WBSLT: A Framework for White-Box Encryption Based on Substitution-Linear Transformation Ciphers
Yang Shi, Tianchen Gao, Yimin Li, Jiayao Gao, Kaifeng Huang
Abstract
includes smart city solutions from Samsara [5] , smart home systems from companies like Google [6], Samsung [7] and Apple [8] , Teladoc Health's smart healthcare and health monitoring products [9], as well as industrial IoT deployments [10] and connected vehicles [11] . The common underlying communication protocols, including LoRaWAN [12], Zigbee [13] , and Bluetooth Low Energy (BLE) [14] , all leverage AES as their core encryption mechanism to ensure secure data transmission and storage in data centers. Unlike Wi-Fi or cellular networks, which are typically equipped with high-performance devices having sufficient computing power to support complex encryption algorithms and frequent key renewal, typical IoT devices are resourceconstrained. So, they usually do not support frequent key renewal and rely on pre-shared keys for encryption. A significant vulnerability then arises when IoT devices are deployed in potentially insecure environments where attackers have full control over the device. In such scenarios, attackers can extract encryption keys, thereby compromising all data encrypted with the same key. For example, Butun et al. [15] indicate that an attacker with full access to a device running LoRaWAN v1.1 can extract AES keys due to the explicit exposure of key-related information during the Over-the-Air Activation (OTAA) key distribution process. And Camurati et al. [16] demonstrate that AES keys used in BLE can be extracted using Simple Power Analysis (SPA), exploiting the direct exposure of key material through physical access. In both cases, the key is compromised due to its direct exposure to the attacker with full control. Tournier et al. [17] also note that gateways control the network and handle all data transmission in common IoT topologies. Therefore, preventing key exposure in the gateways is more important. White-box cryptography addresses this issue by transforming cryptographic operations into protected lookup tables, preventing direct exposure of secret keys, thereby enhancing security in these vulnerable IoT ecosystems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0bfed942-624e-4cf8-b9e3-aaa3d83d73bcBuilds on1
Related papers
- Trust Dies in Darkness: Shedding Light on Samsung's TrustZone Keymaster DesignAlon Shakevsky, Eyal Ronen, Avishai WoolUSENIX Security 2022
- Don't Kick Over the Beehive: Attacks and Security Analysis on ZigbeeXian Wang, Shuang HaoCCS 2022 · 13 citations
- BeeKeeper: Securing Cross-Technology Communication via Channel-Aware Dual-BindingWeizheng Wang, Qipeng Xie, Mu Yuan, Qingqing Ye et al.INFOCOM 2026
- JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoTSam Kumar, Yuncong Hu, Michael P. Andersen, Raluca Ada Popa et al.USENIX Security 2019 · 75 citations
- Caveat (IoT) Emptor: Towards Transparency of IoT Device PresenceSashidhar Jakkamsetti, Youngil Kim, Gene TsudikCCS 2023 · 5 citations
