White-Box Cryptography Use-Dependent Security Settings

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a white-box cryptography context, where an attacker has complete control over the system, existing methods struggle to enforce different security settings for various applications and users using the same cryptographic key, as they lack the ability to differentiate and manage distinct security requirements effectively.

Innovation Solution

A non-transitory machine-readable storage medium encoded with instructions for a white-box system to enforce use-dependent security settings by utilizing a network of lookup tables and finite state machines, where each security setting has a unique set of input messages, and a system identifier is combined with output messages to ensure correct or incorrect outputs based on authorization, allowing the same key to be used for different applications and users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single white-box implementation uses the same cryptographic key for multiple applications and users, then key management flexibility is improved, but the ability to enforce different security settings for different applications and users deteriorates

Engineering Contradiction:
Improvekey management flexibilityVSAvoidsecurity setting differentiation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the message space into multiple disjoint subsets, where each subset corresponds to a specific security setting. The white-box implementation is modified to identify which subset an input message belongs to and apply the appropriate security processing. This segmentation allows a single implementation to handle multiple security requirements simultaneously while maintaining proper differentiation between them.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making the security processing behavior dependent on the local characteristics of the input message (specifically, which message subset it belongs to). Different portions of the message space receive different security treatments based on their classification, enabling the system to enforce appropriate security settings for different applications and users while using the same cryptographic key.

Inventive Principle:
Principle #3Local quality

2Device complexity

If the white-box system processes all input messages with the same security processing, then implementation simplicity is improved, but the precision of security control for different applications deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity control precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by pre-classifying the message space into distinct subsets before processing. Each subset is predetermined to correspond to specific security settings. When an input message arrives, the system quickly identifies which pre-defined subset it belongs to and applies the corresponding security processing. This preliminary organization enables precise security control without requiring complex real-time analysis during message processing.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the system uses multiple cryptographic keys for different applications and users, then security setting differentiation is improved, but key management complexity deteriorates

Engineering Contradiction:
Improvesecurity setting differentiationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by designing a single white-box cryptographic implementation that can handle multiple security settings using one cryptographic key. The system achieves multi-functionality by combining message subset identification with unified cryptographic processing, allowing the same key to serve multiple applications and users with different security requirements. This eliminates the need for separate key management infrastructure while maintaining proper security differentiation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9380033B2Implementing use-dependent security settings in a single white-box implementation
Publication Date: 2016.06.28 NXP BV
  • US9380033B2 patent drawing
  • US9380033B2 patent drawing
  • US9380033B2 patent drawing

AI summary

A method of enforcing security settings in a cryptographic system, including: receiving, by the cryptographic system, a first input message associated with a first security setting of a plurality of security settings; performing, by the cryptographic system, a keyed cryptographic operation mapping the first input message into a first output message, wherein the keyed cryptographic operation produces a correct output message when the cryptographic system is authorized for the first security setting, wherein each of the plurality of security settings has an associated set of input messages wherein the sets of input messages do not overlap.