White-Box Cryptographic System Key Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management systems are vulnerable to attacks due to the difficulty in protecting cryptographic keys, especially in software implementations where attackers can observe and manipulate cryptographic operations, leading to potential key extraction and unauthorized access.

Innovation Solution

A cryptographic system is developed with a white-box implementation of a function and a cryptographic algorithm, combined using a specific operation to enhance security, making it difficult for attackers to predict or extract the key, even with partial control over the environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional cryptographic algorithm is implemented in software, then the cryptographic processing can be performed efficiently, but the cryptographic key becomes vulnerable to extraction by attackers who can observe and manipulate the execution environment

Engineering Contradiction:
Improvekey securityVSAvoidattacker observation and manipulation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent combines the cryptographic algorithm with a white-box implementation technique, merging the key storage and algorithm execution into a single integrated structure. The key is embedded within the algorithm implementation itself, such that the key and algorithm become indistinguishable from each other, preventing attackers from separating and extracting the key through observation or manipulation of the execution environment.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary layer between the key and the execution environment. This intermediary is the white-box implementation structure that obscures the relationship between the key and the algorithm steps, creating a protective barrier that prevents direct observation or manipulation of the key by attackers in the execution environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the cryptographic algorithm is made more complex to protect the key, then key security improves, but the computational efficiency and ease of operation deteriorate

Engineering Contradiction:
Improvekey securityVSAvoidcomputational efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the key and algorithm into a single integrated structure, eliminating the need for separate key management operations. This integration simplifies the overall system operation while maintaining security, as the key is automatically protected within the algorithm implementation without requiring additional protective measures that would increase complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The white-box implementation structure provides self-service key protection, where the algorithm itself automatically protects the key through its integrated design. The key is inherently protected by the structure of the algorithm implementation, eliminating the need for external key protection mechanisms and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9710623B2Cryptographic system
Publication Date: 2017.07.18 IRDETO BV
  • US9710623B2 patent drawing
  • US9710623B2 patent drawing
  • US9710623B2 patent drawing

AI summary

A cryptographic system comprises a white-box implementation of a function; an implementation of a cryptographic algorithm; and an implementation of a combining operation for establishing cryptographically processed data in dependence on an outcome of the function and in dependence on an outcome of the cryptographic algorithm. The combining operation comprises combining an outcome of the cryptographic algorithm with an outcome of the function. Alternatively, the combining operation comprises combining an outcome of the function with a received data element to obtain a combination outcome and applying the cryptographic algorithm to the combination outcome.