PUF Arrays for Session Key Generation via Hashing Latency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Central organizations face challenges in securing networks due to the asymmetry between user identity verification and unverified server authenticity, leading to cyberattacks, especially when servers are mobile or exposed to insiders, and conventional password management systems are vulnerable to password guessing techniques despite using one-way cryptographic functions.
Innovation Solution
A system utilizing physical unclonable function (PUF) devices generates session keys by iteratively hashing passwords and using the difference in hashing cycles as a challenge to authenticate servers and clients, ensuring secure communication without storing the hashed passwords, and employing pseudo-homomorphic methods to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional password management systems use one-way cryptographic functions to store hashed passwords, then security is improved, but the systems remain vulnerable to password guessing techniques
Solution Approach 1:
The patent introduces PUF devices as an intermediary between the password storage system and the authentication process. Instead of directly storing or verifying passwords through traditional cryptographic methods, the system uses PUFs to generate unique challenge-response pairs that mediate the authentication process, making password guessing ineffective while maintaining security
Solution Approach 2:
The patent replaces the traditional mechanical/cryptographic password verification system with a physics-based PUF system. The PUF devices utilize physical characteristics (such as manufacturing variations in electronic circuits) to generate responses, substituting conventional cryptographic mechanisms with physical phenomena that are inherently resistant to guessing attacks
2Adaptability or versatility
If servers are made mobile or distributed to improve adaptability, then system flexibility is enhanced, but the risk of insider attacks and unauthorized access increases
Solution Approach 1:
The patent implements self-service authentication where PUF devices on both client and server sides independently generate and verify challenge-response pairs without relying on centralized password databases. This self-verified authentication mechanism allows mobile and distributed servers to authenticate themselves and clients without exposing centralized credentials that insiders could compromise
Solution Approach 2:
The system performs preliminary authentication actions through PUF challenge-response verification before any sensitive operations occur. By establishing mutual authentication in advance through physics-based verification, the system prevents insider attacks even when servers are mobile or distributed, as each server must prove its identity through unique PUF characteristics before accessing any resources
3Reliability
If users are required to frequently change passwords and use multi-factor authentication, then security is strengthened, but user convenience and ease of operation deteriorate
Solution Approach 1:
The PUF-based system enables self-service authentication where the physical characteristics of the user's device automatically generate authentication credentials. Instead of requiring users to manually change passwords or remember multiple factors, the system leverages the inherent physical properties of the device to continuously provide authentication, eliminating the burden of frequent password changes while maintaining strong security
Solution Approach 2:
The system creates a cryptographic copy of the PUF's physical characteristics through challenge-response pairs. This copy can be used for authentication without requiring the user to physically present the device or remember secrets, enabling convenient remote authentication while maintaining security equivalent to or stronger than multi-factor authentication
Data Source
AI summary
Systems and methods for the generation and use of session keys supporting secure communications between a client and server device are disclosed. The client hashes each of a series of passwords a first number of times. The hashed passwords are sent to a server. The server applies the hashed password to an array of PUF devices, and receives an initial response bitstream which is stored. The client later hashes each of the series of passwords a second number of times, which is less than the first number, and these are sent to the server. The server continues to hash the second message digest, generate PUF responses, and compare the result to the initially stored responses. For each password, the number of hashes necessary to achieve a match is a partial session key. Latency is improved by an array of separately addressable PUFs, each producing a partial session key.


