White-Box Cryptography Opportunities for Secure Online Assessments

Resumo


Secure online assessments depend on software running on student-controlled devices, which leaves exam clients exposed to reverse engineering, tampering, and code lifting. This creates a natural, but still underexplored, use case for white-box cryptography. Using Safe Exam Browser as a concrete case, we discuss how white-box techniques can strengthen assessment workflows without assuming trusted hardware on every student device. We identify the assets that benefit most from software protection and define a pragmatic attacker model for digital examinations. We outline an initial pragmatic design in which a narrow protected client module supports device and application binding for short-lived operations such as token release and protected content access.

Referências

Agrawal, S., Alpírez Bock, E., Chen, Y., and Watson, G. (2023). White-box cryptography with global device binding from message-recoverable signatures and token-based obfuscation. In Kavun, E. B. and Pehl, M., editors, Constructive Side-Channel Analysis and Secure Design, pages 241–261, Cham. Springer Nature Switzerland.

Bock, E. A., Amadori, A., Brzuska, C., and Michiels, W. (2020). On the security goals of white-box cryptography. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2020(2):342–383.

Bogdanov, A. and Isobe, T. (2015). SPACE: A suite of cryptographic primitives for personal space security. In Financial Cryptography and Data Security Workshops, pages 1–18. Springer.

Bos, J. W., Hubain, C., Michiels, W., and Teuwen, P. (2016). Differential computation analysis: Hiding your white-box designs is not enough. In Cryptographic Hardware and Embedded Systems – CHES 2016, pages 215–236. Springer.

Chow, S., Eisen, P., Johnson, H., and van Oorschot, P. C. (2003). White-box cryptography and an AES implementation. In Selected Areas in Cryptography, pages 250–270. Springer.

Moodle (2026). Moodle lms. [link]. Accessed: 2026-05-07.

Rodrigues, F., Dahab, R., López, J., Fujii, H., and Serpa, A. (2023). A minimal white-box dedicated cipher proposal using incompressible lookup tables: Space-hard aes. In Anais do XXIII Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais, pages 125–138, Porto Alegre, RS, Brasil. SBC.

Rodrigues, F. C., Fujii, H., Serpa, A. C. Z., Sider, G., Dahab, R., and Lopez, J. (2019). Fast white-box implementations of dedicated ciphers on the armv8 architecture. In Schwabe, P. and Thériault, N., editors, Progress in Cryptology - LATINCRYPT 2019 - 6th International Conference on Cryptology and Information Security in Latin America, Santiago de Chile, Chile, October 2-4, 2019, Proceedings, Lecture Notes in Computer Science, pages 341–363. Springer.

Safe Exam Browser (2026). About overview. [link]. Accessed: 2026-05-07.

Wyseur, B. (2007). White-Box Cryptography. PhD thesis, Katholieke Universiteit Leuven.
Publicado
01/09/2026
COELHO, Matheus Gomes Martins; RODRIGUES, Felix Carvalho. White-Box Cryptography Opportunities for Secure Online Assessments. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1471-1477. DOI: https://doi.org/10.5753/sbseg.2026.26982.