Download Secure Key Box User Guide
Transcript
Secure Key Box User Guide 1 Introduction 1.1.2 Nomenclature This User Guide uses the terms “secure”, “protect”, ”white-box protected”, “safe”, “tamper resistance” and variations of each to convey very specific concepts — indeed, concepts that are far more specific and limited in their meanings than many meanings often associated with such terms in everyday usage. At the risk of stating the obvious, as used herein, none of these terms describe an absolute condition. Use of SKB in compliance with this User Guide will not render any application or data absolutely secure, absolutely protected or absolutely safe from unauthorized accessing, use or manipulation. Nor will it render any application or data absolutely tamper resistant. In addition, use of these terms is not intended to convey a promise or warranty that SKB will never contain a bug or error, or that SKB will always operate without error. As used in this User Guide: “secure” and variations of “secure” refer to data objects, the values of which reside in a cryptographic container and are white-box protected, and that can be operated on by SKB functions despite the fact that they are not revealed in plain form. “protected”, “white-box protected” and variations of these terms mean that a value has been subjected to some cryptographic processing that has resulted in it being placed in a container that seeks to render the value inaccessible in plain form to the outside world. “safe”, “safely”, “safer” and variations of these terms refer to actions or objects that when processed in accordance with this User Guide will not compromise the security protections provided by SKB. “tamper resistance” and variations of this term refer to the application of whiteCryption’s Code Protection product to render it more difficult for unauthorized parties to engage in reverse engineering and code modification. 1.1.3 Purpose of SKB Cryptographic algorithms and keys are used to protect sensitive data, authenticate communication partners, verify signatures, and implement various other security schemes. A common weak point of cryptographic algorithms in today’s open architectures, such as smartphones, tablets, and desktops, is that the cryptographic keys are revealed in the code or memory at some point. Hackers can monitor such devices with special tools and extract the secret cryptographic keys. Without an efficient protection of cryptographic keys, security features may be compromised. SKB is designed to prevent such attacks by encrypting and hiding cryptographic keys in the code and memory. 1.1.4 White-Box Cryptography The term “white-box cryptography” is used to describe a secure implementation of cryptographic algorithms in an execution environment that is fully observable and modifiable by an attacker, such as a desktop computer or a mobile device. It is different from black-box cryptography where the Copyright © 2000-2015, whiteCryption Corporation. All rights reserved. Copyright © 2004-2015, Intertrust Technologies Corporation. All rights reserved. Page 10 of 137