A cryptographic processing apparatus characterized by comprising
a cryptographic processing section that performs a Feistel-type common-key block-cipher process of repeating an SP-type F-function in a plurality of rounds, the SP-type F-function performing a data transformation process including a non-linear transformation process and a linear transformation process,
wherein the cryptographic processing section
is configured to perform a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, is configured to selectively apply a plurality of at least two or more different matrices to linear transformation processes that are performed in F-functions in respective rounds,
the plurality of two or more different matrices being a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear
transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure,
and is configured so that the plurality of different matrices are repeatedly arranged in the F-functions that are input to the respective data lines in the extended Feistel structure.
2. The cryptographic processing apparatus according to
Claim 1, characterized in that
the plurality of different matrices, which are utilized in the cryptographic processing section,
are a plurality of different matrices satisfying a condition in which a minimum number of branches [BkD] for all of the data lines is equal to or more than three, the minimum number of branches [BkD] for all of the data lines being selected from among minimum numbers of branches [BkD(s(i))] corresponding to the data lines, each of the minimum numbers of branches [BkD(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in k (where k is an integer equal to or more than two) continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure.
3. The cryptographic processing apparatus according to
Claim 1, characterized in that
the plurality of different matrices, which are utilized in the cryptographic processing section,
are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2D] for all of the data lines is equal to or more than three, the minimum number of branches [B2D] for all of the data lines being selected from among minimum numbers of branches [B2D(s(i))] corresponding to the data lines, each of the minimum numbers of branches [B2D(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure.
4. The cryptographic processing apparatus according to Claim 1, characterized in that
the plurality of different matrices, which are utilized in the cryptographic processing section,
are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2L] for all of the data lines is equal to or more than three, the minimum number of branches [B2L] for all of the data lines being selected from among minimum numbers of branches [B2L(s(i))] corresponding to the data lines, each of the minimum numbers of branches [B2L(s(i))] corresponding to the data lines being calculated on the basis of linear
transformation matrices included in two continuous F~ functions that are input to a corresponding data line s(i) in the extended Feistel structure.
5. The cryptographic processing apparatus according to
Claim 1, characterized in that,
when the plurality of different matrices are denoted by n (where n is an integer equal to or more than two) different matrices, i.e.,
M0, Mlf ...Mn-1
the cryptographic processing section is
configured so that the different matrices M0, Mx, ...Mn-1 are repeatedly arranged in an order in the F-functions that are input to the respective data lines in the extended Feistel structure.
6. The cryptographic processing apparatus according to any
of Claims 1 to 5, characterized in that
the cryptographic processing section is
configured to perform a cryptographic process to which an extended Feistel structure that performs only one F-function in one round is applied.
7. The cryptographic processing apparatus according to any
of Claims 1 to 5, characterized in that
the cryptographic processing section is
configured to perform a cryptographic process to which an extended Feistel structure that performs a plurality of
F-functions in parallel in one round is applied.
8. The cryptographic processing apparatus according to any
of Claims 1 to 5, characterized in that
the cryptographic processing section is
configured to perform, when a is any integer satisfying a > 2 and x is any integer satisfying x > 1, a cryptographic process to which an extended Feistel structure that utilizes a types of F-functions and that has the number of data lines: d which is set as d = 2ax is applied, the a types of F-functions performing different linear transformation processes using the plurality of different matrices, and
configured to perform equally x pieces or each of the types (the a types) of F-functions in one round.
9. The cryptographic processing apparatus according to
Claim 8, characterized in that
the cryptographic processing section is configured by including:
an F-function performing unit that performs ax F-functions which are performed in parallel in one round; and
a control unit that performs data input/output control for the F-function performing unit.
10. The cryptographic processing apparatus according to
any of Claims 1 to 5, characterized in that
the cryptographic processing section includes:
a plurality of F-function performing units that perform
different linear transformation processes using the plurality of different matrices; and
a control unit that changes a sequence of utilizing the plurality of F-function performing units in accordance with a setting,
wherein the control unit
is configured to selectively perform any of cryptographic processes (a), (bl), and (b2), i.e.,
(a) a cryptographic process using a Feistel structure having the number of data lines d that is set as d = 2,
(bl) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which only one F-function is allowed to be performed in each round, or
(b2) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which a plurality of F-functions are allowed to be performed in parallel in each round.
11. The cryptographic processing apparatus according to Claim 10, characterized in that
the control unit is
configured to select a processing mode to be performed in accordance with a bit length of data that is to be subjected to an encryption or decryption process.
12. A cryptographic processing method for performing a cryptographic process in a cryptographic processing apparatus, the method characterized by comprising
a cryptographic processing step of performing a Feistel-type common-key block-cipher process of repeating an SP-type F-function in a plurality of rounds in a cryptographic processing section, the SP-type F-function performing a data transformation process including a nonlinear transformation process and a linear transformation process,
wherein the cryptographic processing step
is a step of performing a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, and includes an operation step of performing operations in which a plurality of at least two or more different matrices are selectively applied to linear transformation processes that are performed in F-functions in respective rounds,
wherein the plurality of different matrices, which are applied in the operation step, are a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum
numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure, and
wherein the operation step
is a step of performing linear transformation operations based on the plurality of different matrices in the F-functions that are input to the respective data lines in the extended Feistel structure.
13. The cryptographic processing method according to Claim 12, characterized in that
the plurality of different matrices
are a plurality of different matrices satisfying a condition in which a minimum number of branches [BkD] for all of the data lines is equal to or more than three, the minimum number of branches [BkD] for all of the data lines being selected from among minimum numbers of branches [BkD(s(i))] corresponding to the data lines, each of the minimum numbers of branches [BkD(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in k (where k is an integer equal to or more than two) continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure.
14. The cryptographic processing method according to Claim
12, characterized in that
the plurality of different matrices
are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2D] for all of the data lines is equal to or more than three, the minimum number of branches [B2D] for all of the data lines being selected from among minimum numbers of branches [B2D(s(i))] corresponding to the data lines, each of the minimum numbers of branches [B2D(s(i))] corresponding to the data lines being calculated on the basis of linear transformation matrices included in two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure.
15. The cryptographic processing method according to Claim
12, characterized in that
the plurality of different matrices
are a plurality of different matrices satisfying a condition in which a minimum number of branches [B2L] for all of the data lines is equal to or more than three, the minimum number of branches [B2L] for all of the data lines being selected from among minimum numbers of branches [B2L(s(i))] corresponding to the data lines, each of the minimum numbers of branches [B2L(s(i))] corresponding to the data lines being calculated on the basis of linear
transformation matrices included in two continuous F-functions that are input to a corresponding data line s(i) in the extended Feistel structure.
16. The cryptographic processing method according to Claim
12, characterized in that,
when the plurality of different matrices are denoted by n (where n is an integer equal to or more than two) different matrices, i.e.,
M0, Mx, ...Mn-1
the operation step is
a step of repeatedly performing the different matrices M0, Mlf ...Mn_1 in an order in the F-functions that are input to the respective data lines in the extended Feistel structure.
17. The cryptographic processing method according to any
of Claims 12 to 16, characterized in that
the cryptographic processing step is
a step of performing a cryptographic process to which an extended Feistel structure that performs only one F-function in one round is applied.
18. The cryptographic processing method according to any
of Claims 12 to 16, characterized in that
the cryptographic processing step is
a step of performing a cryptographic process to which an extended Feistel structure that performs a plurality of
F-functions in parallel in one round is applied.
19. The cryptographic processing method according to any
of Claims 12 to 16, characterized in that
the cryptographic processing step is
a step of performing, when a is any integer satisfying a > 2 and x is any integer satisfying x > 1, a cryptographic process to which an extended Feistei structure that utilizes a types of F-functions and that has the number of data lines: d which is set as d = 2ax is applied, the a types of F-functions performing different linear transformation processes using the plurality of different matrices, and
a step of performing equally x pieces of each of the types (the a types) of F-functions in one round.
20. The cryptographic processing method according to Claim
19, characterized in that
the cryptographic processing step is
a step of performing a cryptographic process, in which an F-function performing unit that performs ax F-functions performed in parallel in one round is applied, in accordance with control performed by a control unit that performs data input/output control for the F-function performing unit.
21. The cryptographic processing method according to any
of Claims 12 to 16, characterized in that
the cryptographic processing step is a step of performing a cryptographic process
by using a plurality of F-function performing units that perform different linear transformation processes using the plurality of different matrices, and
by using a control unit that changes a sequence of utilizing the plurality of F-function performing units in accordance with a setting,
wherein the cryptographic processing step is a step of, in accordance with control performed by the control unit, selectively performing any of cryptographic processes (a), (bl), and (b2), i.e.,
(a) a cryptographic process using a Feistel structure having the number of data lines d that is set as d = 2,
(bl) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which only one F-function is allowed to be performed in each round, or
(b2) a cryptographic process which uses an extended Feistel structure having the number of data lines d that is set to any number satisfying d > 2, and in which a plurality of F-functions are allowed to be performed in parallel in each round.
22. The cryptographic processing method according to Claim 21, characterized in that the control unit selects a processing mode to be performed in accordance with a bit length of data that is to be subjected to an encryption or
decryption process.
23. A cryptographic-processing-algorithm constructing method for constructing a cryptographic processing algorithm in an information processing apparatus, the method characterized by comprising:
a matrix-determining step in which, in a cryptographic-processing-algorithm configuration to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, a control unit provided in the information processing apparatus determines a plurality of at least two or more different matrices that are to be applied to linear transformation processes performed in F-functions in respective rounds; and
a matrix-setting step in which the control unit repeatedly arranges the plurality of different matrices, which are determined in the matrix-determining step, in the F-functions that are input to the respective data lines in the extended Feistel structure,
wherein the matrix-determining step
is a step of performing a process of determining, as the plurality of two or more different matrices, as matrices to be applied, a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data
lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure.
24. A computer program that causes a cryptographic processing apparatus to perform a cryptographic process, the program characterized by comprising
a cryptographic processing step of causing a cryptographic processing section to perform a Feistel-type common-key block-cipher process of repeating an SP-type E1-function in a plurality of rounds, the SP-type F-function performing a data transformation process including a nonlinear transformation process and a linear transformation process,
wherein the cryptographic processing step is a step of causing the cryptographic processing section to perform a cryptographic process to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, and includes an operation step of performing operations in which a plurality of at least two or more different matrices are selectively applied to linear transformation processes that are performed in F-functions in respective rounds,
wherein the plurality of different matrices, which are applied in the operation step, are a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure, and
wherein the operation step
is a step of performing linear transformation operations based on the plurality of different matrices in the F-functions that are input to the respective data lines in the extended Feistel structure.
25. A computer program that causes an information processing apparatus to construct a cryptographic processing algorithm, the program characterized by comprising:
a matrix-determining step of causing, in a cryptographic-processing-algorithm configuration to which an extended Feistel structure having a number of data lines: d that is set to an integer satisfying d > 2 is applied, a control unit provided in the information processing apparatus to determine a plurality of at least two or more
different matrices that are to be applied to linear transformation processes performed in F-functions in respective rounds; and
a matrix-setting step of causing the control unit to repeatedly arrange the plurality of different matrices, which are determined in the matrix-determining step, in the F-functions that are input to the respective data lines in the extended Feistel structure,
wherein the matrix-determining step
is a step of performing a process of determining, as the plurality of two or more different matrices, as matrices to be applied, a plurality of different matrices satisfying a condition in which a minimum number of branches for all of the data lines is equal to or more than a predetermined value, the minimum number of branches for all of the data lines being selected from among minimum numbers of branches corresponding to the data lines, each of the minimum numbers of branches corresponding to the data lines being based on linear transformation matrices included in F-functions that are input to a corresponding data line in the extended Feistel structure.

Documents