IC Chip Auto-Identification Using PUF Responses Against Spoofing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing IoT networks are vulnerable to spoofing attacks, which compromise the security and integrity of information communication between electronic apparatuses, leading to potential malfunctions and disruptions in smart systems, as conventional cybersecurity measures are inadequate in detecting and preventing such attacks.
Innovation Solution
A network of electronic apparatuses employs IC chips with integrated cell arrays and decoders to generate unique responses to challenges, using specific random numbers, and generates pairs of secret and public keys for authentication, establishing a physical firewall that uses electronic signatures for secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional cybersecurity measures are used for IoT networks, then basic data protection is provided, but the networks remain vulnerable to spoofing attacks and man-in-the-middle attacks
Solution Approach 1:
The patent applies preliminary action by pre-provisioning each IC chip with a unique physical unclonable function (PUF) characteristic during manufacturing. This unique identifier is embedded before the chip is deployed, enabling automatic identification and authentication of electronic apparatuses before they can be spoofed or attacked, thus preventing security breaches in advance
Solution Approach 2:
The patent implements feedback mechanisms through challenge-response authentication protocols where the inspector sends challenges to inspected apparatuses, which respond using their unique PUF characteristics. The inspector verifies these responses against expected values, providing continuous feedback to detect and exclude spoofed devices from the network, thereby maintaining security reliability
2Ease of operation
If physical addresses are used to link electronic apparatuses to logical addresses, then information communication is enabled, but the physical addresses can be tampered with by hackers
Solution Approach 1:
The patent replaces the conventional mechanical/address-based linkage system with a cryptographic authentication system. Instead of relying on tamperable physical addresses, each electronic apparatus uses its unique PUF-based identifier to authenticate itself, substituting the vulnerable address linkage mechanism with a secure cryptographic verification process that prevents unauthorized tampering
Solution Approach 2:
The patent changes the fundamental parameter of identification from mutable physical addresses to immutable PUF characteristics. The PUF-based identifier is physically embedded in the chip's manufacturing process and cannot be changed or tampered with, providing a reliable and permanent link between the electronic apparatus and its logical address that resists hacker interference
3Reliability
If automatic identification and exclusion of spoofed devices is implemented, then network security is enhanced, but the system complexity increases due to authentication protocols and key management
Solution Approach 1:
The patent applies self-service by enabling each IC chip to autonomously generate cryptographic key pairs and perform authentication operations using its embedded PUF characteristics. The chip independently computes challenge responses and manages its own cryptographic credentials without requiring external assistance, thereby enhancing security while minimizing the complexity of centralized key management infrastructure
Solution Approach 2:
The patent reduces operational complexity by performing key generation and authentication setup in advance during chip manufacturing. The PUF characteristics and initial cryptographic parameters are pre-configured before deployment, eliminating the need for complex runtime key distribution and management systems, thus enhancing security with minimal added system complexity
Data Source
AI summary
An authentication (or identification) of an electronic apparatus is performed using a response to be generated from a specific random number, which is specific to an IC chip included in the electronic apparatus, and a challenge, which is input to the electronic apparatus. A physical firewall, which is composed of the authenticated electronic apparatuses, is configured. Furthermore, a pair of a secret and public keys are generated using the said response. The said public key or a code information generated using the said public key serves as a logical address of the said electronic apparatus. An electronic signature generated using the said secret key is used to perform data transmission between electronic apparatuses inside the physical firewall.


