Tools for White‐Box Cryptanalysis
Philippe Teuwen · 2025
Until some years ago, the white-box cryptanalysis field was driven exclusively by academic papers. This chapter introduces various methods to trace the activity of a program, illustrates how these traces can be exploited graphically to learn about the program structure, and explains how to acquire traces suitable for cryptanalysis attacks. It presents two side-channel analyses on such traces, details how to inject faults in a program execution, and presents cryptanalysis attacks to exploit faulty results. The chapter discusses how to deal with white-box implementations protected by external encodings. Fortunately, there exists a variant of the differential fault analysis (DFA) meant to cope with external encodings and DarkPhoenix is a tool implementing such a technique. It has stronger requirements than standard DFA as we must provide instrumentation or emulation able to inject faults in the three last full rounds (those with a MixColumns) for an AES-128.