PUF Array Authentication System for Secure Credential Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems are vulnerable to attacks when an attacker gains access to lookup tables or databases storing user authentication information, as they can decrypt or decode the information using computational methods, and hashing functions are susceptible to password guessing and brute force attacks.
Innovation Solution
The system employs an array of physical unclonable function (PUF) devices to generate challenge responses based on user credentials, which are stored instead of the credentials themselves, making it computationally difficult for attackers to guess passwords without access to both the data and the hardware containing the PUF, and uses multiple PUF arrays for redundancy and secure backdoor access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional lookup tables or databases store user authentication information (user identifiers and passwords), then authentication can be performed efficiently, but the system becomes vulnerable to attacks where attackers can decrypt or decode the information using computational methods
Solution Approach 1:
The patent replaces conventional cryptographic mechanisms (encryption and hashing) with a physical unclonable function (PUF) based authentication mechanism. Instead of storing passwords in encrypted or hashed form that can be computationally attacked, the system uses physical characteristics of PUF devices to generate authentication responses, making the system resistant to traditional cryptanalytic attacks
Solution Approach 2:
The patent changes the fundamental parameter of authentication from storing cryptographic transformations of passwords to storing challenge-response pairs generated by physical devices. The authentication security relies on the physical parameters of PUF devices rather than mathematical complexity, fundamentally changing how authentication data is stored and verified
2Reliability
If hashing functions are used to protect user information, then storage security is improved, but the system remains susceptible to password guessing and brute force attacks
Solution Approach 1:
The patent substitutes cryptographic hashing functions with physical unclonable function devices. The PUF-based challenge-response mechanism replaces the mathematical one-way function with a physical process that is inherently resistant to brute force attacks, as each PUF device produces unique responses based on its physical characteristics
Solution Approach 2:
The patent introduces PUF devices as an intermediary between the user credentials and the authentication verification process. The PUF device acts as a physical mediator that transforms challenge inputs into unique response outputs, adding a layer of physical security that cannot be replicated or guessed through computational methods
3Device complexity
If a single PUF array is used for authentication, then the system complexity is reduced, but the system lacks redundancy and resilience against failures
Solution Approach 1:
The patent divides the authentication system into multiple independent PUF arrays, each capable of performing authentication separately. This segmentation provides redundancy, as the failure of one PUF array does not compromise the entire authentication system, and allows for load distribution across multiple arrays
Data Source
AI summary
Systems and methods for improving security in computer-based authentication systems by using physical unclonable functions are presented. A computing device used to provide authentication includes multiple arrays of physical unclonable function devices. Rather than storing user passwords or message digests of passwords, the computing device generates a message digest based on a user's credentials. A challenge response generated by measuring physical parameters of set of physical unclonable function devices specified by the message digest. The computing device can provide authentication without storing information which could be used by an attacker to compromise user credentials. Redundancy and robustness to varying loads are provided by the use of multiple PUF arrays which may be used as backups or to provide load balancing. Backdoor access may be provided to trusted parties without exposing user credentials.


