White-Box Cryptography Use-Dependent Security Settings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a white-box cryptography context, where an attacker has complete control over the system, existing methods struggle to enforce different security settings for various applications and users using the same cryptographic key, as they lack the ability to differentiate and manage distinct security requirements effectively.
Innovation Solution
A non-transitory machine-readable storage medium encoded with instructions for a white-box system to enforce use-dependent security settings by utilizing a network of lookup tables and finite state machines, where each security setting has a unique set of input messages, and a system identifier is combined with output messages to ensure correct or incorrect outputs based on authorization, allowing the same key to be used for different applications and users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single white-box implementation uses the same cryptographic key for multiple applications and users, then key management flexibility is improved, but the ability to enforce different security settings for different applications and users deteriorates
Solution Approach 1:
The patent segments the message space into multiple disjoint subsets, where each subset corresponds to a specific security setting. The white-box implementation is modified to identify which subset an input message belongs to and apply the appropriate security processing. This segmentation allows a single implementation to handle multiple security requirements simultaneously while maintaining proper differentiation between them.
Solution Approach 2:
The patent applies local quality by making the security processing behavior dependent on the local characteristics of the input message (specifically, which message subset it belongs to). Different portions of the message space receive different security treatments based on their classification, enabling the system to enforce appropriate security settings for different applications and users while using the same cryptographic key.
2Device complexity
If the white-box system processes all input messages with the same security processing, then implementation simplicity is improved, but the precision of security control for different applications deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-classifying the message space into distinct subsets before processing. Each subset is predetermined to correspond to specific security settings. When an input message arrives, the system quickly identifies which pre-defined subset it belongs to and applies the corresponding security processing. This preliminary organization enables precise security control without requiring complex real-time analysis during message processing.
3Reliability
If the system uses multiple cryptographic keys for different applications and users, then security setting differentiation is improved, but key management complexity deteriorates
Solution Approach 1:
The patent implements universality by designing a single white-box cryptographic implementation that can handle multiple security settings using one cryptographic key. The system achieves multi-functionality by combining message subset identification with unified cryptographic processing, allowing the same key to serve multiple applications and users with different security requirements. This eliminates the need for separate key management infrastructure while maintaining proper security differentiation.
Data Source
AI summary
A method of enforcing security settings in a cryptographic system, including: receiving, by the cryptographic system, a first input message associated with a first security setting of a plurality of security settings; performing, by the cryptographic system, a keyed cryptographic operation mapping the first input message into a first output message, wherein the keyed cryptographic operation produces a correct output message when the cryptographic system is authorized for the first security setting, wherein each of the plurality of security settings has an associated set of input messages wherein the sets of input messages do not overlap.


