Home White Box Cryptography Security Evaluations

White Box Cryptography Security Evaluations

White Box Cryptography partnership

Solutions in mobile payment and content protection often heavily rely on software to provide security. The open nature of the devices running these solutions, such as smartphones, tablets and set-top-boxes, make the software vulnerable to attacks since the attacker has complete control over the platform and software implementation. White-Box Cryptography (WBC) aims to protect cryptographic assets on such open systems, even when attackers have complete control over the platform and software implementation.

With its extensive knowledge on cryptographic security testing in software and hardware, Riscure has proven to be uniquely positioned to assess White-Box Cryptographic solutions. Both the obfuscation techniques and the cryptanalytic aspects require a wide range of capabilities to perform thorough and innovative security testing. Riscure performs such testing in an efficient manner where we ensure minimal project duration while providing optimal insight into the security of your White-Box Cryptographic implementation and recommendations for improvement.

White Box Crypto services

Design review and evaluation of White-Boxed ciphers

We provide you with the opportunity to review and evaluate the design and implementation of your white-boxes and additional software protection techniques (e.g. obfuscation, anti-tampering, anti-debugging, root detection, device binding etc). Such evaluations are typically performed with the purpose of improving the WBC and software protection techniques.

Security evaluation of White-Box Cryptographic based solutions

We can evaluate the robustness of your White-Box cryptographic solution against attackers. Such evaluations are typically performed in a black-box approach, meaning without further details on the actual implementation, with the objective to break or circumvent the White-Boxed ciphers and software protection techniques and gain access to pre-defined protected assets (e.g. payment keys, encryption keys, content, etc).

Training & consulting

Riscure provides support with consulting and training in order to enable WBC manufacturers, integrators and others to improve the development, integration and testing of White-Box Cryptographic solutions and implementations. Read more on our open training course for security testing of WBC technology.

Test your WBC implementation yourself

Our advanced Inspector test tools include an option to evaluate and test the robustness of your own White Box Crypto implementation. The module is available as part of an Inspector SCA or FI subscription license.

  • Contact us
  • Pascal van Gimst

  • Vice President Global Services Sales and Business Development