Whitebox Encryption Device Using Trapdoor One-Way Function
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing whitebox model encryption methods are insecure as attackers can easily construct a decryption function from an encryption function, making it difficult to ensure security by suppressing reverse direction calculations.
Innovation Solution
An encryption device and method utilizing a whitebox encoding function configured with a trapdoor one-way function and a conversion function having a special property, which prevents the creation of a decryption function from the encryption function, ensuring whitebox one-wayness by performing operations with a trapdoor one-way function using a public key and a conversion function that determines all input and output values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If table reference operations are used for whitebox encryption, then encryption can be performed in a whitebox model, but reverse direction calculation becomes easy allowing attackers to construct decryption functions
Solution Approach 1:
The patent inverts the traditional approach by making the encryption function appear simple and reversible while embedding the actual security mechanism in the inverse direction. The encoding function uses a trapdoor one-way function that appears reversible but actually prevents decryption without specific secret information, turning the attacker's advantage of easy reverse calculation into a security feature.
Solution Approach 2:
The patent introduces an encoding function as an intermediary layer between the plaintext and the actual encryption process. This encoding function uses trapdoor one-way functions and conversion functions with special properties to transform the data in a way that prevents direct reversal, while still allowing legitimate decryption through the proper decoding function that possesses the trapdoor information.
2Productivity
If existing block cipher conversion methods are used, then encryption can be performed, but it is difficult to suppress reverse direction calculation
Solution Approach 1:
The patent applies asymmetry by using trapdoor one-way functions that have fundamentally different computational properties in forward and reverse directions. The encoding function is easy to compute forward but extremely difficult to reverse without the trapdoor, creating an asymmetric security profile that prevents attackers from using reverse calculation techniques that work on symmetric operations.
Solution Approach 2:
The patent changes the computational parameters of the encryption function by incorporating trapdoor one-way functions and conversion functions with special properties. These parameter changes ensure that the function behaves differently under forward and reverse operations, making reverse calculation infeasible while maintaining efficient forward encryption through the structured conversion process.
3Reliability
If trapdoor one-way function is used to prevent reverse calculation, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments the encryption process into distinct functional components: the trapdoor one-way function for security, conversion functions with special properties for data transformation, and the overall encoding/decoding structure. This segmentation allows each component to be optimized independently and managed separately, reducing the perceived complexity while maintaining the security benefits of trapdoor functions.
Data Source
Figure 1~3
Figure 4~5
Figure 6~7
AI summary
[Object] To suppress calculation in the reverse direction in whitebox model encryption. [Solution] An encryption device according to the present disclosure includes: having a predetermined relationship that outputs a plurality of output values according to a plurality of input values configured of plain text, with a part of the plurality of output values being inputted to a trapdoor one-way function, the predetermined relationship being defined by the output values that are not inputted to the trapdoor one-way function and one arbitrary input value of the plurality of input values; and having a property of encrypting a part of the plurality of output values according to the trapdoor one-way function, and the trapdoor one-way function not being able to decrypt encrypted data in a state in which a trapdoor is unknown.