PUF Authentication via Adversarial Challenge Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Physically Unclonable Functions (PUFs) are vulnerable to modeling attacks using machine learning or neural networks, allowing sophisticated attackers to clone devices even with previously unused challenges, despite their design to prevent replay attacks.

Innovation Solution

Implementing stability-based adversarial challenge selection techniques that utilize unstable Challenge-Response Pairs (CRPs) during device authentication, characterizing PUF devices across voltage and temperature ranges to disrupt attacker models and increase complexity, without requiring additional PUF circuit changes or degrading response reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PUF CRPs are used only once to eliminate replay attacks, then replay attack resistance is improved, but sophisticated attackers can still monitor CRPs and use machine learning models to learn PUF behavior and clone devices

Engineering Contradiction:
Improvereplay attack resistanceVSAvoidmodeling attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system preemptively applies countermeasures by selecting challenges that are predicted to produce unstable responses based on environmental condition analysis. This preliminary action prevents attackers from obtaining reliable training data before the authentication occurs, countering modeling attacks in advance while maintaining replay attack resistance through one-time CRP usage

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system changes the stability parameter of challenge responses by selecting challenges whose response stability varies under different environmental conditions (temperature, voltage, frequency). This parameter change ensures that responses are unreliable for modeling purposes while remaining functional for authentication, resolving the contradiction between replay protection and modeling attack vulnerability

Inventive Principle:
Principle #35Parameter changes

2Reliability

If stable challenge responses are used for authentication, then response reliability is improved, but attackers can more easily train machine learning models on consistent responses

Engineering Contradiction:
Improveresponse reliabilityVSAvoidattack model training ease
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system makes the response stability dynamic by selecting challenges whose stability characteristics change based on environmental conditions. Challenges are chosen such that their responses are stable under current operating conditions for reliable authentication but would be unstable under varying conditions, making them unsuitable for model training. This dynamic approach maintains response reliability while increasing attack complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary analysis of environmental conditions (temperature, voltage, frequency) to predict which challenges will produce unstable responses. This preliminary action allows the selection of appropriate challenges before authentication occurs, ensuring both reliable authentication responses and difficult-to-model behavior for attackers

Inventive Principle:
Principle #10Preliminary action

3Reliability

If additional PUF circuit changes are implemented to improve security, then resistance to modeling attacks is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvemodeling attack resistanceVSAvoidPUF circuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system improves modeling attack resistance by changing operational parameters (selecting challenges based on predicted response stability under environmental conditions) rather than changing the physical PUF circuit structure. This approach maintains simplicity of the PUF device itself while achieving enhanced security through intelligent challenge selection, avoiding increased device complexity and manufacturing cost

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11768966B2Secure PUF-based device authentication using adversarial challenge selection
Publication Date: 2023.09.26 INTEL CORP
  • US11768966B2 patent drawing
  • US11768966B2 patent drawing
  • US11768966B2 patent drawing

AI summary

A method comprises generating, during an enrollment process conducted in a controlled environment, a dark bit mask comprising a plurality of state information values derived from a plurality of entropy sources at a plurality of operating conditions for an electronic device, and using at least a portion of the plurality of state information values to generate a set of challenge-response pairs for use in an authentication process for the electronic device.