Method and device for generating secret keys configured to multi-bit based on unclonable component

KR103020575B1Active Publication Date: 2026-09-21KOREA INST OF SCI & TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
KR1020230194210
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2026-09-21
Estimated Expiration
2043-12-28

Smart Images

  • Figure 112023146803607-PAT00001_ABST
    Figure 112023146803607-PAT00001_ABST
Patent Text Reader

Abstract

The embodiments are a method and apparatus for generating a secret key composed of multibits based on non-cloning elements, comprising: a step of defining a current signal range at a specific voltage from individual elements of an array composed of a plurality of elements into 2k (k=2, 3, 4…) regions; a step of generating a plurality of maps that assign different k-bit values ​​to each of the 2k regions; and a step of extracting a multibit response using the current signal distribution characteristics measured at the specific voltage from the individual elements and the maps.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] This invention relates to a method and apparatus for generating a secret key composed of multibits based on a non-cloning element.

[0002] [Explanation of government-supported R&D]

[0003] This study was conducted with the support of the National Police Agency's field support technology development project for efficient policing activities (establishment of an augmented reality (XR)-based complex terror response education and training testbed, project unique number: PR08-04-000-23-C5). Background Technology

[0004] With the recent advent of the Internet of Things (IoT) era and the emergence of various devices such as smart home appliances, autonomous vehicles, and financial transactions via smartphones, security risks associated with IoT devices, including the leakage of personal information, are increasing. Consequently, the 'Physical Unclonable Function (PUF),' which complements software-based key methods susceptible to hacking, is garnering attention.

[0005] The PUF concept involves generating random digital values ​​using inherent deviations that are difficult to predict due to uncontrollable variability and high randomness in the semiconductor manufacturing process. Physical parameters make key duplication extremely difficult due to random variations occurring during the manufacturing process.

[0006] Hardware-based PUF semiconductor chips possess a unique physical code, much like a human iris or fingerprint. Because they utilize microstructural variations generated during the manufacturing process as key values, security keys produced by PUFs are randomly generated, possess uniqueness, and are impossible to duplicate.

[0007] Existing inventions allocated the response output range of a PUF element to multiple regions and assigned multi-bits to individual regions, and generated limited challenge-response pairs (CRPs) by generating multi-bits through a map that converts them into fixed bits. This had problems in terms of efficiency and predictability. The problem to be solved

[0008] The present invention aims to solve the aforementioned technical problem by including bit transformation map information in the challenge to generate more CRPs from the same PUF array, thereby enhancing security. Additionally, it enhances security by bit shuffling so that the Hamming distance of the multibits assigned to adjacent regions becomes greater than 2, making it impossible to predict the secret key. means of solving the problem

[0009] A method for generating a secret key composed of a multibit based on a non-cloning element according to an embodiment of the present invention, wherein a current signal range at a specific voltage from an individual element of an array composed of a plurality of elements is 2 k Step of defining (k=2,3,4…) regions; the above 2 k The method may include the step of generating a plurality of maps that assign different k-bit values ​​to each of the regions; and the step of extracting a multi-bit response using the current signal distribution characteristics measured at the specific voltage from the individual elements and the maps.

[0010] In one embodiment, the response may include: a first step of obtaining a k-bit value of a map corresponding to a current signal range measured in a selected individual element cell (x1, y1) of the array; and a second step of repeating the first step in a plurality of cells (x2, y2), cell (x3, y3) … cell (xi, yi) different from the individual element cell (x1, y1) to obtain a k-bit value of the corresponding map, and concatenating the obtained plurality of k-bit values ​​to obtain a final response value.

[0011] In one embodiment, the method may further include the step of generating a key as unique encryption information for the array by utilizing the multibit response.

[0012] In one embodiment, the method may further include the step of exchanging the key and performing encrypted communication between a user device and a server comprising an array composed of the plurality of elements.

[0013] In one embodiment, 2 k The step of generating a plurality of maps that assign different k-bit values ​​to each of the regions may use bit shuffle, and the Hamming distance (HD) between the divided adjacent current signal ranges may be at least 2.

[0014] In one embodiment, the final response value is n-bit, and the step of extracting the multi-bit response can be repeated n / k times according to the request of the challenge to extract the n-bit final response value.

[0015] In one embodiment, the current signal range is 2 k In the step defined by (k = 2, 3, 4…) regions, the current signal range can be between 1.8 mA and 5.3 mA.

[0016] In one embodiment, k may be 4.

[0017] In one embodiment, the key may be used as an identifier for the array or as an identifier for a user device including the array.

[0018] In one embodiment, the array may be a device array fabricated by spraying CNTs onto a flexible substrate.

[0019] In one embodiment, the array may be implemented as a wearable device including a smart band.

[0020] A secret key generation device composed of a multibit based on a non-cloning element according to another embodiment of the present invention comprises a current signal range at a specific voltage from an individual element of an array composed of a plurality of elements, 2 k Defined as (k = 2, 3, 4…) regions, and the above 2 k It may include: a map generation unit that generates a plurality of maps, each assigning a different k-bit value to a region; a response extraction unit that extracts a multi-bit response using the map and the current signal distribution characteristics measured at a specific voltage from the individual elements; a key generation unit that generates a key as unique encryption information for the array using the multi-bit response; and an encryption communication unit that exchanges the key between a user device and a server, the array composed of the plurality of elements.

[0021] In one embodiment, the response may include: a first step of obtaining a k-bit value of a map corresponding to a current signal range measured in a selected individual element cell (x1, y1) of the array; and a second step of repeating the first step in a plurality of cells (x2, y2), cell (x3, y3)… cell (xi, yi) different from the individual element cell (x1, y1) to obtain a k-bit value of the corresponding map, and concatenating the obtained plurality of k-bit values ​​to obtain a final response value. Effects of the invention

[0022] The present invention enables authentication through efficient response extraction by reducing the number of accesses to the PUF array required for response extraction through multi-bits.

[0023] The security of security authentication can be enhanced by generating unique encryption information for a specific array. The extracted encryption information can be used in applications requiring security, such as secure communication, secure data processing, user identification, and firmware updates.

[0024] It can be used as an encryption element for the security of the Internet of Things (IoT), wearable devices, etc.

[0025] It can compensate for the security vulnerabilities of IoT devices with limited performance and software-based encryption systems.

[0026] The effects of the present invention are not limited to those mentioned above, and other unmentioned effects will be clearly understood by those skilled in the art from the description in the claims. Brief explanation of the drawing

[0027] To more clearly explain the technical solution of the embodiments of the present invention or the prior art, the drawings necessary for the description of the embodiments are briefly introduced below. It should be understood that the drawings below are for the purpose of explaining the embodiments of this specification only and are not for the purpose of limitation. Additionally, for clarity of explanation, some elements in the drawings below may be depicted with various modifications, such as exaggeration or omission. FIG. 1 is a flowchart of a secret key generation method composed of multibits based on a non-cloning element according to one embodiment of the present invention. FIG. 2 is a block diagram of a secret key generation device composed of multibits based on a non-cloning element according to one embodiment of the present invention. FIG. 3 is an example showing a comparison of current distribution of elements within an array according to one embodiment of the present invention. FIG. 4 is a flowchart illustrating the process of configuring a challenge for authentication and extracting a response according to an embodiment of the present invention. FIGS. 5a and 5b are comparative figures comparing the randomness and uniqueness of random numbers generated depending on whether or not bit shuffling is performed during map generation, according to an embodiment of the present invention. FIG. 6 is by a process variation according to one embodiment of the present invention This is a diagram showing fine patterns occurring randomly on individual elements of a nano-device array. Specific details for implementing the invention

[0028] When elements or a layer are referred to as being "on" or "on" another element or layer, it includes not only being directly on top of the other element or layer but also cases where another layer or element is interposed in between. On the other hand, when an element is referred to as being "directly on" or "directly on," it indicates that no other element or layer is interposed in between.

[0029] Spatially relative terms such as "below," "beneath," "lower," "above," and "upper" may be used to facilitate the description of the relationship between one element or component and another, as illustrated in the drawings. Spatially relative terms should be understood as encompassing different orientations of the element during use or operation, in addition to the orientations illustrated in the drawings. For example, if an element illustrated in the drawings is flipped, an element described as "below" or "beneath" another element may be placed "above" of that other element. Therefore, the exemplary term "below" may encompass both the lower and upper directions. Elements may also be oriented in other directions, in which case the spatially relative terms may be interpreted according to the orientation.

[0030] The terms used herein are for describing the embodiments and are not intended to limit the invention. In this specification, the singular form includes the plural form unless specifically stated otherwise in the text. As used herein, "comprises" and / or "comprising" do not exclude the presence or addition of one or more other components, steps, actions, and / or elements to the mentioned components, steps, actions, and / or elements.

[0031] Unless otherwise defined, all terms used in this specification (including technical and scientific terms) may be used in a meaning commonly understood by those skilled in the art to which the present invention pertains. Additionally, terms defined in commonly used dictionaries are not to be interpreted ideally or excessively unless explicitly and specifically defined otherwise.

[0032] Meanwhile, in describing the present invention, if it is determined that a detailed description of related known functions or configurations could unnecessarily obscure the essence of the invention, such detailed description will be omitted. Furthermore, the terminology used in this specification is used to appropriately express embodiments of the present invention, and such terminology may vary depending on the intent of the user or operator, or the conventions of the field to which the invention belongs. Accordingly, the definitions of these terms should be based on the content throughout this specification.

[0033] Hereinafter, embodiments of the present invention will be examined in detail with reference to the drawings.

[0034] FIG. 1 is a flowchart of a secret key generation method composed of multibits based on a non-cloning element according to one embodiment of the present invention.

[0035] Referring to FIG. 1, a secret key generation method composed of multibits based on uncloning elements (hereinafter, “secret key generation method”) comprises a current signal range at a specific voltage from individual elements of an array composed of multiple elements, 2 k Step (S11) of defining regions (k=2,3,4…); the above 2 k The method may include: a step of generating a plurality of maps that assign different k-bit values ​​to each of the regions (S12); a step of extracting a multi-bit response using the maps and the current signal distribution characteristics measured at the specific voltage from the individual elements (S13); a step of generating a key as unique encryption information for the array using the multi-bit response (S14); and a step of exchanging the key and performing encrypted communication between a user device and a server including an array composed of the plurality of elements (S15).

[0036] An array composed of multiple elements may further include multiple electrodes inside a silicon substrate, a channel connected to the electrodes, one or more capacitance elements, or one or more resistance elements.

[0037] An array composed of multiple elements may include a connected electrode array comprising a plurality of electrodes electrically connected to some or all of them. The connected electrode array receives an output signal generated by the array in response to an external stimulus, and the output signal may include the external stimulus itself or a signal resulting from the interaction between the electrode and a change in a target caused by the external stimulus.

[0038] The above key can be used as an identifier for the array or as an identifier for a user device including the array.

[0039] FIG. 2 is a block diagram of a secret key generation device composed of multibits based on a non-cloning element according to one embodiment of the present invention.

[0040] Referring to FIG. 2, a secret key generating device (1) (hereinafter, “secret key generating device”) composed of multibits based on non-cloning elements may include a map generating unit (21); a response extraction unit (22); a key generating unit (23) and an encrypted communication unit (24). Referring again to FIG. 1, the map generating unit (21) generates a current signal range at a specific voltage from individual elements of an array composed of a plurality of elements, 2 k Defined as (k=2, 3, 4 … ) regions, and the above 2 kMultiple maps can be generated (S11 and S12) by assigning different k-bit values ​​to each of the regions. The response extraction unit (22) extracts a multi-bit response using the current signal distribution characteristics measured at the specific voltage from the individual elements and the maps (S13). The key generation unit (23) generates a key as unique encryption information for the array using the multi-bit response. The encryption communication unit (24) exchanges the key between a user device and a server that includes the array composed of the plurality of elements (S15).

[0041] FIG. 3 is an example showing a comparison of current distribution of elements within an array according to one embodiment of the present invention.

[0042] Referring to FIG. 3, it can be seen that the current signals measured at a specific voltage from individual elements of the array are different. Therefore, the individual elements of the array exhibit different unique current distribution characteristics even at the same voltage, making them suitable for use as electronic fingerprints. In one embodiment, under specific voltage conditions, each cell of the cell array constituting the individual elements is represented such that cells with higher current values ​​appear red, and cells with lower current values ​​appear blue. The current signal range is 2 k In step (S11) defining the range, the current signal range may be between 1.8 mA and 5.3 mA.

[0043] FIG. 4 is a flowchart illustrating the process of configuring a challenge for authentication and extracting a response according to an embodiment of the present invention.

[0044] Referring to FIG. 4, the PUF is a challenge-response mechanism that utilizes manufacturing process variations within the circuit to obtain a unique identifier. In one example, the relationship between the corresponding response and the challenge is determined by complex statistical variations of logic components and interconnections in the circuit (e.g., an integrated circuit). The step (S14) in which the key generator (23) generates a key may generate a secret key or an authentication key by utilizing the response. The authentication process submits a pre-agreed, device-specific answer called a response to a question called a challenge. The challenge for authentication of the secret key generation method and device of the present application may be composed of [select cell combination cell (x,y), current-bit conversion map (i)]. In one example, Challenge = {[Cell(2,6), Map(i)] + [Cell(3,3), Map(i)] + [Cell(1,7), Map(i)]… … It can be expressed as}.

[0045] The above response may include: a first step of obtaining a k-bit value of a map corresponding to a current signal range measured in a selected individual element cell (x1, y1) of the array; and a second step of repeating the first step in a plurality of cells (x2, y2), cell (x3, y3) … cell (xi, yi) different from the individual element cell (x1, y1) to obtain a k-bit value of the corresponding map, and concatenating the obtained plurality of k-bit values ​​to obtain a final response value.

[0046] When k is 4, the map generation unit (21) ranges the current signal range at a specific voltage from individual elements of an array composed of multiple elements to 2 4Multiple maps can be generated by defining 16 regions and assigning different 4-bit values ​​to each of the 16 regions. If the defined current signal range is between 1.8 mA and 5.3 mA, the range can be divided into 16 regions.

[0047] The generated multiple maps are Map(i) = {0000, 1100, 1000, 1110, 0100, 1111, 0010, 1001, 0001, 1010, 0011, 0101, 0110, 1101, 1011, 0111}, i=1, 2, … 2 k A k-bit fragment can be obtained from the response for a single selected cell combination cell (x, y). In one example, if the current signal of a specific cell (2, 6) is 2.6 mA, a k-bit fragment assigned to a map corresponding to the area defined as the range to which 2.6 mA belongs can be obtained. In FIG. 4, 1110 can be obtained as a 4-bit response fragment as Map (4). For cells (3, 3) and cells (1, 7) that are different from the individual element cell (2, 6), 4-bit response fragments can be obtained in the same way, and 1010 and 0111 can be obtained, respectively. Multiple obtained 4-bit values ​​can be concatenated to extract 1110101001111… as the final response value. The above final response value is n-bit, and the step (S13) of extracting the multi-bit response can be repeated n / k times according to the challenge request to extract the n-bit final response value. That is , The number of response extractions is reduced from n to n / k, enabling efficiency.

[0048] FIGS. 5a and 5b are comparative diagrams comparing the randomness and uniqueness of random numbers generated depending on whether or not bit shuffling is performed during map generation, according to an embodiment of the present invention.

[0049] Referring to FIGS. 5A and 5B, the step (S12) of generating a plurality of maps that assign different k-bit values ​​to each of 2k regions utilizes bit shuffling, and the Hamming distance (HD) between adjacent divided current signal ranges may be at least 2. Hamming distance refers to the number of instances where corresponding bit values ​​do not match between binary codes having the same number of bits. The step (S12) of generating the maps assigns the values ​​assigned to each map in the direction of the larger Hamming distance as the current value increases through bit shuffling. For example, in the case where HD = 1 in a 16-division (4-bit) current region without bit shuffling, and is assigned to adjacent current regions sequentially to increase by 1, it can be expressed as i=1 multi-bit 0000 and i=2 multi-bit 0001. On the other hand, if HD = 2 is assigned to adjacent current regions sequentially by increasing by 2 through bit shuffling, it can be expressed as i=1 multi-bit 0000 and i=2 multi-bit 0101. In one embodiment, 10,000 responses of 240-bit length were extracted from individual PUF element arrays in FIGS. 5a and 5b. Randomness or diffuseness is an indicator that evaluates how random the generated 240-bit response is as the average ratio of Hamming distances. The closer the randomness is to 50%, the more random the generated response is, making it unpredictable. The x-axis of FIG. 5a represents the randomness ratio value of the Hamming distance between two randomly selected responses, and the y-axis represents the count of cases where two responses correspond to that ratio value. In other words, it is a randomness distribution. In this case, if the overall average is close to 50% and the variance is also concentrated around 50%, it indicates that it is close to an ideal PUF as an unpredictable cryptographic element. When using bit shuffle (w BS) When not using bit shuffle (w / o B.Compared to S), the center of variance shifts to near 50% overall and the variance is reduced, allowing it to operate as a more ideal PUF.

[0050] The uniqueness in Fig. 5b is an indicator evaluated by the ratio of Hamming distances to how different the responses R1, R2, and R3 obtained by applying the same challenge to three different PUF element arrays are from each other. The uniqueness is the average of the values ​​obtained by calculating HD(R1, R2), HD(R1, R3), and HD(R2, R3) and dividing by the response length. Uniqueness also appears as a difference between 0 and 1, and in the ideal case, it is close to 50%. Therefore, an ideal PUF is one where the mean is located near 50% and the variance is also concentrated near 50%. Similarly, using bit shuffling shows an improvement effect close to 50%. That is, when using bit shuffling, the probability of being different when filling the same position with 0 or 1 is 0.5, so it reflects random characteristics well and uniqueness can also be secured.

[0051] FIG. 6 is by a process variation according to one embodiment of the present invention This is a diagram showing fine patterns occurring randomly on individual elements of a nano-device array.

[0052] Referring to Fig. 6, fine patterns that randomly occur on individual devices of a nanodevice array due to process variations are impossible to replicate. Authentication is possible by measuring the electrical signal of a device selected by a challenge in a PUF composed of a nanodevice array, extracting a unique response, and comparing it with a defined Challenge-Response Pair. In one example, the array may be a device array fabricated by spraying CNTs onto a flexible substrate. Fig. 6 is an example of a device array fabricated through an electrode process following CNT spraying. With the advent of the Internet of Things era, the importance of sensors is increasing, and in particular, the demand for wearable electronic sensors that can be worn on the body is rapidly growing. In one example, the nanodevice array may be an Organic Thin-Film Transistor (OTFT) flexible sensor array; since the flexible sensor array possesses flexibility and excellent sensitivity and enables low-cost production, it is the most suitable candidate for the implementation of wearable electronic sensors. The combination of such wearable electronic sensors with healthcare systems has a high potential to form a large-scale market. It can be used as a flexible sensor and possesses both the flexibility and sensitivity suitable for manufacturing pulse and blood glucose sensors that detect human health in real time, and production costs are also expected to be very low. In the future, along with the improvement of the performance of individual sensor elements, there will be a demand for the integration of sensors capable of multi-signal detection through the integration of various physical, biological, and chemical sensors. Furthermore, efforts to fabricate these sensors into a single flexible chip by integrating them with flexible actuators are accelerating, and ultimately, they can be utilized as a comprehensive healthcare system by combining them with communication and information processing technologies using smartphones, etc. The array of the present application can be implemented as a wearable device including a smart band. The wearable device can be worn on the user's wrist, and the body part where the wearable device is worn is not limited to the wrist but can be worn on other body parts.In such cases, the shape of the wearable device may be modified to facilitate wearing or attaching to the relevant body part.

[0053] According to the secret key generation method and device composed of multibits based on such non-cloning elements, authentication through efficient response extraction is possible by reducing the number of accesses to the PUF array required for response extraction through multibits.

[0054] The security of security authentication can be enhanced by generating unique encryption information for a specific array. The extracted encryption information can be used in applications requiring security, such as secure communication, secure data processing, user identification, and firmware updates.

[0055] It can be used as an encryption element for the security of the Internet of Things (IoT), wearable devices, etc.

[0056] It can compensate for the security vulnerabilities of IoT devices with limited performance and software-based encryption systems.

[0057] One or more of the components, features, and / or functions illustrated in FIGS. 1 through 6 may be rearranged and / or combined into a single component, feature, or function, or implemented as multiple components or functions. Additional elements, components, and / or functions may also be added without departing from the invention. The apparatus and / or devices illustrated in FIGS. 1 through 6 may be configured to perform one or more of the methods, features, or steps. The methods may be efficiently implemented in software as algorithms and / or embedded in hardware.

[0058] Additionally, in one aspect of the present disclosure, the illustrated circuit may be specialized processors (e.g., application-specific integrated circuits (e.g., ASICs)) specifically designed and / or hard-wired to perform algorithms, methods, and / or steps. Thus, such specialized processors (e.g., ASICs) may be an example of a means for executing said algorithms, methods, and / or steps.

[0059] It is also noted that aspects of the present disclosure may be described as a process illustrated as a flow chart, flow diagram, structure diagram, or block diagram. While a flow chart may describe operations as a sequential process, most operations may be performed in parallel or simultaneously. Additionally, the order of operations may be rearranged. A process terminates when its operations are completed. A process may correspond to a method, function, procedure, subroutine, subprogram, etc. When a process corresponds to a function, its termination corresponds to the function's return to the calling function or the main function.

[0060] Additionally, the storage medium may represent one or more devices for storing data, including read-only memory (ROM), random access memory (RAM), magnetic disk storage media, optical storage media, and flash memory devices, and / or other machine-readable media and processor-readable media and / or computer-readable media for storing information. The terms “machine-readable medium,” “computer-readable medium,” and / or “processor-readable medium” may include, but are not limited to, non-transient media such as portable or stationary storage devices, optical storage devices, and various other media capable of storing, containing, or transmitting instruction(s) and / or data. Accordingly, the various methods described herein may be fully or partially implemented by instructions and / or data stored in a “machine-readable medium,” “computer-readable medium,” and / or “processor-readable medium” and executable by one or more processors, machines, and / or devices.

[0061] Additionally, aspects of the present disclosure may be implemented by hardware, software, firmware, middleware, microcode, or any combination thereof. When implemented by software, firmware, middleware, or microcode, program code or code segments for performing necessary tasks may be stored in a machine-readable medium, such as a storage medium, or other storage(s). A processor may perform the necessary tasks. A code segment may represent any combination of procedures, functions, subprograms, programs, routines, subroutines, modules, software packages, classes, or instructions, data structures, or program statements. A code segment may be coupled to another code segment or hardware circuit by transmitting and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc. may be transmitted, forwarded, or sent via any suitable means, including memory sharing, message passing, token passing, network transmission, etc.

[0062] The various exemplary logic blocks, modules, circuits, elements, and / or components described in connection with the examples disclosed herein may be implemented or performed as a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic components, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any conventional processor, a controller, a microcontroller, or a state machine. The processor may also be implemented as a combination of computing components, for example, a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP core, or any other such configuration.

[0063] The methods or algorithms described in connection with the examples disclosed herein may be realized in the form of processing units, programming instructions or other instructions, directly in hardware, as software modules executable by a processor, or a combination of both, and may be contained in a single device or distributed across multiple devices. Software modules may reside in RAM memory, flash memory, ROM memory, EPROM memory, EEPROM memory, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium known in the art. A storage medium may be combined with a processor so that the processor can read information from the storage medium and write information to the storage medium. Alternatively, the storage medium may be integrated into the processor.

[0064] Those skilled in the art will further understand that the various exemplary logic blocks, modules, circuits, and algorithm steps described in connection with the aspects disclosed herein may be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate this interchangeability between hardware and software, various exemplary components, blocks, modules, circuits, and steps have been generally described in terms of their functionality. Whether such functionality is implemented in hardware or software depends on the design constraints imposed on the overall system and the specific application.

[0065] The present invention described above has been explained with reference to the embodiments illustrated in the drawings, but this is merely illustrative and those skilled in the art will understand that various modifications and variations of the embodiments are possible therefrom. However, such modifications should be considered to be within the technical scope of protection of the present invention. Accordingly, the true technical scope of protection of the present invention should be determined by the technical concept of the appended claims.

Claims

Claim 1 A secret key generation method composed of multibits based on uncloning elements, wherein the current signal range at a specific voltage from individual elements of an array composed of multiple elements is 2 k A step of defining (k = 2, 3, 4 …) regions; said 2 k A method comprising: a step of generating a plurality of maps, each assigning a different k-bit value to each of the regions; and a step of extracting a multibit response using a current signal distribution characteristic measured at a specific voltage from the individual element and a map identified by the challenge in response to a challenge including information identifying a selected individual element cell (x, y) of the array and information identifying one of the plurality of maps; wherein the step of generating the plurality of maps assigns the k-bit values ​​such that the Hamming distance (HD) between k-bit values ​​assigned to adjacent current signal ranges divided using a bit shuffle is at least 2, and the step of extracting the multibit response extracts an n-bit final response value by repeating n / k times in response to the request of the challenge. Claim 2 The method according to claim 1, wherein the step of extracting the multibit response comprises: a first step of obtaining a k-bit value of a map identified by the challenge corresponding to a current signal range measured in a selected individual element cell (x1, y1) of the array; and a second step of repeating the first step in a plurality of cells (x2, y2), cell (x3, y3) … cell (xi, yi) different from the individual element cell (x1, y1) to obtain a k-bit value of the corresponding map, and concatenating the obtained plurality of k-bit values ​​to obtain a final response value. Claim 3 A method comprising, in claim 1, the step of generating a key as unique encryption information for the array using the multibit response. Claim 4 A method according to claim 3, further comprising the step of exchanging the key and performing encrypted communication between a user device and a server, the user device including an array composed of the plurality of elements. Claim 5 A method according to claim 1, wherein the bit shuffle is performed such that the k-bit value assigned to an adjacent current signal range as the current value increases is assigned in the direction of a larger Hamming distance. Claim 6 delete Claim 7 In paragraph 1, the current signal range is 2 k A method characterized in that, in the step of defining regions (k = 2, 3, 4 …), the current signal range is between 1.8 mA and 5.3 mA. Claim 8 A method according to claim 1, characterized in that k is 4. Claim 9 A method according to paragraph 3, wherein the key is utilized as an identifier for the array or as an identifier for a user device including the array. Claim 10 A method according to claim 1, characterized in that the array is a device array fabricated by spraying CNTs onto a flexible substrate. Claim 11 A method according to claim 1, characterized in that the array is implemented as a wearable device including a smart band. Claim 12 A secret key generation device composed of multibits based on uncloning elements, wherein the current signal range at a specific voltage from individual elements of an array composed of multiple elements is 2 k Defined as (k = 2, 3, 4 …) regions, and the above 2 k A map generation unit that generates a plurality of maps, each assigning a different k-bit value to a respective region; a response extraction unit that extracts a multibit response using a current signal distribution characteristic measured at a specific voltage from the individual element and one of the plurality of maps; and a key generation unit that generates a key as unique encryption information for the array using the multibit response. The device comprises: an encryption communication unit that exchanges the key between a user device and a server, the user device including an array composed of the plurality of elements; wherein the map generation unit assigns the k-bit values ​​such that the Hamming distance (HD) between k-bit values ​​assigned to adjacent current signal ranges divided using bit shuffle is at least 2; and the response extraction unit extracts the multibit response using the map identified by the challenge in response to a challenge including information identifying a selected individual element cell (x, y) of the array and information identifying one of the plurality of maps, and extracts the n-bit final response value by repeating n / k times according to the request of the challenge. Claim 13 In claim 12, the response extraction unit extracts the multibit response through: a first step of obtaining a k-bit value of a map identified by the challenge corresponding to a current signal range measured in a selected individual element cell (x1, y1) of the array; and a second step of repeating the first step in a plurality of cells (x2, y2), cell (x3, y3) … cell (xi, yi) different from the individual element cell (x1, y1) to obtain a k-bit value of the corresponding map, and concatenating the obtained plurality of k-bit values ​​to obtain a final response value.

Citation Information

Patent Citations

  • Organized nanoparticulate and microparticulate coatings and methods of making and using same

    KR1020180113505A

  • Security device including physical unclonable function cells, operation method of security device, and operation method of physical unclonable function cell device

    KR1020210053029A

  • Device identification by quantum tunneling current

    KR1020220002340A