跳到主要导航 跳到搜索 跳到主要内容

Affine Equivalence-Based Key-Recovery Attacks on White-Box Implementations of the SM4 Block Cipher

  • Beihang University

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The SM4 block cipher has a generalised Feistel structure with four 32-bit branches and a 128-bit user key, which is a Chinese national standard and an ISO international standard. Following Chow et al.’s seminal work of white-box cryptography in 2002, a few white-box SM4 implementations with external encodings have been proposed since 2009, among which, except the one using linear internal encodings, all the others (i.e. the ones using affine internal encodings) are regarded as (practically) secure against key-recovery attack so far, partially because secret constant parts from affine encodings hinder some attack methods under Feistel structure, like algebraic and affine equivalence attacks, though several published attacks recovered a masked key with such constants, while by contrast all published white-box AES implementations have been practically broken mainly with such attack methods. As a consequence, one may think that Feistel structure is better than SPN structure in terms of their security on white-box cryptography. In this paper, we apply Derbez et al.’s affine equivalence algorithm to the generalised Feistel cipher SM4, and give an affine equivalence-based attack framework to recover the original user key of these white-box SM4 implementations with a very practical complexity of about t2·232 for affine encodings or t·227 for linear encodings (with t being a small integer 1 or 2), by exploring implementation particulars and exploiting a differential meet-in-the-middle approach and the SM4 key expansion formula to filter out a few secret parameters. Finally, as examples, we apply this framework to recover the original user key of Xiao and Lai’s and Bai and Wu’s white-box SM4 implementations for the first time, with a time complexity of 232 and 234 respectively, and to recover the original user key of Shi et al.’s white-box SM4 implementation with a time complexity of 227, significantly lower than the previous attack complexity of 249. Our work shows how to apply Derbez et al.’s affine equivalence algorithm to a Feistel cipher and all such white-box SM4 implementations are not practically secure like white-box AES, and designers of white-box implementations of Feistel ciphers should pay attention to this framework.

源语言英语
主期刊名Topics in Cryptology – CT-RSA 2025 - Cryptographers’ Track at the RSA Conference 2025, Proceedings
编辑Arpita Patra
出版商Springer Science and Business Media Deutschland GmbH
401-425
页数25
ISBN(印刷版)9783031886607
DOI
出版状态已出版 - 2025
活动Cryptographers’ Track at the RSA Conference, CT-RSA 2025 - San Francisco, 美国
期限: 28 4月 20251 5月 2025

出版系列

姓名Lecture Notes in Computer Science
15598 LNCS
ISSN(印刷版)0302-9743
ISSN(电子版)1611-3349

会议

会议Cryptographers’ Track at the RSA Conference, CT-RSA 2025
国家/地区美国
San Francisco
时期28/04/251/05/25

学术指纹

探究 'Affine Equivalence-Based Key-Recovery Attacks on White-Box Implementations of the SM4 Block Cipher' 的科研主题。它们共同构成独一无二的学术指纹。

引用此