Cryptanalysis of the Xiao - Lai White-Box AES Implementation

Cryptanalysis of the Xiao - Lai White-Box AES Implementation
复制标题

DOI:
10.1007/978-3-642-35999-6_3
复制
发表时间:
2012-08
期刊:
--
影响因子:
--
通讯作者:
Yoni De Mulder;Peter Roelse;B. Preneel
Yoni De Mulder;Peter Roelse;B. Preneel
中科院分区:
其他
文献类型:
--
作者:
Yoni De Mulder;Peter Roelse;B. Preneel

文献摘要

被引文献

相似文献

在白盒攻击环境中,即,在不受信任的平台上执行密码算法的实现的情况下,对手可以完全访问该实现及其执行环境。2002年,Chowet等人提出了一种白盒AES实现,其目的是防止白盒攻击环境中的密钥提取。然而,在2004年,Billetet等人提出了一个有效的实际攻击Chowet等人。的白盒AES实现。作为回应,在2009年,Xiao和Lai提出了一种新的白盒AES实现,据称可以抵抗Billetet等人的攻击。的攻击。本文对Xiaoet等人提出的白盒AES实现进行了实用的密码分析,并以Biryukovet al.is提出的线性等价算法作为构建块。密码分析有效地提取了Xiaoet al.的白盒AES实现,工作因子约为232。
In the white-box attack context, i.e., the setting where an implementation of a cryptographic algorithm is executed on an untrusted platform, the adversary has full access to the implementation and its execution environment. In 2002, Chowet al.presented a white-box AES implementation which aims at preventing key-extraction in the white-box attack context. However, in 2004, Billetet al.presented an efficient practical attack on Chowet al.’s white-box AES implementation. In response, in 2009, Xiao and Lai proposed a new white-box AES implementation which is claimed to be resistant against Billetet al.’s attack. This paper presents a practical cryptanalysis of the white-box AES implementation proposed by Xiaoet al.The linear equivalence algorithm presented by Biryukovet al.is used as a building block. The cryptanalysis efficiently extracts the AES key from Xiaoet al.’s white-box AES implementation with a work factor of about 232.