PERSONALIZED WHITEBOX DESCRAMBLERS
The invention prevents intercepted keys from being used in unauthorized whitebox descrambler modules for the decryption of a ciphertext. Hereto a receiver with a personalized whitebox descrambler is proposed, whereby a part of the descrambling operation of the personalized descrambler is performed in a preprocessing module external to the descrambler.
1 - 17 . (canceled)
18 . A descrambler, comprising:
a processor configured to:
receive a transformed key, the transformed key comprising data as a result of applying a first part of a descrambling operation;
generate an output of the descrambling operation by applying a second part of the descrambling operation, comprising:
partitioning the transformed key into a plurality of transformed key parts for a plurality of block cipher round modules;
for each of the plurality of transformed key parts, receiving, in a corresponding block cipher round module, input ciphertext data and selecting, from one or more lookup tables, an output at a location indicated by a first bit pattern of the input ciphertext data and a second bit pattern based on the transformed key part.
19 . The descrambler according to claim 18 , wherein the processor is configured to:
apply an inverse transformation to the transformed key part to obtain the second bit pattern.
20 . The descrambler according to claim 18 , wherein the processor is configured to:
apply XOR operation to the transformed key part with a key to obtain the second bit pattern.
21 . The descrambler according to claim 18 , wherein the transformed key are split into the plurality of transformed key parts of equal bit length.
22 . The descrambler according to claim 18 , wherein the block cipher round module comprises a confusion module, and wherein the lookup table is a part of the confusion module.
23 . The descrambler according to claim 22 , wherein the block cipher round module comprises a diffusion module outputting the input ciphertext data.
24 . The descrambler according to claim 18 , wherein the processor is configured to:
personalize the plurality of transformed key parts with one or more unique keys to form a plurality of round keys for the plurality of block cipher round modules; and
for each of the plurality of round keys, receive, in the block cipher round module, the input ciphertext data and select, from the one or more lookup table, an output at a location indicated by the first bit pattern of the input ciphertext data and the second bit pattern based on the round key.
25 . The descrambler according to claim 18 , wherein a row or column of the look up table is selected based on the second bit pattern.
26 . The descramble according to claim 18 , wherein the block cipher round module is configured to skip or use the lookup table depending on a value of the bit of the second bit pattern.
27 . The descrambler according to claim 18 , wherein the output data in the lookup table at the location indicated by the first bit pattern of the input ciphertext data and the second bit pattern of the transformed key part has a preconfigured value corresponding with the inverse transformation of the transformed key part.
28 . The descrambler according to claim 18 , wherein the descrambler is a whitebox iterated block cipher based descrambler, and
wherein a first block cipher round module and a second block cipher round module are configured such that the second block cipher round module uses an output of the first block cipher round module as the input ciphertext data of the second block cipher round module.
29 . The descrambler according to claim 18 , wherein the descrambler is a whitebox stream cipher based descrambler or a whitebox public key based descrambler.
30 . A method for a descrambling operation, comprising:
receiving a transformed key, the transformed key comprising data as a result of applying a first part of a descrambling operation;
generating an output of the descrambling operation by applying a second part of the descrambling operation, comprising:
partitioning the transformed key into a plurality of transformed key parts for a plurality of block cipher round modules;
for each of the plurality of transformed key parts, receiving, in a corresponding block cipher round module, input ciphertext data and selecting, from one or more lookup tables, an output at a location indicated by a first bit pattern of the input ciphertext data and a second bit pattern based on the transformed key part.
31 . The method according to claim 30 , comprising:
applying an inverse transformation to the transformed key part to obtain the second bit pattern.
32 . The method according to claim 30 , comprising:
applying an XOR operation to the transformed key part with a key to obtain the second bit pattern.
33 . The method according to claim 30 , comprising:
personalizing the plurality of transformed key parts with one or more unique keys to form a plurality of round keys for the plurality of block cipher round modules; and
for each of the round keys, receiving, in the block cipher round module, the input ciphertext data and selecting, from the lookup table, an output at a location indicated by the first bit pattern of the input ciphertext data and the second bit pattern of the round keys.
34 . The method according to claim 30 , comprising:
selecting a row or column of the look up table based on the second bit pattern.
35 . The method according to claim 30 , wherein the output data in the lookup table at the location indicated by the first bit pattern of the input ciphertext data and the second bit pattern of the transformed key part has a preconfigured value corresponding with the inverse transformation of the transformed key part.
36 . A computer readable storage medium storing one or more instructions, which when executed by a processor in a device, cause the device to perform a method comprising:
receiving a transformed key, the transformed key comprising data as a result of applying a first part of a descrambling operation;
generating an output of the descrambling operation by applying a second part of the descrambling operation, comprising:
partitioning the transformed key into a plurality of transformed key parts for a plurality of block cipher round modules;
for each of the plurality of transformed key parts, receiving, in a corresponding block cipher round module, input ciphertext data and selecting, from one or more lookup tables, an output at a location indicated by a first bit pattern of the input ciphertext data and a second bit pattern based on the transformed key part.