WBSLT: A Framework for White-Box Encryption Based on Substitution-Linear Transformation Ciphers
Yang Shi, Tianchen Gao, Yimin Li, Jiayao Gao, Kaifeng Huang
摘要
includes smart city solutions from Samsara [5] , smart home systems from companies like Google [6], Samsung [7] and Apple [8] , Teladoc Health's smart healthcare and health monitoring products [9], as well as industrial IoT deployments [10] and connected vehicles [11] . The common underlying communication protocols, including LoRaWAN [12], Zigbee [13] , and Bluetooth Low Energy (BLE) [14] , all leverage AES as their core encryption mechanism to ensure secure data transmission and storage in data centers. Unlike Wi-Fi or cellular networks, which are typically equipped with high-performance devices having sufficient computing power to support complex encryption algorithms and frequent key renewal, typical IoT devices are resourceconstrained. So, they usually do not support frequent key renewal and rely on pre-shared keys for encryption. A significant vulnerability then arises when IoT devices are deployed in potentially insecure environments where attackers have full control over the device. In such scenarios, attackers can extract encryption keys, thereby compromising all data encrypted with the same key. For example, Butun et al. [15] indicate that an attacker with full access to a device running LoRaWAN v1.1 can extract AES keys due to the explicit exposure of key-related information during the Over-the-Air Activation (OTAA) key distribution process. And Camurati et al. [16] demonstrate that AES keys used in BLE can be extracted using Simple Power Analysis (SPA), exploiting the direct exposure of key material through physical access. In both cases, the key is compromised due to its direct exposure to the attacker with full control. Tournier et al. [17] also note that gateways control the network and handle all data transmission in common IoT topologies. Therefore, preventing key exposure in the gateways is more important. White-box cryptography addresses this issue by transforming cryptographic operations into protected lookup tables, preventing direct exposure of secret keys, thereby enhancing security in these vulnerable IoT ecosystems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper1
相关 Paper
- Trust Dies in Darkness: Shedding Light on Samsung's TrustZone Keymaster DesignAlon Shakevsky, Eyal Ronen, Avishai WoolUSENIX Security 2022
- Don't Kick Over the Beehive: Attacks and Security Analysis on ZigbeeXian Wang, Shuang HaoCCS 2022 · 被引用 13 次
- BeeKeeper: Securing Cross-Technology Communication via Channel-Aware Dual-BindingWeizheng Wang, Qipeng Xie, Mu Yuan, Qingqing Ye 等INFOCOM 2026
- JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoTSam Kumar, Yuncong Hu, Michael P. Andersen, Raluca Ada Popa 等USENIX Security 2019 · 被引用 75 次
- Caveat (IoT) Emptor: Towards Transparency of IoT Device PresenceSashidhar Jakkamsetti, Youngil Kim, Gene TsudikCCS 2023 · 被引用 5 次
