White-Box Encryption Device Using TEE Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing white-box encryption methods face security vulnerabilities when external encoding is not used, leading to diminished security and the possibility of practical attacks, and methods that attempt to enhance security through repeated functional processing lack qualitative evaluation of security, especially in the white-box model.

Innovation Solution

An encryption device and method that implement a white-box model by tabulating part or all of the round functions, using a secure block cipher from a black-box model, where input and output values are recognizable but intermediate values are not, ensuring confidentiality of the secret key and enhancing data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external encoding is added to enhance security in white-box model, then security is improved, but the encryption function becomes different from the original encryption function and applications are limited

Engineering Contradiction:
ImprovesecurityVSAvoidapplication compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary between the white-box encryption components and the external environment. The TEE provides a secure domain that enables external encoding operations while isolating the core encryption logic, thus maintaining both security enhancements and application compatibility. The TEE acts as a mediator that allows encoded plaintext to be processed securely without requiring the entire system to operate in a restricted white-box mode.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If external encoding is not used in white-box model, then application flexibility is improved, but security is greatly diminished and practical attacks become feasible

Engineering Contradiction:
Improveapplication flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the encryption system into multiple components: a secure core that implements the original encryption function without external encoding, and external encoding layers that can be selectively applied. This segmentation allows different parts of the system to operate with different security requirements, maintaining overall security while preserving application flexibility. The round functions are divided into those that require security (using TEE protection) and those that can operate in standard mode.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite encryption architecture that combines multiple approaches: traditional encryption functions, white-box techniques, and TEE-protected external encoding. This composite structure allows the system to leverage the strengths of each approach while mitigating their individual weaknesses, achieving both security and flexibility that neither approach could provide alone.

Inventive Principle:
Principle #40Composite materials

3Reliability

If repeated functional processing is used to enhance security in white-box model, then security may be improved, but the method lacks qualitative evaluation and the complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs disposable, easily replaceable encryption round functions that can be rapidly generated and discarded. Instead of relying on complex, hard-to-evaluate repeated processing, the system uses multiple instances of simpler, well-understood encryption functions. These can be independently analyzed and replaced if security concerns arise, reducing the overall system complexity while maintaining security through quantity and diversity rather than individual complexity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS10277391B2Encryption device, encryption method, decryption device, and decryption method
Publication Date: 2019.04.30 DANMARKS TEKNISKE UNIV
  • US10277391B2 patent drawing
  • US10277391B2 patent drawing
  • US10277391B2 patent drawing

AI summary

There is provided an encryption device including a data encryption unit configured to conduct encryption on the basis of a white box model in which at least a part of a plurality of round functions for sequentially conducting encryption processing on an input value is tabulated, and input and output values of the round function are recognizable from an outside. The plurality of round functions each have an encryption function that is tabulated and encrypts an input value in a black box model in which input and output values are recognizable from the outside and an intermediate value is not recognizable from the outside.