IP Library Granted Patent US 11,689,352
Granted Patent B2
US 11,689,352 · App. 15/839,266 · Granted Jun 27, 2023

Strong white-box cryptography

Inventor: Lex Aaron Anderson (Auckland, NZ)
Assignee: ARRIS Enterprises LLC
H04L9/002H04L9/06H04L9/0631H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,352
App. No.
15/839,266
Filed
Dec 12, 2017
Granted
Jun 27, 2023
Kind
B2
Art Unit
2437
USPC
380/28
Abstract

A method is provided for generating an output from an input according to a secret using a white-box implementation of a cryptographic function having a first operation, a second operation, and a third operation. The method applies the input to a first operation to generate a first intermediate result, applies the first intermediate result to a second operation to generate a second intermediate result, and applies the second intermediate result to a third operation to generate the output, wherein at least two of the first operation, the second operation, and the third operation is implemented by a plurality of interconnected logic elements, the interconnection of the plurality of logic elements being comprised of one of a non-algebraic interconnection of logic elements and an algebraic interconnection of logic elements having obfuscated boundaries between the at least one of the first operation, the second operation and the third operation.

Claims (40)

1. A method for providing digital signal security comprising:

generating at least one output from at least one input and at least one secret that uses a white-box implementation of a randomized cryptographic function, the randomized cryptographic function obtained by at least one random operation performed on the whole of a nonrandomized function;

providing the randomized cryptographic function as a plurality of interconnected logic elements, the interconnection of the plurality of logic elements being comprised of non-algebraic interconnection of logic elements and algebraic interconnection of logic elements having obfuscated boundaries between the at least one input and output;

wherein the non-algebraic interconnected logic elements comprises a cyclic connection of at least a portion of the plurality of interconnected logic elements that produces an equivalent input-output relationship of a non-cyclic connection of logic elements;

wherein the logic elements are Boolean circuit gates; and

wherein the randomized cryptographic function has fewer Boolean circuit gates than the whole of the nonrandomized function.

2. The method of claim 1 wherein the logic elements are implemented by associated lookup tables.

3. The method of claim 1 , wherein the randomized cryptographic function is implemented by a subset (S) of the plurality of interconnected logic elements.

4. The method of claim 3 , wherein the subset (S) of the plurality of interconnected logic elements is defined by:

slicing a graph of the plurality of interconnected logic elements into the subset (S) of the plurality of interconnected logic elements; and

converting the subset (S) into a logic element having a fan-in equal to a number of inputs to the slice.

5. The method of claim 4 , wherein each of the plurality of interconnected logic elements are Boolean hardware circuit gates.

6. The method of claim 4 , wherein the each of the plurality of interconnected logic elements are implemented by an associated lookup table.

7. The method of claim 1 , wherein the plurality of interconnected logic elements is randomized by performing a plurality of Mal'tsev superposition operations on a non-randomized interconnection of plurality of logic elements for computing the randomized cryptographic function.

8. The method of claim 1 , wherein the plurality of interconnected logic elements is a randomized plurality of interconnected logic elements, randomized by:

generating a non-randomized plurality of interconnected logic elements C1 for computing the randomized cryptographic function;

performing at least one of the following on the non-randomized plurality of interconnected logic elements—C1 to generate the randomized plurality of interconnected logic elements:

introduction of a variable to the non-randomized plurality of interconnected logic elements C1;

permutation of a variable of the non-randomized plurality of interconnected logic elements C1;

deletion of a logic element of the non-randomized plurality of interconnected logic elements C1, the deleted logic element being an input gate having all outgoing edges removed and assigned to another input gate of the plurality of interconnected logic elements C1; and

substitution of a logic gate of the plurality of interconnected logic elements C1 by a second interconnection of logic elements C2.

9. An apparatus for providing digital signal security comprising:

a processor;

a memory, communicatively coupled to the processor, the memory storing instructions comprising instructions for:

generating at least one output from at least one input according to a secret that uses a white-box implementation of a randomized cryptographic function, the randomized cryptographic function obtained by at least one random operation performed on the whole of a nonrandomized function;

providing the randomized cryptographic function as a plurality of interconnected logic elements, the interconnection of the plurality of logic elements being comprised of anon-algebraic interconnection of logic elements and an algebraic interconnection of logic elements having obfuscated boundaries between the at least one input and output;

wherein the non-algebraic plurality of interconnected logic elements comprises a cyclic connection of at least a portion of the plurality of interconnected logic elements that produces an equivalent input-output relationship of a non-cyclic connection of logic elements,

wherein the logic elements are Boolean circuit gates; and

wherein the randomized cryptographic function has fewer Boolean circuit gates than the whole of the nonrandomized function.

10. The apparatus of claim 9 , wherein the randomized cryptographic function is implemented by a subset (S) of the plurality of interconnected logic elements.

11. The apparatus of claim 10 , wherein the subset (S) of the plurality of interconnected logic elements is defined by:

slicing a graph of the plurality of interconnected logic elements into the subset (S) of the plurality of interconnected logic elements; and

converting the subset (S) into a logic element having a fan-in equal to a number of inputs to the slice.

12. The apparatus of claim 11 , wherein the each of the plurality of interconnected logic elements are implemented by an associated lookup table.

13. A non-transitory computer readable medium containing program instructions for causing a computer to perform the method of:

generating at least one output from at least one input according to a secret that uses a white-box implementation of a randomized cryptographic function, the randomized cryptographic function obtained by at least one random operation performed on the whole of a nonrandomized function;

providing the randomized cryptographic function as a plurality of interconnected logic elements, the interconnection of the plurality of logic elements being comprised of non-algebraic interconnection of logic elements and algebraic interconnection of logic elements having obfuscated boundaries between at the least one input and output;

wherein the non-algebraic interconnected logic elements comprises a cyclic connection of at least a portion of the plurality of interconnected logic elements,

wherein the logic elements are Boolean circuit gates; and

wherein the randomized cryptographic function has fewer Boolean circuit gates than the whole of the nonrandomized function.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2018
From: ANDERSON, LEX AARON
To: ARRIS ENTERPRISES LLC
Reel/Frame 044636/0609 →
Continuity (2)
Provisional Application 62432830 · Dec 12, 2016
Related Publication 20180167197A1 · Jun 14, 2018
Cited By (1)
US 12,561,486