Hardware verification method for physical random number generators
By leveraging the physical variability of entropy sources for device fingerprints, the method addresses environmental sensitivity and integration issues of PUFs, providing secure and reliable hardware verification.
Patent Information
- Application Number
- PCT/EP2025/061093
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-24
- Filing Date
- 2025-04-23
- Publication Date
- 2025-10-30
AI Technical Summary
Current hardware verification methods, particularly Physically Unclonable Functions (PUFs), face challenges such as sensitivity to environmental conditions and integration complexities, affecting reliability and practicality, while the verification of entropy sources for cryptographic systems remains unsolved.
Utilizing the physical variability of entropy sources, including quantum and hardware-based phenomena, to derive device fingerprints through statistical metrics and challenge-response protocols, with adaptive constraints and computational complexity, to enhance security and integration with computing devices.
Ensures robust and reliable hardware verification, protecting against cloning and tampering, while ensuring the authenticity and integrity of devices and data across various applications.
Smart Images

Figure EP2025061093_30102025_PF_FP_ABST
Abstract
Description
[0001] HARDWARE VERIFICATION METHOD FOR PHYSICAL RANDOM NUMBER GENERATORS
[0002] BACKGROUND
[0003] Hardware attestation and verification stand as crucial processes in ensuring the integrity, authenticity, and security of electronic devices. By implementing rigorous verification methods, stakeholders can protect devices against counterfeiting, tampering, and various security breaches. This process is vital in maintaining trust and reliability across several domains, including critical infrastructure, cloud environments, military systems, financial services, and consumer electronics.
[0004] The application of hardware verification spans a broad spectrum of industries, highlighting its universal importance. In critical infrastructure, it ensures the operational integrity of systems governing water, electricity, and transportation. For cloud environments, it provides guarantees for advanced privacy-preserving cloud schemes, such as zero-trust computing. Military applications demand the highest level of security to protect against espionage and sabotage. In the financial sector, it guards against fraud and ensures the security of transactions. Consumer electronics, on the other hand, benefit from verification to protect users' data and privacy.
[0005] With all these applications in hand, failing to implement robust hardware verification can lead to dire consequences. This includes the potential for catastrophic failures in critical infrastructure, compromised cloud and national security, financial losses due to fraud, and severe breaches of user privacy in consumer electronics.
[0006] Traditional hardware verification methods include checksums, cryptographic signatures, hardware root of trust, and Physically Unclonable Functions (PUFs), among others. Each of these plays a pivotal role in validating the authenticity and integrity of devices. Checksums provide a simple means for integrity checks, cryptographic signatures offer a robust mechanism for authentication, and hardware root of trust establishes a foundation of trust from which to validate further processes and operations.
[0007] Among current on-going efforts for better hardware verification methods, Physically Unclonable Functions (PUFs) emerge as one of the potentially enabling hardware components for such task. PUFs leverage the inherent physical variations in manufacturing the hardware devices to create a unique fingerprint for each device. This uniqueness is practically impossible to replicate, making PUFs an ideal solution for secure device authentication and verification.
[0008] The process of generating and utilizing PUFs involves capturing and encoding these unique physical characteristics. This information is then used as a secure anchor for verifying the device's identity, providing a highly secure verification method. This verification is generally done through the use of "challenges", subjecting the PUF to a series of known answer questions, and verifying that the PUF does indeed respond to these challenges in the expected manner.
[0009] Several types of PUFs exist, including silicon PUFs, optical PUFs, and coating-based PUFs. Each type utilizes a different physical property to generate the PUF, from microscopic variations in silicon chips to unique patterns in optical coatings.
[0010] Despite their advantages, PUFs face several issues. These include sensitivity to environmental conditions, difficulties in consistent reading across different conditions, and the complexity of integrating them into existing verification frameworks. These limitations can affect the reliability and practicality of using PUFs for hardware verification. The sensitivity to environmental factors may lead to inconsistent verification results, while integration challenges can limit their widespread adoption.
[0011] Other widely relevant verification methods appear when verifying the existence, identity, and authenticity of an entropy source. Entropy source devices are fundamental to cryptographic systems, as they provide a source of unpredictability that is essential for almost every cryptographic primitive. Being able to verify the existence, identity, and authenticity of an entropy source is essential to ensure that the entropy source has not been compromised and that it has not been tampered with to reduce or even suppress its entropy generation capabilities. However, verifying the existence, identity, and authenticity of an entropy source is a problem that has not been completely solved, and is a subject of active research and innovation. SUMMARY
[0012] The present disclosure relates to devices, systems, and methods for hardware attestation and verification, using the physical variability of at least one entropy source and its effect over at least one magnitude or metric of the device or system, to derive a given fingerprint of the device from at least one of these said magnitudes or metrics. In some embodiments, at least one of these magnitudes is a statistical metric.
[0013] An entropy source, according to the present disclosure, produces random numbers by either using at least one unpredictable physical phenomenon, an algorithmic procedure, or a suitable combination of both. Preferably, the entropy source relates to at least one unpredictable physical phenomenon, with further post-processing through a suitable algorithmic procedure. Preferably, at least one of the unpredictable physical phenomena has a quantum origin. Examples of said entropy sources include -but are not limited to- phase-diffusion entropy sources and polarization-flips in VCSEL entropy sources, such as, but without limitation, VCSEL entropy sources as described in EP24382409.1, which is incorporated by reference in its entirety herein.
[0014] A magnitude, according to the present disclosure, refers to any property that can be either measured or computed from at least one measurement. Examples of magnitudes include -but are not limited to- the temperature of the entropy source, its power consumption, the optical power, laser back-reflections, and / or the number of requests per second experienced by the entropy source.
[0015] A metric, according to the present disclosure, includes (i) at least one measured magnitude of the entropy source and / or its environment; (ii) at least a result obtained after processing of any magnitude(s), and / or (iii) a combination of two or more of the above (as non-limiting examples, the combination of one of type (i) and another of type (ii), or three of type (i)). In some embodiments, the processing depends on at least one of: environmental parameters, operational parameters, or identification parameters. Examples of metrics include -but are not limited to- estimations of the conditional min-entropy bound, statistical metrics, and / or the average number of users of the entropy source. A statistical metric, according to the present disclosure, refers to any property related to the random data generated by the entropy source. Examples of statistical magnitudes include -but are not limited to- the running average, the bias of the data, the correlation with a given bitstring, the autocorrelation of the random data with itself (either before or after a given time), and / or the significance value of a given test over a given set of data.
[0016] For the sake of simplicity and clarity, embodiments of the disclosure will be simply described hereinafter as a device, although a device as described herein includes also systems comprising for instance two or more elements, apparatuses, or devices, those two or more elements, apparatuses or devices being functionally related to each other.
[0017] This disclosure also relates to systems and methods for generating those fingerprints of the device or system. In some embodiments, the correlation of the generated random numbers with at least another sequence is used as a challenge. In some embodiments, the sequence is the same random number sequence, with a given offset. Examples of these offsets include, but are not limited to, 1, 2, 4, and 8 bits. In some embodiments, at least one parameter of the entropy source is modified, such that the random number sequence acquires hard-to-replicate properties. Examples of these include, but are not limited to, driving signals to the entropy source, driving parameters of the entropy source, such as the bias of a laser, changing the bias of the random numbers, changing the temperature of the device, or artificially introducing artifacts in the stream itself.
[0018] This disclosure also relates to systems and methods for avoiding the pre-generation and / or storage of known challenge-response pairs. In some embodiments, a constraint is added to the challenge-response protocol. Examples of these constraints include, but are not limited to, temporal and / or physical constraints. In some embodiments, these constraints are specifically tailored to the device or system that needs to be hardware-verified.
[0019] In some embodiments of the devices, systems and methods, challenges of increasing computational complexity are used. Examples of these increasing challenges include, but are not limited to, increasing the window size on which the estimation of statistical magnitudes is done, increasing the difficulty of the challenges applied, or by multiple repetitions of the protocol. In some embodiments, those repetitions of the protocol are at least partially or totally independent one of the other.
[0020] This disclosure also relates to methods for compensating the effects of aging over the devices or systems. Examples of these aging effects include, but are not limited to, degradation, changes in performance, or drifts of the magnitudes and / or its effects used for hardware verification.
[0021] This disclosure also relates to devices and systems that act complementary or supplementary to PUFs. In some embodiments, the entropy source integrates at least one PUF that facilitates hardware verification. In some embodiments, the entropy source replaces PUFs by itself being capable of generating a series of known challenge-response pairs.
[0022] This disclosure also relates to devices and systems that integrate entropy sources. In some embodiments, at least one entropy source is integrated together with a computing device, with the entropy source serving both as a source of uncertainty and as a verification of the ensemble.
[0023] It is an object of this disclosure that the devices, systems, and methods described herein are used in applications including, but not limited to, at least one of: protection against cloning, hardware authentication, anti-counterfeiting, secure key generation, and / or secure communication.
[0024] It is a purpose of this disclosure to enhance security in physical systems by providing a cost- effective and robust mean of attesting, verifying, and protecting sensitive information from unauthorized access. It is also a purpose of this disclosure to ensure the authenticity and integrity of devices and data. Examples of applications that fulfill at least one of these purposes include, but are not limited to, medical device security, automotive security, voting systems, secure sensor networks, spacecraft and satellite security, data center infrastructure security, and / or smart grids.
[0025] BRIEF DESCRIPTION OF THE DRAWINGS
[0026] To complete the description and to provide a better understanding of the disclosure, a set of drawings is provided. Said drawings form an integral part of the description and illustrate embodiments of the disclosure, which should not be interpreted as restricting the scope of the disclosure but just as examples of how the disclosure can be carried out. The drawings comprise the following figures:
[0027] • Figure 1 shows a device or system with a single entropy source and computing device connected by a communications channel, describing a method for verification of the entropy source.
[0028] • Figure 2 shows a challenge-response method for verification of entropy sources.
[0029] • Figure 3 shows a challenge-response protocol for verification of entropy sources, with temporal constraints to exclude pre-generated or excessively delayed responses.
[0030] • Figure 4 shows a method for generating unique fingerprints through entropy source variability in response to challenge-response pairs.
[0031] • Figure 5 shows a method using challenges of increasing computational complexity to validate entropy sources.
[0032] • Figure 6 shows a method for adjusting a generic challenge-response method for verification of entropy sources for entropy source degradation.
[0033] • Figure 7 shows a fingerprinting method using an entropy source alongside an identification device for enhanced verification.
[0034] • Figure 8 shows the integration of an entropy source with a computing device, used as a hardware validation for both components.
[0035] DETAILED DESCRIPTION
[0036] Figure 1 shows a device or system 100 in accordance with some embodiments of this disclosure. In this case, the device or system 100 comprises at least one entropy source 101 and at least one computing device 102, communicating between themselves through a communications channel.
[0037] The illustrated device or system 100 shows a single entropy source 101 and a single computing device 102, connected via a communications channel, which, in some embodiments, is part of the device or system 100 and, in some other embodiments, it is not. In some embodiments, other devices or systems include more than one entropy source 101, and / or more than one computing device or system 102, and one or more communications channel. As a non-limiting example, in some embodiments multiple entropy sources 101 are connected to a single or to a plurality of computing device(s) or system(s) 102.
[0038] In the following, and for the sake of simplicity, 102 would be referred only as a device, but it will apply to "device, or system". Also, those devices and systems are readily translated into a corresponding method, i.e., the functions of those devices and systems may be steps of a corresponding method according to the present disclosure.
[0039] In some embodiments, the at least one entropy source 101 comprises one or more Physical Entropy Sources that leverage natural phenomena. Examples of these entropy sources include quantum effects such as phase diffusion or VCSELs. Other examples include -but are not limited to- atmospheric noise, thermal noise, environmental phenomena, chaotic effects, Brownian motion, fluid dynamics, avalanche noise in semiconductors, background radiation, variations in atmospheric conditions, variations in the Earth's magnetic field, and / or quantum effects such as energy level transitions, photon generation or detection times, or radioactive sources, among others.
[0040] In some embodiments, the at least one entropy source 101 comprises one or more Hardware- Based Entropy Sources that utilize hardware components of computing devices. Examples of these entropy sources include -but are not limited to- mouse movements, keyboard typing dynamics, sensor readings, network packet timing, system clock jitter, transistor noise, and / or physically unclonable functions (PUFs), among others.
[0041] In some embodiments, the at least one entropy source 101 comprises one or more Software- Based Entropy Sources that rely on patterns and timing in software activities. Examples include -but are not limited to- process timing variability, thread scheduling patterns, interrupt request timing, and / or system load variations, among others.
[0042] These sources are relevant for cryptographic applications, among others. In some embodiments, these sources are a component of various computing devices, including -but not limited to- servers, desktop computers, and mobile devices. In some of these embodiments, the at least one entropy source 101 and the at least one computing device 102 are embedded into the same physical device. Examples of these include -but are not limited to- a CPU that uses its own thermal noise as an entropy source, or an FPGA that uses its own clock jitter as entropy source.
[0043] In some embodiments, the at least one entropy source 101 comprises one or more Biological or Human-Generated Entropy Sources that leverage biological or human actions for randomness. Examples of these sources include -but are not limited to- biometric measurements like heart rate variability, among others.
[0044] In some embodiments, the at least one entropy source 101 comprises one or more data streams as input and sources of randomness, for instance those generated from a physical event, including those related to natural or human events or actions. Examples of these sources include -but are not limited to- global financial transactions, stock market fluctuations, live weather data, and / or global news feeds, among others.
[0045] In some embodiments, the at least one entropy source 101 comprises Deterministic Entropy Sources such as deterministic random number generators (DRBGs). These generators use initial seed values to produce sequences of pseudorandom numbers. Examples include -but are not limited to- hash-based DRBGs, block-based DRBGs, and / or other algorithms like CTR- DRBG and HMAC-DRBG.
[0046] In some embodiments, the at least one entropy source 101 comprises Quantum Entropy Sources that utilize quantum effects for randomness. Quantum random number generators (QRNGs) exploit the inherent randomness of quantum processes. Examples of these Quantum Entropy Sources include -but are not limited to- phase-diffusion processes, VCSELs, Photon polarization states, vacuum fluctuations, and / or quantum computers.
[0047] In some embodiments, two or more entropy sources that rely on different origins for their entropy are combined together. Examples of these combinations include -but are not limited to- distributed entropy sources that combine their streams, for example using XOR gates. In some embodiments, the at least one computing device 102 comprises the entropy source controllers themselves, responsible for managing and controlling entropy sources. Examples of these controllers include -but are not limited to- Application-Specific Integrated Circuits (ASICs), Systems-on-Chip (SoCs), Field-Programmable Gate Arrays (FPGAs), Microcontrollers (uCs), and / or Central Processing Units (CPUs).
[0048] In some embodiments, the at least one computing device 102 comprises personal devices, encompassing portable and handheld computing devices for personal tasks and communication. Examples of these personal devices include -but are not limited to- Personal Digital Assistants (PDAs), Wearable Devices like smartwatches and fitness trackers, phones, Smartphones, and / or Tablets.
[0049] In some embodiments, the at least one computing device 102 comprises more general computers, including -but not limited to- desktop computers, laptop computers, embedded systems, servers, datacenters, quantum, thin-client computers, virtual machines, and / or containers.
[0050] In some embodiments, the at least one computing device 102 comprises security and cryptography devices. Examples of these include -but are not limited to- Hardware Security Modules (HSMs), and Trusted Platform Modules (TPMs).
[0051] In some embodiments, the at least one computing device 102 comprises quantum technology devices. Examples of these include -but are not limited to- quantum computers, quantum processors, quantum cryptography systems, quantum repeaters, and / or quantum communication devices.
[0052] In some embodiments, the at least one computing device 102 comprises networking and communication devices that manage and facilitate data transmission. Examples of these include -but are not limited to- routers, switches, or firewalls, either real or virtual.
[0053] In some embodiments, the at least one computing device comprises one or more specialized computing devices or systems. Examples of these include -but are not limited to- Engine Control Units in vehicles, On-Board Computers in satellites and space-based systems, Application-Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), Graphical Processing Units (GPUs) and Microcontrollers.
[0054] In some embodiments, the at least one computing device 102 comprises an Artificial Intelligence (Al) engine, for instance a Narrow Al, General Al, and / or Superintelligent AL Such an engine in some embodiments includes a Generative Al module and or a Large Language Model (LLM) to generate a set of random numbers from the output of the entropy source 201.
[0055] A purpose of the at least one entropy source 101 together with element 102 is to generate sequences of random numbers, the quality of which is estimated within the at least one computing device 102 using a posteriori metrics and processing algorithms. These metrics and processing algorithms relate to various aspects of randomness and the quality of generated random number sequences, as well as being related to the device features, operation, or environment.
[0056] Regarding the generated random numbers, quality metrics encompass measurements that evaluate properties including one or more of the following: uniformity, independence, complexity, entropy levels, statistical moments, autocorrelation, compression, cryptographic properties, cycle length, and / or transformation effects.
[0057] Examples of quality, independence, and complexity metrics include, but are not limited to, the Frequency Test (Monobit), Long Run Test, and Poker Test for Uniformity; the Runs Up and Down Test and Autocorrelation Test for Independence; and / or the Entropy Test and Komogorov-Smirnov Test for Complexity.
[0058] Examples of entropy metrics include, but are not limited to, Shannon Entropy and Renyi Entropy definitions for Entropy estimation; as well as Mean Length of Code and Lempel-Ziv Compression Algorithm for Compression Test, alongside algorithms like Walsh-Hadamard Transform and Fourier Transform for Transformation Algorithms. Examples of statistical moments metrics include, but are not limited to, the Mean Test and Standard Deviation Test for Mean and Standard Deviation; and / or the Third Moment Test (Skewness) and Fourth Moment Test (Kurtosis) for Statistical Moments.
[0059] Examples of autocorrelation metrics include, but are not limited to, Autocorrelation at Lag 1 and Autocorrelation at Lag k for Linear Autocorrelation; and Up and Down Runs Test as well as Up and Down Correlation Test for Runs and Correlation Test.
[0060] Additionally, in some embodiments the selection of metrics and their ranges differ based, for example, on the at least one entropy source 101, the at least one computing device 102 under study, or the surrounding environment. For example, the Shannon entropy of a human entropy source is expected to be lower than that of a purified quantum entropy source.
[0061] Additionally, in some embodiments the selection of metrics is flexible, or even is not predefined. An example of these includes, but is not limited to, the leveraging of machine learning models to determine the quality of entropy and using the model as a classifier for good or bad behavior of the at least one entropy source.
[0062] Additionally, in some embodiments the at least one entropy source 101, the at least one computing device 102, or both includes at least a sensor, or at least an actuator which, either by themselves or by a suitable method, enable the measurement of magnitudes associated with, among others, operational or environmental factors in each of them.
[0063] In some embodiments, various metrics are combined within at least one computing device 102, e.g., by at least one processor thereof. In some embodiments, these metrics are merged either with other metrics originating from the same computing device 102 or from at least one sensor 103 of at least one of said entropy sources 101. Examples of such derived metrics include, but are not limited to, statistical correlation between temperature and entropy quality, frequency distribution analysis of noise levels, time-based entropy rate variations, and / or physical estimation of entropy bounds. A purpose of the at least one communications channel is to allow data transferring from and / or to at least one of the entropy sources 101 from and / or to at least one of the computing devices 102. In some embodiments, at least one of these channels is monodirectional; in some embodiments, at least one of these channels is bidirectional. Examples of these channels include, but are not limited to, wired channels such as metallic cables and PCB vias, wireless channels, secured and encrypted channels. In some embodiments, the data transferred via these channels complies with a given communication protocol; examples of these include, but are not limited to, MODBUS, CAN, and SMTP protocols.
[0064] A purpose of the disclosure is the sending of at least one response 111 to a given challenge, from the entropy source 101 to the computing device 102. In some embodiments, this response comprises the random numbers generated by the entropy source. In some embodiments, this response comprises at least one of the metrics aforementioned. In some embodiments, this response comprises at least one additional piece of information, not related to the aforementioned metrics. Examples of these non-related metrics include, but are not limited to, environmental, physical, or manufacturing parameters.
[0065] In some embodiments, such additional information is known previously by the computing device 102. In some embodiments, the information required is retrieved separately from the challenge response 111.
[0066] In some embodiments, the challenge response is generated under a given request 110 by the computing device. In some embodiments, this request is initiated by the computing device 102. In some embodiments, the request does not need to be initiated, and the entropy source 101 provides response to at least one challenge following a given schedule. In some embodiments, this enables continuous verification of the entropy source 101 by the computing device 102. Examples of these schedules include, but are not limited to, continuous, periodic and random times for sending the response. In some embodiments, such response schedule is changed dynamically.
[0067] In some embodiments, at least one of the parameters of the entropy source 101 is modified in order to configure the challenge response method. In some embodiments, this enables additional safety against the possibility for an external agent to learn valid responses, thus reducing the impersonating risk of the entropy source 101. In some embodiments, such change of parameters is included within the challenge response 110. In some embodiments, such change of parameters is sent separately from the challenge response.
[0068] In some embodiments, the challenge response method is controlled by a program 121 executing in at least one of the computing devices 102. This program implements the methods for performing the challenge response protocol. In some embodiments, the program itself implements the decision of whether the entropy source 101 has passed or failed the challenge. In some embodiments, the control of the protocol and the decision are implemented in the same computing device 102. However, in some embodiments the program is split into two or more computing devices 102; for example, the program can be run in distributed form between two or more computing devices 102, either as sequential parts of the program each run by one or more computing devices 102 or as parallel execution of the program by two or more computing devices 102. In some embodiments, this allows for spliting the verification process from any other process that the computing device 102 is carrying out.
[0069] Figure 2 shows a non-limiting example of a challenge-response protocol for an entropy source. In some embodiments, the method configures the entropy source 201, for example by reading and writing parameters, so that the entropy source is configured in any of the states required or admissible to the challenge-response protocol. After this configuration, the system is requested to generate a given set of random numbers 202, using the configuration from the previous step. These random numbers are sent to the computing device 203 and further processed 204, to derive from those at least one metric, including (but not limited to) any of the aforementioned metric examples. Once at least one metric is computed, each of these metrics are used in order to determine whether the challenge has been successful 205. Examples of these challenges include, but are not limited to, verifying that the bias is within a given range, verifying that the autocorrelation is within a given range, and verifying the probability of a given number of runs. In some embodiments, the metric calculations can be carried out directly at the entropy source 101. Therefore, the metric generation 204 and the sending to a computing device stages 203 are exchanged with respect to the scheme described in Figure 2.
[0070] In some embodiments, the challenge is required to be passed successfully multiple times 206. Examples of these schemes include, but are not limited to, probabilistic schemes and zeroknowledge proofs. For those cases, the whole process could be started again, until the decision protocol is in condition of making a determination regarding the verification of the device. In some embodiments, those repetitions of the protocol are at least partially or totally independent one of the other.
[0071] Some of these verification protocols are adapted to determine the difference between the device being verified and a model of it, such as a digital twin, that is capable of simulating the device's dynamics. Another adaptation, for example, avoids the usage of pre-generated or known challenge-response pairs. Figure 3 shows a non-limiting example of a challengeresponse protocol for an entropy source, with an added constraint, in accordance with some embodiments. In this non-limiting example, a temporal constraint 305 is added to the challenge verification scheme 300. In this non-limiting example, results that take less time than a given threshold are considered to be pre-generated and, thus, discarded; additionally, results that take more time than a (preferably different) given threshold are considered to be simulated and, thus, discarded as well. In preferred embodiments, such thresholds are tailored to the entropy source and the computing device under verification.
[0072] In some embodiments, the constraints are of physical kind: for example, the challengeresponse pair is received via a specific communication path, or with a given signature: any challenge-response pair that does not comply with the signature is automatically discarded. In some embodiments, this signature is response dependent. Examples of these include, but are not limited to, adding a nonce (such as a counter) to each challenge-response pair, and imposing their reception in sequential order; in some embodiments, any violation of this sequential order is considered a breach, and therefore the challenge is considered to be failed. Figure 4 shows a non-limiting example of a method for fingerprint generation using an entropy source. In this non-limiting example, the manufacturing variability of the entropy source is leveraged in such a way that they provide different, unique responses to the challengeresponse pairs of at least one challenge protocol. Examples of these challenges include, but are not limited to: the correlation of the generated random numbers with at least another, known sequence; the correlation of the generated random numbers with at least another, known sequence; the autocorrelation of the generated random numbers with themselves, with a given offset (including, but not limited to, 1, 2, 4, and 8 bits).
[0073] For some cases, the entropy source manufacturing variability manifests itself, not only in its optimal nominal working parameters, but also using parameters that may not be considered the optimal for random number generation. Leveraging this, in some embodiments at least one parameter of the entropy source is modified, such that the random number sequence acquires hard-to-replicate properties. Examples of these include, but are not limited to, modifying the calibrated parameters, driving parameters of the entropy source (including, but not limited to, the bias of a laser, the bias of the random numbers, the temperature of the device), or artificially introducing artifacts in the stream itself (including, but not limited to, XOR-ing the generated sequence with a known sequence).
[0074] Another way to avoid fake verification involves using challenges of increasing computational complexity. By these means, in those embodiments for which the simulation of the entropy source scales differently than the entropy source solving the challenge itself, the fake devices are identified and, thus, discarded. Figure 5 shows an example of a challenge-response protocol for an entropy source, in which challenges of increasing computational complexity are used 507. In this particular example, the window size on which the computation of statistical magnitudes is carried on increases for each challenge-response pair. Other examples include, but are not limited to, increasing the difficulty of the challenge applied, or by multiple repetitions of the protocol.
[0075] Figure 6 shows a non-limiting example of a method to compensate for degradations effects over the entropy source device or systems response on a generic challenge-response protocol. Examples of these degradations include, but are not limited to, aging effects, changes in performance, or drifts of the magnitudes and / or its effects used for hardware verification. In this particular example, the set of expected challenge-response pairs is executed by the hardware device. However, in this non-limiting example, besides checking the parameters against the expected response 605, the given response is taken as the ground truth for the following challenge-response pairs 607 if the degradation process is being executed 606. In some embodiments, the challenge verification phase 605 does not take place, and the result is taken directly as the ground truth 607.
[0076] Figure 7 shows a non-limiting example of a method for fingerprint generation using an entropy source, together with at least one additional component that acts complementary or supplementary to this functionality. In this case, the challenge-response pair is not carried out by the entropy source alone 701, 702, 703, but the entropy source comprises at least one identification device (including, but not limited to, physically unclonable functions). In some embodiments, the entropy source integrates at least one of these identification devices. In such embodiments, the verification protocol is modified to include challenging the identification device, 706, 707 either in parallel, in substitution of, or in combination with the challenges to the entropy source.
[0077] In all previous embodiments, the entropy source 101 and the computing device 102 are represented as separated entities. However, in some other embodiments, at least one entropy source and at least one computing device are integrated together and may operate in the same manner described with reference to the previous embodiments, aside from other ways of operation. Figure 8 shows a non-limiting example of an integration of an entropy source 101 and a computing device 102. Examples of these include, but are not limited to, CPUs and ASICs. In some embodiments, at least one entropy source 801 is integrated together with a computing device 802, with the entropy source serving both as a source of uncertainty and as a verification of either the entropy source, the computing device that integrates with it, and / or both, with respect to a third party 803. Examples of these include, but are not limited to, other computing devices.
[0078] In some embodiments, the verification protocol 121 executes at the computing device 802. In some embodiments, the verification protocol 121 executes at the third party device 803. In some embodiments, the verification protocol 121 executions are split between both parties.
[0079] As a non-limiting example, the computing device 802 executes the metric determination, whereas the third-party device 803 performs the challenge verification itself.
[0080] Methods in accordance with embodiments of the present disclosure are, in some embodiments, entirely run by one or more processors and, thus, are computer-implemented methods. Such methods can be implemented, in some cases, by a data processing device or system comprising means for carrying out the methods. Also, such methods can be implemented, in some cases, in the form of a computer program product that comprises instructions which, when the program is executed by at least one computer, cause the at least one computer to carry out the method. The instructions or the computer program product may be comprised by a non-transitory computer-readable storage medium. Alternatively, the instructions or the computer program product may be comprised by a data carrier signal carrying the instructions or the computer program product.
[0081] In this text, the term "includes", "comprises" and derivations thereof (such as "including", "comprising", etc.) should not be understood in an excluding sense, that is, these terms should not be interpreted as excluding the possibility that what is described and defined may include further elements, steps, etc.
[0082] On the other hand, the disclosure is obviously not limited to the specific embodiment(s) described herein, but also encompasses any variations that may be considered by any person skilled in the art (for example, as regards the choice of materials, dimensions, components, configuration, etc.), within the general scope of the invention as defined in the claims.
Claims
CLAIMS1. A device or system for hardware verification, comprising: a. at least one entropy source, b. at least one computing device, connected or connectable to said at least one entropy source, c. wherein the at least one computing device is adapted to use at least one challenge-response protocol to verify hardware of one or more said entropy sources by using at least one statistical metric of the said at least one entropy source, the at least one challenge-response protocol comprising at least one challenge-response pair; d. and wherein the at least one statistical metric is used in the at least one challenge-response pair.
2. The device or system of claim 1, wherein the challenge-response protocol comprises using multiple individual challengeresponse pairs.
3. The device or system of claim 2, wherein the challenge-response protocol comprises a periodic request of multiple individual challenge-response pairs.
4. The device or system of any one of claims 1-3, wherein the at least one challenge-response pair is to be completed fulfilling either a temporal or physical condition to be considered successful.
5. The device or system of any one of claims 1-4, wherein the at least one computing device is configured to output or use results from the hardware verification for fingerprint of the one or more entropy sources.
6. The device or system of any one of claims 1-5, wherein the at least one computing device is configured to redefine results from the hardware verification at least based on a predetermined process for accounting for degradation effects.
7. The device or system of any one of claims 1-6, wherein the at least one computing device is configured to receive at least one identity verification result for the hardware from at least one additional identityverification device or system; and the at least one computing device is configured to combine results from the challenge-response protocol with the at least one result identity verification result.
8. The device or system of claim 6, or claim 7 when depending upon claim 6, wherein degradation effects are accounted for by taking at least one challenge-response pair as ground truth.
9. The device or system of any one of claims 1-8, wherein the at least one entropy source is integrated into the computing device.
10. The device or system of any one of claims 1-9, wherein the at least one entropy source comprises at least one quantum entropy source.
11. The device or system of any one of claims 1-10, wherein the at least one entropy source is configured with different calibration parameters before starting the challenge-response protocol.
12. The device or system of claim 11, wherein the at least one entropy source is restored to the previous state after concluding the challenge-response protocol.
13. The device or system of any one of claims 1-12, wherein the at least one computing device is configured to determine whether the entropy source is verified or not verified.
14. The device or system of any one of claims 1-13, wherein the verified hardware comprises at least one entropy source and at least one computing device.
15. A method comprising: a) obtaining, by at least one computing device, at least one statistical metric of at least one entropy source; b) computing, by the at least one computing device, a challenge-response pair at least based on the at least one statistical metric; and c) verifying, by the at least one computing device, the hardware of the at least one entropy source by using the computed challenge-response pair.
Citation Information
Patent Citations
Systems and methods for leveraging path delay variations in a circuit and generating error-tolerant bitstrings
WO2015031683A1
EP24382409A
Cited By
Identity authentication method and system of Internet of Vehicles terminal
CN121985333A