Masking PUF Responses in FPGAs via Hash Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Physical unclonable functions (PUFs) used in field programmable gate arrays (FPGAs) for security can be compromised if their responses are directly exposed, allowing malicious systems to obtain and misuse the PUF values for generating cryptographic keys.

Innovation Solution

A masked PUF response is generated by applying a cryptographic hash function to the PUF response and a configuration file, ensuring that only the same configuration can produce the same masked response, thereby preventing exposure of the actual PUF response to malicious entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the PUF response is directly exposed to configurable logic blocks, then the PUF value is easily accessible for key generation, but the security is compromised allowing malicious systems to obtain and misuse the PUF values

Engineering Contradiction:
Improveaccessibility of PUF valueVSAvoidsecurity of PUF
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a masked PUF response as an intermediary between the PUF and the configurable logic blocks. This masked response (e.g., through hashing or encryption) allows authorized systems to generate keys while preventing malicious entities from obtaining the actual PUF value. The intermediary transforms the direct exposure problem into a controlled access mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the PUF response is masked using cryptographic functions, then the security is maintained preventing direct exposure, but the complexity of the system increases due to additional cryptographic operations

Engineering Contradiction:
Improvesecurity of PUFVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex security management mechanisms with cryptographic functions. Instead of implementing complex access control logic or physical security mechanisms, the system uses cryptographic hashing or encryption to mask the PUF response. This substitution reduces the need for complex control logic while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Stability of the object's composition

If the same masked PUF response is provided to different configuration files, then consistency is maintained, but security is weakened as the same key can be generated by different configurations

Engineering Contradiction:
Improveconsistency of masked responseVSAvoidsecurity of key generation
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The patent introduces asymmetry by incorporating the configuration file into the masking process. The masked PUF response becomes a function of both the PUF value and the configuration file (e.g., hash(PUF response + configuration file)). This ensures that each configuration file produces a unique masked response, preventing key reuse across different configurations while maintaining consistency for the same configuration.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS10177922B1Repeatable masking of sensitive data
Publication Date: 2019.01.08 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US10177922B1 patent drawing
  • US10177922B1 patent drawing
  • US10177922B1 patent drawing

AI summary

The various technologies presented herein relate to enabling a value generated based upon a physical unclonable function (PUF) response to be available as needed, while also preventing exposure of the PUF to a malicious entity. A masked PUF response can be generated based upon applying a function to a combination of the PUF response and a data file (e.g., a bitstream), and the masked PUF response is forwarded to a requesting entity, rather than the PUF response. Hence, the PUF is masked from any entity requiring access to the PUF. The PUF can be located in a FPGA, wherein the data file is a bitstream pertinent to one or more configurable logic blocks included in the FPGA. A first masked PUF response generated with a first data file can have a different value to a second masked PUF response generated with a second data file.