IP Library › Granted Patent US 9,363,244
Granted Patent B2
US 9,363,244 · App. 14/263,191 · Granted Jun 7, 2016

Realizing authorization via incorrect functional behavior of a white-box implementation

Inventors: Wil Michiels (Reusel, NL); Jan Hoogerbrugge (Helmond, NL)
Assignee: NXP B.V.
H04L63/0428G06F21/51H04L9/002
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,363,244
App. No.
14/263,191
Filed
Apr 28, 2014
Granted
Jun 7, 2016
Kind
B2
Art Unit
2438
USPC
713/168
Abstract

A method of authorization in a cryptographic system that provides separate authorization for a plurality of different input message groups using a single cryptographic key, including: receiving, by the cryptographic system, a first input message from a first input message group; performing, by the cryptographic system, a keyed cryptographic operation mapping the first input message into a first output message, wherein the keyed cryptographic operation produces a correct output message when the cryptographic system is authorized for the first input message group, wherein the keyed cryptographic operation does not produce a correct output when the cryptographic system is not authorized for the first input message group, and wherein each of the plurality of input message groups has an associated set of input messages wherein the sets of input messages do not overlap.

Claims (65)

1. A non-transitory machine-readable storage medium encoded with instructions for execution by a cryptographic system that provides separate authorization for a plurality of different input message groups using a single cryptographic key, the non-transitory machine-readable storage medium comprising:

instructions for receiving, by the cryptographic system, a first input message from a first input message group;

instructions for performing, by the cryptographic system, a keyed cryptographic operation mapping the first input message into a first output message,

wherein the keyed cryptographic operation produces a correct output message when the cryptographic system is authorized for the first input message group,

wherein the keyed cryptographic operation does not produce a correct output when the cryptographic system is not authorized for the first input message group, and

wherein each of the plurality of input message groups has an associated set of input messages wherein the sets of input messages do not overlap,

wherein an input message space includes all potential input messages to the keyed cryptographic operation and the plurality of input message groups includes all of the input messages in the input message space.

2. The non-transitory machine-readable storage medium of claim 1 , wherein the when cryptographic system is not authorized for the first input, the keyed cryptographic operation produces an incorrect output message.

3. The non-transitory machine-readable storage medium of claim 1 , wherein the when cryptographic system is not authorized for the first input, the keyed cryptographic operation terminates.

4. The non-transitory machine-readable storage medium of claim 1 , further comprising:

instructions for receiving a second input message from a second input message group; and

instructions for performing, by the cryptographic system, a keyed cryptographic operation mapping the second input message into a second output message,

wherein the keyed cryptographic operation produces a correct output message when the cryptographic system is authorized for the second input message group,

wherein the keyed cryptographic operation does not produce a correct output when the cryptographic system is not authorized for the second input message group.

5. The non-transitory machine-readable storage medium of claim 4 , wherein the when cryptographic system is not authorized for the second input, the keyed cryptographic operation produces an incorrect output message.

6. The non-transitory machine-readable storage medium of claim 4 , wherein the when cryptographic system is not authorized for the second input, the keyed cryptographic operation terminates.

7. The non-transitory machine-readable storage medium of claim 1 , wherein the cryptographic syst2em includes a network of lookup tables.

8. The non-transitory machine-readable storage medium of claim 1 , wherein the cryptographic system includes a network of finite state machines.

9. The non-transitory machine-readable storage medium of claim 1 , wherein the cryptographic operation is one of encryption system (AES) or data encryption standard (DES).

10. The non-transitory machine-readable storage medium of claim 1 , wherein

the cryptographic system includes a network of lookup tables,

the cryptographic operation is an advanced encryption system (AES) operation,

one of the lookup tables is modified to produce an incorrect output for input messages associated with unauthorized input message groups.

11. A method of creating a cryptographic implementation of a cryptographic operation mapping an input message to an output message, wherein the cryptographic implementation provides separate authorization for a plurality of different input message groups using a single cryptographic key, comprising:

producing a cryptographic implementation of the keyed cryptographic operation;

receiving information identifying the authorization settings to be applied by the cryptographic implementation, wherein each identified authorization setting has an associated input message group, wherein each input message group is associated with a set of input messages, and wherein the sets of input messages do not overlap;

modifying the cryptographic implementation based upon the received information identifying the authorization settings so that:

when a received input message is associated with one of the authorized input message groups, the cryptographic implementation outputs a correct output message associated with the received input message; and

when a received input message is not associated with one of the authorized input message groups, the cryptographic implementation outputs an incorrect output message associated with the received input message or terminates the operation of the keyed cryptographic operation,

wherein an input message space includes all potential input messages to the keyed cryptographic operation and the plurality of input message groups includes all of the input messages in the input message space.

12. The method of claim 11 , wherein modifying the cryptographic implementation further comprises modifying a portion of the cryptographic implementation associated with only input messages associated with the non-authorized input message groups.

13. The method of claim 11 , wherein the cryptographic implementation includes a network of lookup tables.

14. The method of claim 11 , wherein the keyed cryptographic operation is one of advanced encryption system (AES) or data encryption standard (DES).

15. The method of claim 11 , wherein

the cryptographic system includes a network of lookup tables,

the keyed cryptographic operation is an advanced encryption system (AES) operation,

one of the lookup tables is modified to produce an incorrect output for input messages associated with unauthorized input message groups.

16. The method of claim 11 , wherein

the cryptographic system includes a network of lookup tables,

the keyed cryptographic operation is an advanced encryption system (AES) operation,

one of the lookup tables is modified to terminate the operation of the keyed cryptographic operation.

17. The method of claim 11 , wherein the cryptographic system includes a network of finite state machines.

18. A method of authorization in a cryptographic system that provides separate authorization for a plurality of different input message groups using a single cryptographic key, comprising:

receiving, by the cryptographic system, a first input message from a first input message group;

performing, by the cryptographic system, a keyed cryptographic operation mapping the first input message into a first output message,

wherein the keyed cryptographic operation produces a correct output message when the cryptographic system is authorized for the first input message group,

wherein the keyed cryptographic operation does not produce a correct output when the cryptographic system is not authorized for the first input message group, and

wherein each of the plurality of input message groups has an associated set of input messages wherein the sets of input messages do not overlap,

wherein an input message space includes all potential input messages to the keyed cryptographic operation and the plurality of input message groups includes all of the input messages in the input message space.

19. The method of claim 18 , wherein the when white-box system is not authorized for the first input, the keyed cryptographic operation produces an incorrect output message.

20. The method of claim 18 , wherein the when white-box system is not authorized for the first input, the keyed cryptographic operation terminates.

21. The method of claim 18 , further comprising:

receiving a second input message from a second input message group; and

performing, by the white-box system, a keyed cryptographic operation mapping the second input message into a second output message,

wherein the keyed cryptographic operation produces a correct output message when the white-box system is authorized for the second input message group,

wherein the keyed cryptographic operation does not produce a correct output when the white-box system is not authorized for the second input message group.

22. The method of claim 21 , wherein the when white-box system is not authorized for the second input, the keyed cryptographic operation produces an incorrect output message.

23. The method of claim 21 , wherein the when white-box system is not authorized for the second input, the keyed cryptographic operation terminates.

24. The method of claim 18 , wherein the white-box system includes a network of lookup tables.

25. The method of claim 18 , wherein the white-box system includes a network of finite state machines.

26. The method of claim 18 , wherein the cryptographic operation is one of advanced encryption system (AES) or data encryption standard (DES).

27. The method of claim 18 , wherein

the white-box system includes a network of lookup tables,

the cryptographic operation is an advanced encryption system (AES) operation,

one of the lookup tables is modified to produce an incorrect output for input messages associated with unauthorized input message groups.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042985 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051029/0387 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051030/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12298143 PREVIOUSLY RECORDED ON REEL 042762 FRAME 0145. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Oct 22, 2019
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 051145/0184 →
RELEASE OF SECURITY INTEREST Recorded Sep 10, 2019
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: NXP B.V.
Reel/Frame 050745/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 039361 FRAME 0212. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042762/0145 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12681366 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded May 9, 2017
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 042985/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE APPLICATION 12092129 PREVIOUSLY RECORDED ON REEL 038017 FRAME 0058. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY AGREEMENT SUPPLEMENT. Recorded Jul 14, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 039361/0212 →
SECURITY AGREEMENT SUPPLEMENT Recorded Mar 7, 2016
From: NXP B.V.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 038017/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2014
From: MICHIELS, WIL; HOOGERBRUGGE, JAN
To: NXP B.V.
Reel/Frame 032768/0961 →
Continuity (1)
Related Publication 20150312223A1 · Oct 29, 2015