IP Library Patent Application 12514922
Patent Application
App. No. 12/514,922

CRYPTOGRAPHIC METHOD FOR A WHITE-BOX IMPLEMENTATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/514,922
Abstract

A cryptographic method is implemented in a white-box implementation thereof. The method comprises applying a plurality of transformations ( 802 ) each replacing an input word by an output word, and applying a diffusion operator ( 804 ) to a concatenation of a plurality of the output words for diffusing information represented by the output words among the output words. A key ( 806 ) to the cryptographic method comprises information representing the diffusion operator. The diffusion operator satisfies a property that a change of one bit in an input to the diffusion operator corresponds to a change of more than one bit in an output of the diffusion operator.

Claims (20)

1 . A cryptographic method for being implemented in a white-box implementation thereof, the method comprising

applying a plurality of transformations ( 802 ) each replacing an input word by an output word; and

applying a diffusion operator ( 804 ) to a concatenation of a plurality of the output words for diffusing information represented by the output words among the output words;

wherein a key ( 806 ) to the cryptographic method comprises information representing the diffusion operator.

2 . The method according to claim 1 , wherein the diffusion operator satisfies a property that a change of one bit in an input to the diffusion operator corresponds to a change of more than one bit in an output of the diffusion operator.

3 . The method according to claim 1 , wherein the diffusion operator is a nonlinear operator.

4 . The method according to claim 1 , wherein

an input of the diffusion operator is given by a sequence of k outputs of S-boxes, the output of each S-box being an n-bit value, where k and n are predetermined positive integer values,

an output of the diffusion operator represents a sequence of l inputs to non-linear output encodings of the white-box implementation, the input to each output encoding being an m-bit value, where l and m are predetermined positive integer values, and

the diffusion operator is a linear operator having a representation as an invertible matrix dividable into l rows of k submatrices of m×n elements, each row satisfying a property that a matrix formed by a concatenation of a first subset of the submatrices forming that row and a matrix formed by a concatenation of a second subset of the submatrices forming that row, the first subset and the second subset being disjunct, do not both have a rank of m.

5 . The method according to claim 1 , wherein the key comprises a representation of the invertible matrix.

6 . The method according to claim 1 , wherein the cryptographic method comprises a Rijndael method in which a MixColumns operator is replaced by the diffusion operator.

7 . A system comprising

an input for receiving a key, the key comprising information representing a diffusion operator; and

a white-box implementation of a cryptographic method, the cryptographic method comprising applying a plurality of transformations each replacing an input word by an output word; and applying the diffusion operator to a concatenation of a plurality of the output words for diffusing information represented by the output words among the output words.

8 . The system according to claim 7 , wherein the key comprises one or more look-up tables representing the diffusion operator obfuscated with input and output encodings.

9 . A client-server system comprising

a client comprising an input for receiving a key, the key comprising information representing a diffusion operator; the client further comprising a white-box implementation of a cryptographic method, the cryptographic method comprising applying a plurality of transformations each replacing an input word by an output word, and applying the diffusion operator represented by the information in the key to a concatenation of a plurality of the output words for diffusing information represented by the output words among the output words;

a server for applying a cryptographic method corresponding to the cryptographic method implemented in the client, in dependence on the key; and

means for generating the key.

Assignments (4)
MERGER Recorded Dec 16, 2014
From: IRDETO CORPORATE B.V.
To: IRDETO B.V.
Reel/Frame 034512/0718 →
CHANGE OF NAME Recorded Sep 4, 2013
From: IRDETO B.V.
To: IRDETO CORPORATE B.V.
Reel/Frame 031156/0553 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2010
From: KONINKLIJKE PHILIPS ELECTRONICS N. V.
To: IRDETO B.V.
Reel/Frame 023985/0760 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2009
From: MICHIELS, WILHELMUS PETRUS ADRIANUS JOHANNUS; GORISSEN, PAULUS MATHIAS HUBERTUS MECHTILDIS ANTONIUS
To: KONINKLIJKE PHILIPS ELECTRONICS N V
Reel/Frame 022685/0333 →