Using secure key storage to bind a white-box implementation to one platform
Abstract
A method for performing a secure function in a data processing system is provided. In accordance with one embodiment, the method includes generating and encoding an encryption key. The encoded encryption key may be encrypted in a key store in a trusted execution environment (TEE) of the data processing system. The encrypted encryption key may encrypted, stored, and decrypted in the key store in the TEE, but used in a white-box implementation to perform a secure function. The secure function may include encrypting a value in the white-box implementation for securing a monetary value on, for example, a smart card. In one embodiment, each time an encryption key or decryption key is used, it is changed to a new key. The method makes code lifting and rollback attacks more difficult for an attacker because the key is stored separately from, for example, a white-box implementation in secure storage.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . (canceled)
3 . (canceled)
4 . (canceled)
5 . (canceled)
6 . (canceled)
7 . (canceled)
8 . (canceled)
9 . (canceled)
10 . A method for performing a secure function using a white-box implementation in a data processing system, the method comprising:
inputting an encoded encryption key in the white-box implementation; storing the encoded encryption key in the unsecure execution environment; and using the encoded encryption key in a trusted execution environment (TEE) to perform the secure function using the white-box implementation.
11 . The method of claim 10 , wherein encoding the encryption key further comprises encoding the encryption key using one of a fixed mask, a linear function, or an affine function.
12 . The method of claim 10 , wherein the secure function further comprises encrypting a data value.
13 . The method of claim 10 , wherein storing the encoded encryption key in the unsecure execution environment further comprises storing the encoded encryption key in a non-volatile memory.
14 . The method of claim 10 , wherein the encoded encryption key is changed each time it is used to perform the secure function.
15 . The method of claim 10 , wherein the data processing system is implemented in an integrated circuit.
16 . A method for decrypting a data value in a data processing system, the method comprising:
generating a decryption key; encrypting the decryption key in a key store supported by a trusted execution environment (TEE) of the data processing system; using the encrypted decryption key to decrypt a data value in the key store; storing the encrypted data value in unsecured memory of the data processing system; and changing the decryption key to a new decryption key each time it is used to decrypt a data value.
17 . The method of claim 16 , wherein using the encrypted decryption key to decrypt a data value in the key store further comprises using a software application in the key store to decrypt the data value.
18 . The method of claim 16 , wherein the data processing system is implemented on an integrated circuit.
19 . The method of claim 16 , wherein generating a decryption key further comprises generating an encryption/decryption key pair, and wherein changing the decryption key to a new decryption key further comprises changing the encryption/decryption key pair to a new encryption/decryption key pair each time one of the encryption key or decryption key of the pair is used to encrypt or decrypt a data value.
20 . The method of claim 16 , wherein the data value is further protected using one or more of obfuscation and tamper proofing.Join the waitlist — get patent alerts
Track US2019312718A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.