Formalizes fault attacks on white-box ciphers, then shows Feistel designs like SPACE and Galaxy are easier to bruise than SPNs.
4 comments
This feels like another nudge for vendors to stop selling white-box as some magical anti-tamper moat, because once fault injection is in scope the pitch gets a lot less clean for anyone triyng to ship DRM or mobile wallet keys.
If Feistel tables bruise easier than SPNs, people are going to quietly move procurement toward whatever looks more annoying to poke at, which is probably good for auditors and bad for the whole white-box cottage industry.
The remote trusted server probe scheme adds a new online trust anchor, which feels operationally fragile.
How do they model “corrupt a bounded number of key-embedded lookup-table entries” in a real white-box binary, is that something a fault injector can actually target repeatably, or is it mostly a clean abstraction?
Mostly a clean abstraction, not a repeatable fault target in real binaries.