Encoder, decoder, system and method for transmitting encrypted data
10904228 · 2021-01-26
Assignee
- Fraunhofer-Gesellschaft zur Foerderung der angewandten Forschung e.V. (Munich, DE)
- timeproof gmbh (Hamburg, DE)
Inventors
- Olaf Feller (Ribeauvillé, DE)
- Ute Troppenz (Berlin, DE)
- Norbert Grote (Berlin, DE)
- Torsten Mehlhorn (Berlin, DE)
Cpc classification
H04L63/0485
ELECTRICITY
G02B6/2821
PHYSICS
International classification
H04L9/08
ELECTRICITY
H04L9/32
ELECTRICITY
Abstract
An encoder for providing encrypted data for transmission via a transmission medium includes an encryption unit that is configured to encrypt data received at the encoder block by block and a processing unit. The processing unit is configured to randomly distribute an encrypted data block to a plurality of channels that are allocated to the transmission medium and to provide a sub-block, which includes part of the encrypted data block, to be transmitted via one of the channels, together with a channel identification allocated to the channel and a code value that is based on the encrypted data in the sub-block to be transmitted and the channel identification, for transmission via the allocated channel of the transmission medium.
Claims
1. An encoder for providing encrypted data for transmission via a transmission medium, comprising: an encryption processor, wherein the encryption processor is to encrypt data received at the encoder block by block; and a processor connected to the encryption processor, wherein wherein the processor is to receive from the encryption processor an encrypted data block provided at an output of the encryption processor, wherein the processor is to distribute the encrypted data block randomly to a plurality of channels allocated to the transmission medium such that respective sub-blocks result, each sub-block comprising a portion of the encrypted data in the encrypted data block and wherein the processor is to create for each sub-block a code value using the encrypted data in the sub-block and a channel identification, the channel identification allocated to one of the plurality of channels of the transmission medium, the sub-block to be transmitted via the one channel, and wherein the processor is to provide each sub-block together with the channel identification and the code value for a transmission via the one channel, wherein the encryption processor and the processor are implemented in hardware.
2. The encoder according to claim 1, wherein the transmission medium comprises an optical multicore fiber, wherein one core of the multicore fiber defines a channel, and wherein the processor is to provide the sub-blocks for a parallel transmission via the multicore fiber, wherein the channel identification indicates a channel number allocated to the sub-block to be transmitted.
3. The encoder according to claim 2, wherein at least one core of the multicore fiber defines a monitor channel, and wherein the processor is to provide one or several monitoring signals for transmission via the at least one monitor channel, the monitoring signal selected to detect a change of the multicore fiber.
4. The encoder according to claim 1, wherein the transmission medium comprises at least one optical monomode fiber, wherein a predetermined transmission time is allocated to a channel, and wherein the processor is to provide the sub-blocks for transmission via the monomode fiber successively in time, the channel identification indicating the splitting time allocated to the sub-block to be transmitted.
5. The encoder according to claim 4, wherein the processor is to effect an asymmetrical encryption of the sub-blocks to be transmitted.
6. The encoder according to claim 1, wherein the code value comprises a hash value for the encrypted data in the sub-block to be transmitted and the channel identification.
7. The encoder according to claim 6, wherein the unit processor comprises logic for dividing the encrypted data block and a plurality of hash processors for generating hash values based on the encrypted data in the sub-block to be transmitted and the channel identification.
8. The encoder according to claim 1, wherein the encryption processor is to effect a symmetrical encryption of the data received at the encoder.
9. A decoder for decrypting data provided by the encoder according to claim 1 and transmitted via the transmission medium, comprising: a further processor connected to the transmission medium, wherein the further processor is to verify, based on the received code value, the portion of the encrypted data block in the sub-block and the channel identification allocated to the channel, a manipulation-free transmission of the data, and wherein the further processor is to combine the received sub-blocks to an encrypted data block; and a crypto-processor connected to the further processor, wherein the crypto-processor is to receive the encrypted data block from the further processor, wherein the crypto-processor is to decrypt the encrypted data block, wherein the further processor and the crypto-processor are implemented in hardware.
10. The decoder according to claim 9, wherein the further processor is to detect a change of the multicore fiber based on one or several received monitoring signals.
11. A system for transmitting data, comprising: the encoder according to claim 1 for providing encrypted data for transmission; and the transmission medium for transmitting the encrypted data provided by the encoder.
12. The system according to claim 11, wherein the transmission medium comprises an optical multicore fiber, wherein one core of the multicore fiber defines one channel, and wherein one channel number is allocated to one channel.
13. The system according to claim 12, wherein at least one core of the multicore fiber defines a monitor channel for transmitting one or several monitoring signals for detecting a change of the multicore fiber.
14. The system according to claim 11, further comprising the decoder according to claim 9 for decrypting the encrypted data transmitted by the transmission medium.
15. A method comprising: providing encrypted data for transmission via a transmission medium by block by block encrypting of the data; randomly distributing an encrypted data block to a plurality of channels allocated to the transmission medium such that respective sub-blocks result, each sub-block comprising a portion of the encrypted data in the encrypted data block, and for each sub-block creating a code value using the encrypted data in the sub-block and a channel identification, the channel identification allocated to one of the plurality of channels of the transmission medium, the sub-block to be transmitted via the one channel, and providing the sub-block, the channel identification and the code value for transmission via the one channel.
16. The method of claim 15, further comprising: transmitting the encrypted data via the transmission medium, and decrypting the encrypted data by verifying a manipulation-free transmission of the encrypted data based on the received code value, the portion of the encrypted data block in the sub-block and the channel identification allocated to the channel; combining the received sub-blocks to the encrypted data block; and decrypting the encrypted data block.
17. A non-transitory digital storage medium having a computer program stored thereon to perform a method comprising: providing encrypted data for transmission via a transmission medium by block by block encrypting of data; randomly distributing an encrypted data block to a plurality of channels allocated to the transmission medium such that respective sub-blocks result, each sub-block comprising a portion of the encrypted data in the encrypted data block, and for each sub-block creating a code value using the encrypted data in the sub-block and a channel identification, the channel identification allocated to one of the plurality of channels of the transmission medium, the sub-block to be transmitted via the one channel, and providing the sub-block, the channel identification and the code value for transmission via the one channel, when said computer program is run by a computer.
Description
BRIEF DESCRIPTION OF THE DRAWINGS
(1) Embodiments of the present invention will be detailed subsequently referring to the appended drawings, in which:
(2)
(3)
(4)
(5)
(6)
(7)
DETAILED DESCRIPTION OF THE INVENTION
(8) In the following description of the embodiments of the present invention, the same or equal elements are provided with the same reference numbers.
(9) The following description of embodiments is based on a transmission system using optical links, for example, MC fibers (MC=multicore) or single core fibers. However, it should be noted here that the basic inventive approach can also be used in different transmission connections, for example, in a wired connection but also wireless communication, since due to the inventive approach the transmission of sensitive data is performed in data blocks that are divided onto a plurality of sub-channels whose manipulation alone does not enable decryption of the data, rather, at the same time, massive manipulation of all sub-channels is necessitated in order to obtain the information necessitated for an entire data block, which significantly increases the security against interception of each transmission path, independent of its design.
(10) Based on
(11) The system illustrated in
(12) In the following, the mode of operation of the structure illustrated based on
(13) As mentioned above, high transmission rates are frequently desired and are obtained by using high bit rate transmitters and receivers, wherein further parallelization of the transmission contributes to increasing the transmission rates. The inventive solution combines high data rates via optical fiber paths with highest security against interception. The protection method is based on usage of the parallel hash processors 110.sub.1 to 110.sub.4 shown in
(14) A) the 1/n portion of the SYMBLOCKs
(15) B) the channel number n
(16) C) the hash value for A) and B)
(17) The manipulation of such a sub-channel does not yet allow decryption of the data, for this, simultaneous massive manipulation of all optical channels would be necessitated. However, currently, this is merely possible for individual separate fibers but not for connected multicore fibers, such as quad cores. According to the embodiment illustrated based on
(18)
(19)
(20) According to embodiments of the present invention, the transmission medium 200 includes an optical transmission medium, wherein transmission by using fast optical components necessitates the conversion of the data into optical data which are then transmitted via the optical link medium, which advantageously includes a multicore single mode fiber. The secure optical link consists of active multicore single mode fibers as described, for example, in references [4] and [5]. With single mode fiber paths and respective optical power, signals can be transmitted via paths of up to several 10 kilometers without necessitating regeneration. Thus, the optical link remains closed and unamended. When using multicore links, all fiber cores are guided within a common cladding and according to an embodiment of the present invention, such a multicore link is used for realizing the interception-proof optical link, wherein the fiber cores as already discussed briefly based on
(21)
(22) The monitor fiber cores can be used in different ways, for example, for carrying separate transmission signals or for detecting evanescent optical fields of the data carrier if changes e.g. bending or the like, takes place at the optical fiber.
(23) The above-discussed embodiments use multicore fibers allowing parallelization of data transmission as transmission medium. According to other implementations of the present invention, however, simpler monomode fibers can be used, as illustrated schematically in
(24)
(25)
(26) The data are transmitted either in parallel or in series as explained above based on
(27) Embodiments of the invention have been described with reference to an encoder encrypting the data signals block by block and dividing each encrypted block to a plurality of data channels for parallel transmission via the optical multicore fiber. The present invention is not limited to these embodiments.
(28) According to a further aspect of the present invention, secure transmission of data is obtained by using the above-described multicore fiber wherein, as described based on
(29) In these embodiments, both encrypted data and unencrypted data can be securely transmitted. The data are securely transmitted via the inventive transmission medium, since by the used monitor channels manipulation of the fiber and/or coupling out of data can be detected securely and reliably, e.g. based on an evanescent optical field in the monitor channel due to the data signal in the data channel. Different to known approaches for monitoring, the inventive approach is advantageous since due to monitoring via the monitor channel, manipulation is detected quickly (almost in real time) and reliably without great measurement technological effort, such that counter measures can be taken at an early time, e.g. interrupting the transmission. A further advantage is that transmitting a data signal together with a signal (optical interference signal) in the monitor channel provides no useful data, even when reading out data from the fiber (e.g. by bending the fiber), since due to the bending of the fiber, the optical signals that can be read out or detected represent a non-separable superposition of the evanescent optical fields of the signal in the monitor channel and the signal in the data signal caused by the bending. In other words, when trying to manipulate the fiber, the data signal is protected by the optical signal (light) in the monitor channel.
(30) Although some aspects have been described in the context of an apparatus, it is clear that these aspects also represent a description of the corresponding method, such that a block or device of an apparatus also corresponds to a respective method step or a feature of a method step. Analogously, aspects described in the context of a method step or as a method step also represent a description of a corresponding block or item or feature of a corresponding apparatus.
(31) Depending on certain implementation requirements, embodiments of the invention can be implemented in hardware or in software. The implementation can be performed using a digital storage medium, for example a floppy disk, a DVD, a Blu-Ray disc, a CD, an ROM, a PROM, an EPROM, an EEPROM or a FLASH memory, a hard drive or another magnetic or optical memory having electronically readable control signals stored thereon, which cooperate or are capable of cooperating with a programmable computer system such that the respective method is performed. Therefore, the digital storage medium may be computer readable. Some embodiments according to the invention include a data carrier comprising electronically readable control signals, which are capable of cooperating with a programmable computer system, such that one of the methods described herein is performed.
(32) Generally, embodiments of the present invention can be implemented as a computer program product with a program code, the program code being operative for performing one of the methods when the computer program product runs on a computer. The program code may for example be stored on a machine readable carrier.
(33) Other embodiments comprise the computer program for performing one of the methods described herein, wherein the computer program is stored on a machine readable carrier.
(34) In other words, an embodiment of the inventive method is, therefore, a computer program comprising a program code for performing one of the methods described herein, when the computer program runs on a computer. A further embodiment of the inventive methods is, therefore, a data carrier (or a digital storage medium or a computer-readable medium) comprising, recorded thereon, the computer program for performing one of the methods described herein.
(35) A further embodiment of the inventive method is, therefore, a data stream or a sequence of signals representing the computer program for performing one of the methods described herein. The data stream or the sequence of signals may for example be configured to be transferred via a data communication connection, for example via the Internet.
(36) A further embodiment comprises a processing means, for example a computer, or a programmable logic device, configured to or adapted to perform one of the methods described herein.
(37) A further embodiment comprises a computer having installed thereon the computer program for performing one of the methods described herein.
(38) In some embodiments, a programmable logic device (for example a field programmable gate array, FPGA) may be used to perform some or all of the functionalities of the methods described herein. In some embodiments, a field programmable gate array may cooperate with a microprocessor in order to perform one of the methods described herein. Generally, the methods are performed by any hardware apparatus. This can be a universally applicable hardware, such as a computer processor (CPU) or hardware specific for the method, such as ASIC.
(39) While this invention has been described in terms of several advantageous embodiments, there are alterations, permutations, and equivalents which fall within the scope of this invention. It should also be noted that there are many alternative ways of implementing the methods and compositions of the present invention. It is therefore intended that the following appended claims be interpreted as including all such alterations, permutations, and equivalents as fall within the true spirit and scope of the present invention.
REFERENCES
(40) [1] Tentative SHA-3 standard (FIPS XXX) development timeline NIST, Retrieved 2013-05-27, NIST SHA-3 pages and the hash-forum list [2] http://www.luxtera.com [2] http://www.finisar.com [4] M.-J. Li, B. Hoover, V. N. Nazarov, and D. L. Butler, Multicore Fiber for Opti-cal Interconnect applications, 2012 17th Opto-Electronics and Communications Conference (OECC2012) Technical Digest, Paper 5E4-2 [5] R. Ryf, et. al., Space-Division Multiplexed Transmission over 4200-km 3-Core Microstructured Fiber, PDP5C.2, Optical Fiber Communication Conference and Exposition (OFC/NFOEC), 2012