The invention belongs to the technical field of data
encryption, and relates to a symmetric
white box encryption method based on a substitution-permutation
network structure. The method comprises the following steps: step 1, generating a
white box assembly; step 2,
encryption; and step 3, decryption. The above steps use eight algorithms, including a pre-
processing matrix generation
algorithm, a front external coding matrix generation
algorithm, a post-
processing matrix generation
algorithm, a rear external coding matrix generation algorithm, a T table generation algorithm, an M matrix generation algorithm, an encryption algorithm and a decryption algorithm. According to the method, substitution and key XOR operation are converted into a pre-calculated
lookup table, random secret components are introduced into the
lookup table, a
permutation matrix is expanded, and the structure of an encryption internal state is changed, so that an attacker is difficult to recover a key or decrypt data through a white-box
attack means. Compared with an existing white-box AES scheme, the method has the advantages that compatibility with a standard decryption algorithm is kept, all existing white-box attacks can be resisted, and white-box safety is achieved.