White-box Cryptographic Key Protection via Random Bijections

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management systems face challenges in securing cryptographic keys, as they can be compromised through reverse engineering or observation of memory access, especially in open CE platforms where users have control over hardware and software.

Innovation Solution

A method is presented to compute the outcome of an exponentiation without exposing the base or exponent, by establishing and providing specific values ωi and φi to a device, making it difficult for attackers to derive the cryptographic key, even if they can inspect or debug the entity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are stored in memory for decryption operations, then decryption functionality is enabled, but attackers can retrieve keys through memory observation

Engineering Contradiction:
Improvedecryption functionalityVSAvoidkey compromise through memory observation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces random bijections as intermediary transformations between the cryptographic key and the data structures used in decryption operations. These bijections act as mediators that allow decryption to proceed while preventing direct observation of the key in memory, as the key is never stored in its original form but rather transformed through multiple layers of random permutations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies parameter changes by transforming the cryptographic key through random bijections that change the representation of key data at each processing stage. The key material is continuously transformed through different random permutations and compositions, ensuring that the same logical key value is represented by different parameter configurations in memory, thereby preventing key recovery through static analysis.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If white-box implementation is used to hide cryptographic keys, then key security is improved, but the system complexity increases

Engineering Contradiction:
Improvekey exposure to attackersVSAvoidimplementation complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic key into multiple components that are processed through separate random bijections. Instead of applying a single complex transformation, the key material is divided and transformed through multiple simpler random permutation stages, making the overall system more manageable while maintaining security. Each segment is protected by its own random bijection layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-computing and storing random bijections and their compositions before actual decryption operations. These random transformations are prepared in advance and integrated into the decryption algorithm structure, so that during runtime, the system only needs to execute predetermined transformation sequences rather than generating complex security measures on the fly.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If random bijections are used to encode cryptographic tables, then key derivation difficulty increases, but computational overhead increases

Engineering Contradiction:
Improvedifficulty for attackers to derive keyVSAvoidcomputational overhead
Core Design Contradiction:
Object-affected harmful factorsVSPower

Solution Approach 1:

The patent applies partial action by using random bijections only where absolutely necessary for security-critical operations, rather than transforming all data uniformly. The random permutations are applied selectively to key-related data structures while leaving other non-critical data unchanged, thereby reducing overall computational overhead while maintaining security for the essential cryptographic operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8670559B2White-box implementation
Publication Date: 2014.03.11 IRDETO BV
  • US8670559B2 patent drawing
  • US8670559B2 patent drawing
  • US8670559B2 patent drawing

AI summary

A system for enabling a device to compute an outcome of an exponentiation Cx having a base C and/or an exponent x, the system comprising means for establishing a plurality of values λi; means for establishing a plurality of values ωi satisfying ωi=Cλ<sub2>i</sub2>; means for establishing a plurality of values φi satisfying that the sum of the values λiφi equals x; and an output for providing the device with the plurality of values φi. A device computes an outcome of the exponentiation Cx. The device comprises means for computing a product of the values ωi to the power of φi. The device is arranged for using the product as a result of the exponentiation Cx.