IP Library Granted Patent US 8,625,794
Granted Patent B2
US 8,625,794 · App. 13/378,891 · Granted Jan 7, 2014

White-box cryptographic system with configurable key using intermediate data modification

Inventor: Wilhelmus Petrus Adrianus Johannus Michiels (Hoofddorp, NL)
Assignee: Irdeto Corporate B.V.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,625,794
App. No.
13/378,891
Granted
Jan 7, 2014
Kind
B2
Abstract

A white-box cryptographic system ( 600 ) is presented for performing a key-dependent cryptographic operation, such as AES. The system comprises a network of a plurality of look-up tables ( 640 ) arranged for collectively performing the cryptographic operation, the network being adapted for a particular cryptographic key. By sending a key substitute ( 664 ) which represents to the network a further cryptographic key a key translation unit can arrange the effect of the network on the cryptographic operation such that is adapted for a further cryptographic key. In this way the system can be updated to use the further key instead of the particular key.

Claims (37)

1. A white-box cryptographic system for performing a keyed cryptographic operation mapping an input-message to an output-message, the system comprising:

a network of a plurality of look-up tables arranged for collectively performing the cryptographic operation, the network being adapted for a particular cryptographic key,

wherein,

the system is configured to:

receive a key substitute which represents to the network a further cryptographic key, and

parse the key substitute into a plurality of second key substitutes,

the system comprises at least one key translation unit configured for receiving a first input depending on an intermediate cryptographic result in the network and a second input depending on one of the second key substitutes,

the system is arranged for mapping the input-message to the output-message via the network and the key translation unit to arrange the effect of the network on the cryptographic operation to being adapted for the further cryptographic key.

2. A white-box cryptographic system as in claim 1 , wherein at least one specific look-up table of the plurality of look-up tables is adapted for the particular cryptographic key, the system is arranged for mapping the input-message to the output-message via at least the specific look-up table and the key translation unit to arrange the effect of the specific look-up table on the cryptographic operation to being adapted for the further cryptographic key.

3. A white-box cryptographic system as in claim 2 , wherein the first input depends on the input message by means of one or more of the plurality of look-up tables and wherein the system is arranged for the specific look-up table to receive as an input depending on an output of the key translation unit.

4. A white-box cryptographic system as in claim 3 , wherein the key translation unit is configured with an output-encoding, and wherein the specific look-up table is configured with an input encoding corresponding to the output encoding.

5. A white-box cryptographic system as in claim 2 , wherein the system is configured for the first input to depend on an output data of the specific look-up table.

6. A white-box cryptographic system as in claim 5 , wherein the specific look-up table is configured with an output-encoding, and wherein the key translation unit is configured with an input encoding corresponding to the output encoding of the specific look-up table.

7. A white-box cryptographic system as in claim 1 , wherein the key substitute comprises a difference between the further cryptographic key and the particular cryptographic key.

8. A cryptographic system as in claim 7 , wherein the key translation unit is configured for adding the second input to the first input.

9. A cryptographic system as in claim 8 , wherein the specific look-up table comprises a cryptographic key addition operation of a sub-key depending on the particular key.

10. A cryptographic system as in claim 9 wherein the cryptographic sub-key addition operation and the addition in the key translation unit of the second input to the first input are arranged to compose into a cryptographic key addition operation of a further sub-key depending on the further cryptographic key.

11. A cryptographic system as in claim 1 , wherein the key translation unit is arranged to receive the second input encoded with a key substitute encoding, and wherein the system is configured to receive a key substitute at least part of which is encoded with the second input encoding.

12. A cryptographic method for performing a keyed cryptographic operation mapping an input-message to an output-message, the method comprising

performing the cryptographic operation using a network of plurality of look-up tables arranged for the cryptographic operation, the network being adapted for a particular cryptographic key, wherein the method comprises

receiving a key substitute which represents to the network a further cryptographic key,

parsing the key substitute into a plurality of second key substitute; and

providing a key translation unit with a first input depending on an intermediate cryptographic result of the network and a second input depending on one of the second key substitutes,

wherein

performing the cryptographic operation using the network comprises mapping the input-message to the output-message via the network and the key translation unit to arrange the effect of the network on the cryptographic operation to being adapted for the further cryptographic key.

13. A computer program comprising computer program code means adapted to perform all the steps of the cryptographic method of claim 12 when the computer program is run on a computer.

14. A computer program as claimed in claim 13 embodied on a computer readable medium.

15. A cryptographic system as in claim 8 wherein the cryptographic sub-key addition operation and the addition in the key translation unit of the second input to the first input are arranged to compose into a cryptographic key addition operation of a further sub-key depending on the further cryptographic key.

16. A cryptographic system as in claim 2 , wherein the specific look-up table comprises a cryptographic key addition operation of a sub-key depending on the particular key.

17. The system according to claim 1 , wherein the system is configured for:

selecting one of the second key substitutes to provide the one of the second key substitutes to the key translation unit.

18. The system according to claim 1 , wherein the system is configured for:

selecting one of the second key substitutes for a first look-up table of the plurality of look-up tables and selecting the other second key substitute for a second look-up table of the plurality of look-up tables.

19. The method according to claim 12 , comprising:

selecting one of the second key substitutes to provide the one of the second key substitutes to the key translation unit.

20. The method according to claim 12 , comprising:

selecting one of the second key substitutes for a first look-up table of the plurality of look-up tables, and selecting the other second key substitute for a second look-up table of the plurality of look-up tables.

Assignments (3)
MERGER Recorded Dec 16, 2014
From: IRDETO CORPORATE B.V.
To: IRDETO B.V.
Reel/Frame 034512/0718 →
CHANGE OF NAME Recorded Sep 4, 2013
From: IRDETO B.V.
To: IRDETO CORPORATE B.V.
Reel/Frame 031156/0553 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2011
From: MICHIELS, WILHELMUS PETRUS ADRIANUS JOHANNUS
To: IRDETO B. V.
Reel/Frame 027398/0977 →
Priority Claims (1)
EP 09163250 · Jun 19, 2009 · regional
Continuity (1)
Related Publication 20120093313A1 · Apr 19, 2012