Broadcast-Free Threshold Key Generation with PUFs for Quantum Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key generation protocols over unencrypted channels are vulnerable to quantum attacks and require encrypted communication, broadcast communication, or assumptions of honest parties, making them unsuitable for the quantum era and impractical for cold storage settings.

Innovation Solution

A broadcast-free, threshold post-quantum key generation and verification protocol using hardware-based correlated randomness, specifically through physically unclonable functions (PUFs) to generate learning parity with noise (LPN) instances, which are sent over unencrypted channels to a central combiner for key combination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing key generation protocols are used over unencrypted channels, then key generation can be performed without encrypted communication, but the protocols are vulnerable to quantum attacks

Engineering Contradiction:
Improvekey generation over unencrypted channelsVSAvoidsecurity against quantum attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the cryptographic parameters from classical symmetric/asymmetric encryption to post-quantum cryptographic primitives including lattice-based LPN problems, code-based schemes, and hash-based constructions. This parameter change enables security against quantum attacks while maintaining operation over unencrypted channels.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional cryptographic mechanisms (encrypted communication channels, broadcast protocols) with hardware-based correlated randomness from physically unclonable functions (PUFs). This substitution eliminates the need for trusted communication infrastructure while providing quantum-resistant security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If encrypted communication channels with dedicated cryptographic commitment are used, then security against quantum attacks is improved, but device complexity and communication overhead increase

Engineering Contradiction:
Improvesecurity against quantum attacksVSAvoidcommunication channel requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from the communication channel layer and relocates it to the hardware randomness layer through PUFs. This extraction eliminates the need for encrypted channels while maintaining quantum security, as the PUFs provide correlated randomness directly at the hardware level.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces physically unclonable functions (PUFs) as an intermediary between the communication channels and the key generation process. These PUFs serve as a trusted randomness source that enables secure key generation over unencrypted channels by providing hardware-based correlated randomness.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If broadcast communication with zero knowledge proofs is used, then verification of key correctness is improved, but communication overhead and computational complexity increase

Engineering Contradiction:
Improveverification of key correctnessVSAvoidcommunication and computational requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent enables each device to self-verify its contribution to the key generation process using locally stored PUF responses and shared secrets. This self-service mechanism eliminates the need for complex broadcast zero-knowledge proofs while maintaining verification capability through distributed local computations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the verification process into individual local verification steps at each device rather than requiring centralized broadcast verification. Each device independently verifies its partial key contribution using its own PUF responses, distributing the verification workload and eliminating complex communication requirements.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If complete reliance on back and forth zero-knowledge proofs is used, then verification consistency is improved, but time for key generation increases

Engineering Contradiction:
Improveverification consistencyVSAvoidkey generation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-computing and storing PUF responses and verification data at each device before the actual key generation process. This preliminary preparation enables fast local verification without requiring time-consuming back-and-forth zero-knowledge proofs during key generation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables devices to perform self-verification using pre-stored PUF responses and local computations, eliminating the need for lengthy interactive verification protocols. Each device can independently and quickly verify key consistency using its own hardware randomness characteristics.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12407501B1Broadcast-free threshold post-quantum key generation and verification over unencrypted channels from hardware-based correlated randomness
Publication Date: 2025.09.02 CIRCLE INTERNET GRP INC
  • US12407501B1 patent drawing
  • US12407501B1 patent drawing
  • US12407501B1 patent drawing

AI summary

Methods, systems, and apparatus for generating an encryption key. In one aspect, a method includes the generating and sending, by a first device, a stream of random challenges to other devices. Each other device processes, by a physically unclonable function (PUF) included in the device, the stream of random challenges twice to obtain pairs of responses and computes a first Bernoulli matrix vector. Each other device generates a first LPN instance using a pre-stored public matrix, a partial encryption key, and the first Bernoulli error matrix, and sends the first LPN instance to the first device. The first device computes a threshold number of the first LPN instances and an estimated combined error of PUFs included in the other devices. The first device generates an encryption key by recovering a summation of each partial encryption key encoded in the threshold number of first LPN instances.