Development of a National Mobile White-Box Cryptographic Library and an End-to-End Secure Communication System
Project Partners
- Private-Sector Partner: Procenne – Güvenpark Bilişim Teknolojileri Ar-Ge Tic. Ltd. Şti.
- Project Consultant: Istanbul Technical University, Embedded Systems Design Laboratory
- Funding Organization: TÜBİTAK 2244 – Industrial PhD Program



Project Team
- Project Leader: Prof. Dr. Berna Örs Yalçın
Project Overview
The increasing use of mobile applications and the growing number of attacks targeting these applications have made security requirements more critical than ever. This situation has created a need for the development of domestic and national mobile security technologies. This need applies to all parties involved in developing and using mobile applications.
For this purpose, the project aims to develop a fully domestic system that addresses requirements such as mobile-system security, data confidentiality, endpoint authentication, end-to-end secure data transmission, and the secure storage of data on mobile devices or centralized systems.
The system to be designed within the scope of the research will consist of three main components:
- A white-box cryptographic library running on mobile devices.
- A Secure Channel Manager system that securely connects mobile devices to centralized systems or other devices.
- A centralized system that provides mobile-device security and performs authentication and verification operations.
The primary objective of the project is to develop a software library that provides mobile application developers with secure data storage, secure data transmission, and endpoint authentication capabilities without requiring any additional hardware at the endpoints.
An SDK will be prepared for this library, and a centralized management system will be developed to enable the system to be managed in either an open or private environment.
The planned system is intended to provide the following capabilities:
- End-to-end secure communication between mobile devices.
- Secure storage of sensitive data within mobile applications.
- End-to-end protection of communication between mobile devices and centralized systems.
- A communication and management infrastructure that can operate independently of the mobile application.
- Compatibility with peer-to-peer communication systems.
The proposed product differs from similar solutions by offering all three components together, using a fully domestically developed white-box library at the endpoint, and allowing the centralized system to provide services independently of the mobile application.
The project outputs will be directly applicable to the following types of applications without requiring an additional security solution:
- Mobile e-government applications.
- Mobile instant-messaging applications.
- Mobile banking, digital-wallet, and financial applications.
- Applications used by law-enforcement, military, and security organizations.
- Applications used by civil-registration, land-registry, and similar public institutions.
- Any mobile application that processes personal or sensitive data.
Objectives and Targets
The project aims to develop a software library that provides mobile application developers with secure data storage, secure data transmission, and endpoint authentication capabilities without creating a need for additional hardware at the endpoints.
An SDK will be prepared for the library, and a centralized system will be developed to enable the system to be managed in either an open or private manner.
Güvenpark’s expertise in security systems, its technical team experienced in mobile devices and mobile applications, and the up-to-date research, literature reviews, testing, and analysis activities to be conducted by doctoral researchers will be brought together. These efforts are expected to produce next-generation solutions that are entirely domestic and national.
Because white-box cryptography is a relatively new technology, research conducted in this field in Türkiye remains limited. Worldwide, the technology is still developing largely under the leadership of academic research.
Since no common published standard exists for white-box cryptography, laboratories providing testing and analysis services in the field of digital security also lack standardized testing procedures. The evaluation methods used may therefore differ among laboratories.
Conducting original research in white-box cryptography requires strong expertise in cryptographic algorithms, protocols, and the mathematical theories on which they are based.
Güvenpark’s experience in the secure implementation of cryptographic algorithms and protocols will complement the research team planned to be formed from doctoral scholarship students. This combination will enable the development of the targeted original and innovative system.
The expertise acquired by the doctoral research team during the project will be highly important for developing future versions of the system, monitoring international advances, and updating the system when necessary.