Data-Driven.Ciphers.Suitable.for.Software.Implementation
Nikolai Moldovyan, Alexander A. Moldovyan · Auerbach Publications eBooks · 2007
There are two types of data-driven operations efficient on the general purpose microprocessors available today: data-dependent rotation (DDR) and DDSS. The DDRs are extensively used in the well-known ciphers RC5 and RC6. Ciphering mechanism described in the following text characterizes a class of block encryption functions based on DDSS. We suppose that an expanded encryption key that represents a sequence containing 2δ b-bit subkeys Q [ j], where j = 0, 1, 2, …, 2δ − 1, is used. This sequence is to be precomputed, depending on the secret key, the length of which is 128 to 256 bits. The input data block is represented as a concatenation of b-bit subblocks: M = (B(0), B(1), …, B(w−1)) (5.1) Encryption and decryption are executed as a sequence of elementary conversion steps: C = E(M) = ek(ek−1(… e2(e1(M)))) (5.2) M = D(C) = e′k(e′k−1(… e′2(e′1(C)))) (5.3) where e1, e2, …, ek and e′1, e′2, …, e′k are elementary encryption and decryption functions; C is a cipher text block. Elementary decryption function e′i is the inverse of function ek−i+1. Elementary encryption functions have the following structures: j(s, g′) = (B(g′ )) B(g) ← ei(B(g), Q[ j(s,g′)]) (5.5) where B