Method for performing secure function and associated system

The method enhances the security and efficiency of white-box encryption by encrypting data in a non-secure environment and using a secure element for decryption, addressing vulnerabilities and resource inefficiencies in existing solutions.

JP2025094919APending Publication Date: 2025-06-25IDEMIA FRANCE SAS
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024216105
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-12-11
Publication Date
2025-06-25

AI Technical Summary

Technical Problem

Existing white-box encryption implementations are not sufficiently secure and resource-efficient, particularly when executed in insecure environments, and are vulnerable to code unlocking attacks.

Method used

A method and system utilizing a secure element and a white-box implementation form in a non-secure execution environment, where processing data is encrypted and processed by the white-box implementation form, then sent to a secure element for decryption using a decryption key, and the result is used to calculate an output message, with the encryption and decryption keys being separate and stored in different components to enhance security and reduce resource consumption.

Benefits of technology

The method provides enhanced security by encrypting processing data, limiting resource consumption, and preventing attackers from deducing the intermediate function, thus making the secure function more secure and resource-efficient.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025094919000001_ABST
    Figure 2025094919000001_ABST
Patent Text Reader

Abstract

To provide a method for performing a secure function that maps an input message to an output message, and an associated system.SOLUTION: In a system comprising a secure element and a white box implementation, a method includes: a step E100 of the white box implementation computing processing data based on an input message; a step E200 of the white box implementation encrypting the processing data; a step E300 of sending the encrypted processing data to the secure element; a step E400 of the secure element obtaining a result data based on the encrypted processing data, the result data being an image of the processing data by an intermediate function; and a step E500 of computing an output message based on the result data.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for performing a secure function that maps an input message to an output message, and a related system.

[0002] Conventionally, secure functions (e.g., cryptographic functions) use data (e.g., basic cryptographic keys) that are intended to remain secret.

[0003] When implementing a secure function by software running in an insecure environment, specific countermeasures need to be taken to prevent an attacker from accessing the secret data.

[0004] The search for techniques to protect the implementation form of a function in an insecure environment is known as "white-box encryption."

[0005] A software implementation form that can protect the implementation form of a function in an insecure environment is known as a white-box implementation form.

[0006] A paper (Non-Patent Document 1) proposes a technique for generating an AES algorithm suitable for specific cryptographic keys, for example.

[0007] In the case of a generally proposed solution in this situation, a secure function is decomposed into a series of basic processing operations, and mask data is manipulated using look-up tables respectively associated with these basic processing operations.

[0008] However, white-box implementation forms may not guarantee a sufficient level of security.

[0009] Some secure functions are intended to be executed in a permitted environment. For example, a secure function that can access a vehicle is designed to be executed only in the environment of a permitted user.

[0010] To infer the secret data of the secure function, an attack known as the "code unlocking" attack is to copy the white-box implementation form of the secure function to an insecure environment under the complete control of the attacker.

[0011] In such an environment, the attacker can execute a very large number of iterations of the secure function and / or use tools (typically, debugging tools) to execute the secure function step by step. Furthermore, in such an attack, for example, in order to access the vehicle of this authorized user, the attacker can replace the authorized user with the attacker himself and replace the authorized environment with an environment under the attacker's control.

[0012] To counter this type of attack, the first solution described in the patent document (Patent Document 1) consists of a white-box implementation form that uses the decoded cryptographic key received from the trusted execution environment in a decoded form.

[0013] However, this solution has the drawbacks of not being sufficiently secure or requiring a connection to the server that receives the key.

[0014] The second known solution consists of a white-box implementation form that sends data to a secure element. The secure element calculates the result of applying the function to this data, and then the white-box implementation form verifies that the result calculated by the secure element corresponds to the application of the function to this data (for example, by calculating another result obtained by applying the function to this data or applying the inverse of this function to the result).

[0015] This second solution has the drawbacks of not being sufficiently secure or being expensive in terms of the resources of the insecure environment (typically, computing time and memory size) in which the solution is implemented.

[0016] The third solution is to use a secure element to update the white-box implementation form and thus modify the behavior of this white-box implementation form.

[0017] Unfortunately, the implementation of this solution requires the replacement of the lookup table in the white box implementation form, which is costly in terms of the resources of the system (especially the secure element) implementing this solution.

Prior Art Documents

Patent Documents

[0018]

Patent Document 1

Non-Patent Documents

[0019]

Non-Patent Document 1

Non-Patent Document 2

Non-Patent Document 3

[0020] According to a first aspect, in order to correct these drawbacks, the present invention is a method for executing a secure function that maps an input message to an output message, and the method is implemented by a system including a secure element and a white-box implementation form in a non-secure execution environment. - The white-box implementation form calculates processing data based on the input message. - The white-box implementation form encrypts the processing data using an encryption key. - Transmitting the encrypted processing data to the secure element. - The secure element obtains result data based on the encrypted processing data and a decryption key related to the encryption key, and the result data is an image of the processing data by an intermediate function different from the identification function. - Calculating an output message based on the result data. A method is proposed, characterized by including the above.

[0021] Further advantageous and non-limiting features of the method according to the present invention, taken individually or in any technically possible combination, are as follows. - The output message includes the result data. - The method further includes a step in which the white-box implementation form calculates at least one other processing data, and the output message further includes the other processing data. - The white-box implementation form has a first part and a second part. The step of calculating processing data based on the input message and the step of encrypting the processing data using an encryption key are implemented by the first part of the white-box implementation form. The step of calculating the output message based on the result data is implemented by the second part of the white-box implementation form. The method further includes a step of transmitting the result data to the second part of the white-box implementation form. - The method further includes a step in which a first part of the white box implementation form calculates at least one other processing data, and a step in which a second part of the white box implementation form uses at least one other processing data and calculates an output message based on the result data. - The secure element obtains result data through function decryption of encrypted processing data using a function decryption key for an intermediate function, and this function decryption key is for the intermediate function. - The encryption key is a public key of the RSA algorithm. The function decryption key is obtained based on the private key of this RSA algorithm, and the private key is associated with the public key. The RSA algorithm has a deterministic encryption modulus, and the intermediate function is modular exponentiation that raises the processing data to a deterministic exponent modulo the deterministic encryption modulus. - The encryption key includes an encryption exponent, and the function decryption key includes the modular inverse of the encryption exponent and the deterministic exponent, or the result of the product of the encryption exponent and the deterministic exponent. - The encryption key is only included in the step where the white box implementation form encrypts the processing data, and the decryption key is only included in the step where the secure element obtains the result data. - The secure function is composed of a series of operations, and the intermediate function is part of these series of operations. - The secure function is an encryption function that maps an input message to an output message using a predetermined encryption key. - The predetermined encryption key is a key different from the encryption key and the decryption key.

[0022] At least a part of the method according to the present invention may be implemented by a computer. As a result, the present invention may take the form of an embodiment that combines a software aspect (including firmware, resident software, microcode, etc.) and a hardware aspect, which can all be referred to here as "components" together.

[0023] According to a second aspect, the present invention is a system that executes a secure function for mapping an input message to an output message, - A first component including all or part of a white-box implementation form in a non-secure execution environment, where all or part of this white-box implementation form is configured to calculate processing data based on an input message and encrypt the processing data using an encryption key, and the first component; - A secure element configured to receive encrypted processing data and obtain result data based on the encrypted processing data and a decryption key related to the encryption key, where the result data is an image of the processing data by an intermediate function different from an identification function, and the secure element; - A second component configured to receive the result data and calculate an output message based on the result data A system is proposed, characterized by including the above.

[0024] Further advantageous non-limiting features of the system according to the invention, taken individually or in any technically possible combination, are as follows. - The output message includes the result data. - The white-box implementation form has a first part and a second part. All or part of the white-box implementation form of the first component is the first part of the white-box implementation form, and the second component includes the second part of the white-box implementation form in a non-secure execution environment. The second part of the white-box implementation form is configured to receive the result data and calculate an output message based on the result data.

[0025] This system may be configured to implement each of the possible embodiments contemplated for the method as described above.

[0026] Of course, various features, variants, and embodiments of the present invention may be combined with each other in various combinations, provided that the various features, variants, and embodiments of the present invention are compatible or do not conflict with each other.

[0027] Other features and advantages of the present invention will become apparent from the following description with reference to the accompanying drawings, which illustrate exemplary embodiments of the present invention without any limitation.

Brief Description of the Drawings

[0028]

Figure 1

Figure 2

Figure 3

[0029] Unless otherwise indicated, elements common to multiple drawings or similar elements in multiple drawings are denoted by the same reference numerals, have the same or similar features, and thus these common elements are generally not described repeatedly for simplicity.

[0030] In the context of this specification, the qualifiers "first", "second", "third", and "fourth" merely serve as identifiers to distinguish the elements being limited and do not imply an order among the elements.

[0031] FIG. 1 generally shows one preferred embodiment of system 1 according to the present invention.

[0032] System 1 includes an insecure execution environment 2 and a secure element 3.

[0033] System 1 is designed to execute a secure function that maps an input message to an output message.

[0034] The insecure execution environment 2 includes processor type data processing means 20, data storage means 21, random access memory 22, a first communication interface 23, and a second communication interface 24.

[0035] The data storage means 21 and / or the random access memory 22 in the non-secure execution environment 2 are each linked to the data processing means 20 in this non-secure execution environment 2 so that the data processing means 20 can read and write data to and from the data storage means 21 and / or the random access memory 22.

[0036] The data storage means 21 stores computer program instructions, and a part of the computer program instructions is designed to perform the steps of a method for executing a secure function as described with reference to FIG. 2 when these instructions are executed by the data processing means 20.

[0037] The data storage means 21 is, for example, actually a rewritable hard drive or non-volatile memory such as an EEPROM type (instead of an "electrically erasable programmable read-only memory").

[0038] Furthermore, the data storage means 21 and the random access memory 22 may store at least a part of elements (in particular, encrypted processing data and result data as described later with reference to FIG. 2) that are operated during various processing operations executed in the process of the method described later.

[0039] In the remaining part of the specification, one of the data storage means 21 and the random access memory 22 is referred to as a memory.

[0040] The non-secure execution environment 2 further includes a plurality of components (not shown).

[0041] Typically, the non-secure execution environment 2 includes a first component and a second component.

[0042] These components may actually be formed by a combination of hardware elements and software elements.

[0043] Each component is configured to execute the steps of the method according to the present invention, and thus has the functions described in and later described in the method according to the present invention.

[0044] The first component includes all or part of the white box implementation form.

[0045] Therefore, system 1 includes a white box implementation form in the non-secure execution environment 2. System 1, typically, the non-secure execution environment 2 stores the white box implementation form.

[0046] According to the first exemplary embodiment of the component, the white box implementation form has a first part and a second part, and all or part of the white box implementation form of the first component is the first part of the white box implementation form, and the second component includes the second part of the white box implementation form.

[0047] According to the second exemplary embodiment of the component, the first component includes all or part of the white box implementation form, and the second component does not include all or part of the white box implementation form.

[0048] For each component, a hardware element (e.g., a memory) is used, and thus, to implement the function provided by the component, the non-secure execution environment 2 stores software instructions (also called computer program instructions) executable by, for example, the processing means 20.

[0049] According to one possible embodiment, the computer program instructions stored in the data storage means 21 are received during the operation phase of the non-secure execution environment 2 (e.g., from a remote computer via the second communication interface 24) before the method described with reference to FIG. 2.

[0050] Therefore, the data processing means 20 is configured to perform specific steps of the method for executing the secure function described below.

[0051] The data processing means 20 may have an arbitrary structure. The data processing means 20 includes one or more cores, and each core is configured to execute the code instructions of the program so as to perform the above-described steps.

[0052] Connect the first communication interface 23 to the data processing means 20 so that the non-secure execution environment 2 can communicate with the secure element 3 via another communication interface 33 of the secure element 3.

[0053] The first communication interface can be of any type. For example, the first communication interface is a wired interface using, for example, an OPC ("Open Platform Communication") type or any communication protocol compliant with the ISO / IEC 7816 standard in one of the already issued versions.

[0054] Via the first communication interface 23, the non-secure execution environment 2 can send data (for example, encrypted processing data as described with reference to FIG. 2) to the secure element 3 and / or receive data (for example, result data as described with reference to FIG. 2) from the secure element 3.

[0055] Connect the second communication interface 24 to the data processing means 20 so that the data processing means 20 can receive an input message from an electronic device (not shown) and / or send an output message to this electronic device (not shown).

[0056] The second communication interface 24 can be of any type. The second communication interface is, for example, a wired (Ethernet) interface or a wireless interface using any communication protocol (such as Wi-Fi, Bluetooth, NFC, etc.).

[0057] The secure element 3 includes another processor type data processing means 30, another data storage means 31, another random access memory 32, and other communication interfaces 33.

[0058] The other data storage means 31 and the other random access memory 32 of the secure element 3 are each linked to the other data processing means 30 of this secure element 3 so that the other data processing means 30 can read and write data to and from the other data storage means 31 and / or the other random access memory 32.

[0059] The other data storage means 31 stores computer program instructions, and some of the computer program instructions are designed to perform steps of a method for performing a secure function as described with reference to FIG. 2 when these instructions are executed by the other data processing means 30.

[0060] The other data storage means 31 is, for example, actually a rewritable non-volatile memory such as an EEPROM type (instead of an “electrically erasable programmable read-only memory”).

[0061] Furthermore, the other data storage means 31 and the other random access memory 32 may store at least a part of elements (in particular, encrypted processing data and result data as described later with reference to FIG. 2) that are operated during various processing operations executed in the process of the method described later.

[0062] In the remainder of the specification, one of the other data storage means 31 and the other random access memory 32 is referred to as another memory.

[0063] Using a hardware element (for example, another memory), and thus, to perform one or more steps of the method according to the present invention, and thus, one or more functions described in the method according to the present invention described later, the secure element 3 stores, for example, software instructions executable by the other processing means 30.

[0064] According to one possible embodiment, computer program instructions stored in other data storage means 31 are received during the operating phase of the secure element 3, before the method described with reference to FIG. 2, (for example, from another remote computer or from the non-secure execution environment 2 via another communication interface 33).

[0065] Accordingly, the other data processing means 30 is configured to perform specific steps of the method for executing the secure function described below.

[0066] The other data processing means 30 may have any structure. The other data processing means 30 includes one or more cores, and each core is configured to execute the code instructions of the program so as to perform the steps described above.

[0067] Connect another communication interface 33 to the other data processing means 30 so that the secure element 3 can communicate with the non-secure execution environment 2 via the first communication interface 23 of the non-secure execution environment 2.

[0068] The other communication interface 33 is of the same type as the first communication interface 23. For example, the other communication interface 33 is a wired interface using a communication protocol compliant with, for example, the OPC (\"Open Platform Communications\") type or the ISO / IEC 7816 standard in one of the already issued versions.

[0069] Via the other communication interface 33, the secure element 3 can transmit data (for example, result data as described with reference to FIG. 2) to the non-secure execution environment 2 and / or receive data (for example, encrypted data as described with reference to FIG. 2) from the non-secure execution environment 2.

[0070] According to the first example, the non-secure environment 2 is a communication terminal, a personal computer, a tablet or a server, and the secure element 3 is a chip incorporated in a chip card (e.g., an identity card, a bank card), or a universal integrated circuit card (also known as UICC) (e.g., a subscriber card for a cellular network, typically a SIM card).

[0071] According to the second example, the system 1 is a communication terminal, a personal computer, a tablet or a server, and the secure element 3 is a secure microcontroller or a trusted execution environment (also referred to by the acronym TEE) incorporated in these communication terminals, personal computers, tablets or servers.

[0072] FIG. 2 illustrates, in the form of a flowchart, the main steps of a method for executing a secure function according to the present invention.

[0073] This method is implemented by the system 1.

[0074] The secure function maps an input message to an output message.

[0075] The secure function may be an encryption function that maps an input message to an output message using a predetermined cryptographic key.

[0076] The encryption function includes, for example, an encryption function, a decryption function, a signature function or a signature verification function using a predetermined cryptographic key. Next, preferably, the predetermined cryptographic key is a key different from the cryptographic key and the decryption key described below.

[0077] In the step of calculating the processing data (step E100), the processing data is calculated based on the input message in a white box implementation form.

[0078] According to one possibility, the processing data may be the input message or the first part of the input message.

[0079] According to another possibility, the processing data may be the result of applying a first other function to the input message or the first part of the input message.

[0080] Next, the method may include a step of calculating at least one other processing data by a white-box implementation form (step E110).

[0081] According to a first possibility, the other processing data may be the input message or the second part of the input message.

[0082] According to a second possibility, the other processing data may be the result of applying a second other function to the input message, the second part of the input message, the processing data, or the first part of the processing data.

[0083] This step of calculating at least one other processing data is optional and may be omitted.

[0084] Next, the method includes an encryption step (step E200) in which the white-box implementation form encrypts the processing data using a cryptographic key.

[0085] Typically, the encryption follows an asymmetric cryptographic algorithm (e.g., RSA), or is based on an elliptic curve or a symmetric cryptographic algorithm (e.g., DES, 3DES, or AES).

[0086] When the encryption follows an asymmetric cryptographic algorithm, the cryptographic key is a public key in the sense of this asymmetric cryptographic algorithm.

[0087] Next, the method includes a step of sending the encrypted processing data to the secure element 3 of the system 1 (E300), and the encrypted processing data is the result of the encryption performed by the white-box implementation form during the encryption step (step E200).

[0088] Typically, the insecure execution environment 2 of the system 1 transmits the encrypted processing data to the secure element 3 via the first communication interface 23, and the secure element 3 receives the encrypted processing data via the other communication interface 33.

[0089] Next, the method includes an acquisition step (step E400) in which the secure element 3 acquires result data based on the decryption key related to the encrypted processing data and the encryption key, and the result data is an image of the processing data (i.e., non-encrypted processing data) by an intermediate function different from the identification function.

[0090] Typically, when the encryption in the encryption step (step E200) follows a symmetric encryption algorithm (e.g., DES, 3DES, or AES), the secure element 3 decrypts the encrypted processing data according to this symmetric encryption algorithm having this decryption key, and then applies an intermediate function to the result of the decryption to acquire result data based on the decryption key related to the encrypted processing data and the encryption key.

[0091] When the encryption in the encryption step (step E200) follows an asymmetric encryption algorithm (e.g., RSA) or is based on an elliptic curve, the secure element 3 may decrypt the encrypted processing data according to this asymmetric encryption algorithm having this decryption key, and then apply an intermediate function to the result of the decryption to acquire result data based on the decryption key related to the encrypted processing data and the encryption key. Next, the decryption key is a private key in the sense of this asymmetric encryption algorithm.

[0092] Preferably, the asymmetric encryption algorithm is a functional encryption algorithm.

[0093] In this case, the secure element 3 acquires result data through functional decryption of the encrypted processing data using a functional decryption key for the intermediate function, and the decryption key is this functional decryption key for the intermediate function.

[0094] Therefore, the method is safer. The intermediate function is hidden in the function decryption key, thereby increasing confidentiality.

[0095] Furthermore, the method can limit the computing time and memory space consumed by the secure element, and the decryption implementation applies the intermediate function to the processed data.

[0096] Some examples of functional encryption algorithms are described in the literature (Non-Patent Document 2).

[0097] Therefore, the algorithm in Section 3 of that literature called "Inner-Product from DDH" can obtain intermediate data having a value of the generator g raised to an exponent equal to the product of the processed data (x in the cited reference) and another predetermined data (y in the cited reference), and the generator g belongs to a group of order p (where p is a prime number). The result data may be the intermediate data, and then the intermediate function is a function of raising the generator g to an exponent equal to the product of the processed data (x in the cited reference) and another predetermined data (y in the cited reference). According to another possibility, for example, the result data may be obtained by the secure element 3 based on the intermediate data through the discrete logarithm of the intermediate data, and then the result data has a value of the result of the product of the processed data and other predetermined data, and the intermediate function is the product of the processed data and other predetermined data. It should be noted that the decryption key and the encryption key are sk y and mpk respectively in Section 3 of the cited reference.

[0098] Preferably, the functional encryption algorithm is the RSA algorithm having a decision encryption modulus N, and the intermediate function is modular exponentiation of raising the processed data to a decision exponent modulo the decision encryption modulus.

[0099] Therefore, the encryption key is the public key of the RSA algorithm, the functional decryption key is obtained based on the private key of this RSA algorithm, the private key is associated with the public key, the RSA algorithm has a deterministic encryption modulus, and the intermediate function is a modular exponentiation that raises the processing data to the power of a deterministic exponent with the deterministic encryption modulus as the modulus.

[0100] Therefore, the method enables a simple and resource - inexpensive implementation form of the intermediate function using functional decryption.

[0101] Typically, the encryption key includes an encryption exponent e, and the functional decryption key includes the modular inverse d of the encryption exponent e and a deterministic exponent a, or the result of the product of the encryption exponent and the deterministic exponent (i.e., a × d).

[0102] Therefore, during the encryption step (step E200), the white - box implementation form may encrypt the processing data as follows (u = x e mod N (where x is the processing data and u is the encrypted processing data)).

[0103] During the acquisition step (step E400), the secure element 3 may obtain the result data as follows (z = u a×d mod N (where z is the result data)).

[0104] Therefore, the result data z has the value x a mod N. In other words, the intermediate function is a modular exponentiation that raises the processing data x to the power of a deterministic exponent a with the deterministic encryption modulus N as the modulus.

[0105] The deterministic exponent a is an integer (e.g., 2).

[0106] Preferably, the intermediate function does not implement all or part of the encryption key.

[0107] Therefore, this gives more freedom in terms of selecting the secure function and the encryption key, expanding the encryption key, and managing related access operations.

[0108] Next, the method includes a step of calculating an output message (step E500) in which system 1 calculates the output message based on the result data.

[0109] According to one particular embodiment of the method, typically, when implementing the first and second components of system 1 according to the first exemplary embodiment of the components described with reference to FIG. 1, the white box implementation form has a first part and a second part, and calculates processing data based on the input message (step E100), and encrypts the processing data using the encryption key (step E200) are performed by the first part of the white box implementation form, and the step of calculating the output message based on the result data (step E500) is performed by the second part of the white box implementation form.

[0110] Next, the method typically includes a step (not shown) of transmitting the result data to the second part of the white box implementation form between the acquisition step (step E400) and the step of calculating the output message (step E500).

[0111] Typically, the secure element 3 of system 1 transmits the result data to the second part of the white box implementation form by transmitting the result data to the non-secure execution environment 2 of system 1 via another communication interface 33, and the non-secure execution environment and the second part of the white box implementation form receive the result data via the first communication interface 23.

[0112] According to another particular embodiment of the method, typically, when implementing the first and second components of system 1 according to the second exemplary embodiment of the components described with reference to FIG. 1, the step of calculating the output message based on the result data (step E500) is performed by all or part of the white box implementation form.

[0113] Next, the method may typically include a step (not shown) of transmitting the result data to the non-secure environment 2 between the acquisition step (step E400) and the step of calculating the output message (step E500).

[0114] Typically, the secure element 3 of the system 1 may transmit the result data to the non-secure environment 2 of the system 1 via another communication interface 33, and the non-secure execution environment 2 may receive the result data via the first communication interface 23.

[0115] Preferably, when the method follows other specific embodiments, the output message includes the result data. The output message may be the result data.

[0116] In particular, the method according to the above-described specific embodiments or other specific embodiments can limit the calculation time and memory space consumed by the white box implementation form.

[0117] Calculate the output message based on the result data.

[0118] The acquisition step (step E400) performed by the secure element 3 contributes to the calculation of the secure function by acquiring the result data based on the processed data.

[0119] The system 1 (in particular, the second part of the white box implementation form) does not need to verify that the result data corresponds to the result of applying the intermediate function to the processed data. If the result data does not correspond to the result of applying the intermediate function to the processed data, the acquired output message is incorrect. In fact, the output message is not an image of the input message by the secure function.

[0120] Therefore, select the calculation in the step of calculating the processed data (step E100), the intermediate function, and the calculation in the step of calculating the output message (step E500) so as to implement the secure function.

[0121] The method is even more particularly secure.

[0122] An attacker observing the data exchange between the white box implementation form (and / or non-secure environment 2) and the secure element 3 cannot access the processed data and cannot deduce the intermediate function from the processed data because the processed data is encrypted.

[0123] Within system 1, preferably, the encryption key is only incorporated into the white box implementation form and is not stored in the memory of system 1 itself.

[0124] When the method follows the above-described specific embodiment, preferably, the encryption key is only incorporated into the first part of the white box implementation form and is not stored in the memory of system 1 itself.

[0125] Within system 1, preferably, the decryption key is only stored in the secure element 3 and is not incorporated into the white box implementation form.

[0126] More preferably, the encryption key is only included in the step where the white box implementation form encrypts the processed data (step E200), and the decryption key is only included in the step where the secure element obtains the result data (step E400).

[0127] Therefore, the method is more secure.

[0128] As described above, system 1 (particularly, the second part of the white box implementation form) does not need to verify that the result data corresponds to the result of applying the intermediate function to the processed data. If the result data does not correspond to the result of applying the intermediate function to the processed data, the output message obtained is incorrect. In fact, the output message is not an image of the input message by the secure function.

[0129] Preferably, calculating the output message based on the result data during the step of calculating the output message (step E500) is different from applying the inverse function of the intermediate function to the result data.

[0130] Furthermore, when the method is in accordance with the specific embodiments described above, the step of calculating the output message based on the result data (step E500) is different from the identification function.

[0131] Therefore, the method is more secure.

[0132] When the method is in accordance with the specific embodiments described above and the method includes a step of calculating at least one other processing data (step E110), this step of calculating at least one other processing data (step E110) is implemented by the first part of the white box implementation form. Advantageously, the second part of the white box implementation form uses at least one other processing data and calculates the output message based on the result data (step E500).

[0133] More advantageously, when the method is in accordance with other specific embodiments described above and the method includes a step of calculating at least one other processing data (step E110), the output message further includes other processing data.

[0134] Therefore, the method is more secure.

[0135] The step of calculating at least one other processing data (step E110) contributes to the calculation of the secure function by obtaining other processing data. Select at least one other calculation of other processing data and, if necessary, a second other function to implement the secure function.

[0136] It should be noted that in the method of executing the secure function according to the present invention and / or in the system 1 according to the present invention, the secure function can be composed of a series of operations, and the intermediate function is a part of these series of operations.

[0137] Typically, a secure function is composed of a series of operations performed on input data.

[0138] The operations may be arithmetic operations or Boolean arithmetic operations (e.g., addition, subtraction, multiplication, division, exponentiation, or logarithm).

[0139] Furthermore, the operations may be logical operations (e.g., logical OR, logical AND, or negation).

[0140] The input data may include all or part of the input message and / or all or part of at least one intermediate data.

[0141] The intermediate data is the result of applying at least one operation from these series of operations to at least one input data.

[0142] Next, the step of calculating the processed data based on the input data by the white box implementation form (step E100) is to apply the first part of the series of operations that constitute the secure function.

[0143] Therefore, the processed data is the intermediate data.

[0144] The first part of the series of operations that constitute the secure function includes at least one operation from these series of operations that constitute the secure function.

[0145] Typically, applying the first other function to the input message or the first part of the input message consists of the first part of the series of operations that constitute the secure function.

[0146] Next, the acquisition step (step E400) performed by the secure element executes the second part of the series of operations that constitute the secure function, and this second part of the series of operations that constitute the secure function constitutes an intermediate function applied to the processed data.

[0147] The second part of the series of operations that make up the secure function includes at least one operation from these series of operations that make up the secure function.

[0148] The second part of the series of operations that make up the secure function is typically separated from the first part of the series of operations described above.

[0149] The processed data is the input data for the intermediate function.

[0150] The result data is the result of performing this second part of the series of operations that make up the secure function. Therefore, the result data is intermediate data.

[0151] When the method is in accordance with the specific embodiments described above, the result data is used as the input data for at least one operation of the third part of the series of operations that make up the secure function.

[0152] This at least one operation of the third part of the series of operations is performed by the second part of the white box implementation form in the step of calculating the output message based on the result data (step E500).

[0153] The third part of the series of operations that make up the secure function is typically separated from the first part of these series of operations and the second part of these series of operations described above.

[0154] When the method is in accordance with other specific embodiments described above, the result data may be used as the input data for at least one operation of the third part of the series of operations that make up the secure function. This at least one operation of the third part of the series of operations is typically performed by the second module of system 1 in the step of calculating the output message based on the result data (step E500).

[0155] Note that the step in which the white box implementation form calculates at least one other processing data (step E110) can be to perform the fourth part of a series of operations constituting the security function.

[0156] Typically, applying a second other function to the input message, the second part of the input message, the processing data, or the first part of the processing data consists of this fourth part of a series of operations constituting the security function.

[0157] The fourth part of a series of operations constituting the security function includes at least one operation from these series of operations constituting the security function.

[0158] The fourth part of a series of operations constituting the security function is typically separated from the first part, the second part, and the third part of these series of operations described above.

[0159] FIG. 3 shows an example of a security function executed by the method or system according to the present invention.

[0160] The security function illustrated in this drawing maps the input message I to the output message O and executes the symmetric encryption algorithm E having a predetermined encryption key K k which can be protected against failures by using countermeasures.

[0161] The security function includes obtaining a first intermediate result through a first execution of the encryption E k applied to the input message I, and obtaining a second intermediate result through a first execution of the diffusion function D R applied to the first intermediate result.

[0162] Furthermore, the security function includes obtaining a third intermediate result through a second execution of the encryption E k applied to the input message I, and obtaining a fourth intermediate result through a second execution of the diffusion function D Rincluding obtaining a fourth intermediate result through a second execution of

[0163] Next, the security function obtains output message O through an "exclusive OR" combination between the second intermediate result, the fourth intermediate result, and another intermediate result from among the first intermediate result and the third intermediate result.

[0164] Diffusion function D R is typically a hash function parameterized with value R.

[0165] The security function illustrated in FIG. 3 is described in the literature (Non-Patent Document 3).

[0166] One example of the method according to the present invention for executing this security function is two executions of encryption E k and one execution of diffusion function D R One execution of which is typically implemented in a white-box implementation form during the step of calculating processing data (step E100) and the step of calculating at least one other processing data (step E110).

[0167] The other processing data includes the first intermediate result or the third intermediate result.

[0168] When the white-box implementation form performs the first execution of diffusion function D R the processing data includes the third intermediate result and value R, the other processing data further includes the second intermediate result, the intermediate function is the diffusion function, and the result data is the fourth intermediate result.

[0169] When the white-box implementation form performs the second execution of diffusion function D R the processing data includes the first intermediate result and value R, the other processing data further includes the fourth intermediate result, the intermediate function is the diffusion function, and the result data is the second intermediate result.

[0170] Next, the step of calculating the output message based on the result data (step E500) is performed by the second part of the white box implementation form, and the output message is obtained through the "exclusive OR" combination of the second intermediate result, the fourth intermediate result, and another intermediate result from among the first intermediate result and the third intermediate result, and the other intermediate results are the first intermediate result or the third intermediate result included in other processing data.

[0171] According to one variant of this example, the other processing data is the second intermediate result when the white box implementation form performs the first execution of the diffusion function D R or the fourth intermediate result when the white box implementation form performs the second execution of the diffusion function D R and has the value of the "exclusive OR" combination of the intermediate results from among the first intermediate result or the third intermediate result, and the step of calculating the output message based on the result data (step E500) obtains the output message through the "exclusive OR" combination between the result data and the other processing data.

[0172] Those skilled in the art will understand that the above-described embodiments, variants, and various features can be combined with each other in various combinations on the condition that they are compatible or do not conflict with each other.

Explanation of Reference Numerals

[0173] 1 System 2 Non-secure Execution Environment 3 Secure Element 20 Data Processing Means 21 Data Storage Means 22 Random Access Memory 23 First Communication Interface 24 Second Communication Interface 30 Other Data Processing Means 31 Other Data Storage Means 32 Other Random Access Memory 33 Other Communication Interface

Claims

1. A method for performing a secure function of mapping an input message to an output message, said method being carried out by a system (1) including a secure element (3) and a white-box implementation in a non-secure execution environment (2), - said white-box implementation calculating (E100) processing data based on said input messages; - the white-box implementation encrypts (E200) the processing data using an encryption key; - a step (E300) of transmitting said cryptographically processed data to said secure element, - a step (E400) of said secure element obtaining result data based on said encrypted processed data and on a decryption key related to said encryption key, said result data being an image of said processed data by an intermediate function different from an identification function; - a step (E500) of calculating said output message on the basis of said result data; A method comprising:

2. The method of claim 1 , wherein the output message includes the result data.

3. The method further comprises a step (E110) of the white-box implementation calculating at least one other processing data, the output message further comprises the further processed data, A method for performing a secure function according to claim 1 or 2.

4. - the white-box implementation has a first part and a second part, - the step (E100) of calculating processed data based on the input message and the step (E200) of encrypting the processed data using an encryption key are performed by the first part of the white-box implementation, - the step (E500) of calculating the output message based on the result data is performed by the second part of the white-box implementation, The method further includes transmitting the result data to the second part of the white-box implementation. A method for performing a secure function according to claim 1.

5. - said first part of said white-box implementation calculating (E110) at least one other processing data; - the second part of the white-box implementation uses the at least one other processing data and calculates the output message based on the result data; The method of claim 4 further comprising:

6. 3. A method for performing a secure function according to claim 1 or 2, wherein the secure element (3) obtains (E400) the result data via functional decryption of the encrypted process data using a functional decryption key for the intermediate function, the decryption key being the functional decryption key for the intermediate function.

7. 7. A method of performing a secure function as claimed in claim 6, wherein the encryption key is a public key of an RSA algorithm, the functional decryption key is derived based on a private key of the RSA algorithm, the private key being associated with the public key, the RSA algorithm having a determined encryption modulus, and the intermediate function is a modular exponentiation in which the processed data is raised to a determined exponent modulo the determined encryption modulus.

8. 8. The method of claim 7, wherein the encryption key comprises an encryption exponent and the functional decryption key comprises a modular inverse of the encryption exponent and the determination exponent or a result of a product of the encryption exponent and the determination exponent.

9. - the encryption key is included only in the step (E200) in which the white-box implementation encrypts the processing data, said decryption key is included only in said step (E400) in which said secure element obtains the result data, A method for performing a secure function according to claim 1 or 2.

10. 3. A method for performing a secure function according to claim 1, wherein the secure function is composed of a sequence of operations, and the intermediate function is part of the sequence of operations.

11. 3. A method of performing a secure function as claimed in claim 1 or 2, wherein the secure function is a cryptographic function that maps the input message to the output message using a predefined cryptographic key.

12. 12. The method of claim 11, wherein the predetermined encryption key is a different key than the encryption key and the decryption key.

13. A system (1) for performing a secure function for mapping an input message to an output message, comprising: a first component comprising all or part of a white-box implementation in a non-secure execution environment (2), the all or part of the white-box implementation being configured to calculate processing data based on the input message and to encrypt the processing data using a cryptographic key; a secure element (3) configured to receive said encrypted processed data and to obtain result data based on said encrypted processed data and on a decryption key associated with said encryption key, said result data being an image of said processed data with an intermediate function different from an identification function; a second component configured to receive said result data and to calculate said output message based on said result data; A system (1) comprising:

14. The system (1) for performing a secure function according to claim 13, wherein the output message includes the result data.

15. - the white-box implementation has a first part and a second part, the whole or part of the white-box implementation of the first component is the first part of the white-box implementation, the second component comprises a second part of the white-box implementation in the non-secure execution environment (2), the second part of the white-box implementation being configured to receive the result data and to calculate the output message based on the result data; A system (1) for performing a secure function according to claim 13.

Citation Information

Patent Citations

  • Using secure key storage to bind a white-box implementation to one platform

    US20190312718A1