IC Authentication via PUF Obfuscation State Machine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The semiconductor industry faces challenges in ensuring the authenticity and integrity of integrated circuits (ICs) due to counterfeiting and overbuilding, where unauthorized or counterfeit parts are introduced into the supply chain, eroding trust and potentially causing catastrophic damage.
Innovation Solution
An embedded and active obfuscation system that requires authentication by the Intellectual Property (IP) owner before a protected electronic device can function, using a Physically Unclonable Function (PUF) to generate a unique obfuscation code and authentication key, ensuring only authorized devices are operational, thereby preventing unauthorized reuse or deployment of counterfeit parts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional technologies are used in the supply chain, then manufacturing cost and ease of operation are maintained, but reliability and trustworthiness deteriorate due to counterfeiting and overbuilding
Solution Approach 1:
The patent applies preliminary action by embedding authentication credentials and obfuscation logic into the IC device during the manufacturing process itself. The authentication subsystem is pre-configured with unique identifiers and cryptographic keys before the device enters the supply chain, enabling immediate verification of authenticity without adding external complexity later.
Solution Approach 2:
The patent introduces an intermediary authentication subsystem that mediates between the IC device and the supply chain ecosystem. This subsystem includes credential verification mechanisms and obfuscation logic that act as a trusted intermediary, allowing parties in the supply chain to verify device authenticity without direct trust relationships between all participants.
2Reliability
If authentication systems are implemented to prevent counterfeiting, then reliability improves, but ease of operation and manufacturing complexity worsen
Solution Approach 1:
The patent merges the authentication subsystem with the core IC device functionality, integrating credential storage, verification logic, and obfuscation mechanisms directly into the device architecture. This consolidation eliminates separate authentication hardware or software layers, streamlining the manufacturing process while maintaining security functions.
Solution Approach 2:
The authentication subsystem is designed to be self-service, with the IC device automatically performing credential verification and applying obfuscation without requiring external authentication infrastructure during normal operation. The device independently manages its own authentication state, reducing manufacturing and operational complexity.
3Object-affected harmful factors
If obfuscation and authentication are required before device functionality, then harmful factors from counterfeit devices are reduced, but device complexity and operational requirements increase
Solution Approach 1:
The patent applies preliminary anti-action by implementing obfuscation logic that actively prevents counterfeit devices from functioning before they can cause harm. The authentication subsystem verifies device credentials and applies cryptographic obfuscation to critical functions, blocking unauthorized or spurious parts from operating in the supply chain before they can inflict damage.
Data Source
AI summary
A system and method for authenticating and enabling an electronic device in an electronic system are disclosed. A particular embodiment includes: an electronic system comprising: a protected device; a requesting device node, executing on a computing system, the requesting device node including: a device query data packet generator to generate a device query packet including data representing one or more identifiers of the protected device and a particular paired system; and an authentication key retriever to obtain an authentication key based on the device query data packet from an authentication provisioning node using an external data communication; and an obfuscation state machine of the particular paired system configured with a pre-defined quantity of state elements, a pre-defined quantity of the state elements being functional state elements, the obfuscation state machine being programmed with the authentication key to cause the obfuscation state machine to transition the protected device from an initial obfuscation state to a functional state.


