White-Box Cryptography SDK overview
  • 22 Oct 2024
  • 1 Minute à lire
  • Sombre
    Lumière

White-Box Cryptography SDK overview

  • Sombre
    Lumière

The content is currently unavailable in French. You are viewing the default English version.
Résumé de l’article

The purpose of the White-Box Cryptography SDK (WBC SDK) is to keep secret cryptographic keys hidden in the source code, even during runtime. To achieve this, application developers can convert key values into an encoded key table with the White-Box Table Generator. This encoded key table is ready to be integrated into the application, instead of hard-coding the key values into the source code.On iOS, the WBC SDK does not support multi-threading, i.e., running multiple encryption or decryption threads concurrently is not possible!

Conversion of clear-text key into obfuscated source code

During runtime, the White-Box Cryptography SDK uses the source code that represents the key for encryption and/or decryption; the key is based on an AES 128-bit block cipher that runs in counter (CTR) mode.

If white-box cryptography is not used, cryptographic keys can be extracted from the source code as clear-text assets. Application without the White-Box Cryptography SDK and Application with the White-Box Cryptography SDK illustrate the difference between an application that does not use white-box cryptography and one that does.

Application without the White-Box Cryptography SDK    

Application with the White-Box Cryptography SDK    

For more detailed information about the SDK and integration instructions, refer to the OneSpan White-Box Cryptography SDK Integration Guide included in the OneSpan Mobile Security Suite product package.


Cet article vous a-t-il été utile ?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Ozzy, facilitant la découverte de connaissances grâce à l’intelligence conversationnelle