Paper 2025/1221

EWEMrl: A White-Box Secure Cipher with Longevity

Avik Chakraborti, IAI TCG CREST, Kolkata, Academy of Scientific and Innovative Research (AcSIR)
Shibam Ghosh, INRIA, Paris
Takanori Isobe, Osaka University, Japan
Sajani Kundu, IAI TCG CREST, Kolkata, Ramakrishna Mission Vivekananda Educational and Research Institute
Abstract

We propose the first updatable white-box secure cipher, EWEMrl (Extended WEM with longevity against non-adaptive read-only adversaries), and its natural extension, EWEMxl (Extended WEM with longevity against executable adversaries), both based on WEM (White-box Even-Mansour), and both achieving longevity against non-adaptive read-only malware. The notion of longevity, introduced by Koike et al., addresses continuous code leakage and is stronger than incompressibility. While Yoroi claimed longevity, but was broken by Isobe and Todo. Given the prevalence of continuous leakage, developing such ciphers is crucial in white-box cryptography. Precisely, we have the following. • We first present EWEMr (Extended WEM against non-adaptive read-only adver- saries), a generalization of WEM (White-box Even-Mansour). WEM is the first (and possibly only) white-box cipher based on Even-Mansour (EM), replacing its key addition layer with a secret Sbox. EWEMr achieves a high space-hardness bound in the non-adaptive model, with a new generic proof strategy, but does not provide longevity. Instead, it serves as the base for EWEMrl. • We also present EWEMx (Extended WEM against executable adversaries), which uses EWEMr as subroutines and achieves a high space-hardness bound in the stronger adaptive model. While EWEMx does not achieve longevity, it is the base design for EWEMxl. • We next propose EWEMrl, that achieves longevity against non-adaptive read-only malware. None of the existing ciphers, such as SPNbox and SPACE, are designed for longevity. We show that EWEMrl ensures (against non-adaptive read-only adversaries) (1) longevity, (2) high space-hardness in both known-space and chosen-space settings, and (3) security against hybrid code-lifting attacks. • Finally, we introduce EWEMxl, a natural extension of EWEMrl with a structure similar to EWEMx. EWEMxl achieves (2) and (3) in the stronger adaptive model while maintaining (1) in the same non-adaptive and read-only setting. In summary, our proposals EWEMrl and EWEMxl provide longevity against non- adaptive read-only malware while ensuring security confidence in the black-box setting.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Published by the IACR in CIC 2025
DOI
10.62056/ak2i5wol7
Keywords
White-BoxEMWEMEWEMrEWEMxEWEMrlEWEMxlSpace-hardnessLongevityBlock cipher
Contact author(s)
avikchkrbrti @ gmail com
shibam math @ gmail com
takanori isobe @ ist osaka-u ac jp
sajani kundu 89 @ tcgcrest org
History
2026-01-20: revised
2025-06-30: received
See all versions
Short URL
https://ia.cr/2025/1221
License
No rights reserved
CC0

BibTeX

@misc{cryptoeprint:2025/1221,
      author = {Avik Chakraborti and Shibam Ghosh and Takanori Isobe and Sajani Kundu},
      title = {{EWEMrl}: A White-Box Secure Cipher with Longevity},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1221},
      year = {2025},
      doi = {10.62056/ak2i5wol7},
      url = {https://eprint.iacr.org/2025/1221}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.