ELECTRONIC AUTHENTICATION SYSTEM

The electronic authentication system addresses the challenge of ensuring the integrity and reliability of connections between multiple electronic components by using a challenge-response authentication protocol with PUFs, achieving efficient and reliable mutual authentication and enhancing system security.

FR3156554A1Pending Publication Date: 2025-06-13COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
FR2023013750
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-07
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Existing electronic systems lack a comprehensive method for ensuring the integrity and reliability of connections and information between multiple electronic components, particularly in systems with numerous interconnected sensors where security across the entire operating chain is not adequately addressed.

Method used

An electronic authentication system that employs a challenge-response type authentication protocol using Physical Unclonable Functions (PUFs) to establish mutual authentication between electronic components. The system broadcasts a single challenge to all components, which respond with individual or group responses compared to expected responses stored in a memory device, ensuring the integrity of the components and their connections.

Benefits of technology

This solution enables efficient and reliable mutual authentication between electronic components, ensuring the integrity and reliability of the system by verifying the consistency of responses across all components, thus enhancing overall system security and trustworthiness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Electronic authentication system comprising a computer (102), a memory device (106) connected to the computer (102), and a set of electronic components (104), the computer (102) and the electronic components (104) are connected to each other by direct or indirect links according to a predetermined configuration, each of the electronic components (104) being provided with a PUF intended to apply a challenge-response type authentication protocol, characterized in that the electronic system is configured to broadcast a single challenge (C) to the set of electronic components (104), and in that the computer (102) is configured to receive in return from the set of electronic components at least one response (Rc) allowing it to verify the integrity of this set of electronic components (104) by comparing said at least one response to at least one expected response (R'c) previously stored in the memory device (106),the integrity of the set of electronic components (104) being authenticated as being valid if said at least one response (Rc) and said at least one expected response (R'c) coincide. Figure for the abstract: Fig. 3,
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: ELECTRONIC AUTHENTICATION SYSTEM TECHNICAL FIELD OF THE INVENTION

[0001] The field of the invention is that of data security, and in particular that of systems equipped with electronic components and in which significant security of the processed data is required. STATE OF THE ART

[0002] An electronic system may comprise several electronic components of the sensor type which are capable of measuring physical parameters from which it is possible to extract information, or functions, considered critical or sensitive.

[0003] For example, extended reality glasses have several sensors intended to measure parameters that may be confidential. Thus, it is essential to have confidence in this system and to be sure that all the sensors provide information from the system. In addition, it is important to check that the system is intact and that there is no doubt about the reliability of the connections between the different electronic components.

[0004] Document US 2019 / 312740 deals with securing sensors based on the use of physical unclonable functions (PUFs) generated from data from a first calibrated sensor. A second uncalibrated sensor is also used, and the generated PUF is compared with a database of sensor identification PUFs. The data used for generating the PUF may correspond to physical or chemical signals obtained in the first sensor. This document does not propose security across the entire operating chain of the system and, more particularly, does not propose verifying the integrity of the system.

[0005] Indeed, the electronic components can be very numerous and can be connected together in a chain or according to any configuration. It is therefore important to be sure that the system is integrated in the sense that it is always the same components which are present in this system.

[0006] Thus, the object of the present invention is to remedy the aforementioned drawbacks by proposing an authentication method and system making it possible to carry out mutual authentication between the different electronic components of the system, consequently establishing a high level of integrity and reliability of the connections and information between these different electronic components. Statement of the invention

[0007] The invention proposes an electronic authentication system comprising a computer, a memory device connected to the computer, and a set of electronic components, the computer and the electronic components are connected to each other by direct or indirect links according to a predetermined configuration, each of the electronic components being provided with a PUF intended to apply a challenge-response type authentication protocol.The electronic system is configured to broadcast a single challenge to the set of electronic components, and the computer is configured to receive in return from the set of electronic components at least one response allowing it to verify the integrity of this set of electronic components by comparing said at least one response to at least one expected response previously stored in the memory device, the integrity of the set of electronic components being authenticated as being valid if said at least one response and said at least one expected response coincide.

[0008] This makes it possible to propagate the interrogation of the same challenge in a simple and rapid manner across the set of electronic components, enabling two-by-two mutual authentication to be carried out between the different electronic components.

[0009] According to a first embodiment, the calculator is configured to retrieve a set of individual responses from said set of electronic components and to compare it bijectively to a set of expected individual responses specific to said challenge and to said set of electronic components.

[0010] Thus, mutual authentication between different electronic components can be achieved in a simple manner without adding new functionalities to the components.

[0011] According to a second embodiment, the calculator is configured to:

[0012] -recover a set of individual responses from said set of electronic components,

[0013] -calculate a group response based on said set of individual responses,

[0014] - compare said group response to an expected group response.

[0015] This saves time by allowing the calculator to query the enrollment database only once while minimizing the size of this database.

[0016] According to a third embodiment, a specific electronic component among the set of electronic components is configured to have a set of responses representative, explicitly or implicitly, of the set of individual responses, allowing it to calculate and transmit a response of group to the calculator which is configured to compare said group response to an expected group response.

[0017] This allows to minimize the consumption of querying the enrollment database and allows the calculator to minimize the time by querying only the specific electronic component to have the group response. In addition, a possible attack against the calculator will not succeed in modifying the group response calculation.

[0018] Advantageously, said set of responses arranged by the specific electronic component comprises at least one intermediate group response calculated by at least one other electronic component.

[0019] This makes it possible to simplify the system architecture and allows for easily interchangeable modules.

[0020] According to a fourth embodiment, each of the electronic components is configured to have the set of individual responses allowing it to calculate and transmit a group response to the calculator which is configured to compare the group response received from any one of the electronic components to an expected group response.

[0021] This allows the computer to minimize time by interrogating only one electronic component. Furthermore, in the event of unavailability of an electronic component, the computer can interrogate any other electronic component to obtain the group response. Furthermore, as before, an attack against the computer cannot modify the group response calculation.

[0022] According to a particular embodiment, the electronic system is configured to use a first encryption key to form a secure link between the computer and at least one electronic component, called the electronic identification component, among the set of electronic components, the computer being configured to transmit a user challenge to the electronic identification component using the secure link, the electronic identification component being configured to carry out a measurement on the user by means of said user challenge and to send via the secure link the response of the measurement to the computer which is configured to compare the response of the measurement with an expected identification response previously stored by the memory device, the user being authenticated as valid if the response of the measurement corresponds to the expected identification response.

[0023] Thus, by transitivity, the fact that the already validated electronic identification component has authenticated the user, guarantees that all the electronic components carry out their measurements on the same user.

[0024] Advantageously, the calculator is configured to calculate the first key of encryption from said unique challenge and the individual response of said electronic identification component.

[0025] Advantageously, the calculator is further configured to:

[0026] calculating a second encryption key from said user challenge and said measurement response, the second encryption key being shared between the calculator and the electronic identification component,

[0027] calculating a third encryption key from the first and second encryption keys, the second encryption key being shared between the calculator and the electronic identification component,

[0028] exchange encrypted data between the electronic identification component and the computer using the third encryption key.

[0029] Advantageously, the memory device comprises a database remote from the set of electronic components and the computer.

[0030] Advantageously, the set of electronic components and the calculator form part of an electronic device corresponding to a smartphone, or an electronic watch connected to the Internet, or extended reality glasses connected to the Internet, or a vehicle.

[0031] Advantageously, the set of electronic components and the calculator are part of a set of electronic devices worn or used by the user.

[0032] Advantageously, the set of electronic components and the computer are part of a set of electronic devices corresponding to a set of equipment in a vehicle.

[0033] Advantageously, the electronic components correspond to memories held in a printed circuit PCB.

[0034] The invention also relates to a challenge-response type authentication method, implemented in an electronic system according to one of the preceding characteristics. BRIEF DESCRIPTION OF THE FIGURES

[0035] Other advantages, aims and particular characteristics of the present invention will emerge from the following non-limiting description of at least one particular embodiment of the devices and methods which are the subject of the present invention, with reference to the appended drawings, in which:

[0036] [Fig.l] very schematically illustrates an electronic authentication system, according to one embodiment of the invention;

[0037] [Fig.2] very schematically illustrates an electronic component corresponding to a sensor, according to one embodiment of the invention;

[0038] Figs. 3-7 illustrate diagrams representing the steps implemented during authentication of a set of electronic components by the electronic system electronics, according to different embodiments of the invention;

[0039] [Fig.8] very schematically illustrates an electronic authentication system, according to a particular embodiment of the invention; and

[0040] [Fig.9] illustrates a diagram representing the steps implemented during authentication of a user by the electronic system, according to a preferred embodiment of the invention. DETAILED DESCRIPTION OF THE INVENTION

[0041] The principle of the invention is to propagate the same challenge through the electronic components of a system in order to achieve mutual authentication between the different electronic components two-by-two.

[0042] [Fig.l] very schematically illustrates an electronic authentication system, according to one embodiment of the invention.

[0043] The electronic system 100 comprises at least the following elements: a computer 102, a set of electronic components 104 and a memory device 106. The electronic components 104 are referenced 1041, 1042,..., 104i,..., 104n.

[0044] The calculator 102 corresponds for example to a central processing unit (CPU), a microcontroller, an application processor, or any other electronic calculation device.

[0045] The memory device 106 is connected to the computer 102. According to an advantageous exemplary embodiment, the memory device 106 may correspond to a database remote from the computer 102. In this case, the memory device 106 may communicate via a confidential link with the computer 102 via at least one communication network, for example the Internet. Alternatively, the memory device 106 may correspond to a local memory forming part of a device including the electronic components 104 and the computer 102 and communicating for example with the computer 102 without passing through a network external to the device.

[0046] The computer 102 and the electronic components 104 are connected to each other by direct or indirect links according to a predetermined configuration. Generally, the computer 102 and the electronic components 104 form a more or less complex circuit where each element (i.e. electronic component or computer) can be directly connected to any number of other elements. For example, these elements can be connected sequentially according to a chain where each element is connected to at most two other elements. Another example is the case of a circuit where each element is connected to all the other elements.

[0047] Each electronic component 104i comprises a 'non-clonable physical function' PUF for applying a challenge-response type authentication protocol. The PUF may be obtained using one or more constituents of the electronic component 104. The electronic component 104i may correspond to a sensor, a memory, an actuator, etc.

[0048] The PUF used in each electronic component 104 can belong indifferently to one of the two large families of PUFs which are the weak-PUFs 'weak-PUF' and the strong-PUFs 'strong-PUF'. If the chosen PUF is a strong-PUF, the authenticator generates a challenge C, it is sent to the PUF which generates a response R (specific to C). This response is returned to the authenticator for comparison with the expected response. In the case of a weak-PUF, the authenticator challenges the PUF by asking for its key, the PUF returns the response R (which is its fixed key or derived information). In the remainder of the description, we consider the case of strong-PUFs, knowing that it is simple to transpose it to the case of weak-PUFs.

[0049] [Fig.2] very schematically illustrates an electronic component corresponding to a sensor, according to one embodiment of the invention.

[0050] In this case, the electronic component 104i is a sensor comprising a measurement module 108, a digital interface 110, and a volatile memory 112. The measurement module 108 transforms the measured physical, chemical or biological parameter into an analog electrical signal. The digital interface 110 is configured to shape the analog measurement signal into a digital signal and ensures the digital communication of this signal to the computer 102 or another component.

[0051] [Fig.3] illustrates a diagram representing the steps implemented during authentication of a set of electronic components by the electronic system, according to the invention.

[0052] During steps E1 and E2, the electronic system 100 is configured to broadcast a single authentication challenge to the set of electronic components 104 referenced 1041, 1042, ..., 104i, ..., 104n. In other words, the challenge C is shared to interrogate all the electronic components 104 with it.

[0053] More particularly, in step E1, the computer 102 retrieves from the memory device 106 a challenge C which is common to all the electronic components 104 to be authenticated. Indeed, the computer 102 knows which electronic components 104 make up the set, it can therefore select a challenge C for which the responses to the electronic components 104 to be authenticated are known.

[0054] In step E2, the computer 102 is configured to transmit the single challenge C to at least one electronic component 1041 which calculates, using its PUF1, the response Ri that it temporarily stores. The latter then transmits the same challenge C to at least one other electronic component 1042 and so on, so that the same challenge C propagates rapidly in the electronic system 100 according to the connection configuration between the different electronic components 104 to reach each of them.

[0055] In step E3, the computer 102 is configured to receive from the set of electronic components 104 at least one response Rc to the single challenge C. According to different embodiments (see Figs. 4-7), the set of electronic components 104 can transmit to the computer 102 a single group response Rc= Rg or a set of individual responses Rc= (Rb..., Rn) or a mixture of partial group responses and individual responses.

[0056] In step E4, the computer 102 is configured to compare said at least one response Rc to at least one expected response R'c previously recorded in the memory device 106. An equivalence between said at least one response Rc and said at least one expected response R'c implies a mutual authentication between the different electronic components 104 two-by-two. Thus, the integrity of the set of electronic components 104 is authenticated as being valid if said at least one response Rc and said at least one expected response R'c coincide.

[0057] Before performing the authentication of the electronic components 104, an enrollment of these electronic components 104 is first implemented. The enrollment of the set of electronic components 104 is for example carried out by sending numerous different challenge data to the set of electronic components 104 and by recording in the memory device 106 the response data returned by the set of components. In this case, the enrollment of the set of electronic components 104 may correspond to the construction, in the memory device 106, of a table giving, for each of the different challenges, corresponding expected responses. Each challenge may correspond for example to common calibration data with which the electronic components 104 can make reference measurements.

[0058] [Fig.4] illustrates a diagram representing the steps implemented during authentication of a set of electronic components by the electronic system, according to a first embodiment of the invention.

[0059] In step El 1, the computer 102 requests the memory device 106 to provide, among all the challenges of the stored electronic components 104, a challenge C common to all the electronic components 104 to be authenticated.

[0060] In step E12, the calculator 102 is configured to send the challenge C to a first electronic component 1041 which then transmits it to a second electronic component 1042 and so on up to the last electronic component 104n. The challenge C is submitted as input to each electronic component 104i so that the PUF of the electronic component 104i generates an individual response R;. Each individual response R; is specific to the corresponding electronic component 104i. It will be noted that the PUFs can calculate their responses in parallel (i.e., each at the same time) or in series (i.e., one after the other).

[0061] In step E13, each electronic component 104i sends its individual response R; to the computer 102. A set of individual responses (Rb..., Rn) from the corresponding set of electronic components 1041,1042,.. .,104i,.. .,104n is thus sent to the computer 102.

[0062] In step E14, after retrieving the set of individual responses (Rb..., Rn) from the set of electronic components 104, the computer 102 is configured to bijectively compare the set of individual responses (Ri,..., Rn) to a set of expected individual responses (R'i,..., R'n) specific to the challenge C and to the set of electronic components 104. The set of expected individual responses (R'b..., R'n) is previously recorded in the memory device 106.

[0063] This first embodiment has a simple architecture and the electronic components remain intrinsically simple without requiring additional functionalities. On the other hand, in the case of a very large number of electronic components, this system may possibly request a relatively large enrollment database.

[0064] [Fig.5] illustrates a diagram representing the steps implemented during authentication of a set of electronic components by the electronic system, according to a second embodiment of the invention.

[0065] Steps E21-E23 are identical to those of steps E1 1-E13 of the first embodiment relating to [Fig.4].

[0066] In step E24, the computer 102 retrieves the set of individual responses (Ri,..., Rn) from the set of electronic components 104. Using a predetermined function f, the computer 102 is configured to calculate a group response Rg based on the set of individual responses Rg=f(Rb..., Rn). For example, the predetermined function f may be one of the following functions: bitwise exclusive-or (XOR), concatenation, hash, encryption, addition, etc.

[0067] In step E25, the calculator 102 is configured to compare the group response R g to an expected group response R'g previously stored by the memory device 106. Thus, the calculator 102 interrogates the enrollment database only once instead of a set of times in a row and consequently, reduces the processing time while minimizing the size of this database.

[0068] For example, the PUFs of the various electronic components 104 may be enrolled by the manufacturer of the hardware which also provides the group responses. This allows the manufacturer to control the integrity of the electronic components 104.

[0069] [Fig.6] illustrates a diagram representing the steps implemented during authentication of a set of electronic components by the electronic system, according to a third preferred embodiment of the invention.

[0070] According to this third embodiment, a specific electronic component among the set of electronic components 104 is configured to have a set of responses explicitly or implicitly representative of the set of individual responses from at least a portion of the electronic components 104. In this case, the specific electronic component is configured to calculate a group response based on the set of responses. The specific electronic component transmits the group response to the calculator, which is configured to compare the group response to an expected group response.

[0071] It will be noted that the set of responses provided by the specific electronic component may comprise at least one intermediate group response. The intermediate group response is calculated by at least one other electronic component as a function of its own individual response and a subset of individual responses from a corresponding subset of electronic components.

[0072] The process according to [Fig.6] refers to the particular case where the specific electronic component has all the individual responses from which it calculates a group response. In this embodiment, the specific electronic component is referenced by 1041 in [Fig.6].

[0073] More particularly, in step E31, the computer 102 retrieves from the memory device a challenge C which is common to all the electronic components 104 to be authenticated. Indeed, the computer 102 knows which electronic components 104 make up the set, it can therefore select a challenge C for which the individual responses to the electronic components 104 to be authenticated are known. Thanks to a predetermined function f, the computer 102 is configured to calculate an expected group response R'g as a function of the expected individual responses R'g=f(R'i,..., R'n ). For example, the predetermined function f can be an exclusive-or, a concatenation, a condensate, an encryption, an addition, etc.

[0074] In step E32, the computer 102 is configured to transmit the single challenge C to the specific electronic component 1041, called the first electronic component 1041, which calculates, using its PUF, the individual response Ri that it temporarily stores. The latter then transmits the same challenge to the second electronic component 1042. The second electronic component 1042 calculates, using its PUF, the second individual response R2 that it retransmits to the first electronic component 1041. In addition, the second electronic component 1042 then transmits the same challenge C to the third electronic component 1043 and so on. This step is repeated on each electronic component 104i. The last electronic component 104n calculates, using its PUF, the last individual response Rn that it retransmits to the first electronic component 1041.

[0075] In step E33, the first electronic component 1041 centralizes the individual responses Rb.. .,Rn of the set of electronic components 104 from which it calculates the group response Rg=f(Ri,.. .,Rn), which it then sends to the calculator 102.

[0076] It will be noted that according to a particular embodiment, the set of responses provided by the specific electronic component may comprise at least one intermediate group response calculated by at least one other electronic component. This intermediate group response may be calculated by said at least one other electronic component as a function of its own individual response and a subset of individual responses from a corresponding subset of electronic components. However, in the remainder of the description relating to [Fig. 6], it is considered that the specific electronic component 1041 has the individual responses Ri,...,Rn.

[0077] In step E34, the computer 102 is configured to compare the group response R g with the expected group response R'g previously recorded in the memory device 106. If the two responses coincide, the system will have been able to authenticate the set of electronic components 104.

[0078] This third embodiment makes it possible to minimize the consumption of querying the enrollment database and allows the computer 102 to minimize the time by only querying the specific electronic component 1041 to have the group response. Furthermore, a possible attack against the computer 102 will not succeed in modifying the calculation of the group response.

[0079] [Fig.7] illustrates a diagram representing the steps implemented during a authentication of a set of electronic components by the electronic system, according to a fourth preferred embodiment of the invention.

[0080] Step E41 is similar to step E31 of [Fig.6] in which the computer 102 retrieves from the memory device a challenge C which is common to all the electronic components 104 to be authenticated.

[0081] In step E42, the calculator 102 is configured to transmit the single challenge to the first electronic component 1041, which calculates, using its PUF, the individual response Ri that it temporarily stores. The latter then transmits the same challenge to the second electronic component 1042. The second electronic component 1042 calculates, using its PUF, the second individual response R2 that it temporarily stores, and so on.

[0082] In step E43, each electronic component 104i transmits its own individual response R to all the other electronic components 104 so that each electronic component 104i has all the individual responses (Ri,...,Rn) allowing it to calculate the overall response.

[0083] In step E43, each electronic component 104i centralizes the responses indi individual RB.. .,Rn of the set of electronic components 104 from which it calculates the overall group response Rg=f(Rb.. .,Rn).

[0084] In step E44, each electronic component 104i can transmit its group response Rg to the computer 102.

[0085] In step E45, the computer 102 can individually verify the group response Rg with all the authenticated electronic components 104 by comparing the group response Rg with the expected group response R'g. Thus, in the event of unavailability of an electronic component, the computer can use the group response coming from another available electronic component.

[0086] [Fig.8] very schematically illustrates an electronic authentication system, according to a particular embodiment of the invention.

[0087] This figure differs from [Fig.l] in that the electronic system 100 also takes into account the authentication of a user 107.

[0088] Thus, the electronic system 100 comprises a computer 102, a set of electronic components 104 and a memory device 106. In [Fig.8], the user is designated by the reference 107.

[0089] According to a particular exemplary embodiment, at least one of the electronic components 104 is an electronic identification component, corresponding to a biometric sensor such as for example a fingerprint sensor. Here, the electronic identification component is designated by the reference 104n.

[0090] This at least one electronic identification component 104n or biometric sensor may be part of an electronic device also including the other electronic components 104 and the calculator 102 and with which the user 107 is intended to authenticate or be authenticated. The electronic device may correspond to a smartphone, or an electronic watch connected to the Internet, or extended reality glasses connected to the Internet, or a connected vehicle. According to another example, the set of electronic components and the calculator may be part of a set of electronic devices worn or used by the user such as a smartphone, and / or a connected electronic watch, and / or connected glasses, etc. The set of electronic components and the calculator may also be part of a set of electronic devices corresponding to a set of equipment in a vehicle.In yet another example, electronic components may correspond to memories held in a PCB printed circuit board.

[0091] The two-to-two challenge-response mutual authentication of the electronic components has been described above with reference to Figs. 3-7. The challenge-response authentication of the user implemented by the system 100 is described below.

[0092] Before performing user authentication 107, a user enrollment is first implemented. This user enrollment is for example obtained by carrying out different measurements by the electronic identification component (biometric sensor) 104n and by recording in the memory device 106 the response data corresponding to these user authentication measurements 107.

[0093] [Fig.9] illustrates a diagram representing the steps implemented during a authentication of a user by the electronic system, according to a preferred embodiment of the invention.

[0094] The process of authenticating the user 107 can continue after the authentication of all the electronic components 104 including that of the electronic identification component 104n has been previously carried out according to any one of the preceding embodiments of [Fig.3]-7.

[0095] At this stage, in step E51, the electronic system 100 is configured to call upon a first encryption key Ki to form a secure link between the computer 102 and at least one electronic identification component 104n. The computer 102 calculates the first encryption key Kb for example with a condensate function h taking as parameter the unique challenge C and the individual response Rn of the electronic identification component 104n (Ki=C, Rn). This function h performs for example a concatenation of the data C and Rn and a condensate function for example of SHA-256 type. In [Fig.8], the secure link formed between the computer 102 and the electronic identification component 104n and calling upon the first encryption key Ki is symbolically designated by the reference 118.Thus, after authentication of the electronic identification component 104n, the data exchanges between the electronic identification component 104n and the computer 102 can be carried out via the secure link 118.

[0096] In step E52, the computer 102 retrieves user challenge data 107, called Cu, stored in the memory device 106 and forming part of the valid identification data of the user 107 obtained previously during the user's enrollment. For example, in the case of an electronic identification component 104n corresponding to a fingerprint sensor, the user challenge data Cu may correspond to a signal controlling the illumination of the user's finger by the electronic identification component 104n.

[0097] In step E53, the computer 102 is configured to transmit the user challenge data Cu to the electronic identification component 104n using the secure link 118, i.e. by encrypting this data with the first encryption key Ki. In [Fig.9], the data Cu encrypted with the key Ki is called EKi(Cu).

[0098] In step E54, the electronic identification component 104n decrypts the received message Eki(Cu) to reconstruct the unencrypted data Cu.

[0099] In step E55, the electronic identification component 104n carries out a measurement user authentication 107.

[0100] In step E56, the measurement response, called R( in [Fig.9], corresponding to the authentication measurement of the user 107 by the electronic identification component 104n, is sent from the electronic identification component 104n to the computer 102 via the secure link. For this transmission, the data of the measurement response R( are encrypted using the first encryption key Ki, these encrypted data being called EKi(Ru) in [Fig.9].

[0101] In step E57, the response of the measurement Ru is deciphered by the computer 102, then compared to an expected identification response R'u previously stored by the memory device 106. The user 107 is authenticated as being valid if the response of the measurement Ru corresponds to the expected identification response R'u of the user. Thus, by transitivity, the fact that the electronic identification component 104n already validated has authenticated the user 107, guarantees that all the electronic components 104 carry out their measurements on the same user 107.

[0102] After the challenge-response type authentication of the user 107, a second encryption key K2 can be calculated by the computer 102 from the user's challenge data Cu and the user's measurement response data Ru, for example with the hash function h taking the data Cu and RG as parameters. Thus, the computer 102 and the electronic identification component 104n share a key Ki specific to the pair formed by the electronic identification component 104n and the computer 102 and a key K2 specific to the user / computer pair.

[0103] A third encryption key K3 can then be calculated from the first K and second K2 encryption keys and shared between the computer 102 and the electronic identification component 104n. This third key K3 is for example obtained by producing a condensate of the concatenated first and second keys Kb K2, or by carrying out an “exclusive or” type operation between the two keys K2. Other ways of calculating the key K3 are possible. The calculated third key K3 can then be used to exchange encrypted data between the electronic identification component 104n and the computer 102, and guarantee the confidentiality of the data in the processing chain of the system 100. The third key K3 can be used to encrypt the stored data from the electronic identification component 104n, this key K3 therefore being required to decrypt the encrypted data from the electronic identification component 104n.

[0104] In a particular embodiment, the computer 102 can use a correcting code in order to be able to regenerate the encryption key used to encrypt the data exchanged between the electronic identification component 104n and the computer 102, in the event of disturbances. For example, an element of the “helper data” type can be included in the computer 102 and the electronic identification component. 104n to be able to correct the extracted data in the event of a disturbance.

[0105] In the computer 102, it is possible for a secure routine to be executed to interface the computer 102 with the electronic identification component 104n and then generate the encryption key K3 securely. The use of a secure enclave of the “Trust Execution Environment” (TEE) type can thus allow the generation, storage and use of this key securely. In the electronic identification component 104n, a dedicated digital circuit can be associated in an integrated circuit of the electronic identification component 104n to extract the authentication data and generate the encryption key K3 which is stored in an internal register or a secure memory of the electronic identification component 104n.

[0106] The electronic system 100 can be configured to implement, periodically or not, and after a first challenge-response type authentication of the user:

[0107] - another challenge-response type authentication of the electronic component identification component 104n, wherein the response data of the electronic identification component 104n are intended to be generated by the PUF of the electronic identification component 104n, and / or

[0108] - another challenge-response authentication of the user, during which the data exchanged between the calculator 102 and the electronic identification component 104n are encrypted using the first encryption key Ki or another encryption key calculated from the challenge data of the electronic identification component 104n and the response data of the electronic identification component 104n generated obtained during said other challenge-response type authentication of the electronic identification component 104n.

[0109] Thus, the security of the system 100 is improved because the authenticity of the electronic identification component 104n and / or of the user is verified again after the first authentication of the user.

Claims

Claims

1. Electronic authentication system comprising a computer (102), a memory device (106) connected to the computer (102), and a set of electronic components (104), the computer (102) and the electronic components (104) are connected to each other by direct or indirect links according to a predetermined configuration, each of the electronic components (104) being provided with a PUF intended to apply a challenge-response type authentication protocol, characterized in that the electronic system is configured to broadcast a single challenge (C) to the set of electronic components (104),and in that the calculator (102) is configured to receive in return from the set of electronic components at least one response (Rc) allowing it to verify the integrity of this set of electronic components (104) by comparing said at least one response to at least one expected response (R'c) previously stored in the memory device (106), the integrity of the set of electronic components (104) being authenticated as being valid if said at least one response (Rc) and said at least one expected response (R'c) coincide.,

2. System according to claim 1, characterized in that the calculator (102) is configured to retrieve a set of individual responses (Ri,..., Rn) from said set of electronic components (104) and to compare it bijectively to a set of expected individual responses (R'i,..., R'n) specific to said challenge (C) and to said set of electronic components.

3. System according to claim 1, characterized in that the calculator (102) is configured to: -recover a set of individual responses from said set of electronic components, -calculate a group response based on said set of individual responses, -compare said group response to an expected group response.

4. System according to claim 1, characterized in that a specific electronic component among the set of electronic components is configured to have a set of responses representative, explicitly or implicitly, of the set of individual responses, allowing it to calculate and transmit a group response to the calculator which is configured to compare said response group response to an expected group response.

5. System according to claim 4, characterized in that said set of responses arranged by the specific electronic component comprises at least one intermediate group response calculated by at least one other electronic component.

6. System according to claim 1, characterized in that each of the electronic components is configured to have the set of individual responses allowing it to calculate and transmit a group response to the calculator which is configured to compare the group response received from any one of the electronic components to an expected group response.

7. System according to any one of the preceding claims, characterized in that the system is configured to use a first encryption key to form a secure link between the computer and at least one electronic component, called the electronic identification component, among the set of electronic components, the computer being configured to transmit a user challenge to the electronic identification component using the secure link, the electronic identification component being configured to carry out a measurement on the user by means of said user challenge and to send via the secure link the response of the measurement to the computer which is configured to compare the response of the measurement with an expected identification response previously stored by the memory device, the user being authenticated as valid if the response of the measurement corresponds to the expected identification response.

8. System according to claim 7, characterized in that the calculator is configured to calculate the first encryption key from said unique challenge and the individual response of said electronic identification component.

9. System according to claim 7 or 8, characterized in that the calculator is further configured to: calculate a second encryption key from said user challenge and said measurement response, the second encryption key being shared between the calculator and the electronic identification component, calculate a third encryption key from the first and second encryption keys, the second encryption key being shared between the calculator and the electronic component identification, exchange encrypted data between the electronic identification component and the computer using the third encryption key.

10. Electronic system according to one of the preceding claims, in which the memory device comprises a database remote from the set of electronic components and the computer.

11. Electronic system according to one of the preceding claims, in which the set of electronic components and the calculator form part of an electronic device corresponding to a smartphone, or an electronic watch connected to the Internet, or extended reality glasses connected to the Internet, or a vehicle.

12. Electronic system according to one of claims 1 to 10, in which the set of electronic components and the calculator are part of a set of electronic devices carried or used by the user.

13. Electronic system according to one of claims 1 to 10, in which the set of electronic components and the computer are part of a set of electronic devices corresponding to a set of equipment in a vehicle.

14. Electronic system according to one of claims 1 to 10, in which the electronic components correspond to memories held in a PCB printed circuit.

15. Challenge-response type authentication method, implemented in an electronic system according to one of the preceding claims.

Citation Information

Patent Citations

  • Multi-PUF authentication from sensors and their calibration

    US20190312740A1