Expanded PUF Framework for Secure Blockchain Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for identity verification and payment authorization lack robustness and efficiency, particularly in ensuring the authenticity of transactions and user identities within blockchain networks, due to limitations in challenge-response pair management and access control.
Innovation Solution
The implementation of an expanded Physically Unclonable Function (PUF) framework, which includes an ePUF device that generates a large range of challenge-response pairs, integrated with blockchain-agnostic protocols for identity establishment and verification, and lightweight storage techniques, enhances identity protocols by leveraging blockchain for secure and efficient identity management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a weak PUF is used for identity verification, then the verification process is simple and fast, but the challenge-response space is limited making it vulnerable to enumeration attacks
Solution Approach 1:
The patent combines a weak PUF with a cryptographic hash function to create an expanded PUF system. The weak PUF provides fast verification while the hash function expands the challenge-response space, merging the advantages of both approaches to achieve both speed and security.
Solution Approach 2:
The system uses a composite approach by integrating the physical weak PUF device with a mathematical hash function. This composite structure allows the system to leverage the physical uniqueness of the PUF while adding cryptographic strength through the hash function to prevent enumeration attacks.
2Reliability
If a strong PUF is used for identity verification, then the challenge-response space is large providing security, but the device complexity and cost increase
Solution Approach 1:
The cryptographic hash function acts as an intermediary that transforms the limited output of a simple weak PUF into a expanded challenge-response space. This intermediary component provides the security benefits of a strong PUF without requiring the complex hardware architecture of actual strong PUF devices.
Solution Approach 2:
The patent replaces the complex mechanical/physical structure of strong PUFs with a simpler weak PUF combined with a mathematical hash function. This substitution achieves the same security effect through software/mathematics rather than complex hardware, reducing device complexity and cost.
3Adaptability or versatility
If response data is stored in a distributed peer-to-peer network, then the system achieves decentralization and censorship resistance, but the storage and retrieval efficiency decreases
Solution Approach 1:
The patent extracts only the essential response data needed for verification and stores it in a distributed network, while using cryptographic techniques to enable efficient retrieval. This extraction approach minimizes storage requirements while maintaining decentralization benefits.
4Reliability
If the PUF interface is restricted to trusted parties only, then the security against unauthorized access is improved, but the versatility and usability of the system decreases
Solution Approach 1:
The expanded challenge-response space created by combining the weak PUF with the hash function allows the system to serve multiple trusted parties simultaneously. Each party can have their own challenge-response pairs without compromising security, making the system universally applicable to multiple verification scenarios while maintaining restricted access security.
Data Source
AI summary
A computer-implemented method of authorising a payment by a target party to a verifying party. The method comprises, by the verifying party: performing a payment verification to verify a source of funds of the target party; and performing an identity verification to verify an identity of the target party. The identity verification comprises accessing response data stored in a data store in association with the identity of the target party, the data store being implemented in third party computer equipment of a trusted third party or on a peer-to-peer publication medium, wherein the response data comprises either a) a stored instance of a response to a challenge, or b) an attestation comprising a transformation of the response. The payment is authenticated on condition that the outputs of both the payment verification and identity verifications is true.


