Skip to main content

Arxan Key & Data Protection

Encrypt keys and sensitive data with FIPS-certified technology

Protecting information you send to users with in-transit encryption is a way to protect it from network eavesdropping, but attackers look not only at what is sent across the network but also at the app itself and what they receive in their own copy of the app. This is a new threat vector that must be mitigated, since traditional cryptography is not designed to defend keys and data from being observed at the endpoint.

White-Box Cryptography is designed to address the concern that an attacker may look not only at data while it is in transit, but may also look at the endpoint where the data is decrypted and keys reside. Using mathematical techniques and transformations, White-Box Cryptography blends together the code and keys for cryptographic operations such that the key cannot be found nor extracted from the app.

Arxan Key & Data Protection is a fully featured White-Box Cryptography suite that can be used for adding protection to your new and existing crypto systems
  • Easy to integrate - directly interoperate with other crypto packages, such as OpenSSL, and devices in your architecture without requiring server side changes
  • Real-time alerting - notifies organizations of attempted code tampering or analysis to quarantine suspicious accounts and update code protections
Differential Fault Analysis, or DFA, is an attack technique that is designed to recover cryptographic keys from apps by injecting “faults” into the app’s crypto code at runtime and observing changes in the app’s behavior. Learn how to protect apps against DFA attacks with Arxan.

Arxan Key & Data Protection Tech Specs

Supports all major ciphers, modes, and key sizes on iOS, Android, Windows, Mac and Linux

Symmetric Encryption

  • AES (128 or 256 bit, CBC, ECB, GCM)
  • DES (Single, Triple)

Key Exchange

  • ECC/DH (Diffie-Hellman)
  • FCC/DH

Secure Hashing & HMAC

  • SHA-1 / 2 / 3
  • HMAC (SHA)
  • CMAC (AES)
  • DES MAC3

Asymmetric Encryption

  • ECC/EG (EIGamal)
  • RSA (1024 or 2048)

Signature Generation

  • ECC/DSA (Digital Signature Algorithm)
  • RSA (1024 or 2048 key size)

Key Wrapping & Derivation

  • NIST & CMLA Key Wrapping
  • NIST, CMLA & OMA Key Derivation

The Arxan Enterprise Solution

Multi-Layered Application Protection

Adaptive app and data protection prevents tampering, IP theft and reverse engineering — Learn More

Visibility & Intelligence

Real-time analytics and predictive intelligence against potential threats — Learn More

Advanced Threat Team

Industry-recognized security thought-leaders with more than 50 years of experience — Learn More

Enterprise Customer Success

Comprehensive suite of services, tailored to each enterprise’s singular needs — Learn More