Cryptographic Device Dual-Path Authentication PUF Entropy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face challenges due to medium security levels of FIDO public keys and limited randomness in physical unclonable function (PUF) identifiers, making them vulnerable to quantum computing attacks and side-channel attacks.

Innovation Solution

A cryptographic device with dual-path authenticated key-exchange security mechanisms, utilizing a novel entropy-entanglement process to generate high-diversity PUF-generated keys, and incorporating biometric features to enhance security without the need for passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If FIDO public-key cryptography is used for authentication, then device-centric security model is established, but the security level remains medium due to key length and side-channel attack vulnerabilities

Engineering Contradiction:
Improveauthentication securityVSAvoidquantum computing attack and side-channel attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication process is segmented into two independent paths: (1) FIDO public-key authentication path and (2) PUF-based authentication path. Each path operates independently with its own key material and authentication mechanism, so that compromise of one path does not affect the other. The final authentication result is determined by combining results from both paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system combines two different cryptographic approaches (asymmetric cryptography and PUF-based symmetric cryptography) into a composite authentication mechanism. This composite approach leverages the strengths of both methods while mitigating their individual weaknesses, achieving higher overall security than either method alone.

Inventive Principle:
Principle #40Composite materials

2Reliability

If traditional PUF identifiers are used for key generation, then hardware-based security is provided, but the randomness is limited and can be deciphered by statistical modeling

Engineering Contradiction:
Improvekey generation securityVSAvoidrandomness strength and PUF identifier diversity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system transforms the limited-randomness PUF identifiers into high-entropy key material by introducing a second dimension of randomness through the entropy pool. Instead of relying solely on the PUF identifier's inherent randomness, the system combines it with additional entropy sources, effectively moving from a single-source to a multi-source entropy model.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system changes the entropy parameter by pooling multiple entropy sources including PUF identifiers, random numbers from hardware random number generators, and other system entropy sources. This parameter change transforms the entropy pool into a high-entropy source that can generate cryptographically secure random numbers even when individual PUF identifiers have limited diversity.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If single-path key-exchange is used, then authentication process is simplified, but vulnerability to Man-In-The-Middle attacks remains

Engineering Contradiction:
Improveauthentication process complexityVSAvoidMan-In-The-Middle attack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

Each authentication path (FIDO path and PUF path) has its own local quality characteristics and operates independently with its own security properties. The FIDO path uses asymmetric cryptography with its own key pairs and authentication flow, while the PUF path uses symmetric cryptography derived from PUF identifiers. This local quality differentiation allows each path to be optimized for its specific security requirements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12255880B2Cryptographic device, system and method thereof
Publication Date: 2025.03.18 WU PAUL YING FUNG
  • US12255880B2 patent drawing
  • US12255880B2 patent drawing
  • US12255880B2 patent drawing

AI summary

The invention provides a device with cryptographic function, which includes: a hardware unit, exhibiting hardware-intrinsic properties; a key generating unit, generating a private key according to the hardware-intrinsic properties, and generating a public key according to the private key, for exchanging public keys with an outside device to convert communication payload information into first encrypted information based on the received public key; and a session operational unit, establishing a session key configured to encrypt the first encrypted information into second encrypted information to be transmitted between the cryptographic device with cryptographic function and the outside device. The key generating unit further optionally generates a secret key according to the hardware-intrinsic properties for securing data at rest in the cryptographic device.