{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T09:09:18Z","timestamp":1762506558918,"version":"build-2065373602"},"reference-count":40,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2015,5,21]],"date-time":"2015-05-21T00:00:00Z","timestamp":1432166400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61202382"],"award-info":[{"award-number":["61202382"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Wireless Sensor Networks (WSNs) are often deployed in hostile environments and, thus, nodes can be potentially captured by an adversary. This is a typical white-box attack context, i.e., the adversary may have total visibility of the implementation of the  build-in cryptosystem and full control over its execution platform. Handling white-box attacks in a WSN scenario is a challenging task. Existing encryption algorithms for white-box attack contexts require large memory footprint and, hence, are not applicable for wireless sensor networks scenarios. As a countermeasure against the threat in this context, in this paper, we propose a class of lightweight secure implementations of the symmetric encryption algorithm SMS4. The basic idea of our approach is to merge several steps of the round function of SMS4 into table lookups, blended by randomly generated mixing bijections. Therefore, the size of the implementations are significantly reduced while keeping the same security efficiency. The security and efficiency of the proposed solutions are theoretically analyzed. Evaluation shows our solutions satisfy the requirement of sensor nodes in terms of limited memory size and low computational costs.<\/jats:p>","DOI":"10.3390\/s150511928","type":"journal-article","created":{"date-parts":[[2015,5,21]],"date-time":"2015-05-21T10:30:59Z","timestamp":1432204259000},"page":"11928-11952","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":34,"title":["A Lightweight White-Box Symmetric Encryption Algorithm against Node Capture for WSNs"],"prefix":"10.3390","volume":"15","author":[{"given":"Yang","family":"Shi","sequence":"first","affiliation":[{"name":"School of Software Engineering, Tongji University, No.4800 Cao'An Highway, Shanghai 201804, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wujing","family":"Wei","sequence":"additional","affiliation":[{"name":"School of Software Engineering, Tongji University, No.4800 Cao'An Highway, Shanghai 201804, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zongjian","family":"He","sequence":"additional","affiliation":[{"name":"School of Software Engineering, Tongji University, No.4800 Cao'An Highway, Shanghai 201804, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2015,5,21]]},"reference":[{"key":"ref_1","unstructured":"Laurent, E., and Virgil, D.G. (2002). A key-management scheme for distributed sensor networks."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1221","DOI":"10.1109\/TMC.2009.33","article-title":"Mitigation of Control Channel Jamming under Node Capture Attacks","volume":"8","author":"Patrick","year":"2009","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_3","unstructured":"Tanya, R., Shiuhpyng, S., and Shankar, S. (2006, January 13\u201315). Taxonomy of Security Attacks in Sensor Networks and Countermeasures. Proceedings of the first IEEE International Conference on System Integration and Reliability Improvements, Hanoi, Vietnam."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1638","DOI":"10.1109\/TWC.2012.031212.110887","article-title":"Exact Formulae for Resilience in Random Key Predistribution Schemes","volume":"11","author":"Yum","year":"2012","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_5","unstructured":"Stanley, C., Philip, A.E., Harold, J., and Paul, C.V.O. (2002). A White-Box DES Implementation for DRM Applications, Carleton University."},{"key":"ref_6","unstructured":"Stanley, C., Philip, A.E., Harold, J., and Paul, C.V.O. (2002). White-Box Cryptography and an AES Implementation, Springer."},{"key":"ref_7","unstructured":"Hamilton, E.L., and William, D.N. (2005). Clarifying Obfuscation: Improving the Security of White-Box DES. IEEE Comput. Soc., 679\u2013684."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Xiao, Y., and Lai, X. (2009, January 10\u201312). A Secure Implementation of White-Box AES. Proceedings of the 2nd International Conference on Computer Science and its Applications, 2009 (CSA\u201909), Jeju, Korea.","DOI":"10.1109\/CSA.2009.5404239"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"278","DOI":"10.1007\/978-3-642-24209-0_19","article-title":"Protecting White-Box AES with Dual Ciphers","volume":"Volume 6829","author":"Rhee","year":"2011","journal-title":"Information Security and Cryptology\u2014ICISC 2010"},{"key":"ref_10","unstructured":"Xiao, Y., and Lai, X. (2009). White-Box Cryptography and a White-Box Implementation of the SMS4 Algorithm, Shanghai Jiaotong University."},{"key":"ref_11","first-page":"227","article-title":"Cryptanalysis of a White Box AES Implementation","volume":"Volume 3357","author":"Handschuh","year":"2005","journal-title":"Selected Areas in Cryptography"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Michiels, W., Gorissen, P., and Hollmann, H.D.L. (2008). Cryptanalysis of a Generic Class of White-Box Implementations, Springer.","DOI":"10.1007\/978-3-642-04159-4_27"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1007\/978-3-642-35999-6_3","article-title":"Cryptanalysis of the Xiao\u2013Lai White-Box AES Implementation","volume":"Volume 7707","author":"Knudsen","year":"2013","journal-title":"Selected Areas in Cryptography"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Shi, Y., and He, Z. (2014, January 6\u20139). A lightweight white-box symmetric encryption algorithm against node capture for WSNs. Proceedings of 2014 IEEE Wireless Communications and Networking Conference (WCNC), Istanbul, Turkey.","DOI":"10.1109\/WCNC.2014.6952994"},{"key":"ref_15","unstructured":"Matthias, J., Dan, B., and Edward, W.F. (2002). Attacking an Obfuscated Cipher by Injecting Faults, Springer."},{"key":"ref_16","unstructured":"Brecht, W., Wil, M., Paul, G., and Bart, P. (2007). Cryptanalysis of White-Box DES Implementations with Arbitrary External Encodings, Springer."},{"key":"ref_17","unstructured":"Goubin, L., Masereel, J.-M., and Quisquater, M. (2007). Cryptanalysis of White Box DES Implementations, Springer."},{"key":"ref_18","unstructured":"Tolhuizen, L. (2012, January 24\u201325). Improved cryptanalysis of an AES implementation. Proceedings of the 33rd WIC Symposium on Information Theory in the Benelux, Boekelo, The Netherlands."},{"key":"ref_19","first-page":"981","article-title":"A White-Box Encryption Algorithm for Computing with Mobile Agents","volume":"12","author":"Shi","year":"2011","journal-title":"J. Internet Technol."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1007\/3-540-68671-1_6","article-title":"Time Limited Blackbox Security: Protecting Mobile Agents from Malicious Hosts","volume":"Volume 1419","author":"Vigna","year":"1998","journal-title":"Mobile Agents and Security"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Biryukov, A., Canni\u00e8re, C.D., Braeken, A., and Preneel, B. (2003). A Toolbox for Cryptanalysis: Linear and Affine Equivalence Algorithms, Springer.","DOI":"10.1007\/3-540-39200-9_3"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Lange, T., Lauter, K., and Lison\u011bk, P. (2014). Selected Areas in Cryptography\u2014SAC 2013, Springer.","DOI":"10.1007\/978-3-662-43414-7"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"2238","DOI":"10.3724\/SP.J.1001.2013.04356","article-title":"Efficient attack to white-box SMS4 implementation","volume":"24","author":"Lin","year":"2013","journal-title":"J. Softw."},{"key":"ref_24","first-page":"329","article-title":"SMS4 Encryption Algorithm for Wireless Networks","volume":"2008","author":"Diffie","year":"2008","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"ref_25","first-page":"158","article-title":"Analysis of the SMS4 Block Cipher","volume":"Volume 4586","author":"Pieprzyk","year":"2007","journal-title":"Information Security and Privacy"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"160","DOI":"10.1007\/3-540-36178-2_10","article-title":"In How Many Ways Can You Write Rijndael?","volume":"Volume 2501","author":"Zheng","year":"2002","journal-title":"Advances in Cryptology\u2014ASIACRYPT 2002"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"142","DOI":"10.1007\/11506447_12","article-title":"More Dual Rijndaels","volume":"Volume 3373","author":"Dobbertin","year":"2005","journal-title":"Advanced Encryption Standard\u2014AES"},{"key":"ref_28","unstructured":"Park, J.-Y., Yi, O., and Choi, J.-S. (2010, January 17\u201319). Methods for practical whitebox cryptography. Proceedings of the 2010 International Conference on Information and Communication Technology Convergence (ICTC), Jeju, Korea."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Adler, R., Flanigan, M., Huang, J., Kling, R., Kushalnagar, N., Nachman, L., Wan, C.-Y., and Yarvis, M. (2005, January 2\u20134). Intel Mote 2: An advanced platform for demanding sensor network applications. Proceedings of the 3rd International Conference on Embedded Networked Sensor Systems, San Diego, CA, USA.","DOI":"10.1145\/1098918.1098963"},{"key":"ref_30","unstructured":"Kim, T., Kim, J., Hong, S., and Sung, J. (2008). Linear and Difierential Cryptanalysis of Reduced SMS4 Block Cipher. IACR Cryptol. ePrint Arch., 281."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1007\/978-3-642-04159-4_4","article-title":"The Cryptanalysis of Reduced-Round SMS4","volume":"Volume 5381","author":"Avanzi","year":"2009","journal-title":"Selected Areas in Cryptography"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"324","DOI":"10.1007\/978-3-642-00843-6_28","article-title":"Some New Observations on the SMS4 Block Cipher in the Chinese WAPI Standard","volume":"Volume 5451","author":"Bao","year":"2009","journal-title":"Information Security Practice and Experience"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"130","DOI":"10.1007\/s11390-011-9420-y","article-title":"Security of the SMS4 Block Cipher against Differential Cryptanalysis","volume":"26","author":"Su","year":"2011","journal-title":"J. Comput. Sci. Technol."},{"key":"ref_34","first-page":"141","article-title":"Analysis of Two Attacks on Reduced-Round Versions of the SMS4","volume":"Volume\u00a05308","author":"Chen","year":"2008","journal-title":"Information and Communications Security"},{"key":"ref_35","first-page":"103","article-title":"An Analysis of the Compact XSL Attack on BES and Embedded SMS4","volume":"Volume\u00a05888","author":"Garay","year":"2009","journal-title":"Cryptology and Network Security"},{"key":"ref_36","first-page":"73","article-title":"Algebraic Cryptanalysis of SMS4: Gr\u00f6bner Basis Attack and SAT Attack Compared","volume":"Volume\u00a05984","author":"Lee","year":"2010","journal-title":"Information, Security and Cryptology\u2014ICISC 2009"},{"key":"ref_37","unstructured":"Wyseur, B. White-Box Cryptography. Available online: http:\/\/summerschool08.iaik.tugraz.at\/slides\/Brecht_wbc1_crete_final.pdf."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1016\/j.jss.2008.06.032","article-title":"Differential fault analysis on the contracting UFN structure, with application to SMS4 and MacGuffin","volume":"82","author":"Li","year":"2009","journal-title":"J. Syst. Softw."},{"key":"ref_39","first-page":"016","article-title":"Cache timing attack on SMS4","volume":"6","author":"Zhao","year":"2010","journal-title":"J. Commun."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Wang, S., Gu, D., Liu, J., Guo, Z., Wang, W., and Bao, S. (2013, January 14\u201315). A Power Analysis on SMS4 Using the Chosen Plaintext Method. Proceedings of the 2013 9th International Conference on Computational Intelligence and Security (CIS), Leshan, China.","DOI":"10.1109\/CIS.2013.163"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/15\/5\/11928\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T20:46:43Z","timestamp":1760215603000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/15\/5\/11928"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,5,21]]},"references-count":40,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2015,5]]}},"alternative-id":["s150511928"],"URL":"https:\/\/doi.org\/10.3390\/s150511928","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2015,5,21]]}}}