Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

58 results about "Key derivation function" patented technology

In cryptography, a key derivation function (KDF) derives one or more secret keys from a secret value such as a master key, a password, or a passphrase using a pseudorandom function. KDFs can be used to stretch keys into longer keys or to obtain keys of a required format, such as converting a group element that is the result of a Diffie–Hellman key exchange into a symmetric key for use with AES. Keyed cryptographic hash functions are popular examples of pseudorandom functions used for key derivation.

Distributed photovoltaic annular communication group key generation method and system

According to the distributed photovoltaic ring communication group key generation method provided by the invention, safe and efficient group key management is realized by combining a group number derivation mechanism, environment feature binding and a quantum key enhancement technology. The method comprises the steps that a preset broadcast root key is called from a concentrator, and the broadcast root key is used for deriving group keys of members in each group; acquiring environment characteristics of members in each group in a communication group corresponding to the concentrator, and recording an acquisition timestamp; summarizing the environmental characteristics of all members in the communication group, and performing hash processing on the summarized environmental characteristics to obtain an initial environmental characteristic vector; and generating a first group key with a preset length through a key derivation function based on the broadcast root key, the initial environment feature vector, the timestamp and a preset group identifier.
Owner:CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +1

Vehicle information safety protection system based on combination of national secret algorithm and PUF (Physical Unclonable Function)

The invention discloses a vehicle information safety protection system based on combination of a national cryptographic algorithm and a PUF (Physical Unclonable Function), which belongs to the field of vehicle information safety and encrypted communication, and comprises a response generation module used for generating a PUF response in a safety chip of a vehicle; the key derivation module is used for generating an encrypted master key through a key derivation function based on the PUF response, the vehicle owner identity and the random number nonce; the encryption and signature module is used for generating a ciphertext and carrying out digital signature on the ciphertext; the state monitoring module is used for monitoring the running state of the vehicle hardware; the key management module is used for triggering a failure operation of the encrypted master key when the state monitoring module detects that the hardware state is abnormal; and the decryption verification module is used for regenerating the PUF response and verifying the consistency of the generated key so as to execute data decryption. According to the method, hardware-level encryption protection of the vehicle data is realized through combination of the PUF and the national cryptographic algorithm, so that the safety of the vehicle owner data is protected in the whole life cycle of the vehicle.
Owner:HUBEI UNIV

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Method and system for establishing a secure messaging channel between a smartcard and an end device

PendingDE102024129366A1Security arrangementSecuring communicationPersonal identification numberTerminal equipment
A method for establishing a secure messaging channel between a smartcard and an end device is described. The smartcard contains a Personal Identification Number (PIN), an initial key derivation function, and a communication channel establishment protocol. The end device contains the PIN, the initial key derivation function, and the communication channel establishment protocol. The method comprises the following steps: creating an initial key on the smartcard and on the end device based on the PIN and the initial key derivation function; creating a nonce value, which further comprises the following steps: generating the nonce value on one end device or the end device; encrypting the nonce value with the initial key; and sending the encrypted nonce value to the other end device or the smartcard.and decrypting the encrypted nonce value with the first key, executing the communication channel establishment protocol on the smartcard and on the terminal device based on the generated nonce value to generate a second key on the smartcard and on the terminal device, first deriving a first secure messaging channel key on the smartcard and on the terminal device based on the second key, and second deriving a second secure messaging channel key on the smartcard and on the terminal device based on the second key.
Owner:SECUNET SECURITY NETWORKS GMBH

System and method for multi-factor key derivation

A system and method for multi-factor key derivation includes: a user having a plurality of authentication factors; whereby the plurality of authentication factors are converted into key material using intermediate factor-specific functions, and whereby said key material is then converted into a key using a key derivation function.
Owner:MULTIFACTOR INC

Firmware updating method, electronic device, server and system

This disclosure relates to a firmware update method, an electronic device, a server, and a system. The method includes: obtaining from a user device an encrypted firmware update package sent by a server to the user device in response to a firmware update request from the electronic device, and a firmware decryption key enDecKey encrypted by the server using a key encryption key KEK, wherein the key encryption key KEK is a temporary key derived based on a predetermined key derivation function; decrypting the received encrypted firmware decryption key enDecKey using the key encryption key KEK to obtain a firmware decryption key decKey; and decrypting the encrypted firmware update package using the firmware decryption key decKey to obtain a firmware update package for updating the firmware in the electronic device.
Owner:TP-LINK INT SHENZHEN CO LTD

Key establishment and secure communications based on satellite-connected entropy sources

Systems and techniques for secure communications and distribution of random values, provided via satellite communications, are described. These random values are generated from one or more ground-based entropy sources (e.g., quantum random number generators (QRNGs) at terrestrial locations), and optionally combined with values from satellite-based entropy sources (e.g., QRNGs at non-terrestrial locations). An example method includes: receiving a first random value generated by a first QRNG at a terrestrial location; receiving a second random value and a third random value via at least one satellite communication, each additional random value generated by other QRNGs; and generating a cryptographic key based on the first random value, the second random value, and the third random value. The cryptographic key may be produced by a key derivation function that combines the random values, and the cryptographic key may be used to establish a secure communication session.
Owner:WELLS FARGO BANK NA

A private AI model calling method and system based on encrypted data interaction

The application belongs to the technical field of artificial intelligence, and particularly relates to a private AI model calling method and system based on encrypted data interaction, which comprises the following steps: S1, a client generates a series of structured random numbers through a key derivation function based on a main random number seed and each dimension index, encrypts an original input vector into an initial ciphertext vector by using a partial homomorphism encryption public key and the structured random numbers, generates a conditional re-encoding key pair for nonlinear calculation in the AI model, and sends a re-encoding public key to a server. The application can eliminate the confusion ciphertext, so that the server side constructs a quasi-gradient noise based on the intermediate state of the calculation process and injects the result, resisting side channel attacks on the output ciphertext; and the client can reconstruct and remove the noise, so that the lossless calling result is obtained without sacrificing any calculation accuracy, and end-to-end privacy protection of the whole model reasoning process is realized.
Owner:XIAN MINGFU CLOUD COMPUTING CO LTD

Bluetooth data transmission encryption method based on intelligent terminal

The application relates to the field of Bluetooth data transmission security technology and discloses a Bluetooth data transmission encryption method based on an intelligent terminal. After the intelligent terminal and a receiving device establish a Bluetooth connection, a temporary session key is generated. A built-in hardware security module of the terminal is accessed to obtain a pre-stored root key. The root key and the temporary session key are used as inputs to generate a session encryption key with higher strength through a key derivation function. The session encryption key is used to encrypt data to be transmitted by using a symmetric encryption algorithm. The hash value of the original transmission data is independently calculated based on a hash function and used as an integrity check code of the data. The encrypted data and the integrity check code are encapsulated and sent to the receiving device through a Bluetooth protocol stack. The application strengthens the security of the key by combining hardware security and dynamic negotiation, and improves the anti-attack ability and reliability of Bluetooth data transmission by adopting an independent integrity check mechanism.
Owner:深圳市乾海芯联科技有限公司 +1

Locking and unlocking the communication interface of electronic devices for powered vehicles.

To lock the communication interface of an electronic device (1) for a powered vehicle, a first identifier (3) is determined, which characterizes a hardware component or a software component of a computing unit (2) on the production line in which the electronic device (1) was produced. A second identifier (4) characterizing the electronic device (1) is obtained. A first input value for a predetermined key derivation function is generated by the computing unit (2) based on the first identifier (3), and a second input value for the key derivation function is generated based on the second identifier (4). A key is generated by the computing unit (2) using the key derivation function based on the first and second input values, and the communication interface is locked using the key.
Owner:CONNAUGHT ELECTRONICS

A Hybrid Quantum-Resistant Security Enhancement Method for IPSec VPN

PendingCN122372190AKey exchangeData pack
This invention proposes a hybrid quantum-resistant security enhancement method for IPSec VPNs. The method includes: intercepting Internet Key Exchange (ITE) packets and adding a proxy header between the transport layer header and the ISE payload of the packets; obtaining a quantum key from a key pool using quantum key distribution technology and generating a first-stage session key based on the quantum key; protecting the ISE key negotiation process using a quantum-resistant cryptographic algorithm to generate a second-stage session key; and using the first-stage and second-stage session keys as input parameters for a key derivation function to generate a final session key for encrypted data transmission. This invention, without modifying the original IPSec negotiation process, supports dynamic key combinations of different security levels, enhancing the quantum security protection capability of VPN data transmission while maintaining system flexibility and performance.
Owner:CHINA MOBILE COMM GRP CO LTD +3

Method and system for hierarchical encryption of multi-type data of 5G new call

The invention relates to the technical field of 5G communication security and service encryption, and discloses a 5G new call multi-type data hierarchical encryption method and system, and the method comprises the steps: obtaining a voice stream and continuous video frames in a 5G new call, and extracting a voice emotion sequence and a video time sequence feature sequence; based on a pre-negotiated master key, the emotion-expression consistency hash value and the timestamp of the time window, generating a consistency binding key through a key derivation function, and forming a cross-modal synchronization key pair; adding an emotion-expression consistency hash value and a cross-modal association feature vector into the encrypted data packet to generate an encrypted data packet group; and the receiving end extracts the cross-modal association feature vector from the encrypted data packet, recalculates the emotion-expression consistency hash value, compares the emotion-expression consistency hash value with the received hash value for verification, and decrypts the data by using the consistency binding key after the verification is passed. According to the invention, deep fusion of encryption protection and multi-modal authenticity verification is realized.
Owner:HANGZHOU FREE TRAVEL INFORMATION TECHNOLOGY CO LTD

Secure parallel upgrading method and system for embedded device firmware based on CAN bus, electronic device and medium

The invention discloses a secure parallel upgrading method and system for firmware of embedded equipment based on a CAN bus, electronic equipment and a medium, and belongs to the field of embedded systems.The secure parallel upgrading method comprises the steps that an equipment management server generates an upgrading data packet; the server generates a temporary session key through a key derivation function, encrypts firmware to be upgraded by using the temporary session key, and then generates a digital signature for encrypted firmware data by using a private key of the server; the server issues the upgrade data packet to the embedded device in parallel through a CAN bus; the embedded device receives the upgrade data packet, derives the same temporary session key by using a preset fixed key and the received random number, verifies the digital signature by using a preset server public key, decrypts the firmware data by using the temporary session key after the verification is passed, and performs integrity verification; and finally, loading and operating the new firmware according to the firmware effective strategy. According to the method, the problems of firmware version synchronization and low serial upgrading speed are solved, and the efficiency and the safety are improved.
Owner:CHENGDU SANLING RUITONG MOBILE COMM CO LTD

Database access control method and computer device

PendingCN122286835AHash functionEngineering
This application provides a database access control method and computer device. The method first receives a privileged access request and generates a request digest and session identifier to determine the session validity period. Then, after the approval node completes valid signing, a threshold authorization token is generated. Next, an alias seed is generated using a key derivation function with an alias root key and multiple authorization information including at least the threshold authorization token and session identifier. Based on this seed, a transient access alias and a role lease identifier are derived using a hash message authentication code and a hash function, respectively. Finally, a zero-resident privileged session is established based on the transient access alias, role lease identifier, and session validity period, valid only in the current session. The transient access alias and role lease identifier are reclaimed when the session ends or a revocation condition is triggered. Through these steps, security risks are reduced, and on-demand, dynamic, and revocable database privileged access control is achieved, significantly improving database access security.
Owner:JIUYOU TECH (SHENZHEN) CO LTD

Controller and its safe operation method and system

The application relates to the technical field of embedded systems, and provides a controller and a safe operation method and system thereof. The method is applied to a controller without a hardware security module, and comprises the following steps: obtaining device unique characteristic information of the controller; generating a device root key through a key derivation function based on the device unique characteristic information; wherein the device root key exists in a volatile memory; deriving a function key based on the device root key; and performing a safe operation on target data by using the function key. The safe operation of the controller is realized by combining the device unique characteristic information in a software mode, and security threats such as firmware tampering and data leakage are effectively resisted.
Owner:WUHAN JIANGXIA CHUNENG AUTOMOBILE TECHNOLOGY R&D CO LTD

Method and system for establishing a secure messaging channel between a smart card and a terminal device

PCT designated stageWO2026078046A1Key distribution for secure communicationPersonal identification numberMessage delivery
The invention relates to a method for establishing a secure messaging channel between a smart card and a terminal device. A personal identification number (PIN), a first key derivation function and a communication channel establishment protocol are provided on the smart card. The PIN, the first key derivation function and the communication channel establishment protocol are provided on the terminal device. The method comprises the following steps: creating a first key on the smart card and on the terminal device on the basis of the PIN and the first key derivation function, creating a nonce value, wherein creation further comprises the following steps: generating the nonce value on one of the smart card or the terminal device, encrypting the nonce value using the first key, sending the encrypted nonce value to the other of the terminal device or the smart card, and decrypting the encrypted nonce value using the first key, executing the communication channel establishment protocol on the smart card and on the terminal device on the basis of the created nonce value in order to create a second key on the smart card and on the terminal device, deriving, a first time, a first secure messaging channel key on the smart card and on the terminal device on the basis of the second key and deriving, a second time, a second secure messaging channel key on the smart card and on the terminal device on the basis of the second key.
Owner:SECUNET SECURITY NETWORKS GMBH

Authentication method, system, client and server based on key derivation function

The application discloses a kind of authentication method, system, client and server based on key derivation function, wherein the method includes: client is based on key derivation function according to Secret Key, salt and master password Derivation authentication key, and corresponding verification key is calculated;VC of service end is obtained and verified, and the DID of service end in VC is used to obtain the communication key of service end from the verifiable data registry to encrypt account information, verification key and salt, and the encrypted content is sent to service end;Service end decrypts the account information to be registered, verification key and salt, and sends verification request to client, after verification succeeds, stores verification key and salt, and returns the account information of registration success to client;Verification key and salt are used for mutual authentication between client and server when user identity authentication is carried out.The application can completely authenticate user identity independently of TLS / SSL certificate chain, and improves the security of identity authentication.
Owner:北京泰尔英福科技有限公司

Method for storing and sharing confidential data between multiple instances of application programs

The invention relates to a method for storing and sharing data between instances of application programs, comprising steps of defining a structure (DS1) of data fields (DF1-DF8), defining an encryption key derivation tree structure comprising key derivation paths based on a root node (Nr), defining an association rule whereby each data field is associated with a leaf node and with a derivation path, identifying the derivation path (m / 1 / 1 / 1... m / 1 / 3 / 4) associated with a data field pursuant to the association rule, generating an encryption key (K111-K134) by way of a key derivation function and based on the root encryption key (Kr) and the associated derivation path, encrypting the datum with the encryption key and storing the encrypted datum.
Owner:LEDGER

Systems and methods for utilizing machine learning models to generate encryption keys

A device may receive input key material, and may process the input key material, with a trained generative adversarial network (GAN) model, to generate an encryption key with a maximized entropy. The trained GAN model may include a key generator network model trained to generate encryption keys that generalize key derivation functions with higher entropy to enhance cryptographic security, and a key discriminator network model trained to predict authenticities of the encryption keys generated by the key generator network model. The device may perform one or more actions based on the encryption key.
Owner:VERIZON PATENT & LICENSING INC

Distinct user plane security

Apparatuses, methods, and systems are disclosed for setting up multiple user plane (“UP”) security contexts. One apparatus includes a transceiver and a processor that derives distinct UP integrity and ciphering keys for a selected central unit user plane (“CU-UP”) node in the RAN, said derivation using a key derivation function. The processor assigns a UP Security Indicator to uniquely identify the derived distinct UP integrity and ciphering keys and the transceiver sends a setup request to the selected CU-UP node, said setup request containing the UP Security Indicator and the distinct UP integrity and ciphering keys. The transceiver receives a setup response from the selected CU-UP node and the processor activates distinct UP security at a UE.
Owner:LENOVO (SINGAPORE) PTE LTD

Oracle for authenticating software layers using software security version numbers and security context

Example embodiments of the present disclosure provide for an example method including maintaining a current version info list including version info tuples for software layers. The example method includes, upon receipt of a request for a registered version key, performing a comparison algorithm to authenticate a requested version info list including a number of version info tuples associated with software layers. The tuples can include a security version number (SVN) and a security context string for each software layer. The requested version info list can be authenticated using the comparison algorithm to determine that the requested version info list includes version info tuples with higher SVNs than the current version info list. Responsive to authenticating the requested version info list, the method include providing a portion of the requested version info list as input into a key derivation function (KDF) and obtaining a device requested version key as output.
Owner:GOOGLE LLC

Quantum key distribution and anti-quantum signature secure fusion method

The invention relates to a quantum key distribution and anti-quantum signature secure fusion method, which comprises the following steps: two communication parties initialize a system and establish a communication channel, establish a data channel for transmitting public information, and complete physical synchronization of a quantum channel for transmitting quantum states, and the two communication parties distribute the quantum states through the quantum channel, a shared quantum key is obtained on a data channel through basis vector comparison, information coordination and privacy amplification, two communication parties obtain a session working key for data encryption through a key derivation function based on the shared quantum key, a sender encrypts plaintext data by using the session working key and a symmetric encryption algorithm, and the encrypted plaintext data is transmitted to a server. And S105, the ciphertext is transmitted to a receiver through a data channel, the receiver carries out decryption by using the same session working key, and according to a preset strategy, S103 to S105 are repeatedly executed to update the session working key and carry out secure erasure on an invalid old key.
Owner:WEIDE GUANGDONG INFORMATION TECH CO LTD

Method for fusing quic protocol link establishment process and 5g nas process

The application discloses a method for fusing a QUIC protocol link establishment process and a 5G NAS process, belongs to the field of Internet transmission protocols, and comprises the following steps: a terminal embeds a QUIC context descriptor (QCD) in a 5G NAS registration request, wherein the QCD contains a 64-bit connection identifier, a 4-bit maximum flow quantity field and a 1-bit pre-shared key request flag; an access management function on the network side analyzes the QCD and generates a KgNB key based on 5G AKA authentication, generates a QUIC pre-shared key through a key derivation function, and allocates a dynamic connection identifier list, wherein the list contains a main CID and a standby CID; a session management function issues a CID-QoS flow mapping rule to a user plane function through an N4 interface, and establishes a preconfigured QUIC connection context. The application embeds QUIC parameters in 5G NAS signaling through a terminal-side QUIC-NAS fusion module, realizes deep coupling of protocol stacks, reduces network interaction delay, quickly establishes a connection, returns the derived KgNB key to a network-side application end, and constructs a transmission layer security protection.
Owner:STAR DIGITAL CHAIN (BEIJING) TECHNOLOGY CO LTD

Dynamic encryption authentication method and system based on channel adaptation and multi-modal fingerprint

The application relates to the technical field of data encryption, and relates to a dynamic encryption authentication method and system based on channel self-adaptation and multi-modal fingerprints, which comprises the following steps: firstly, using a receiving end and a spectrum analyzer and other devices to obtain the signal-to-noise ratio, channel state information, error vector amplitude and channel impulse response of a communication channel, and using a current transformer to obtain the current harmonic amplitude ratio of a motor of the device, and calculating the average bit error rate; then, according to the real-time signal-to-noise ratio and the average bit error rate, combining a preset strategy to dynamically select an encryption algorithm and the corresponding key length; then, taking the channel impulse response characteristics, the current harmonic amplitude ratio and the error vector amplitude as multi-modal fingerprints, splicing according to preset weights and generating a temporary session key through a key derivation function; finally, using the selected encryption algorithm and the generated temporary session key to perform dynamic encryption authentication. The application can improve the security of the authentication process and reduce the communication delay.
Owner:JINAN UNIVERSITY

Key generation for a cluster of nodes within a single security association

Each computing node in a computing cluster includes at least a key generator and a cryptographic engine. The key generator implements a key derivation function and generates a first data encryption key based on the key derivation key. The key derivation key is a global security association encryption key shared by multiple nodes in the computing cluster. The first data encryption key is unique to a node pair, including a first node and a second node among multiple nodes. The cryptographic engine uses the first data encryption key to encrypt data packets.
Owner:ADVANCED MICRO DEVICES INC

Data management method and device for fingerprint solid state disk, medium and product

The invention discloses a data management method and device for a fingerprint solid-state disk, a medium and a product, and relates to the field of solid-state disks. In the method, if it is monitored that a fingerprint sensor collects and successfully verifies a user fingerprint, a main session key is generated, and an empty dynamic access context is initialized; analyzing the first data access instruction in a state that the dynamic access context is empty, and determining a first initial logic block address and a first static logic partition from the first data access instruction; taking the main session key and the identifier of the first static logic partition as input, and calculating a first partition access key through a preset key derivation function; and adding the identifier of the first static logical partition and the first partition access key into the dynamic access context, and performing decryption operation or encryption operation on the data of the first initial logical block address by using the first partition access key to complete the first data access instruction. By implementing the technical scheme, the security of solid state disk data management is improved.
Owner:SHENZHEN XINGYAO SEMICON CO LTD

Dynamic data encryption transmission method and system and storage medium

The invention discloses a dynamic data encryption transmission method and system and a storage medium, and belongs to the technical field of data communication security. The method aims to solve the problems of high key leakage risk and high key management overhead in a traditional static key encryption scheme. According to the method, the initial key and the initial vector are pre-shared at the sending end and the receiving end, and the encryption key of each data block is dynamically generated by depending on the ciphertext content of the previous data block in the transmission process. Specifically, a sending end and a receiving end synchronously calculate a current dynamic key according to a previous ciphertext block through hash and a key derivation function, and encrypt and decrypt a current data block by using the key. Due to the chained evolution characteristic of the secret key, cracking of a single ciphertext does not affect the security of other data, and data tampering can cause subsequent decryption failure, so that extremely high security, built-in integrity verification and replay attack resistance are provided, additional transmission of the secret key is not needed, and the communication overhead is reduced.
Owner:白玉

Forward-secure end-to-end encryption method, device and storage medium

The application relates to the field of network security and discloses a forward security end-to-end encryption method, equipment and a storage medium. The method comprises the following steps: a WebSocket server receives a hardware key handle and a hardware ECDH public key, and sends the hardware ECDH public key to a client front end; the client front end receives the hardware ECDH public key, performs deducing encryption processing on session plaintext according to a preset key derivation function, the hardware ECDH public key and a client ECDH private key, generates session data, and transmits the session data to the WebSocket server; the WebSocket server receives the session data, transmits the session data to a hardware key end based on the hardware key handle; and the hardware key end performs decryption processing on the session data based on a master key, and generates session plaintext. In the embodiment of the application, the key separation design ensures forward security and overcomes the problem that the private key can be intercepted in a side channel.
Owner:SHENZHEN ECHOSENS MEDICAL EQUIP CO LTD

Electric power communication unified authentication method based on quantum

The invention relates to an electric power communication unified authentication method based on quantum. The method comprises the following steps: a terminal device initiates an authentication request to a unified authentication platform; the unified authentication platform forwards the equipment identifier to the quantum key service system based on the authentication request; the quantum key service system obtains a true random quantum key, dynamically allocates a disposable session key pair for the current authentication session, and returns a session public key to the unified authentication platform; the unified authentication platform sends challenge information to the terminal equipment; the terminal equipment generates a temporary private key corresponding to the current session based on the root key and the session public key, performs digital signature and returns a signature result; the unified authentication platform sends the signature data, the device identifier and the session public key to a quantum key service system for signature verification; and the quantum key service system executes black box type signature verification operation, verifies the signature validity through a key derivation function, and returns a Boolean type signature verification result to the unified authentication platform.
Owner:STATE GRID FUJIAN ELECTRIC POWER CO LTD

Systems and methods of physically unclonable function (PUF)-based key derivation function

Solutions and methods are disclosed herein for generating a key from outputs of a Physically Unclonable Function (PUF) and using the key for a cryptographic algorithm. In one embodiment, a device generates the key, which comprises (i) receiving a request to generate a key comprising a defined number of bits for a particular cryptography algorithm and (ii) responsive to receiving the request, generating a valid key for the particular cryptography algorithm. The step of generating the valid key further comprises (a) generating one or more first challenges for a PUF, which is one or more of a plurality of challenges in a challenge space of the PUF, (b) generating a first potential key based on one or more first responses by the PUF responsive to the one or more first challenges, and (c) determining whether the first potential key satisfies one or more predefined criteria for the particular cryptography algorithm.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)