Cryptanalysis of the Xiao - Lai White-Box AES Implementation
Cryptanalysis of the Xiao - Lai White-Box AES Implementation
复制标题
DOI:
10.1007/978-3-642-35999-6_3
复制
发表时间:
2012-08
期刊:
影响因子:
--
通讯作者:
Yoni De Mulder;Peter Roelse;B. Preneel
中科院分区:
文献类型:
--
作者:
Yoni De Mulder;Peter Roelse;B. Preneel
In the white-box attack context, i.e., the setting where an implementation of a cryptographic algorithm is executed on an untrusted platform, the adversary has full access to the implementation and its execution environment. In 2002, Chowet al.presented a white-box AES implementation which aims at preventing key-extraction in the white-box attack context. However, in 2004, Billetet al.presented an efficient practical attack on Chowet al.’s white-box AES implementation. In response, in 2009, Xiao and Lai proposed a new white-box AES implementation which is claimed to be resistant against Billetet al.’s attack. This paper presents a practical cryptanalysis of the white-box AES implementation proposed by Xiaoet al.The linear equivalence algorithm presented by Biryukovet al.is used as a building block. The cryptanalysis efficiently extracts the AES key from Xiaoet al.’s white-box AES implementation with a work factor of about 232.