IP Library Granted Patent US 8,111,825
Granted Patent B2
US 8,111,825 · App. 11/994,256 · Granted Feb 7, 2012

Encryption apparatus and method therefor

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,111,825
App. No.
11/994,256
Granted
Feb 7, 2012
Kind
B2
Abstract

A modified implementation of the Kasumi algorithm executes on a 32-bit processor using full 32-bit operations. The implementation comprises a series of four rounds, each round including an intermediate sub-function executed between two executions of an FL sub-function. The intermediate sub-function is functionally equivalent to two consecutive 16-bit FO sub-functions.

Claims (37)

1. A processor-implemented method of operating on a 64-bit plaintext input using a key to produce a 64-bit ciphertext output, the method comprising the steps of:

at the processor, sequentially iterating a round function a number of times using the key to generate the 64-bit ciphertext output, the round function comprising:

obtaining a first 32-bit round function input data block and a second 32-bit round function input data block;

executing an FL sub-function using the first 32-bit round function input data block so as to generate a first interim output data block;

executing an intermediate sub-function using the first interim output data block using the second 32-bit round function input data block so as to generate a second interim output data block, the intermediate sub-function being functionally equivalent to execution of two consecutive 16-bit FO sub-functions, the intermediate sub-function comprising a plurality of exclusive-OR operations using pairs of half-words of data;

executing the FL sub-function using the second interim output data block so as to generate a third 32-bit interim output data block;

performing an exclusive-OR operation on the first 32-bit round function input data block and the third 32-bit interim output data block so as to generate a first 32-bit round function output data block;

using a first intermediate result and a second intermediate result generated by the intermediate sub-function so as to generate a second 32-bit round function output data block; and

providing a 64-bit ciphertext output based on the second 32-bit round function output data block, wherein the number of times of execution of the round function is four, and wherein execution of the FL sub-function is a 32-bit operation.

2. A method as claimed in claim 1 , wherein the 64-bit plaintext input is a concatenation of the first and second 32-bit round function input data blocks.

3. A method as claimed in claim 1 , wherein the first 32-bit round function output data block serves as the first 32-bit round function input data block for a subsequent iteration of the round function and the second 32-bit round function output data block serves as the second 32-bit round function input data block for the subsequent iteration of the round function.

4. A method as claimed in claim 1 , wherein the key is a 128-bit key.

5. A method as claimed in claim 1 , wherein execution of the intermediate sub-function is a 32-bit operation.

6. A method as claimed in claim 1 , wherein the intermediate sub-function comprises a plurality of executions of a 32-bit Fl sub-functions.

7. A method as claimed in claim 6 , wherein each of the 32-bit Fl sub-functions comprises a plurality of S-Box sub-functions arranged to be executable in respect of 32-bit data blocks.

8. A method as claimed in claim 6 , wherein the plurality of exclusive-OR operations are performed between executions of the 32-bit Fl sub-function.

9. A method as claimed in claim 8 , wherein the half-words of data are derived from the first interim output data block, outputs of the 32-bit Fl sub-function and/or the second 32-bit round function input data block.

10. A method as claimed in claim 1 , the method further comprising:

generating KL sub-keys from the key; and

using the KL sub-keys in the FL sub-function.

11. A method as claimed in claim 1 , the method further comprising:

generating KO and KI sub-keys from the key; and

using the KO and KI sub-keys in the 32-bit Fl sub-function.

12. A method as claimed in claim 11 , wherein the KO and KI sub-keys are respectively applied as blocks of 32-bits.

13. A method as claimed in claim 1 , wherein after iterating the round function the number of times, the 64-bit ciphertext output is a concatenation of the first and second 32-bit round function output data blocks.

14. A hardware encryption apparatus for operating on a 64-bit plaintext input using a key to produce a 64-bit ciphertext output, the apparatus comprising a processor arranged to support:

a round function unit which, when executed, uses the key and executable a number of times to generate the 64-bit ciphertext output, the round function block comprising:

a first input which, when executed, receives a first 32-bit round function input data block, and a second input which, when executed, receives a second 32-bit round function input data block;

a first FL sub-function unit which, when executed, performs an FL sub-function in using the 32-bit round function input data block so as to generate a first interim output data block;

an intermediate sub-function unit which, when executed, performs an intermediate sub-function using the first interim output data block using the second 32-bit round function input data block so as to generate a second interim output data block, the intermediate sub-function being functionally equivalent to execution of two consecutive 16-bit FO sub-functions;

a second FL sub-function unit which, when executed, performs the FL sub-function using second interim output data block so as to generate a third 32-bit interim output data block;

an exclusive-OR gate which, when executed, operates on the first 32-bit round function input data block and the third 32-bit interim output data block so as to generate a first 32-bit round function output data block; and

a register which, when executed, stores a second 32-bit round function output data block generated by using a first intermediate result and a second intermediate result generated, when in use, by the intermediate sub-function; and

an output which, when executed, provides the 64-bit ciphertext output based on the second 32-bit round function output data block, wherein the number of times of execution of the round function is four, and wherein execution of the FL sub-function is a 32-bit operation.

15. An apparatus as claimed in claim 14 , wherein the 64-bit plaintext input is a concatenation of the first and second 32-bit round function input data blocks.

16. An apparatus as claimed in claim 14 , wherein the first 32-bit round function output data block serves as the first 32-bit round function input data block for a subsequent iteration of the round function and the second 32-bit round function output data block serves as the second 32-bit round function input data block for the subsequent iteration of the round function.

17. An apparatus as claimed in claim 14 , wherein the intermediate sub-function comprises a plurality of executions of a 32-bit Fl sub-functions.

Assignments (31)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040925 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Feb 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V. F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 052917/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 040928 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Jan 17, 2020
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 052915/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 11759915 AND REPLACE IT WITH APPLICATION 11759935 PREVIOUSLY RECORDED ON REEL 037486 FRAME 0517. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Dec 10, 2019
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 053547/0421 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050744/0097 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT THE APPLICATION NO. FROM 13,883,290 TO 13,833,290 PREVIOUSLY RECORDED ON REEL 041703 FRAME 0536. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS.. Recorded Feb 20, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: SHENZHEN XINGUODU TECHNOLOGY CO., LTD.
Reel/Frame 048734/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042985/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042762/0145 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENTS 8108266 AND 8062324 AND REPLACE THEM WITH 6108266 AND 8060324 PREVIOUSLY RECORDED ON REEL 037518 FRAME 0292. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS. Recorded Feb 1, 2017
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 041703/0536 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE LISTED CHANGE OF NAME SHOULD BE MERGER AND CHANGE PREVIOUSLY RECORDED AT REEL: 040652 FRAME: 0180. ASSIGNOR(S) HEREBY CONFIRMS THE MERGER AND CHANGE OF NAME. Recorded Jan 12, 2017
From: FREESCALE SEMICONDUCTOR INC.
To: NXP USA, INC.
Reel/Frame 041354/0148 →
CHANGE OF NAME Recorded Nov 8, 2016
From: FREESCALE SEMICONDUCTOR INC.
To: NXP USA, INC.
Reel/Frame 040652/0180 →
RELEASE OF SECURITY INTEREST Recorded Nov 7, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 040928/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 21, 2016
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP, B.V., F/K/A FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 040925/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12092129 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Jul 14, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039361/0212 →
SUPPLEMENT TO THE SECURITY AGREEMENT Recorded Jun 16, 2016
From: FREESCALE SEMICONDUCTOR, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039138/0001 →
SECURITY AGREEMENT SUPPLEMENT Recorded Mar 7, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 038017/0058 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 13, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037518/0292 →
ASSIGNMENT AND ASSUMPTION OF SECURITY INTEREST IN PATENTS Recorded Jan 12, 2016
From: CITIBANK, N.A.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 037486/0517 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037354/0670 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0553 →
PATENT RELEASE Recorded Dec 21, 2015
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 037356/0143 →
SECURITY AGREEMENT Recorded Nov 6, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 031591/0266 →
SECURITY AGREEMENT Recorded Jun 18, 2013
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 030633/0424 →
SECURITY AGREEMENT Recorded May 13, 2010
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 024397/0001 →
SECURITY AGREEMENT Recorded Mar 15, 2010
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A.
Reel/Frame 024085/0001 →
SECURITY AGREEMENT Recorded Jul 11, 2008
From: FREESCALE SEMICONDUCTOR, INC.
To: CITIBANK, N.A.
Reel/Frame 021217/0368 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2007
From: LIN, BO
To: FREESCALE SEMICONDUCTOR, INC.
Reel/Frame 020302/0748 →