Destructive read-only memory-based tamper-evident container and its verification method
The DeRM technology addresses vulnerabilities in existing tamper-proof systems by using destructive read memory elements to ensure data integrity and confidentiality, making unauthorized access detectable and preventing replication, thereby enhancing digital data security during transit.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- UNIV OF HERTFORDSHIRE HIGHER EDUCATION CORP
- Filing Date
- 2021-08-19
- Publication Date
- 2026-05-20
AI Technical Summary
Existing tamper-proof technologies for securing digital data in transit are vulnerable to interception and replication, as they rely on physical destruction and human verification, which is prone to insider attacks and post-audit difficulties.
A tamper-evident container using destructive read memory (DeRM) elements that ensure data integrity by making unauthorized access detectable through irreversible changes, eliminating the need for human verification and ensuring data confidentiality through machine-executed cryptographic procedures.
The DeRM technology provides robust digital security by making unauthorized access detectable and preventing data replication, thus enhancing the security of digital data transmission by ensuring only authorized access and maintaining data confidentiality.
Smart Images

Figure 0007863088000010 
Figure 0007863088000011 
Figure 0007863088000012
Abstract
Description
[Technical Field]
[0001] The present invention relates to a probabilistically digital tamper-proof container for data, a method for loading data into the container, and a method for subsequently reading data from the container and simultaneously verifying that the data loaded into the container has not been read before. [Background technology]
[0002] The movement of a secret from one physical location to another represents the period of greatest exposure in the lifespan of confidential information. In this case, confidentiality is at its greatest risk. Fixed defenses such as locked physical doors, surveillance cameras, security guards, and other forms of physical access control become significantly less effective when the container carrying the secret moves outside the security perimeter of the parties involved in maintaining its confidentiality.
[0003] The physical protection of secrets in transit has not changed much over the centuries. What has changed is the relative importance of tamper evident compared to tamper-proof protection. This is because content physically transported from place to place now tends to be random digital data, and random digital data becomes worthless if stolen unless the content is copied in a way that neither the sender nor the recipient is aware that a copy has been made. If it can be reliably confirmed through reasonably costly inspection that there is no copy access to the data, then truly confidential information can be transmitted digitally through open channels, using that data as a key for strong symmetric encryption. At present, decrypting such encryption is incomparably more time-consuming and expensive than breaking the physical hard shell of whatever the content can be transported between the parties.
[0004] Despite these circumstances, highly secure, tamper-evident packaging remains in high demand, and this packaging still relies, as it has for centuries, on a physical shell manufactured to be as shatterable and unreplicable as possible. The former means that if the shell is penetrated to access the content, it will be significantly destroyed, or "shattered," and the latter means that a shattered shell cannot be undetected as a clone, or a counterfeit copy of the original shell.
[0005] In real-world situations, there is a third factor that relies even more heavily than the two technical elements mentioned above: transport security. Packages are transported by couriers, and armed guards if necessary, and couriers are trusted to prevent any access to the packages while they are in transit.
[0006] None of the three factors provide security as strong as that of cryptographic procedures executed automatically by a machine. Perhaps the biggest vulnerability of all is that it is almost impossible for the recipient to determine with 100% certainty the authenticity of the shell and whether or not the shell has been destroyed. Post-audit of the protocol is difficult because the shell needs to be destroyed anyway in order to retrieve the message; that is, if the package is successfully broken, the recipient may determine that the shell is intact and may not be able to determine that the shell was already destroyed when the shell was destroyed and the message was retrieved.
[0007] The authenticity of the shell requires investigation by an expert who cannot be considered to be within the technical capabilities of the recipient (the expert could be an agency, law firm, or other unit that does not possess expertise in forgery techniques). If the recipient hires a non-local expert, they expose themselves to a simple insider attack, thereby allowing the original package to be intercepted, destroyed, read, and then repackaged into an imperfectly cloned shell, enough to convince a legitimate recipient who is not an expert. The corrupted forged shell is then intercepted en route to the expert and replaced with the original corrupted shell by the same intruder. In this scenario, the insiders are not at all vulnerable to post-hoc detection if they succeed in convincing a legitimate recipient.
[0008] Publicly available tamper-proof shell technologies are exemplified by the following patents:
[0009] U.S. Patent No. 5918983 (CONTROL PAPER CO INC) describes a security envelope for transporting valuable documents and articles, which includes a thin header formed of a thin, brittle material fixed to a back panel having an adhesive layer that seals the header to the front panel when folded and pressed closed. The inner layer of adhesive on the inner surface of the back panel seals the inner front and back panel surfaces to close the envelope compartment and extends further toward the bottom of the envelope than the header adhesive layer when sealed, preventing access of tampering tools to the envelope compartment. When tampering heat is applied, it causes the header to shrink, and sufficient cold heat to release the inner adhesive layer causes pieces of the outer adhesive layer to separate and peel off. Printed markings and a clear flood coat on the inner surface of the header adhere to the header adhesive layer and help indicate any tampering attempts.
[0010] U.S. Patent No. 5,788,377 (UNIFLEX) describes a tamper-proof envelope comprising a first panel and a second panel joined together to define opposing side and bottom edges of the envelope. Each panel has an upper edge that together defines an opening opposite the bottom edge of the envelope to allow access to the inside of the envelope. The upper edge of the second panel extends beyond the upper edge of the first panel to define a panel extension. A layer of adhesive sealant material is placed on the inner surface of the first panel adjacent to the upper edge of the first panel to seal and bond to the inner surface of the second panel. The sealant material has adhesive properties that withstand release at substantially below room temperature. The envelope also includes an adhesive seal strip having a lower part attached to the outer surface of the first panel and an upper part positioned to seal and bond to the panel extension of the second panel.
[0011] U.S. Patent No. 5,108,194 (RADEN DAVID T) describes a closure system for a plastic security bag comprising an access opening with a cellophane carrier film containing an adhesive that regulates access to the closure system. The film is attached to the bag below the lower edge of the access opening and has a “hot melt” band along it. When the releasable liner is removed, the carrier film is positioned so that the “hot melt” spans the access opening and closes it. A lacquer coating on the edges of the opening prevents the releasable liner from adhering undesirably to the security bag. The edges of the access opening are “heat sealed” and, in cooperation with the adhesive, prevent leakage of liquid through the closed opening. Access to the bag is achieved by appropriately tearing the carrier film and / or the bag, which is evident to the observer.
[0012] U.S. Patent Application Publication No. 20050036716 (AMPAC PLASTICS LLC) describes a security bag having a tamper-evident function that can be directly incorporated into the bag during manufacturing without requiring conventional tamper-evident tape. Before processing the bag to improve ink retention properties, a release agent is selectively applied to the bag in the form of a pattern message or a void message. After processing, an ink layer is applied over the release agent. An adhesive layer is applied to the bag to seal the opening of the bag and at least in the area that comes into contact with the ink layer when the bag is sealed. When the bag is opened again after the initial sealing, each portion of the ink layer applied over the release agent is retained by the adhesive, and the remainder of the ink layer is retained on the processed surface of the bag.
[0013] U.S. Patent No. 5,631,068 (TRIGON PACKAGING CORP) describes a tape or label for sealing containers, which provides visual evidence if the seal is pried open or cooled below its break temperature. The tape comprises a plastic strip, a layer of ink printed on the surface of the plastic strip, and a layer of pressure-sensitive adhesive. The tape can be incorporated into a bag to close and seal the bag. The tape includes an ink layer sandwiched between the plastic strip and the adhesive layer. The adhesive can be used to secure each part of the bag to close and seal the bag. If the seal is pried open, the ink layer visibly peels away from the plastic strip. The adhesive layer and the plastic strip are selected to have different shrinkage rates when cooled so that the ink layer peels off when the tape cools below its break temperature. In an alternative embodiment of the tape, two ink layers are printed on the plastic strip. The first ink layer is transparent and is patterned on an untreated plastic strip. The second ink layer is opaque and is printed evenly on the plastic strip and the transparent ink after the plastic strip has been processed.
[0014] U.S. Patent No. 4,449,631 (Level Bar Alvin, Level Bar Tank) describes a resealable package for pharmaceuticals and other products that immediately reveals the presence of tampering. The package consists of a sealed envelope of thermoplastic film with a printed contour, and the package is sealed along the printed contour. After sealing, the film shrinks, making it prone to expanding the sealed area due to trapped air. If the package ruptures, the expansion is lost. If the package is cut in the sealed area, it is impossible to reseal the package without visual guidance caused by irregularities within the printed area.
[0015] If the secret is digital, it still requires an opaque physical container / conduit to any information reader until it is unlocked by an authenticated recipient. If the container is a communication line, the secret must usually be encrypted to prevent eavesdropping on the line. This doesn't solve the problem, because now another secret, the encryption key, must be transmitted to the recipient, which also requires further encryption. Public-key cryptography is currently the best solution to ensure that the secret does not need to be moved, but public-key cryptography is generally vulnerable to quantum computing attacks. [Prior art documents] [Patent Documents]
[0016] [Patent Document 1] U.S. Patent No. 5918983 [Patent Document 2] U.S. Patent No. 5788377 [Patent Document 3] U.S. Patent No. 5108194 [Patent Document 4] U.S. Patent Application Publication No. 20050036716 [Patent Document 5] U.S. Patent No. 5631068 [Patent Document 6] U.S. Patent No. 4449631 [Overview of the project] [Problems that the invention aims to solve]
[0017] According to a first aspect of the present invention, a tamper-evident container is provided comprising one or more destructive read memory (DeRM) elements configured to store content, wherein each of the one or more DeRM elements is configured such that the content stored by each of the one or more DeRM elements is greater than the content revealed when each of the one or more DeRM elements is destructively read. [Means for solving the problem]
[0018] This configuration means that an interceptor cannot read a significant portion of the container's content without destroying more content than would be revealed by reading it. Restoring the content to its previous state would require knowledge of all the destroyed content, including what was not revealed.
[0019] A destructive read memory (DeRM) element is one in which the process of reading the memory destroys the memory's contents. A write-back mechanism can be provided for DeRM elements, and if it is determined that continued access to the retrieved data is permitted, the write-back mechanism writes the data back when the data is read destructively from memory; in this case, it is preferable that no write-back mechanism is provided.
[0020] The present invention provides a completely digital tamper-proof technology, which in one embodiment can be a microelectronic in the form of a memory chip in which the data of individual bits is protected from being read, thereby leaving a noticeable trace of any interceptor's act of reading any significant number of bits. Thus, non-replicability and shatterability are achieved on a nanometer scale. This makes it possible for technology providers to eliminate the human element from all protocols and to place a security boundary around the machine that writes messages to such chips or reads and verifies the data contained in such chips.
[0021] Preferably, the container comprises a physical container. The container can be electronically based, optical, chemical, or micromechanics based. Preferably, the container comprises a physical container that holds digital data within the container.
[0022] Preferably, the container has sufficient storage capacity for practical purposes, for example, this capacity can range from several megabytes to more than one terabyte, and is preferably arranged in such a way that it is impractical or uneconomical to obtain access to all or nearly all individual storage elements other than through the erase and challenge mechanisms described below.
[0023] Preferably, the container is configured to carry or transport digital data between the sender and the recipient.
[0024] Preferably, the container comprises an array of multiple DeRM elements.
[0025] Preferably, each of the one or more DeRM elements comprises one or more DeRM cells.
[0026] Preferably, each of one or more DeRM elements comprises multiple DeRM cells.
[0027] In one alternative example, each of one or more DeRM elements contains three DeRM cells.
[0028] In one alternative example, each of one or more DeRM elements comprises three or more DeRM cells.
[0029] In one alternative example, each of one or more DeRM elements contains four DeRM cells.
[0030] Preferably, each of one or more DeRM elements is configured to be either erased only during manufacturing or repeatedly erased by the user of that element. In the former case, the container can be used to transmit secrets only once.
[0031] Preferably, each of one or more DeRM elements is configured to be challenged.
[0032] Preferably, each of one or more DeRM elements is configured to be challenged by supplying the container with the address of each of the one or more DeRM elements and a digital value from a set of limit values (for each address).
[0033] Preferably, each of one or more DeRM elements is configured to be challenged by supplying the container with the address of each of the one or more DeRM elements and a digital value from a set of limit values for each address.
[0034] Preferably, the address is in the same format as that used in conventional memory.
[0035] Preferably, if each DeRM element comprises three DeRM cells, the limit value set includes 110, 101, and 011.
[0036] Preferably, each of one or more DeRM elements comprises an encoder and an aggregator.
[0037] Preferably, the encoder is configured to convert a 2-bit challenge code into a 3-bit challenge in which the DeRM element is selected from a set of limit values having three DeRM cells.
[0038] Preferably, the encoder is configured to convert a 3-bit challenge code into a 4-bit challenge in which the DeRM element is selected from a set of limit values having 4 DeRM cells.
[0039] Preferably, the aggregator is positioned to allow a single output from the DeRM element.
[0040] Preferably, the container has a clock signal, and the challenge is detected at the edge of the clock signal.
[0041] The challenge preferably causes each of one or more DeRM elements to perform two actions simultaneously, i.e. a. Modify the content of the DeRM element based on the content of the DeRM element and the challenge value. b. Output a 1-bit signal response indicating whether the new content is different in any way from what was there before the modification. If the response indicates that the new content is different, this is a difference (1) response; otherwise, the response is a match (0).
[0042] In this way, there is an output for each of one or more DeRM elements.
[0043] Preferably, the challenge causes each of the DeRM elements themselves to perform the two actions simultaneously, rather than any external interface outside of each of the DeRM elements.
[0044] Preferably, each of one or more DeRM elements is configured to have valid content written to it by challenging the DeRM element with some or all of the content to be written to it.
[0045] In one alternative example, each of one or more DeRM elements is configured to have valid content written to it by repeatedly challenging the DeRM element with some or all of the content to be written until all of the content has been written.
[0046] In one alternative scenario, the DeRM element is erased before any part or all of the content to be written to it is challenged. In another alternative scenario, the DeRM element is already erased during manufacturing and cannot be erased again.
[0047] Preferably, each of one or more DeRM elements follows the following steps, namely: 1. The step of erasing the DeRM element (unless the element was erased during manufacturing and cannot be erased again), then optionally, 2. A step to challenge some or all of the content to be written to the DeRM element, and then optionally, 3. Repeat step 2. By executing this, the DeRM element is configured to have valid content to be written to.
[0048] Preferably, each of the one or more DeRM elements is configured such that the content of the DeRM element cannot be read by any means other than challenging it, for example, preferably, each of the one or more DeRM elements is configured such that the content of the DeRM element cannot be read by tampering with the container interface.
[0049] Preferably, each of one or more DeRM elements is configured to output a 1-bit match / difference response only when challenged.
[0050] Preferably, each of one or more DeRM elements is configured not to output any information other than a 1-bit match / difference response when challenged.
[0051] Preferably, each of one or more DeRM elements is configured to contain more information than the response to any given challenge would yield, preferably the additional information is irreversibly destroyed for at least one challenge value, and which challenge value causes such information loss preferably depends on the content stored in the challenged DeRM element. For example, if each DeRM element has three DeRM cells, challenging content 011 with challenge 011 (leading to a "match" response) would not cause any state change or information loss, whereas challenging content 011 with challenge 110 would shift the content to 111 (leading to a "difference" response), thus destroying the information that the initial content was 011 and not 101.
[0052] Preferably, when each of one or more DeRM elements comprises multiple DeRM cells, a destructive read can reveal that one of the DeRM cells comprising the DeRM element has changed state, but does not disclose which DeRM cell it was.
[0053] Preferably, each of one or more DeRM elements is configured such that any challenge value that triggers a different response destroys some information within the process. Therefore, retrieving the content of each of the one or more DeRM elements preferably requires the recipient to obtain additional information that replaces the information destroyed by the challenge before any of the one or more DeRM elements are challenged. This additional information is called information deficit.
[0054] For example, in a particular embodiment, if a DeRM element contains the values 110, 101, or 011, a challenge with the value 110 would result in a different response that does not indicate whether the content of the DeRM element was 101 or 011, and the previous content is destroyed by the challenge and therefore cannot be challenged again. However, if the recipient was publicly informed by the writer that the content was either 110 or 011 before the challenge was issued, a challenge with either 110 or 011 would reveal the correct content to the recipient but not to a third party.
[0055] Another consequence of combining destructive readout and information depletion is that by positioning a signal probe directly above the physical memory element with feature-size precision, physical intervention within the container to read the contained data and copy it to the same container is disabled unless the intrusion is unable to isolate and measure the state of all or nearly all individual memory elements (bits) comprising one or more DeRM cells in the container.
[0056] This makes it possible to mass-produce containers because they do not need to be individualized for the purpose of detecting tampering.
[0057] A second aspect of the present invention provides a method for loading data into a container of the first aspect of the present invention, preferably by challenging each of the DeRM elements with some or all of the content to be written.
[0058] In one alternative example, each of one or more DeRM elements is configured to have valid content written to it by repeatedly challenging each DeRM element with some or all of the content to be written until all of the content has been written.
[0059] In one alternative, each DeRM element is erased before it is challenged with some or all of the content that is to be written to it. In another alternative, each DeRM element is already erased during manufacturing and cannot be erased again.
[0060] As an alternative example, a method for loading data into a container involves the following steps for each of one or more DeRM elements: 1. The step of erasing the DeRM element (unless the element was erased during manufacturing and cannot be erased again), then optionally, 2. A step to challenge some or all of the content to be written to the DeRM element, and then optionally, 3. Repeat step 2. This includes performing the following actions sequentially.
[0061] Preferably, each of one or more DeRM elements is challenged by supplying the container with the address of each of the one or more DeRM elements and a digital value from a set of limit values (for each address).
[0062] Preferably, each of one or more DeRM elements is challenged by supplying the container with the address of each of the one or more DeRM elements and a digital value from a set of limit values for each address.
[0063] Preferably, the address is in the same format as that used in conventional memory.
[0064] Preferably, if each of one or more DeRM elements comprises three DeRM cells, the limit value set includes 110, 101, and 011.
[0065] Preferably, the container has a clock signal, and the challenge is detected at the edge of the clock signal.
[0066] The challenge preferably causes each of one or more DeRM elements to perform two actions simultaneously, i.e. a. Modify the content of the DeRM element based on the content of the DeRM element and the challenge value. b. Output a 1-bit signal response indicating whether the new content is different in any way from what was there before the modification. If the response indicates that the new content is different, this is a difference (1) response; otherwise, the response is a match (0). In this way, there is an output for each of one or more DeRM elements.
[0067] Preferably, the challenge causes each of the DeRM elements themselves to perform the two actions simultaneously, rather than any external interface outside of each of the DeRM elements.
[0068] Preferably, the method for loading data into the container is the following steps, namely 1. (In information-theoretic terminology) The step of expanding a secret bit sequence using random fillers that are equivalent to information deficient. 2. The sender sends information to the recipient via a side channel about which of the possible challenges will reveal the secret bit string and destroy the filler (rather than destroying some of the information in the secret bit string). This facilitates the transmission of secret bit sequences from the sender to the recipient. In a particular embodiment of the present invention, if the method for loading data into a container includes the steps described in procedure CFP1 or CFP2 below, each of one or more DeRM elements comprises three DeRM cells.
[0069] Container filling procedure CFP1 1. Before writing, the sender specifies a personal exclusion value of 011, 101, or 110 for each DeRM element that the sender is about to fill. The exclusion values are selected randomly, and the sender records their choice in a persistent storage device within the sender's security boundary. This value is excluded from the choices of values to be written to the corresponding DeRM element, leaving the other two information retention values as the only choices. The confidentiality of the exclusion value(s) is important to the security properties of the proposed method, since this confidentiality means that no interceptor (as well as a legitimate recipient before disclosure of information) would know that this property creates a lack of information sufficient to render the secrets within the DeRM container unreadable. 2. The content to be stored in the container is a sequence of binary values encoded in triplet form. The binary values form part of a secret bit sequence that is personal, persistent, and stored within the sender's security perimeter, and are never communicated in their original binary form. In one possible embodiment, the correspondence between triplet values and binary values is established using the preferred encoding rule 011<101<110, so that if any triplet is excluded, the remaining lower value encodes the value "0" and the remaining higher value encodes "1". In this way, the sender and recipient have a consistent interpretation of the content when the excluded values are known. The sender encodes the content accordingly and stores it in a temporary file, which is destroyed after CFP1 is completed. In another possible embodiment, the correspondence between triplet values and binary values is established using the cyclic coding rule 011->101->110->011, where if any triplet is excluded, the next triplet in the cycle will be coded to the value "0", and the previous triplet in the cycle will be coded to the value "1". 3. When the content is encoded, the container is erased (unless the element was erased during manufacturing and cannot be erased again), the triplet's encoded sequence is presented to it as a challenge, which effectively copies the sequence to the consecutive addresses of the DeRM container.
[0070] Container filling procedure CFP2 1. Before writing, the sender specifies a personal coded value of 011, 101, or 110 for each DeRM element that the sender is about to populate. The coded values are chosen randomly, and the sender records their selection in a persistent storage device within the sender's security perimeter. The confidentiality of the coded values is important to the security properties of the proposed method. 2. When an encoded value is selected, the container is erased (unless the element has been erased during manufacturing and cannot be erased again), the sequence of encoded values is presented to it as a challenge, and it effectively copies the sequence to a contiguous address in the DeRM container. 3. The content to be exposed by the container is a set of binary values. These binary values form part of a secret bit sequence that is personal, persistent, and stored within the sender's security perimeter, and are never communicated in their original binary form. These values may not be selected by the sender until the receipt of the container is confirmed by the recipient, for example, by using a side channel. For each binary value to be exposed, the excluded triplet value is selected according to the encoded value. In one possible embodiment, the correspondence between triplet values and binary values is established using a cyclic coding rule 011->101->110->011, where no matter which triplet is encoded, the next triplet in the cycle becomes the excluded value for exposing the binary value "1", and the previous triplet in the cycle becomes the excluded value for exposing the binary value "0".
[0071] A third aspect of the present invention provides a method for loading data into a container comprising one or more destructive read memory (DeRM) elements configured to store content, wherein each of the one or more DeRM elements is configured such that the content stored by each of the one or more DeRM elements is greater than the content revealed when each of the one or more DeRM elements is destructively read, by challenging each of the one or more DeRM elements with some or all of the content to be written.
[0072] In one alternative example, each of one or more DeRM elements is configured to have valid content written to it by repeatedly challenging each of the one or more DeRM elements with some or all of the content to be written until all of the content has been written.
[0073] In one alternative, each of the one or more DeRM elements is erased before attempting to write some or all of the content to each DeRM. In another alternative, each of the one or more DeRM elements has already been erased during manufacturing and cannot be erased again.
[0074] As an alternative example, a method for loading data into a container involves the following steps for each of one or more DeRM elements: 1. The step of erasing the DeRM element (unless the element was erased during manufacturing and cannot be erased again), then optionally, 2. A step to challenge some or all of the content to be written to the DeRM element, and then optionally, 3. Repeat step 2. This includes performing the following actions sequentially.
[0075] Preferably, each of one or more DeRM elements is challenged by supplying the container with the address of each of the one or more DeRM elements and a digital value from a set of limit values (for each address).
[0076] Preferably, each of one or more DeRM elements is challenged by supplying the container with the address of each of the one or more DeRM elements and a digital value from a set of limit values for each address.
[0077] Preferably, the address is in the same format as that used in conventional memory.
[0078] Preferably, if each of one or more DeRM elements comprises three DeRM cells, the limit value set includes 110, 101, and 011.
[0079] Preferably, the container has a clock signal, and the challenge is detected at the edge of the clock signal.
[0080] The challenge preferably causes each of one or more DeRM elements to perform two actions simultaneously, i.e. a. Modify the content of the DeRM element based on the content of the DeRM element and the challenge value. b. Output a 1-bit signal response indicating whether the new content is different in any way from what was there before the modification. If the response indicates that the new content is different, this is a difference (1) response; otherwise, the response is a match (0). In this way, there is an output for each of one or more DeRM elements.
[0081] Preferably, the challenge causes each of the DeRM elements themselves to perform the two actions simultaneously, rather than any external interface outside of each of the DeRM elements.
[0082] Preferably, the method for loading data into the container is the following steps, namely 1. (In information-theoretic terminology) The step of expanding a secret bit sequence using random fillers that are equivalent to information deficient. 2. The sender sends information to the recipient via a side channel about which of the possible challenges will reveal the secret bit string and destroy the filler (rather than destroying some of the information in the secret bit string). This facilitates the transmission of secret bit sequences from the sender to the recipient.
[0083] A fourth aspect of the present invention provides a method for verifying that data loaded into a container of the first aspect of the present invention by a method of the second or third aspect of the present invention has not been previously accessed,
[0084] 1. A sender transmits randomized confidential content contained in a container according to a first aspect of the present invention to a recipient, wherein the sender maintains a copy of the content in the sender's local secure storage device. 2. The sender establishes, via side-channel communication, that the recipient has received the container. 3. The sender reveals to the recipient, via side-channel communication, additional information regarding a subset of data from the container's contents. 4. The recipient uses additional information to retrieve a subset of the data from the container contents from step 3, 5. The recipient creates a summary of the subset of data obtained in step 4, 6. The recipient sends the summary obtained in step 5 to the sender via a side channel, 7. The sender calculates a summary of the copies of the content held in the sender's local secure storage device, 8. The sender compares the recipient's summary to the sender's summary. If the sender's summary is the same as the recipient's summary, the content has not been read by a third party; otherwise, it has been read. 9. The sender sends the results of the comparison performed by the sender in step 8 to the recipient via a side channel. 10. The recipient, at their discretion, removes any remaining information that the container may contain regarding the confidential content from the container. A method is provided that includes this.
[0085] Preferably, the side channel is authenticated. However, the side channel does not need to be personal.
[0086] In one alternative, the method includes step 2a (between step 2 and step 3), with preliminary communication between the sender and recipient via a side channel to determine additional information details as needed.
[0087] Preferably, the summary of the subset of data is an industry-standard cryptographic hash, and preferably, the industry-standard cryptographic hash cannot be reversed by a third party to learn a single bit of the original data from which it was obtained.
[0088] In one alternative example, in step 3, additional information about a subset of data from the container's contents is a series of n(A i ,X i The message to the recipient contains ) pairs, where i = 0...n-1, and n is the length of the secret bit string that the sender wants to share with the recipient at this point. The value n is assumed to be large enough to reduce the probability of guessing the bit string exactly. Typically, n ≥ 100. In each pair, A i is the address of the DeRM element, X i This is an exclusion value previously selected by the sender.
[0089] In an alternative example, in step 4, the recipient is Xi When excluded, for each i-th pair, for the container DeRM element with address A i two remaining possible triplet values {L i , H i} of one of the challenge the container content using additional information to obtain a subset of the data. Which of the two challenges is used is randomly selected by the recipient. The recipient records the output D i from the DeRM element when the challenge cycle ends. If the value D i is 0, the selected challenge will be the same as the stored information content C i . If the value D i is 1, the unselected challenge will be the same as the stored information content.
[0090] In an alternative example, in step 5, the summary of the subset of data obtained in step 4 includes an industry-standard cryptographic hash of the reconstructed bit string C.
[0091] In an alternative example, in step 6, the industry-standard cryptographic hash of the reconstructed bit string C is sent back to the sender by the recipient on the side channel to confirm the sharing.
[0092] In an alternative example, in step 9, an affirmative response is sent to the recipient on the side channel if the hash is correct, or a negative response is sent if the hash is incorrect. This does not expose the shared secret C because it is assumed that the cryptographic hash does not leak information about the preimage.
[0093] In an alternative example, in step 10, the recipient records all container positions A used in step 1 of the method iWrite 111 to it, thus surely destroying all traces of the agreed-upon shared secret within the DeRM element. The shared secret is held in volatile memory and remains valid until overwritten in this memory or until the power is turned off or the method step is repeated, whichever occurs first.
[0094] In an alternative example, in step 3, additional information regarding a subset of data from the contents of the container is a message to the recipient that includes a series of n(A i ,X i ) pairs, where i = 0... n - 1 and n is the length of the secret bit string that the sender wishes to share with the recipient at this point. The value n is assumed to be large enough to reduce the probability of accurately guessing the bit string. Usually, n ≥ 100. In each pair, A i is the address of the DeRM element and X i is either an exclusion value or the actual contents of the DeRM element with address A i . If X i is the former, the pair is called a key pair, and if it is the latter, it is called a choice pair. The greater the computing power freely available to the sender, the greater the number m < n of a series of choice pairs and the longer the time taken for the protocol. For practical purposes, for a minimum length sequence n ~ 100, having m ~ 20 would be sufficient (see below). The sender records the positions of all the choice pairs for use in step 3.
[0095] In an alternative example, in step 4, when X i is excluded, for each i-th pair, the recipient uses the additional information by challenging one of the two possible triplet values {L i} in the container DeRM element with address A i ,H i . Which of the two challenges is used is randomly selected by the recipient. The recipient records the output D i from the DeRM element when the challenge cycle ends. The value D iIf it is 0, the selected challenge is saved information content C i This is the same as the value D. i If the value is 1, the unselected challenges will have the same information content as the saved content.
[0096] In one alternative example, in step 5, the summary of the subset of data obtained in step 4 includes an industry-standard cryptographic hash of the reconstructed bit string C.
[0097] In one alternative example, in step 6, the industry-standard cryptographic hash of the reconstructed bit string C is sent back to the sender on a side channel by the recipient to confirm sharing.
[0098] In one alternative example, in step 7, the sender marks the position corresponding to the original sequence of choice pairs on the bit string C on behalf of the recipient. R Reconstruct it. Bits at such positions are unpredictable because the recipient is sent an incorrect exclusion value, and therefore the output from DeRM when challenged can be 0 or 1 depending on which of the two available challenges the recipient has chosen in each case. The sender typically has a total of 2 on the order of 1 million. m Try individual combinations.
[0099] In one alternative example, in step 8, the combination from step 7 that yields a hash value equal to the received hash value of bit sequence C from step 6 is declared correct.
[0100] In one alternative example, in step 9, an affirmative response is sent to the recipient on the side channel if a match is found, or a negative response is sent if no match is found.
[0101] In one alternative example, in step 10, the recipient receives all container locations A used in step 1 of the protocol. iWrite 111 to it, thus ensuring that all traces of the agreed-upon shared secret within the DeRM element are destroyed. The shared secret is held in volatile memory and remains valid until this memory is overwritten, or until the power is turned off or the method step is repeated, whichever comes first.
[0102] Definition: A watermark is a sequence of 111 and 000 values that begin and end with 111 and are located within a DeRM at consecutive addresses. Apart from the end marker, the triplet 111 is interpreted as binary 1, and the triplet 000 is interpreted as binary 0. The content of the watermark, interpreted as binary, is called the version value.
[0103] In one alternative example, in step 2a, additional communication from the sender to the recipient via the side channel includes the starting address. The recipient uses the starting address to retrieve the version value from the container's contents by challenging the container's starting address (with any triplet). If it is determined that the DeRM element at the address is not 111, the recipient encounters the first watermark and proceeds to the next address until this is fully read. In this alternative example, in step 2a, additional communication from the recipient to the sender via the side channel includes the watermark location and version value. The sender receives the watermark location and version value, and the sender uses a copy of the contents held in the sender's local memory to calculate additional data about a subset of the data from the container's contents by fetching L triplets from the relevant addresses of the content files held by the sender in the sender's non-volatile memory, thereby converting T v (However, v is the watermark version value, T vThe sender applies a sequence of L triplets (which is some public algorithm on which it depends) to obtain a sequence S' to be written to a container at their addresses. Using a binary content file previously saved in a non-volatile memory device (see CFP1 step 2 or CFP2 step 3 as described in a second aspect of the present invention), the sender can reconstruct the exclusion values X' that generate its content from sequence S', i.e., the sender can compute L new key pairs. The sender can also generate choice pairs by simply taking the corresponding triplets from S'.
[0104] In one alternative example, in step 3, additional information about a subset of data from the container's contents is a series of n(A i ,X i The message to the recipient contains ) pairs, where i = 0 · · · n-1, and each pair is either a key pair or a choice pair. The value n is assumed to be large enough to reduce the probability of accurately guessing the bit string. Typically, n ≥ 100. In each pair, A i is the address of the DeRM element, X i This is either an exclusion value in the case of a key pair, or address A in the case of a choice pair. i It is either the actual content of the DeRM element that has it. Since all recipients of a container generally receive different content, recipients can choose not to need choice pairs at all under the assumed threat model. It is recognized that there may be more aggressive threat models in which the use of choice pairs may still be justified.
[0105] In one alternative example, in step 4, for each i-th pair, the recipient is X i When it is excluded, address A i The container DeRM element has the remaining two possible triplet values {L i ,H iOne of the challenges is attempted. The recipient randomly selects which of the two challenges is used. When the challenge cycle is complete, the recipient receives the output D from the DeRM element. i Record the value D. i If the value is 1, the unselected challenges will have the same information content as the saved content. i If it is 0, the selected challenge is saved information content C i It will be the same as, or the saved content is 111. To distinguish between these cases, the recipient pairs L a second time with the DeRM element. i H i The challenge is then attempted with other triplet values, and after the second challenge, the output D from the DeRM element is completed. i Record this value D. i If this value D is 1, the first challenge is the same as the saved information content. i If the value is 0, the saved content is 111. The protocol fails if a watermark is detected before L triplets are read.
[0106] In one alternative example, in step 5, the summary of the subset of data obtained in step 4 includes an industry-standard cryptographic hash of the reconstructed bit string C.
[0107] In one alternative example, in step 6, the cryptographic hash of bit string C is sent back to the sender on a side channel by the recipient to confirm sharing.
[0108] In one alternative example, in step 7, the sender marks the position (if any) corresponding to the original sequence of choice pairs above with bit string C on behalf of the recipient. R Reconstruct it. The bits at those positions are unpredictable because the recipient is sent an incorrect exclusion value, and therefore the output from DeRM when challenged can be 0 or 1 depending on which of the two available challenges the recipient has chosen in each case. The sender, 2m Try all possible combinations.
[0109] In one alternative example, in step 8, any combination that yields a hash value equal to the received hash value of bit sequence C is declared correct. (If no alternative pairs are used, m=0, and only one bit sequence needs to be checked.)
[0110] In one alternative example, in step 9, an affirmative response is sent to the recipient on the side channel if a match is found, or a negative response is sent if no match is found.
[0111] In one alternative example, in step 10, the recipient receives all container locations A used in step 1 of the protocol. i Write 111 to it, thus ensuring that all traces of the agreed-upon shared secret within the DeRM element are destroyed. The shared secret is held in volatile memory and remains valid until this memory is overwritten, or until the power is turned off or the method step is repeated, whichever comes first.
[0112] Preferably, the summary of the subset of data is an industry-standard cryptographic hash, and preferably, the industry-standard cryptographic hash cannot be reversed by a third party to learn a single bit of the original data from which it was obtained.
[0113] The present invention also provides a method for obtaining evidence of tampering by a third party with a physical container that carries digital data between a sender and a recipient, wherein the evidence is reliably obtained in an automatic mode only by sending and receiving digital signals to and from the container using its signal terminal. Tampering is proven by a discrepancy in step 8 of the general method described above.
[0114] The container and its usefulness depend solely on the two fundamental properties described herein: destructive read and information depletion. The destructive read property means that an interceptor cannot read the contents of the container without the possibility of modifying the contents in the process to destroy the information. The information depletion property means that the information content stored by each of the one or more DeRM elements is greater than the information content revealed when each of the one or more DeRM elements is destructively read. This means that an interceptor cannot read a substantial portion of the contents of the container without destroying more information than would be revealed by reading it. Any attempt to restore the contents to their state before they were read, after they have been read and thus modified, is thwarted by the information depletion property, and in order to restore the contents, the interceptor needs all the information stored in the container by the sender, and this information cannot be retrieved without first supplying the portion that the sender is supposed to destroy by reading it.
[0115] One application of the present invention is to share random content so that the content is used as a shared key, including the use of a one-time pad for further confidentiality exchange between the sender and recipient over an open channel. In such a use case, failure of step 8 does not expose the confidential data. If step 8 is successful, this ensures that no third party has seen the content to be shared.
[0116] A fifth aspect of the present invention relates to data to be loaded into a container comprising one or more destructive read memory (DeRM) elements configured to store content, wherein each of the one or more DeRM elements is configured such that the content stored by each of the one or more DeRM elements is greater than the content revealed when each of the one or more DeRM elements is destructively read by challenging each of the one or more DeRM elements with part or all of the content to be written, and a method for verifying that the data has never been accessed before, 1. A sender transmits randomized confidential content contained in a container according to a first aspect of the present invention to a recipient, wherein the sender maintains a copy of the content in the sender's local secure storage device. 2. The sender establishes, via side-channel communication, that the recipient has received the container. 3. The sender discloses to the recipient, via side-channel communication, additional information regarding a subset of data from the container's contents. 4. The recipient uses additional information to retrieve a subset of data from the container contents from step 3, 5. The recipient creates a summary of the subset of data obtained in step 4, 6. The recipient sends the summary obtained in step 5 to the sender via a side channel, 7. The sender calculates a summary of the copies of the content held in the sender's local secure storage device, 8. The sender compares the recipient's summary to the sender's summary. If the sender's summary is the same as the recipient's summary, the content has not been read by a third party; otherwise, it has been read. 9. The sender sends the results of the comparison performed by the sender in step 8 to the recipient via a side channel. 10. The recipient may, at their discretion, remove any remaining information that the container may contain regarding the confidential content from the container. A method is provided that includes this.
[0117] Preferably, the side channel is authenticated. However, the side channel does not need to be personal.
[0118] In one alternative, the method includes step 2a (between step 2 and step 3), with preliminary communication between the sender and recipient via a side channel to determine additional information details as needed.
[0119] Preferably, the summary of the subset of data is an industry-standard cryptographic hash, and preferably, the industry-standard cryptographic hash cannot be reversed by a third party to learn a single bit of the original data from which it was obtained. Herein, the present invention will be described merely as an example with reference to the accompanying drawings. [Brief explanation of the drawing]
[0120] [Figure 1] This is a diagram showing a single-bit DeRM cell. [Figure 2] This figure shows a DeRM element with three DeRM cells. [Figure 3] This figure shows a DeRM element with four DeRM cells. [Modes for carrying out the invention]
[0121] Embodiments of the present invention are described below merely as examples. These examples represent the best way to carry out the present invention as currently known to the applicant, but are not the only way to achieve it.
[0122] The present invention relates to a method and implementation for obtaining a probabilistically tamper-proof (PTP) digital container for data.
[0123] The present invention does not rely on the presence of physical protection at a level beyond the level of individual memory bits, such as destructible wrapping or hard shells that are difficult to counterfeit, but the present invention can be used in connection with any combination of such physical protections.
[0124] The present invention ensures that if there is any tampering with the container, i.e., any attempt by a third party to read any sufficiently large subset of the data stored in the container, such attempt will be detected by the sender and / or recipient when the sender and recipient engage in a post-delivery verification protocol.
[0125] A destructive read-only (DeRM) memory container is a storage device that can store data without requiring external power for a period longer than the maximum time required to transport the container from the sender to the recipient. The container has one or more DeRM elements, each DeRM element containing k enumerated DeRM cells, each DeRM cell capable of storing 1 bit of data. k is a small integer, most often between 3 and 8. In one embodiment of the present invention, k = 3.
[0126] This invention utilizes DeRM containers as a technology for producing fully digital PTP containers.
[0127] One or more DeRM elements are provided, each having one or more DeRM cells, and at any given time, each of the one or more DeRM elements is in the following state, i.e., The erased state when the content of all configuration DeRM cells is 0. The filled state when the contents of a constituent DeRM cell are a mixture of 1s and 0s. The read state when the content of all configuration DeRM cells is 1. It is found individually in one of them.
[0128] The valid content of a filled DeRM element may exclude certain combinations of DeRM cell values to facilitate the maintenance of information deficits. For example, in the k=3 embodiment, the combination of values 001, 010, and 100 may be excluded to ensure 1. Any challenge to a DeRM element that results in a “different” response destroys all information contained within the DeRM element, preventing an interceptor from gradually extracting this information through a series of challenges such as 001, then 010, then 100, and 2. With knowledge of the number of DeRM cells that change the state (which an interceptor monitoring the container's power consumption can know), only one bit (match or difference) of information within the DeRM element is revealed by the output.
[0129] DeRM elements can be deleted individually or when the entire DeRM container is deleted (by the user at any time, or in some cases only once during manufacturing, not again). Failure to delete any DeRM elements will result in a technical failure that prevents the DeRM container from functioning correctly, but it will not pose a security risk.
[0130] DeRM elements can be populated with content at any time. The preferred method for populating a DeRM element with content is after it has been erased and before any other actions are performed on it. Failure to erase a DeRM element before populating it with content constitutes a technical impediment that prevents the DeRM container from functioning correctly, but does not pose a security risk. Preferably, the population hardware is designed to prevent the DeRM cell from being set to an excluded combination in order to ensure that the lack of information is maintained.
[0131] Preferably, the DeRM element is populated as a challenge with a representation of the desired content of the DeRM element by using a destructive read operation.
[0132] A DeRM element can be destructively read at any time. This operation requires a challenge to be presented to the DeRM element. A challenge is a representation of some or all of the information that can be represented by a combination of DeRM cell values. If the challenge modifies the content of the DeRM element, the challenge is said to differ. Otherwise, the challenge is said to match. In the inventors' instantiation example with k=3, the challenge could represent a guess in the content of the DeRM cell, such as 011. Two things happen in the process of destructively reading the content of a DeRM cell:
[0133] The device detects whether the challenges are different or match. In one alternative example, the device can detect this electronically, for example, by focusing on whether a floating-gate transistor (a standard building block of flash memory) is opened at a low or high control gate voltage, which is a standard technique known in the art. However, different detection methods can be used, and these methods are not unique to the present invention.
[0134] If the challenge is different and the DeRM element is in a filled state, the DeRM element is set to a read state, which means the content of all constituent DeRM cells is set to 1. If the challenge is different and the DeRM element is in a cleared state, the DeRM element is set to a filled state with content corresponding to what the challenge represents. In one example, the output of a destructive read operation is the result of the challenge, i.e., a match (0) or a difference (1).
[0135] Preferably, each DeRM element can be read repeatedly without causing technical problems.
[0136] The use of this DeRM architecture ensures that an interceptor cannot read a significant amount of data stored in a DeRM container without the recipient realizing that the data is being read, because the DeRM container is transmitted by the sender along with all associated DeRM elements within the full DeRM container. DeRM elements that are destructively read by an interceptor using different challenges immediately transition to a read state, resulting in the irreversible destruction of some of the information within those DeRM elements, which can be detected by the recipient when the DeRM element reads the data stored in it, and the recipient can then issue a tampering alert. Tampering is demonstrated by a discrepancy in step 8 of the general method described above.
[0137] The present invention is configured to protect each DeRM element individually and locally (with respect to the physical placement of protective circuits on the silicon die) to eliminate interface attacks in which an interceptor would thereby gain access to the chip, control access to memory, and then block out the interface to read, erase, and refill the data portion of each DeRM cell. Given the modern multilayer structure of silicon chips, accessing individual DeRM cells directly using a silicon-mounted microelectronic probe can be considered impossible or impractical if almost all DeRM cells need to be read in this manner. Significantly reading less than 100% (e.g., 99%) of the DeRM elements would be ineffective for an interceptor, as it may be possible to use a reversible function with an inverse bit spreading function. The sender can apply a publicly reversible function to a sequence of secret bits of a certain length L before placing it in a container. If the function is such that its inverse function has a high degree of computational bit spreading, then a change of a few bits will prevent the restoration of the original content to the point where all the resulting bits are unpredictable. Such spreading is a feature of symmetric cryptography, such as AES. Applying AES with a known key to the content before it is placed in a container makes bit alteration catastrophic for any interceptor's restoration process. These techniques allow the sender and receiver to consistently transform the content after it has been delivered in a way that critically depends on the data validity of all DeRM elements.
[0138] architecture Based on the above considerations, the following describes an implementation of a DeRM element suitable for transmitting a single secret binary value encoded in triplet format from sender to receiver.
[0139] The DeRM cell 10 shown in Figure 1 is based on a 1-bit non-volatile memory cell 12 having two inputs, namely challenge 14 and erase 16, and one output 18. The contents of the DeRM cell 10 are always asserted on output 18 as long as the DeRM cell 10 is powered. If input 14 is high when the clock 20 rises (transitions from low to high), the cell 12 transitions to state "1" and remains in that state indefinitely. The cell 12 can be erased to "0" by raising input 16 to high before the clock 20 transitions to high. The cell 12 can be implemented using a floating-gate transistor found in flash memory. However, the present invention does not require a specific implementation form; that is, any digital structure that behaves as described above can be used when implementing the present invention.
[0140] The two NOT gates 22 and AND gate 24 preceding cell 12 make it impossible to challenge and eliminate cell 12 simultaneously, regardless of what values are asserted on inputs 14 and 16.
[0141] A latch 26 is provided that is reset by the rising edge (transition from low to high) of the clock 20 before any input signal can propagate across cell 12. The output 18 of cell 12 is sent to the input 34 of latch 26 through a rising edge-pulse converter 28 (an AND gate 30 with an inverter (such as a NOT gate) 32 between its inputs). Provided the erase signal remains low, this will set latch 26 if the memory contents of cell 12 change before the clock 20 rises again (transitions from low to high). This only occurs if the challenge signal is high and the contents of cell 12 are 0. Otherwise, latch 26 remains reset.
[0142] Figure 2 shows a DeRM element 100 having three DeRM cells 10, an encoder 40, and an aggregator 50. The encoder 40 is configured to convert an input 2-bit challenge code into a 3-bit challenge, as shown in Table 1 below. In the illustrated embodiment, the encoder 40 includes an XOR gate 42, but the encoder 40 may also include different devices. The aggregator 50 is configured to enable a single output from the DeRM element 200. In the illustrated embodiment, the aggregator 50 includes an OR gate, but the aggregator 50 may also include different devices. Table 1 [Table 1]
[0143] Only three values are valid; that is, 01, 10, and 11, corresponding to three triplets, are used as challenges. A fourth value, 00, represents no challenge, which is useful for enabling one DeRM element in an array of DeRM elements by a standard decoder; that is, the enabled DeRM element will see a non-zero challenge, while the rest will receive an unaffected 00. Next, the three DeRM cells 10 are driven by the encoder 40, and finally, the outputs of the DeRM cells 10 are collected by the OR gate 50 to form the output of the DeRM element 100. Note that the state of the DeRM cell 10 conveys log23 ≈ 1.58 bits of information, but the output is strictly binary, i.e., 1 bit. Consequently, if one challenging action potentially changes the state of the DeRM cell 10, the output generated during that action does not convey enough information to determine the previous content, so the DeRM element 100 will show a lack of information in its response.
[0144] Figure 3 shows a DeRM element 200 having four DeRM cells 10, an encoder 140, and an aggregator 150. The encoder 140 is configured to convert an input 3-bit challenge code into a 4-bit challenge, as shown in Table 2 below. In the illustrated embodiment, the encoder 140 comprises a device consisting of an inverter 144 (which may be a NOT gate in one alternative example), an OR gate 146, and an AND gate 148, but the encoder 140 may comprise different devices. The aggregator 150 is configured to enable a single output from the DeRM element 200. In the illustrated embodiment, the aggregator 150 comprises an OR gate, but the aggregator 150 may comprise different devices. Table 2 [Table 2]
[0145] Only four values are valid, namely 100, 101, 110, and 111, which correspond to four triplets and are used as challenges. The other four values 0XX represent non-challenges, which are useful for enabling one DeRM element in an array of DeRM elements by a standard decoder; that is, the enabled DeRM element will see a non-zero challenge, while the rest will receive 000, which has no effect. Next, the four DeRM cells 10 are driven by the encoder 140, and finally, the outputs of the DeRM cells 10 are collected by the OR gate 150 to form the output of the DeRM element 200. Note that the state of the DeRM cell 10 conveys log24 = 2 bits of information, but the output is strictly binary, i.e., 1 bit. As a result, if one challenging action potentially changes the state of the DeRM cell 10, the output generated during that action does not convey enough information to determine the previous content, so the element will show an information deficit in its response.
[0146] Similarly, any DeRM structure exhibiting information deficiency and destructive readout is acceptable as an implementation of DeRM elements for the purposes of the present invention.
[0147] According to one embodiment of the present invention, a slow-release container (SRC) capable of providing PTP (Pressure-Through Packaging) properties is provided.
[0148] In one embodiment of the present invention, the slow-release container uses a 3-cell DeRM element for every bit of content, thus protecting each bit by information deficit. However, it is possible to use four, or even five or more DeRM cells in each DeRM element.
[0149] For example, in one embodiment where each DeRM element contains four DeRM cells, the valid values are empty: 0 (0000), filled: 7 (0111), b (1011), d (1101), e (1110), and read: f (1111), and for each DeRM element, the sender notifies the recipient of two values (e.g., e and 7) through a side channel. In this example, e represents the transmitted binary value 0 and 7 represents the transmitted value 1. A challenge with either of these values allows the recipient to determine what value the DeRM element contained.
[0150] Not only is it impossible for an interceptor to read a significant amount of content undetectably, but the interceptor cannot even reliably read it without involving the sender. Otherwise, the interceptor could read m bits of content simply by confirming a guess with an exponentially small probability of m, which means that the sender and receiver can obtain probabilistic tamper-proof protection against any desired statistical margin simply by using blocks of length L≫m.
[0151] The PTP property requires (public) bit-sensitive content postcoding, either irreversible (e.g., hashing) or reversible (e.g., encryption with a publicly available symmetric key), which must be stronger as the block length L decreases. Due to its probabilistic tamper resistance in the sense described above, slow-release DeRM containers can be used to store large amounts of secrets that are occasionally partially exposed, which can be a useful property for recipients with weak security boundaries, such as things on the Internet of Things.
[0152] Swarm protocols for use with DeRM The following describes another embodiment of the DeRM container that is particularly suitable for IoT applications (but not limited to them). The IoT security situation is unique in the following two respects: 1. The security of IoT devices is extremely weak, to the point that it undermines the concept of a fixed security boundary. The drawbacks stem from the limited computing resources of the devices, high energy costs, or both, which prevent the use of complex cryptographic algorithms with sufficiently high frequencies. If attacked, data contained in non-DeRM memory should be considered immediately compromised. 2. Physical security may also be weak, for example, if the device is located outside a controlled building on a street, rooftop, or in a remote or unmanned location. However, in other situations such as smart factories or smart hospitals, physical security may be sufficient to assume that the DeRM container is inaccessible once the device is installed. 3. IoT devices often exist in swarms of up to several thousand individual things, sharing sensitive information with a well-protected data center, but not necessarily with each other. Under such conditions, it is technically advantageous to install replicas of DeRM containers with identical or nearly identical content in all things in the swarm. This also allows supervisory agents to dynamically introduce new things at any time without expanding their secret database, and authorization is granted simply by installing a replica of a DeRM container with generic, i.e., lightly customized content.
[0153] The above situation requires the following mechanism. (i) All secrets reside within a DeRM container or in volatile memory (short-lived, small amount) that is quickly and effectively erased by the attack detection infrastructure. (ii) The DeRM container supports the slow release of sensitive data, thereby allowing the center-involved protocol to "unlock" a portion of the DeRM container's contents without exposing the rest to this agent or other agents. The protocol should be designed to run repeatedly and should not rely on any previous results.
[0154] For the sake of slow release requirements, any unused portion of the container will also be considered unreadable. It is considered impossible, or highly unlikely, for any agent to read the content anywhere with near 100% accuracy (whether leaving a noticeable trace or not) without engaging with the protocol with the center. Since the existence of an authenticated side channel is assumed, please be reminded that the requirement of engaging with the protocol automatically guarantees that the protocol is with a legitimate party.
[0155] architecture In one embodiment, the present invention uses a DeRM cell triplet that carries a 1-bit payload encoded as a combination of 3 bits, as shown in Figure 2. Specifically, the DeRM element in this instantiation includes three DeRM cells that are electronically constrained to store only the values 000, 011, 101, 110, and 111.
[0156] The three DeRM cells are read destructively simultaneously, and the outputs of these cells are ORed. When a DeRM element is erased, its content is set to 000 if the DeRM element has three DeRM cells, and the DeRM element generates a matching response to the output regardless of the state of the DeRM cells. The container is preferably a set of such DeRM elements equipped with any standard addressing mechanism that allows selecting a particular DeRM element to challenge or erase.
[0157] A challenge is the process of writing initial content to a DeRM element (after erasure), or the process of destructively examining that content (at any point after it has been written). Erasure does not need to be global, because a refill attack relies on an interceptor with complete knowledge of the content to refill the container. Note that the gate structure in Figure 2 prevents the DeRM element from being written with a triplet containing a single 1, where the single 1 is either two 1s corresponding to one of three information-holding (fill) values, namely 011, 101, and 110, or the numerical value 111 / 000, which is read value / empty value respectively. Note that the value 111 cannot be written to the DeRM element in one cycle, but this can be achieved by successively challenging the DeRM element with two of the three challenges 011, 101, and 110.
[0158] Data loading into the container after deletion can be done using one of the following methods:
[0159] Container filling procedure CFP1 1. Before writing, the sender specifies a personal exclusion value of 011, 101, or 110 for each DeRM element that the sender is about to fill. The exclusion values are chosen randomly, and the sender records their choice in a persistent storage device within the sender's security boundary. This value is excluded from the choices of values to be written to the corresponding DeRM element, leaving the other two information retention values as the only choices. The confidentiality of the exclusion values is important to the security properties of the proposed method, as this confidentiality ensures that the security properties are not known to interceptors (as well as legitimate recipients before information release) who create a lack of information sufficient to render the secrets within the DeRM container unreadable. 2. The content to be stored in the container is a set of binary values encoded in triplet format. The binary values are personal, persistent, stored within the sender's security perimeter, and never communicated in their original binary form. In one possible embodiment, the correspondence between triplet values and binary values is established using the priority encoding rule 011<101<110, where if any triplet is excluded, the remaining lower value encodes the value "0" and the remaining higher value encodes "1". In this way, the sender and recipient have a consistent interpretation of the content when the excluded values are known. The sender encodes the content accordingly and stores it in a temporary file, which is destroyed after CFP1 is completed. In another possible embodiment, the correspondence between triplet values and binary values is established using the cyclic coding rule 011->101->110->011, where if any triplet is excluded, the next triplet in the cycle will be coded to the value "0", and the previous triplet in the cycle will be coded to the value "1". 3. When the content is encoded, the container is erased (unless the DeRM element is erased during manufacturing and cannot be erased again), the triplet encoding sequence is presented to it as a challenge, and it effectively copies the triplet sequence to the DeRM element at a consecutive address in the DeRM container.
[0160] Container filling procedure CFP2 1. Before writing, the sender specifies a personal coded value of 011, 101, or 110 for each DeRM element that the sender is about to populate. The coded values are chosen randomly, and the sender records their selection in a persistent storage device within the sender's security perimeter. The confidentiality of the coded values is important to the security properties of the proposed method. 2. When an encoded value is selected, the container is erased (unless the DeRM element is erased during manufacturing and cannot be erased again), the sequence of encoded values is presented to it as a challenge, and it effectively copies the sequence of encoded values to the DeRM elements at consecutive addresses in the DeRM container. 3. The content to be exposed by the container is a set of binary values. The binary values are personal, persistent, stored within the sender's security perimeter, and never communicated in their original binary form. These values may not be selected by the sender until the receipt of the container is confirmed by the recipient, for example, by using a side channel. For each binary value to be exposed, the excluded triplet values are selected according to the encoded value. In one possible embodiment, the correspondence between triplet values and binary values is established using a cyclic coding rule 011->101->110->011, where no matter which triplet is encoded, the next triplet in the cycle becomes the excluded value for exposing the binary value "1", and the previous triplet in the cycle becomes the excluded value for exposing the binary value "0".
[0161] protocol This invention ensures that neither an interceptor nor even the recipient can reliably read a single DeRM element without knowledge of its exclusion value, and since the exclusion value is initially for the sender's personal use, it allows for the sharing of secrets. In fact, if the recipient applies any valid challenge G≠111 to a DeRM element containing a triplet T, the output D will be 0 (match) if G=T, because the DeRM cell does not change its value. If G≠T, the output will be D=1 (difference), and the content will simultaneously be T=111. The output D indicates with 100% confidence whether G=T, given that neither the content nor the challenge is equal to 111.
[0162] After the recipient notifies the sender of the container's arrival on the side channel, the recipient can read the contents by engaging in Protocol A, as described below. In some embodiments, this protocol may be applied consecutively to different address ranges, sometimes with long time delays in between (several days / weeks).
[0163] Protocol A 1. Using a side channel, the sender sends a series of n(A) i ,X i Send a message containing ) pairs to the recipient, where i = 0 · · · n-1, and n is the length of the secret bit string that the sender wants to share with the recipient at this point. The value n is assumed to be large enough to reduce the probability of accurately guessing the bit string. Typically, n ≥ 100. In each pair, A is the address of the DeRM element and X is an exclusion value previously selected by the sender. 2. For each i-th pair, the recipient is X i When it is excluded, address A i The container DeRM element has the remaining two possible triplet values {L i ,H i One of the challenges is attempted. The recipient randomly selects which of the two challenges is used. When the challenge cycle is complete, the recipient receives the output D from the DeRM element. i Record the value D.i If it is 0, the selected challenge is saved information content C i This is the same as the value D. i If the value is 1, the unselected challenges will have the same information content as the saved content. 3. The hash of the reconstructed bit sequence C is sent back to the sender by the recipient on a side channel to confirm sharing. The sender either confirms to the recipient on the side channel that the hash is correct, or sends a denial if no match is found. This does not expose the shared secret C, because it is assumed that the cryptographic hash does not reveal any information about the original image. 4. The recipient will use all container locations A used in step 1 of the protocol. i Write 111 to it, thus ensuring that all traces of the agreed-upon shared secret within the DeRM element are destroyed. The shared secret is held in volatile memory and remains valid until this memory is overwritten, or until the power is turned off or the method step is executed again, whichever comes first.
[0164] Now, let's consider Protocol A from the interceptor's perspective. There are two possible scenarios: 1. The interceptor monitors the side channel but does not intercept the container while it is in transit. 2. The interceptor intercepts the container and initiates a refilling attack against several DeRM elements.
[0165] In the first scenario, the interceptor does not have access to the container, so the knowledge of the pair is not translated into knowledge of string C.
[0166] In the second scenario, the interceptor must accurately read several DeRM elements without knowing the excluded values, erase the DeRM elements (unless the elements were erased during manufacturing and cannot be erased again), and write back the obtained values. Alternatively, the interceptor could attempt to write back the values to another DeRM container where the DeRM elements are in an erased state. In either case, the best the interceptor can do is apply a random challenge to a certain number of elements from which they wish to infer the contents of the DeRM elements from the output. If the challenge delivers an output of 0, the interceptor has certainly established the contents (no bit flips in the DeRM element means an accurately inferred triplet, or an output of 0 could mean an empty DeRM element 000, which we will discuss later, but at this point we will assume the sender will not leave any DeRM elements empty). If the output is 1, one of the other two triplets is stored in the DeRM element and the contents are destroyed so the interceptor does not know or cannot know which triplet it is, and the DeRM element here contains 111. In this latter case, the interceptor makes a guess between the two triplets other than the challenge. Adding the probabilities,
number
number
[0167] For example, if n=100, this probability is
number
[0168] Swarm constraint: Same container The present invention also provides a solution for IoT situations when dealing with large collections of things of the same kind, often called a swarm, such as sensors, instead of individual devices. In this scenario, the sender is a non-IoT entity, such as a high-power server, which will be referred to as the swarm keeper in the sequel. The keeper must maintain a copy of the entire contents of the containers for each thing in the swarm, even if they are all of the same kind. If all containers generally contain different data, the storage requirements in the keeper will be proportional to the size of the swarm and can become prohibitively expensive (consequently limiting the size of individual containers).
[0169] While it is highly desirable that all things in a swarm be able to use the same container data (which could reach gigabytes), additional protocol support is needed to prevent other things (some of which may be compromised) from accessing secrets shared between a given thing and its swarm keeper, despite the fact that other things can access the same container data.
[0170] Thus, the present invention provides Protocol B described below, in which changes are made to Steps 1 and 3 of Protocol A.
[0171] Protocol B. 1. The sender transmits a message containing a series of n(A i ,X i ) pairs to the recipient, where i = 0 ··· n - 1 and n is the length of the secret bit string that the sender wishes to share with the recipient at this point. The value n is assumed to be large enough to reduce the probability of accurately guessing the bit string. Usually, n ≥ 100. In each pair, A i is the address of a DeRM element, and X i is either an outlier or the actual content of the DeRM element with address A i . If it is the former, the pair is called a key pair, and if it is the latter, it is called a choice pair. The greater the computational power freely available to the keeper, the greater the number m < n of a series of choice pairs and the longer the time taken for the protocol. For practical purposes in a minimum length sequence n ~ 100, it will be sufficient to have m ~ 20 (see below). The sender records the positions of all the choice pairs in the series for use in Step 3. 2. For each i-th pair, when X i is excluded, the recipient challenges one of the two possible triplet values {L i ,H i} in the remaining two possible triplets in the container DeRM element with address A i . Which of the two challenges is used is randomly selected by the recipient. When the challenge cycle ends, the recipient records the output D i from the DeRM element. If the value D i is 0, the selected challenge is the same as the stored information content C i . If the value D i is 1, the unselected challenge is the same as the stored information content. 3. The cryptographic hash of bit string C is sent back to the sender by the recipient on a side channel to confirm sharing. The sender, on behalf of the recipient, marks the position of bit string C corresponding to the choice pair on the original sequence. R Reconstruct it. The bits at those positions are unpredictable because the recipient received an incorrect exclusion value, and therefore the output from the DeRM element. When challenged, it can be 0 or 1 depending on which of the two available challenges the recipient chose in each case. The sender typically has a total of 2 on the order of 1 million. m The protocol attempts a certain number of combinations, and any combination that yields a hash value equal to the received hash of bit string C is declared correct. The protocol sends a negation if the acknowledgment sent to the recipient on the side channel is successful, or if no match is found. 4. The recipient will use all container locations A used in step 1 of the protocol. i Write 111 to it, thus ensuring that all traces of the agreed-upon shared secret within the DeRM element are destroyed. The shared secret is held in volatile memory and remains valid until this memory is overwritten, or until the power is turned off or the method step is executed again, whichever comes first. An interceptor who has a container with the same message and wants to know the shared secret from the message exposed in step 1 faces a much greater challenge. Since the interceptor does not know the position of the set of choice pairs, the interceptor must assume that all pairs are potentially choice pairs. If the value of m is exposed (which makes it somewhat easier for the attacker), then to try to guess all possible markings on the sequence of n bits that are marked with m bits, or bit sequences that the recipient may share with the sender, in the example n=100, m=20, 80 20 >10 38 The binomial coefficient that gives the lower bound of the string.
number
[0172] The result seems a little strange, since both the interceptor and the legitimate recipient have copies of the same device at their disposal, but the fact is that the interceptor is missing two pieces of information: the random choice made by the recipient in deciding whether to test 0 or 1, and the original exclusion value known only to the sender, while the sender is missing only the former. It is not surprising that the tasks of the interceptor and the sender are disproportionate in complexity. In fact, if n is significantly larger than the hash length p, there are so many false positives that the interceptor's problem cannot be solved even given infinite computing power, provided that at least 2p bits of the agreed secret are deleted by both the sender and the recipient without ever being used.
[0173] Dual container attack and watermark defense The protocol described above is very satisfactory for IoT applications and leverages many powerful features of the DeRM architecture. However, it also has one weakness.
[0174] Imagine two DeRM containers are stolen from a useful object by an interceptor, and a significant amount of content in both containers remains unread. The interceptor can then challenge all DeRM elements in the first container with challenge 011 and all DeRM elements in the second container with challenge 101. If a result of 0 is obtained from a DeRM element in either container, its content is equal to the challenge. Otherwise, since each DeRM element is expected to contain one of three combinations, the content is 110. If all DeRM containers store the same content, the interceptor can easily and confidently reconstruct the content without needing to know the exclusion values first.
[0175] The inventors conclude that if the threat model includes the possibility of physical intrusion (and this is not necessarily a factor present in all IoT situations), the swarm of things needs to have its DeRM container content individualized. However, the purpose of individualization is not to provide additional entropy, so we do not go back to where we started, and thus things can already share a very large amount of true random data with the thing keeper in this configuration. The purpose of individualization is to prevent the juxtaposition of DeRM elements that are known to hold the same content, and this juxtaposition effectively eliminates the information gap necessary for the method to work (by doubling the data without doubling the information).
[0176] As a result, it is sufficient to superficially individualize the data stored in the DeRM containers of swarm members, without introducing any additional sensitive data, which is enough to render dual-container or any multi-container attack unproductive. The absence of additional sensitive data is important because any secrets need to be managed, i.e., stored, protected, and discarded when no longer needed (to avoid retroactive attacks). If the secrets are personal (one secret per thing), the swarm keeper overhead is multiplied by the size of the swarm, which is undesirable.
[0177] Generally, the inventors desire to introduce random mutations to the content when it is transferred by the Keeper to the DeRM container of the thing, without leaving any information about the mutations with the Keeper. The Keeper must be able to determine how the content has subsequently mutated in the process of interacting with the authenticated thing. The inventors assume that an attacker cannot break the authentication protocol and therefore continue to assume that there is a strong guarantee that the actor on the other end of the communication channel is a genuine thing that identifies itself. This makes it impossible for a multi-container attack to succeed, however, if the content in the different containers is sufficiently different, an attacker will not be able to reconstruct and juxtapose the original secrets without the help of the sender due to the destructive read and information depletion inherent in the DeRM container of the invention.
[0178] Therefore, one embodiment of the present invention described below is a particular technique of personalization that does not require sharing additional secrets with the keeper, in order to demonstrate that it is feasible. Other techniques may be used. The present invention provides an innovative method for preventing multi-container attacks rather than using one particular technique.
[0179] Observation 1. The content 111 within a DeRM element can be determined without any information from the sender and without requiring any specific challenge. Furthermore, by analyzing a DeRM element that has been challenged once, it can be confidently determined whether it originally contained 111, provided that the challenge itself was not 111.
[0180] In fact, if the DeRM element of the received container is first challenged with some challenge x (110, 101, or 011) and the response is 1, we can confidently say that the DeRM element did not contain 111. Alternatively, if the response is 0, and we challenge the DeRM element again with a non-zero triplet y≠x (but y≠111) and get 0 again, the conclusion is that the original content was 111.
[0181] Observation 2. The content 000 within the DeRM element yields result 0 when given any challenge x. Both observations are derived from the DeRM architecture described in the architecture section.
[0182] Definition: A watermark is a sequence of 111 and 000 values that begin and end with 111 and are placed within a DeRM container at consecutive addresses. Apart from the end marker, the triplet 111 is interpreted as binary 1 and the triplet 000 is interpreted as binary 0.
[0183] Watermarks can be placed by a copy machine, detected by a challenger (which may be a recipient or interceptor), and fully read under any series of challenges applied to consecutive addresses of a DeRM container. A copy machine can be a separate entity that acts on behalf of the Keeper, responsible for copying shared content supplied by the Keeper into a mono container (a series of zero-based addresses) before the mono is deployed as a member of the swarm. The copy machine shares no secrets with the Keeper other than the complete DeRM content generated by the Keeper and which the copy machine is instructed to copy into a new DeRM container. A copy machine can also be part of the Keeper, but it is convenient to think of the copy machine as a separate entity within the Keeper's security boundary.
[0184] The watermark is recognized by the recipient without prior knowledge of its location, and is encountered in the process of challenging the DeRM element based on instructions from the Keeper according to Protocol C. This is key to achieving the goal of avoiding the same content in all DeRM containers while using only the original secret throughout the swarm. An example of how this can actually be achieved is shown below.
[0185] Derived content 1. In contrast to protocols A and B, the sender stores a sequence of triplets (written to the container based on those protocols) that should be passed to the copier, rather than exclusion values. The binary content is stored as before. 2. The copier uses a watermark that encodes a random binary number of a certain length (which can actually be limited to several tens of bits, but does not have to be a fixed length) to intersperse the stream of triplets supplied by the center. The watermark replaces the original content to preserve the addresses of the unaffected triplets. The numbers contained in the watermark have version significance. The watermarks continue at regular intervals L, with the length of the watermark itself excluded from the interval. The DeRM element with address 0 is the starting position of the first watermark. 3. Between consecutive watermarks, the copier uses the version value to transform the segment of the original content S. The copier calculates S'=T v Obtain (S), where v is the value of the preceding watermark, T v is some public algorithm that depends on it and replaces S with S'. The algorithm is guaranteed to ensure that the length of S' is the same as S. S' is stored in a container. 4. The process continues until all triplets S' corresponding to the triplets S supplied by the center are stored in the container. The copier does not alter the original content stored in the keeper's non-volatile storage device, nor the inserted watermark and applied transformations, using algorithm T. v Please note that, except for the fact that it is publicly known including to the Keeper, the Keeper will not be notified.
[0186] Protocol B is modified to obtain the following:
[0187] Protocol C. 1. The sender notifies the recipient on the side channel that the container is prepared for Protocol C and gives them the start address. The recipient starts by challenging (with any triplet) the start address of the container. If it is determined that the DeRM element at the address is other than 111, the recipient encounters the first watermark and proceeds to the next address until this is fully read. The watermark position and version value are returned to the sender on the side channel. 2. The sender receives the watermark position and version value. The sender fetches L triplets from the relevant addresses of the content files held in its non-volatile memory. Then it applies T to the sequence of L triplets in order to obtain the sequence S’ that the copier wrote to the containers at those addresses. Using the binary content file previously saved to the non-volatile storage device (see step 2 of CFP1 or step 3 of CFP2), the sender can reconstruct the exclusion value X’ that generates its content from the sequence S’, i.e., the sender can calculate L new key pairs. The sender can also generate the option pairs by simply taking the corresponding triplets from S’. The sender transmits a message containing a series of n(A v ,X i , where i = 0 ··· n - 1 and each pair is either a key pair or an option pair. The value n is assumed to be large enough to reduce the probability of accurately guessing the bit sequence. Usually, n ≧ 100. In each pair, A i is the address of the DeRM element and X i is either the exclusion value in the case of a key pair or the actual content of the DeRM element with the address A i in the case of an option pair. Since all recipients of the container generally receive different content, the recipient can choose that it does not need option pairs at all under the assumed threat model. It is recognized that there may exist more aggressive threat models where the use of option pairs can still be justified. i 3. For each i-th pair, when X i is excluded, the recipient challenges with one of the two possible triplet values {L i , H i} in the container DeRM element having address A i . Which of the two challenges is used is randomly selected by the recipient. At the end of the challenge cycle, the recipient records the output D i from the DeRM element. If the value D i is 1, the unselected challenge will be the same as the saved information content. If the value D i is 0, the selected challenge will be the same as the saved information content C i , or the saved content is 111. To distinguish these cases, the recipient challenges the DeRM element a second time with another triplet value from the pair L i , H i and records the output D i from the DeRM element at the end of the second challenge. If this value D i is 1, the first challenge is the same as the saved information content. If this value D i is 0, the saved content is 111. If the watermark is detected before L triplets are read, the protocol fails. 4. The cryptographic hash of the bit sequence C is sent back to the sender from the recipient on the side channel to confirm the sharing. The sender reconstructs the bit sequence C R on behalf of the recipient marking the positions (if any) corresponding to the choice pairs on the original sequence. The bits at such positions cannot be predicted because the recipient sent an incorrect exclusion value, and thus the output from the DeRM element when challenging it could be either 0 or 1 depending on which of the two available challenges the recipient selected in each case. The sender mAll possible combinations are tried, and any combination that yields a hash value equal to the received C is declared correct. (If no choice pairs are used, m=0, and there is only one bit sequence to check.) The protocol sends a successful acknowledgment via the side channel to the recipient, or a negative acknowledgment if no match is found. 5. The recipient will use all container locations A used in step 1 of the protocol. i Write 111 to it, thus ensuring that all traces of the agreed-upon shared secret within the DeRM element are destroyed. The shared secret is held in volatile memory and remains valid until this memory is overwritten, or until the power is turned off or the method step is executed again, whichever comes first.
[0188] Finally, at least one transformation T that prevents multi-container attacks. v The existence of the following must be demonstrated. The specific transformation shown here is irreversible, but for this purpose, a reversible transformation T v It is also possible to construct and use it.
[0189] Introducing a function M(t,v,S)=ε(T v (S), t), In the above equation, for any sequence x and y of the same length, the function ε(x,y) is: i =y i If so, then ε(x,y) i This yields sequences of the same length, where = 1, otherwise 0. Note that sequence M is what an attacker would see if they stole a container and challenged the corresponding content with some sequence t. For any valid v1≠v2, t1, t2, and any S, we are trying to minimize the mutual information between M(t1, v1, S) and M(t2, v2, S).
[0190] One obvious (but not necessarily the most economical) way to minimize mutual information is to use a cryptographic hash and feed it S and v. The result of such a hash is pseudorandom in the sense that it does not visibly correlate with the arguments.
[0191] Triplet "three-value checksum" operator
number
number
[0192] Here, let R(S,v)=H(S||v) be the cryptographic hash of the concatenation of S and v. Clearly, it is assumed that every bit of R is a pseudorandom function of every bit of S, which is the quality criterion for cryptographic hashes, another way of saying that the mutual information between any bit of S and any bit of R is negligibly small. Next, T v Define it as follows:
number
[0193] Here, we note that it may be possible to find a much simpler procedure, but that the complexity of the hash calculation only affects the sender, in this case the swarmkeeper, and that in our threat model, the sender is strong and protected by its fixed security perimeter, both physically and cryptographically, so even a standard hash, which is invoked each time the sender sends a new sequence, does not incur significant costs.
Claims
1. A tamper-proof container comprising one or more destructible read memory (DeRM) elements configured to store content, Each of the one or more DeRM elements is configured such that the content stored by each of the one or more DeRM elements is larger than the content revealed when each of the one or more DeRM elements is destructively read. Each of the one or more DeRM elements is configured to be challenged with a digital value, The challenge causes each of the one or more DeRM elements to perform two actions simultaneously, that is, a. In order to obtain new content, modify the content of the DeRM element based on the content and challenge value of the DeRM element. b. A system configured to output a digital response indicating whether the new content differs in any way from what was there before the modification. Tamper-evident container.
2. The aforementioned tamper-evident container comprises a physical container. A container that clearly indicates tampering, as described in claim 1.
3. The aforementioned tamper-evident container is configured to transport or carry digital data between the sender and the recipient. A tamper-proof container according to claim 1 or claim 2.
4. The aforementioned tamper-evident container comprises an array of multiple DeRM elements. A container that clearly indicates tampering, as described in any one of claims 1 to 3.
5. Each of the one or more DeRM elements comprises one or more DeRM cells. A container that clearly indicates tampering, as described in any one of claims 1 to 4.
6. Each of the one or more DeRM elements comprises a plurality of DeRM cells. A container that clearly indicates tampering, as described in any one of claims 1 to 5.
7. Each of the one or more DeRM elements comprises three or more DeRM cells. A container that clearly indicates tampering, as described in any one of claims 1 to 6.
8. Each of the one or more DeRM elements is configured to be challenged by supplying the address of each of the one or more DeRM elements and a digital value from the set of limit values to the tamper-evident container. A container that clearly indicates tampering, as described in any one of claims 1 to 7.
9. If each of the one or more DeRM elements comprises three DeRM cells, the limit value set includes 110, 101, and 011. The tamper-proof container according to claim 8.
10. The challenge causes each of the one or more DeRM elements to perform two actions simultaneously, that is, a. In order to obtain the new content, modify the content of the DeRM element based on the content of the DeRM element and the challenge value, which is a digital value used for the challenge. b. Output a 1-bit signal response indicating whether the new content is different in any way from what was there before the modification. If the one-bit signal response indicates that the new content is different, the one-bit signal response is a difference (1) response; otherwise, the one-bit signal response is a match (0). A tamper-proof container according to claim 8 or claim 9.
11. Each of the one or more DeRM elements is configured to have valid content written to it by challenging part or all of the content to be written to the DeRM element. A container that clearly indicates tampering, according to any one of claims 8 to 10.
12. Each of the one or more DeRM elements is configured to have valid content written to it by repeatedly challenging the DeRM element with part or all of the content to be written until all of the content has been written. A container that clearly indicates tampering, according to any one of claims 8 to 11.
13. Before attempting to write some or all of the content to the DeRM element, the DeRM element is erased. A container that clearly indicates tampering, according to any one of claims 8 to 12.
14. Each of the one or more DeRM elements is configured such that the content of the DeRM element cannot be read by any means other than challenging the DeRM element. A container that clearly indicates tampering, according to any one of claims 8 to 13.
15. Each of the one or more DeRM elements is configured to output a 1-bit match / difference response only when challenged. The one-bit match / difference response is a difference (1) response if the one-bit signal response indicates that the new content is different, and a match (0) response otherwise. A container that clearly indicates tampering, according to any one of claims 8 to 14.
16. Each of the one or more DeRM elements is challenged It is configured not to output any information other than the 1-bit match / difference response when this occurs. The tamper-proof container according to claim 15.
17. Each of the one or more DeRM elements is configured to contain more information than the digital response to any given challenge. A container that clearly indicates tampering, according to any one of claims 8 to 16.
18. Compared to the information obtained based on the aforementioned digital response to any challenge, the information obtained includes more additional information than the information obtained by the aforementioned digital response to any challenge, The aforementioned additional information is irreversibly destroyed for at least one challenge value, and which challenge value causes such information loss depends on the content stored in the challenged DeRM element. The tamper-proof container according to claim 17.
19. When each of the one or more DeRM elements comprises multiple DeRM cells, destructive readout can reveal that one of the DeRM cells comprising the DeRM element has changed state, but does not disclose which DeRM cell it was. A container that clearly indicates tampering, according to any one of claims 8 to 18.
20. By challenging each of the DeRM elements to be written to some or all of the aforementioned content, A method for loading data into a tamper-proof container according to any one of claims 1 to 19.
21. A method for loading data into a tamper-proof container comprising one or more destructible read memory (DeRM) elements configured to store content, Each of the one or more DeRM elements is configured such that the content stored by each of the one or more DeRM elements is larger than the content revealed when each of the one or more DeRM elements is destructively read by challenging each of the one or more DeRM elements with part or all of the content to be written to each of the one or more DeRM elements. The challenge causes each of the one or more DeRM elements to perform two actions simultaneously, that is, a. In order to obtain new content, modify the content of the DeRM element based on the content and challenge value of the DeRM element. b. A system configured to output a digital response indicating whether the new content differs in any way from what was there before the modification. method.
22. Each of the one or more DeRM elements is configured to have valid content written to it by repeatedly challenging each of the DeRM elements with some or all of the content to be written until all of the content has been written. The method according to claim 20 or claim 21.
23. Before attempting to write some or all of the content to each of the DeRM elements, the DeRM element is erased. The method according to any one of claims 20 to 22.
24. Each of the one or more DeRM elements is challenged by supplying the address of each of the one or more DeRM elements and a digital value from the set of limit values to the tamper-proof container. The method according to any one of claims 20 to 23.
25. If each of the one or more DeRM elements comprises three DeRM cells, the limit value set includes 110, 101, and 011. The method according to claim 24.
26. The challenge causes each of the one or more DeRM elements to perform two actions simultaneously, that is, a. Modify the content of the DeRM element based on the content of the DeRM element and the challenge value. b. Output a 1-bit signal response indicating whether the new content is different in any way from what was there before the modification. If the one-bit signal response indicates that the new content is different, this is a difference (1) response; otherwise, the one-bit signal response is a match (0). The method according to any one of claims 20 to 25.
27. A method for verifying that data loaded into a tamper-evident container according to any one of claims 1 to 19 has not been previously accessed by the method according to any one of claims 20 to 26, 1. A sender transmits randomized confidential content contained within a tamper-evident container according to a first aspect of the present invention to a recipient, wherein the sender maintains a copy of the content in the sender's local secure storage device.
2. The sender establishes, via side-channel communication, that the recipient has received the tamper-evident container.
3. The sender discloses to the recipient, via the side-channel communication, additional information regarding a subset of data from the contents of the tamper-evident container.
4. The recipient obtains a subset of the data from the contents of the tamper-evident container from step 3 using the additional information, 5. The recipient creates a summary of the subset of data obtained in step 4, 6. The recipient transmits the summary obtained in step 5 to the sender via the side-channel communication, 7. The sender calculates the summary relating to the copy of the content held in the sender's local secure storage device, 8. The sender compares the recipient's summary with the sender's summary, and if the sender's summary is the same as the recipient's summary, the content has not been read by a third party; otherwise, it has been read.
9. The sender transmits the results of the comparison performed by the sender in step 8 to the recipient via the side-channel communication, 10. The recipient, at their discretion, removes from the tamper-evident container any remaining information that the tamper-evident container may contain with respect to the confidential content. including, method.
28. A method for verifying that data has never been previously accessed, wherein data is loaded into a tamper-evident container comprising one or more destructive read memory (DeRM) elements configured to store content, each of the one or more DeRM elements is configured such that the content stored by each of the one or more DeRM elements is greater than the content revealed when each of the one or more DeRM elements is destructively read by challenging each of the one or more DeRM elements with part or all of the content to be written by the method of any one of claims 20 to 26, 1. A sender transmits randomized confidential content contained within a tamper-evident container according to a first aspect of the present invention to a recipient, wherein the sender maintains a copy of the content in the sender's local secure storage device.
2. The sender establishes, via side-channel communication, that the recipient has received the tamper-evident container.
3. The sender discloses to the recipient, via the side-channel communication, additional information regarding a subset of data from the contents of the tamper-evident container.
4. The recipient uses the additional information to obtain a subset of the data from the contents of the tamper-evident container from step 3, 5. The recipient creates a summary of the subset of data obtained in step 4, 6. The recipient transmits the summary obtained in step 5 to the sender via the side-channel communication, 7. The sender calculates the summary relating to the copy of the content held in the sender's local secure storage device, 8. The sender compares the recipient's summary with the sender's summary, and if the sender's summary is the same as the recipient's summary, the content has never been read by a third party; otherwise, it has been read.
9. The sender transmits the result of the comparison performed by the sender in step 8 to the recipient via the side channel communication, 10. The recipient, at their discretion, removes from the tamper-evident container any remaining information relating to the confidential content that the tamper-evident container may contain. including, method.
29. The method includes step 2a (between step 2 and step 3), and if necessary, preliminary communication exists between the sender and the recipient via the side channel communication to determine the details of the additional information. The method according to claim 27 or claim 28.
30. The summary of the subset of the aforementioned data is an industry-standard cryptographic hash. The method according to any one of claims 27 to 29.
31. The falsification is proven by the discrepancy in step 8. The method according to any one of claims 27 to 30.